1 // Package ec2metadata provides the client for making API calls to the
2 // EC2 Metadata service.
4 // This package's client can be disabled completely by setting the environment
5 // variable "AWS_EC2_METADATA_DISABLED=true". This environment variable set to
6 // true instructs the SDK to disable the EC2 Metadata client. The client cannot
7 // be used while the environment variable is set to true, (case insensitive).
19 "github.com/aws/aws-sdk-go/aws"
20 "github.com/aws/aws-sdk-go/aws/awserr"
21 "github.com/aws/aws-sdk-go/aws/client"
22 "github.com/aws/aws-sdk-go/aws/client/metadata"
23 "github.com/aws/aws-sdk-go/aws/corehandlers"
24 "github.com/aws/aws-sdk-go/aws/request"
27 // ServiceName is the name of the service.
28 const ServiceName = "ec2metadata"
29 const disableServiceEnvVar = "AWS_EC2_METADATA_DISABLED"
31 // A EC2Metadata is an EC2 Metadata service Client.
32 type EC2Metadata struct {
36 // New creates a new instance of the EC2Metadata client with a session.
37 // This client is safe to use across multiple goroutines.
41 // // Create a EC2Metadata client from just a session.
42 // svc := ec2metadata.New(mySession)
44 // // Create a EC2Metadata client with additional configuration
45 // svc := ec2metadata.New(mySession, aws.NewConfig().WithLogLevel(aws.LogDebugHTTPBody))
46 func New(p client.ConfigProvider, cfgs ...*aws.Config) *EC2Metadata {
47 c := p.ClientConfig(ServiceName, cfgs...)
48 return NewClient(*c.Config, c.Handlers, c.Endpoint, c.SigningRegion)
51 // NewClient returns a new EC2Metadata client. Should be used to create
52 // a client when not using a session. Generally using just New with a session
55 // If an unmodified HTTP client is provided from the stdlib default, or no client
56 // the EC2RoleProvider's EC2Metadata HTTP client's timeout will be shortened.
57 // To disable this set Config.EC2MetadataDisableTimeoutOverride to false. Enabled by default.
58 func NewClient(cfg aws.Config, handlers request.Handlers, endpoint, signingRegion string, opts ...func(*client.Client)) *EC2Metadata {
59 if !aws.BoolValue(cfg.EC2MetadataDisableTimeoutOverride) && httpClientZero(cfg.HTTPClient) {
60 // If the http client is unmodified and this feature is not disabled
61 // set custom timeouts for EC2Metadata requests.
62 cfg.HTTPClient = &http.Client{
63 // use a shorter timeout than default because the metadata
64 // service is local if it is running, and to fail faster
65 // if not running on an ec2 instance.
66 Timeout: 5 * time.Second,
74 ServiceName: ServiceName,
75 ServiceID: ServiceName,
83 svc.Handlers.Unmarshal.PushBack(unmarshalHandler)
84 svc.Handlers.UnmarshalError.PushBack(unmarshalError)
85 svc.Handlers.Validate.Clear()
86 svc.Handlers.Validate.PushBack(validateEndpointHandler)
88 // Disable the EC2 Metadata service if the environment variable is set.
89 // This shortcirctes the service's functionality to always fail to send
91 if strings.ToLower(os.Getenv(disableServiceEnvVar)) == "true" {
92 svc.Handlers.Send.SwapNamed(request.NamedHandler{
93 Name: corehandlers.SendHandler.Name,
94 Fn: func(r *request.Request) {
95 r.HTTPResponse = &http.Response{
96 Header: http.Header{},
99 request.CanceledErrorCode,
100 "EC2 IMDS access disabled via "+disableServiceEnvVar+" env var",
106 // Add additional options to the service config
107 for _, option := range opts {
114 func httpClientZero(c *http.Client) bool {
115 return c == nil || (c.Transport == nil && c.CheckRedirect == nil && c.Jar == nil && c.Timeout == 0)
118 type metadataOutput struct {
122 func unmarshalHandler(r *request.Request) {
123 defer r.HTTPResponse.Body.Close()
125 if _, err := io.Copy(b, r.HTTPResponse.Body); err != nil {
126 r.Error = awserr.New("SerializationError", "unable to unmarshal EC2 metadata respose", err)
130 if data, ok := r.Data.(*metadataOutput); ok {
131 data.Content = b.String()
135 func unmarshalError(r *request.Request) {
136 defer r.HTTPResponse.Body.Close()
138 if _, err := io.Copy(b, r.HTTPResponse.Body); err != nil {
139 r.Error = awserr.New("SerializationError", "unable to unmarshal EC2 metadata error respose", err)
143 // Response body format is not consistent between metadata endpoints.
144 // Grab the error message as a string and include that as the source error
145 r.Error = awserr.New("EC2MetadataError", "failed to make EC2Metadata request", errors.New(b.String()))
148 func validateEndpointHandler(r *request.Request) {
149 if r.ClientInfo.Endpoint == "" {
150 r.Error = aws.ErrMissingEndpoint