AWS Batch job definition using privileged mode

Check privileged mode in AWS Batch jobs defined with Ansible and remove unnecessary host permissions.

Description

Using privileged: true in an AWS Batch job defined with Ansible grants the container elevated host permissions and can weaken isolation. This is separate from running as the root user inside the container, so enable it only after confirming that the workload needs it. AWS Batch jobs on Fargate cannot use privileged mode.

Potential impact

  • If job code is compromised, the container's elevated host permissions can be misused.
  • Greater access to host devices and resources can extend the impact to other jobs on the same host.

Remediation

  • Set privileged to false or omit it, then test that the job still runs correctly.
  • If privileged mode appears necessary, identify the host access actually required and assess whether a more restricted supported execution method is available.
  • Review the container image, job role, and host device and volume access separately. Disabling privileged mode does not restrict every permission or mount.

Examples

The examples use an older module name. Check which module names and parameters your Ansible collection version supports, and replace the image and role ARN placeholders with actual values.

Before

yaml
- name: My Batch Job Definition
  community.aws.aws_batch_job_definition:
    job_definition_name: My Batch Job Definition
    state: present
    type: container
    parameters:
      Param1: Val1
      Param2: Val2
    privileged: true
    image: <Docker Image URL>
    vcpus: 1
    memory: 512
    command:
      - python
      - run_my_script.py
      - arg1
    job_role_arn: <Job Role ARN>
    attempts: 3
  register: job_definition_create_result

After

yaml
- name: My Batch Job Definition
  community.aws.aws_batch_job_definition:
    job_definition_name: My Batch Job Definition without privilege
    state: present
    type: container
    parameters:
      Param1: Val1
      Param2: Val2
    privileged: false
    image: <Docker Image URL>
    vcpus: 1
    memory: 512
    command:
      - python
      - run_my_script.py
      - arg1
    job_role_arn: <Job Role ARN>
    attempts: 3
  register: job_definition_create_result

Explanation:

  • Before: privileged: true grants the container elevated host permissions.
  • After: privileged: false disables that setting. Test separately that any required device access and job functionality still work.

References