What is being deprecated?
IMDSv1 access will be blocked by default on new instance launches.
| Deadline | 2025-12-31 (-174 days from build date 2026-06-23) |
|---|---|
| Service | EC2 |
| Affected resources | instance|launch-template |
| Severity | high |
| Primary source | https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html |
Every fact on this page is taken from the cited AWS / upstream source above. EOLkits ships no claim without a primary source.
Breaking changes
The following changes take effect at or before the 2025-12-31 deadline. [source]
- IMDSv1 requests fail
- Must use IMDSv2 with session tokens
- SSM agent must be updated
Want it done for you before 2025-12-31?
Audit PDF
Hash-anchored deterministic report scoring every IMDSv1 Enforcement finding by severity × blast-radius, with a roll-forward roadmap and cost-of-not-fixing estimate. Delivered by email in 5 minutes. 30-day money-back guarantee.
Order Audit — $299Migration Pack
A real PR opened on your repo: EOLkits codemods + IaC patches + canary plan + rollback. Auto-refund if your CI fails within 7 days.
Get Migration Pack — $1,499 How it worksNot ready to migrate yet?
Get a reminder before the 2025-12-31 IMDSv1 Enforcement deadline — plus a heads-up on the next AWS EOL that hits your stack. No spam, one email per relevant deadline.
Free. Unsubscribe anytime.
Frequently asked questions
When is the IMDSv1 Enforcement deadline?
2025-12-31. IMDSv1 access will be blocked by default on new instance launches. [AWS source]
What happens if I don't migrate by 2025-12-31?
The breaking changes listed above take effect: IMDSv1 requests fail; Must use IMDSv2 with session tokens; SSM agent must be updated. [source]
Which AWS services does this affect?
EC2 — specifically instance|launch-template resources.