Review the ECS task definition network mode

Choose an ECS network mode supported by the launch environment and allow only the communication each task needs.

Description

An ECS task definition's network_mode determines how tasks connect to the network. Fargate requires awsvpc. EC2 tasks can use other modes depending on the operating system and workload; a mode such as none, which disables external networking, is not inherently insecure.

With awsvpc, each task receives a separate network interface, allowing security groups to be applied at task level. Security groups, subnets, and routing still need appropriate restrictions.

Potential impact

  • A mode unsupported by the launch environment can prevent task registration or execution.
  • Allowing more communication than necessary can broaden access to tasks or hosts beyond the intended scope.

Remediation

  • Use network_mode: awsvpc for Fargate. For EC2, review host-sharing and port-mapping requirements and select a mode suited to the workload.
  • Configure appropriate subnets and least-privilege security groups for services using awsvpc.
  • Apply the new task definition revision to the service and test ports, load balancer connections, and required outbound connectivity.

Examples

These excerpts compare network modes. Port mappings use port 80 to match the default NGINX image's listener. Configure service subnets, security groups, execution roles, and other prerequisites separately.

Before

yaml
- name: Task Definition 생성
  community.aws.ecs_taskdefinition:
    family: nginx
    containers:
      - name: nginx
        essential: true
        image: nginx
        portMappings:
          - containerPort: 80
            hostPort: 80
    launch_type: FARGATE
    cpu: 512
    memory: 1024
    state: present
    network_mode: default

On Linux, default is treated as bridge, which is incompatible with the Fargate configuration in this example.

After

yaml
- name: Task Definition 생성
  community.aws.ecs_taskdefinition:
    family: nginx
    containers:
      - name: nginx
        essential: true
        image: nginx
        portMappings:
          - containerPort: 80
            hostPort: 80
    launch_type: FARGATE
    cpu: 512
    memory: 1024
    state: present
    network_mode: awsvpc

This uses awsvpc, as required by Fargate. Registering a task definition alone does not make an existing service use the new revision; review the service deployment as well.

References