You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置NGINX处理latest/meta-data以防范云元数据暴露风险

解决Cloud Metadata Potentially Exposed告警的NGINX配置方案

针对你遇到的问题——ZAP扫描出「Cloud Metadata Potentially Exposed」告警,且请求https://example.com/latest/meta-data时出现异常重定向而非404,可通过以下NGINX配置修复:

核心配置步骤

  • 拦截元数据IP的Host头请求:在你的server块中添加规则,直接拒绝Host头为169.254.169.254的请求:
if ($host = '169.254.169.254') {
    return 403;
}
  • 直接拦截元数据路径请求:添加location规则,强制所有访问/latest/meta-data路径的请求返回404:
location ~* ^/latest/meta-data {
    return 404;
}
  • 修复异常重定向问题:如果你的NGINX有路径补全类的重定向规则(比如移除末尾斜杠的rewrite),需要确保这类规则不会作用于元数据路径。例如原规则是:
rewrite ^/(.*)/$ /$1 permanent;

修改为:

rewrite ^/(?!latest/meta-data)(.*)/$ /$1 permanent;

或者将拦截元数据路径的location规则放在所有重定向规则之前,NGINX会优先匹配更具体的location配置。

验证方法

配置生效后,用以下curl命令测试:

# 测试Host头为元数据IP的请求
curl -H "Host: 169.254.169.254" https://example.com/latest/meta-data
# 直接访问元数据路径
curl https://example.com/latest/meta-data

前者应返回403,后者应返回404,且无重定向行为。

内容的提问来源于stack exchange,提问作者Tran Van Hieu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 14:23:16