ECS service role permissions need review

Review the actual permissions of an ECS service role and limit them to the required load balancer integration.

Description

An ECS service's role allows calls to a load balancer on the service's behalf. Excessive permissions can increase the impact of role misuse. A role name does not establish administrative access; inspect its policies and trust relationship.

This role is separate from the task role that gives application containers AWS permissions and the task execution role used for image pulls and logging. An explicit service role is permitted only with a load balancer when the task does not use awsvpc network mode. Follow the applicable service-linked role requirements for other configurations.

Potential impact

  • If an overprivileged service role can be misused, resource changes may extend beyond the required load balancer operations. The scope depends on permission and trust policies and other controls.
  • Confusing service and task roles can lead to incorrect container permissions or disrupt required service behavior.

Remediation

  1. Inspect the actual service role's managed, inline and trust policies. Limit permissions to necessary actions and resources, and use the service-linked role appropriate for the network and load balancer configuration.
  2. Apply least privilege separately to task and task execution roles. Renaming a role does not reduce its permissions.
  3. The ecs_service update path in community.aws 11.1.0 does not change role. For an existing service, revise the policies or plan a supported transition. Verify the actual role and policies, load balancer registration and health checks afterward.

Examples

Prepare the cluster, task definition, target group and role separately. These examples target port 8080 of an app container in a task that does not use awsvpc; supply the actual target group ARN in target_group_arn. With desired_count: 0, no tasks are run.

Before

yaml
- name: ECS Service
  community.aws.ecs_service:
    state: present
    name: console-test-service
    cluster: new_cluster
    task_definition: "new_cluster-task:1"
    desired_count: 0
    load_balancers:
      - targetGroupArn: "{{ target_group_arn }}"
        containerName: app
        containerPort: 8080
    role: admin

The service specifies the admin role. Check its actual permissions and the trust policy allowing ECS to assume it.

After

yaml
- name: ECS Service
  community.aws.ecs_service:
    state: present
    name: console-test-service
    cluster: new_cluster
    task_definition: "new_cluster-task:1"
    desired_count: 0
    load_balancers:
      - targetGroupArn: "{{ target_group_arn }}"
        containerName: app
        containerPort: 8080

For a new service, the applicable service-linked role is used instead of an explicit role. Removing this field from an existing service does not itself change its role or permissions.

References