Description
An ECS task definition's network_mode determines how tasks connect to the network. Fargate requires awsvpc. EC2 tasks can use other modes depending on the operating system and workload; a mode such as none, which disables external networking, is not inherently insecure.
With awsvpc, each task receives a separate network interface, allowing security groups to be applied at task level. Security groups, subnets, and routing still need appropriate restrictions.
Potential impact
- A mode unsupported by the launch environment can prevent task registration or execution.
- Allowing more communication than necessary can broaden access to tasks or hosts beyond the intended scope.
Remediation
- Use
network_mode: awsvpcfor Fargate. For EC2, review host-sharing and port-mapping requirements and select a mode suited to the workload. - Configure appropriate subnets and least-privilege security groups for services using
awsvpc. - Apply the new task definition revision to the service and test ports, load balancer connections, and required outbound connectivity.
Examples
These excerpts compare network modes. Port mappings use port 80 to match the default NGINX image's listener. Configure service subnets, security groups, execution roles, and other prerequisites separately.
Before
- name: Task Definition 생성
community.aws.ecs_taskdefinition:
family: nginx
containers:
- name: nginx
essential: true
image: nginx
portMappings:
- containerPort: 80
hostPort: 80
launch_type: FARGATE
cpu: 512
memory: 1024
state: present
network_mode: default
On Linux, default is treated as bridge, which is incompatible with the Fargate configuration in this example.
After
- name: Task Definition 생성
community.aws.ecs_taskdefinition:
family: nginx
containers:
- name: nginx
essential: true
image: nginx
portMappings:
- containerPort: 80
hostPort: 80
launch_type: FARGATE
cpu: 512
memory: 1024
state: present
network_mode: awsvpc
This uses awsvpc, as required by Fargate. Registering a task definition alone does not make an existing service use the new revision; review the service deployment as well.