Review ECS Container Insights settings

Check Container Insights and actual metric collection for the ECS cluster.

Description

Container Insights collects and analyzes more detailed CloudWatch information about ECS cluster and service CPU, memory and other operational metrics. Insufficient observations can delay incident response and performance analysis.

If the cluster setting is omitted, an account default can apply. Verify the effective state and distinguish Container Insights from basic ECS metrics or other monitoring that may still be available.

Potential impact

  • Resource use and performance problems can be harder to identify promptly.
  • Diagnosis of task failures and recovery can be delayed.

Remediation

Specify Name: containerInsights and Value: enabled in ClusterSettings. Consider supported enhanced mode if more detail is needed. Review costs and necessary permissions, then verify CloudWatch dashboards, metrics and alarms in operation.

Examples

Before

yaml
Resources:
  ECSCluster:
    Type: AWS::ECS::Cluster
    Properties:
      ClusterName: MyCluster

There is no cluster-specific setting. Check the account default and actual cluster state.

After

yaml
Resources:
  ECSCluster:
    Type: AWS::ECS::Cluster
    Properties:
      ClusterName: MyCluster
      ClusterSettings:
        - Name: containerInsights
          Value: enabled

This explicitly enables Container Insights. Verify actual metric collection and the alarms needed for operational response.

References