Description
For a Fargate ECS service, assign_public_ip: true can assign a public IPv4 address to each task's network interface. An Internet gateway route, security groups, and other controls may then allow direct connections to the task. Avoid unnecessary public paths for applications that do not need direct exposure.
A public IP alone does not grant service access or authentication. Internal tasks generally belong in private subnets, with controlled entry points such as load balancers when a public service is required.
Potential impact
- If network and service settings permit it, tasks may be exposed to external scanning and connection attempts.
- A direct path that avoids load balancer controls may bypass intended access restrictions.
Remediation
- Set
assign_public_iptofalsefor tasks that do not need direct public access, and use appropriate private subnets and security groups. - First provide the NAT connectivity or supported private endpoints needed to pull images, send logs, and call external services.
- Restrict traffic between load balancers and tasks, and review actual paths, including IPv6. Test functionality and connectivity after deploying new tasks.
Examples
These excerpts require an actual cluster, an awsvpc task definition, subnets, and security groups. The two examples use different service names.
Before
- name: ECS 서비스 생성
community.aws.ecs_service:
state: present
name: example-public-ip-service
cluster: my-ecs-cluster
task_definition: my-task-def:1
desired_count: 2
launch_type: FARGATE
network_configuration:
subnets:
- subnet-aaaa1111
- subnet-bbbb2222
security_groups:
- sg-cccc3333
assign_public_ip: true
This requests public IP assignment for tasks. Actual external access depends on routing, security groups, and application settings.
After
- name: ECS 서비스 생성
community.aws.ecs_service:
state: present
name: example-private-service
cluster: my-ecs-cluster
task_definition: my-task-def:1
desired_count: 2
launch_type: FARGATE
network_configuration:
subnets:
- subnet-aaaa1111
- subnet-bbbb2222
security_groups:
- sg-cccc3333
assign_public_ip: false
This defines a service with public IPv4 assignment disabled. It does not automatically remove the public paths of an existing service; modify or retire that service separately. Disabling address assignment alone does not isolate every network path.