Glance Web-Download & URI Import Hardening Prompt
Helps you safely enable and lock down Glance's web-download / URI image import method so users can pull images from URLs without exposing internal networks to SSRF.
- Target user
- Image and platform security operators
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior Glance operator who hardens the interoperable image import (`web-download`) workflow against abuse. I will provide: - Glance version and current `glance-api.conf` import settings - Which import methods are enabled (`enabled_import_methods`) - Network topology of the glance-api nodes (what internal endpoints they can reach) - Any failed imports or security review findings Your job: 1. **Threat model** — explain the SSRF and resource-exhaustion risks of `web-download` pulling arbitrary URIs from glance-api hosts. 2. **Allow/deny lists** — configure `[import_filtering_opts]` allowed/disallowed schemes, hosts, ports, and CIDRs to block link-local and metadata endpoints. 3. **Quotas & limits** — set image size limits, per-user image count, and staging-store sizing to bound abuse. 4. **Method scoping** — recommend which import methods to enable per audience and how to gate via policy. 5. **Commands** — `openstack image create` + `image import --method web-download --uri ...` examples and how to inspect import task status. 6. **Verification** — tests proving disallowed targets (169.254.169.254, internal CIDRs) are rejected. 7. **Back-out** — disabling web-download and clearing stuck staging data safely. Output as: (a) a config diff for glance-api.conf, (b) test cases with expected pass/fail, (c) a rollback checklist. Validate filtering in staging by attempting to import from a blocked internal address before enabling for tenants.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Glance Image Upload & Store Failure Triage Prompt
Diagnose Glance image problems — uploads stuck in saving/queued, images that won't boot due to bad properties or format, store backend errors (Ceph/Swift/file), and signature/conversion failures — before re-uploading or deleting image data.
-
Glance Image Stuck in saving or killed Status Recovery Prompt
Recover Glance images wedged in saving, importing, queued, or killed status after a failed upload or import, reconciling DB status with backend store data.
-
Glance Tenant Image Sharing & Quota Design Prompt
Design Glance image visibility, member-based sharing, and per-project quotas so teams share golden images safely without exposing private images or blowing past store capacity.
-
Glance Multi-Store & Image Cache Design Prompt
Architect Glance multi-store backends and the image cache — Ceph RBD vs file vs Swift stores, store priorities, copy-image, and per-compute caching — so instance boots are fast and image storage is placed cost-effectively.
More OpenStack prompts & error guides
Browse every OpenStack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.