# Block Metadata Service

**URL:** <https://forums.suse.com/t/block-metadata-service/4017>\
**Category:** Rancher 1.x\
**Created:** [September 15, 2016, 8:42am UTC](https://forums.suse.com/t/block-metadata-service/4017 "2016-09-15T08:42:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![localhost](https://avatars.discourse-cdn.com/v4/letter/l/53a042/32.png) [@localhost](https://forums.suse.com/u/localhost)\
**Post date:** [September 15, 2016, 8:42am UTC](https://forums.suse.com/t/block-metadata-service/4017/1 "2016-09-15T08:42:11Z")

</div>

This is a feature request.

**Please add a way to block access to `rancher-metadata` from a container**. Perhaps with a `label` in the `docker-compose.yml`?

Reasoning:

Disallowing information of the host from being available to untrusted users accessing the container. Per-environment isolation cannot help in this case, since that’s made for isolating users from each other.

Use case:

I am allowing untrusted users to access containers, while routing all their Internet traffic via proxy. Having access to rancher-metadata effectively allows the user to get the host’s real IP. That can expose the host to attacks like DDOS etc.

If rancher-metadata can be made unavailable to (some) containers, the “information leak” problem gets solved easily. As it is, I can’t think of a way to resolve it.

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [September 20, 2016, 3:14am UTC](https://forums.suse.com/t/block-metadata-service/4017/2 "2016-09-20T03:14:33Z")

</div>

Can you file a Github issue for this feature request?
