Description
Using privileged: true in an AWS Batch job defined with Ansible grants the container elevated host permissions and can weaken isolation. This is separate from running as the root user inside the container, so enable it only after confirming that the workload needs it. AWS Batch jobs on Fargate cannot use privileged mode.
Potential impact
- If job code is compromised, the container's elevated host permissions can be misused.
- Greater access to host devices and resources can extend the impact to other jobs on the same host.
Remediation
- Set
privilegedtofalseor omit it, then test that the job still runs correctly. - If privileged mode appears necessary, identify the host access actually required and assess whether a more restricted supported execution method is available.
- Review the container image, job role, and host device and volume access separately. Disabling privileged mode does not restrict every permission or mount.
Examples
The examples use an older module name. Check which module names and parameters your Ansible collection version supports, and replace the image and role ARN placeholders with actual values.
Before
yaml
- name: My Batch Job Definition
community.aws.aws_batch_job_definition:
job_definition_name: My Batch Job Definition
state: present
type: container
parameters:
Param1: Val1
Param2: Val2
privileged: true
image: <Docker Image URL>
vcpus: 1
memory: 512
command:
- python
- run_my_script.py
- arg1
job_role_arn: <Job Role ARN>
attempts: 3
register: job_definition_create_result
After
yaml
- name: My Batch Job Definition
community.aws.aws_batch_job_definition:
job_definition_name: My Batch Job Definition without privilege
state: present
type: container
parameters:
Param1: Val1
Param2: Val2
privileged: false
image: <Docker Image URL>
vcpus: 1
memory: 512
command:
- python
- run_my_script.py
- arg1
job_role_arn: <Job Role ARN>
attempts: 3
register: job_definition_create_result
Explanation:
- Before:
privileged: truegrants the container elevated host permissions. - After:
privileged: falsedisables that setting. Test separately that any required device access and job functionality still work.