Skip to content

Conversation

tomcatlingcma
Copy link

@tomcatlingcma tomcatlingcma commented Apr 9, 2019

Adding the firewall VM as a router in this way destroys some local routes which need to exist for IAM Instance Profiles to work correctly. This change restores static routes to the relevant addresses.

The current setup also grants any instance within the VPC access to IAM credentials associated with the firewall instance, since the firewall handles these requests and returns its own metadata in response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant