Compute
AMI and node OS
15 / 69

The node OS is your attack surface: pick a minimal image and lock down instance metadata.

ec2 icon

Amazon Linux 2023

general purpose
  • EKS-optimized AMI, SSH or SSM access, package manager.
  • Easy to debug and to customise with userdata.
  • You patch by rolling nodes onto new AMI versions.
linux logo

Bottlerocket

minimal, immutable
  • Container-only OS: no shell or package manager by default, read-only root.
  • API-driven, atomic updates; smaller attack surface.
  • Debug through a control or admin container.
launch template: IMDSv2 required
{
  "MetadataOptions": {
    "HttpTokens": "required",        // IMDSv2 only
    "HttpPutResponseHopLimit": 1   // pods cannot reach it
  },
  "BlockDeviceMappings": [{"DeviceName": "/dev/xvda",
     "Ebs": {"VolumeSize": 100, "VolumeType": "gp3"}}]
}

Why IMDSv2 and hop limit

Instance metadata can hand out the node role's credentials. IMDSv2 needs a session token, and a hop limit of 1 stops Pods reaching it, closing an SSRF path to AWS credentials.

Custom AMIs

Needed for compliance-hardened images or pre-baked agents. Then you own the AMI patching pipeline.