Description
Enabling ContainerProperties.Privileged in a CloudFormation AWS::Batch::JobDefinition grants the container elevated host permissions, which can increase the impact of a compromised job. Setting ReadonlyRootFilesystem: true does not disable privileged mode or remove separately configured writable host mounts. Jobs on Fargate cannot use privileged mode.
Potential impact
- A compromised job can misuse elevated access to host devices or resources.
- A problem in job code can affect other jobs running on the same host.
Remediation
- Set
ContainerProperties.Privilegedtofalseor omit it. - Review host mounts, device access, and the job role separately, allowing only what the job requires.
- Test the revised job definition, then check that submitted jobs use the new revision.
Examples
Replace the JobRoleArn: String placeholder with a valid job role ARN, and review the image and host paths for your environment. Both examples use a writable host mount, so confirm that it is needed and limit its access appropriately.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "BatchJobDefinition"
Resources:
JobDefinition:
Type: AWS::Batch::JobDefinition
Properties:
Type: container
JobDefinitionName: nvidia-smi
ContainerProperties:
MountPoints:
- ReadOnly: false
SourceVolume: nvidia
ContainerPath: /usr/local/nvidia
Volumes:
- Host:
SourcePath: /var/lib/nvidia-docker/volumes/nvidia_driver/latest
Name: nvidia
Command:
- nvidia-smi
Memory: 2000
Privileged: true
JobRoleArn: String
ReadonlyRootFilesystem: true
Vcpus: 2
Image: nvidia/cuda
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "BatchJobDefinition"
Resources:
JobDefinition:
Type: AWS::Batch::JobDefinition
Properties:
Type: container
JobDefinitionName: nvidia-smi
ContainerProperties:
MountPoints:
- ReadOnly: false
SourceVolume: nvidia
ContainerPath: /usr/local/nvidia
Volumes:
- Host:
SourcePath: /var/lib/nvidia-docker/volumes/nvidia_driver/latest
Name: nvidia
Command:
- nvidia-smi
Memory: 2000
Privileged: false
JobRoleArn: String
ReadonlyRootFilesystem: true
Vcpus: 2
Image: nvidia/cuda
Explanation:
- Before:
Privileged: truegrants elevated host permissions. A read-only root filesystem does not restrict those permissions. - After:
Privileged: falsedisables privileged mode. Review the remaining host volume and its write access separately.