Hi Dan, Thank you for the update and the detailed analysis. I'm not as familiar with some of the cloud-init use cases so good to know what some of the constraints are. Yep, restricting read access to cloud-init-output.log or redacting the messages when sent to the log both sound like workable strategies to me, although as you noted both have some caveats to work around.  Thanks and have a great day, Carl On Tuesday, March 9, 2021, 2:30:42 PM PST, Dan Watkins