[1] https://www.cyberbit.com/uncategorized/aws-imds-v2-secures-s...
[1] https://www.cyberbit.com/uncategorized/aws-imds-v2-secures-s...
Over years, they moved from alerting to changing the default and will later remove IMDSv1 for new instances. Even then, they will not remove it for the previous generations and those may stay for years, the current oldest is M4 which I think is from 2015.
now they are changing the default modes for instances launched from aws console using quick start process. and sometime in 2024 they will give an option to customers to control the default value for all run instances API calls from an account
for example if you run below curl request on ec2 instances launched from aws console before nov 6th then you will get a response
```sh
curl http://169.254.169.254/latest/meta-data/profile
```
but if you run the same command on ec2 instances launched from aws console after nov 6th, then you will get an error that auth token is missing
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance... has a good example.
Prior to this change, IMDSv2 could be enforced on an account, machine image, and launch API call level.
If you're interested in this topic, you might enjoy reading https://steve-yegge.medium.com/dear-google-cloud-your-deprec...