Network Clients with Instance Metadata
Focus
Focus
Next‑Gen Trust Security

Network Clients with Instance Metadata

Table of Contents

Network Clients with Instance Metadata

When you select Allow network clients authenticated with Instance Metadata in the client access settings for a configuration, cloud compute instances authenticate with Distributed Issuer using signed identity documents from their cloud provider.

To Configure a Network Client with Instance Metadata

  1. Under Policies, select the Allowed Policies that clients can use. This applies to local clients, instance metadata clients, and custom JWT clients. It does not apply to registered JWT clients.
  2. Under Instance Metadata Authentication, select one or more cloud providers and enter the required information.
    Cloud ProviderFieldDescription
    Amazon Web ServicesAccount IDsOne or more AWS account IDs.
    Amazon Web ServicesRegionsOptional. If omitted, all regions are allowed.
    Microsoft AzureSubscription IDsOne or more Azure subscription IDs.
    Google CloudProject IdentifiersOne or more project identifiers. Accepts both project numbers and project IDs.
    Google CloudRegionsOptional. If omitted, all regions are allowed.
    If instance metadata is enabled for any cloud provider, the Distributed Issuer config.yaml must include the identityDocument section with the server port and DNS name or IP address.
  3. Click Create to save the configuration. See What's Next? for next steps.