# Limit metadata service

**URL:** <https://forums.suse.com/t/limit-metadata-service/3087>\
**Category:** Rancher 1.x\
**Created:** [June 10, 2016, 2:42pm UTC](https://forums.suse.com/t/limit-metadata-service/3087 "2016-06-10T14:42:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmls](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jmls/32/1419_2.png) [@jmls](https://forums.suse.com/u/jmls)\
**Post date:** [June 10, 2016, 2:42pm UTC](https://forums.suse.com/t/limit-metadata-service/3087/1 "2016-06-10T14:42:43Z")

</div>

been playing with the meta dataservice within a container, and it strikes me as very odd (and insecure) that a container can get all the information it needs about all other services and containers

surely a container should only see information about itself and it’s service ?

Is there any way of limiting the metadata service to only returning information about it’s service / stack , or turning it off altogether ?

Any user with shell access (or even curl access) can get all the information about the entire rancher deployment at the moment

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 10, 2016, 3:31pm UTC](https://forums.suse.com/t/limit-metadata-service/3087/2 "2016-06-10T15:31:57Z")

</div>

That would break many use-cases and existing catalog templates. The scope for user’s access control and metadata is an environment.

What specifically do you think is in metadata that should be secret, and can’t be easily obtained from e.g. port-scanning the overlay network subnet (10.42/16)?

---

<div class="post-metadata">

**Author:** ![jmls](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jmls/32/1419_2.png) [@jmls](https://forums.suse.com/u/jmls)\
**Post date:** [June 10, 2016, 3:53pm UTC](https://forums.suse.com/t/limit-metadata-service/3087/3 "2016-06-10T15:53:05Z")

</div>

Hi Vincent, I would have thought that adding an option to disable metadata would not break any existing use-case (default is current behaviour, “disabled” is turned off entirely “service” and “container” only data valid for that service/container)

apart from that, any metadata, labels or names from every other service are easily obtainable - for example I’ve seen use-cases where people pass in credentials as labels - for example, the labels

**_labels:_**  
**\_ io.rancher.container.create\_agent: true\_**  
**\_ io.rancher.container.agent.role: environment\_**

generate variables CATTLE\_URL, CATTLE\_ACCESS\_KEY, and CATTLE\_SECRET\_KEY

if these can be grabbed by another container by simply querying the metadata of all containers I would imagine this to be a potential security threat

Quite apart from that, I don’t want a developer to know about the containers, services and names of every other user / developer on the system

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 10, 2016, 4:42pm UTC](https://forums.suse.com/t/limit-metadata-service/3087/4 "2016-06-10T16:42:05Z")

</div>

Environment variables are not included in metadata. Credentials are often provided with environment variables, yes, and those labels _request the creation of_ a set of them to be provided as environment variables. Those credentials let you do nothing more than you already could already do directly if you have the ability to create a container (with those labels set) in the first place.

Access control is at the environment level. If you want users isolated from each other they need separate environments, which will have separate sets of metadata.

---

<div class="post-metadata">

**Author:** ![jmls](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jmls/32/1419_2.png) [@jmls](https://forums.suse.com/u/jmls)\
**Post date:** [June 10, 2016, 5:19pm UTC](https://forums.suse.com/t/limit-metadata-service/3087/5 "2016-06-10T17:19:49Z")

</div>

not exposing the env vars is a good thing 😉

I still feel, though, (and feel free to flame) that it would be a good thing to be able to restrict the meta-data service to _self_ at the very least …

it’s like when someone sends a group email, and puts _everyones_ email in the to field, rather than bcc’ing them. Whilst not actually a disaster, it feels … wrong …
