Description
An ECS task's EFSVolumeConfiguration.TransitEncryption protects data in transit between the ECS host and the EFS server. DISABLED does not use transport encryption for that connection. It does not enable or disable encryption at rest on the EFS file system.
Potential impact
- Without encryption in transit, file contents lack this additional protection against an attacker with access to the communication path.
- A configuration that conflicts with a policy requiring encrypted transport can prevent volume mounting or application startup.
Remediation
- Check the task definition and EFS volume actually used by the service and set
TransitEncryption: ENABLED. EFS IAM authorization and access points require encryption in transit. - Prepare a supported ECS environment, EFS mount targets, network paths and permissions. Update the service to a new task-definition revision, then verify mounts and application reads and writes.
- Check file-system encryption at rest and access policies separately. Transport encryption does not restrict excessive file access by otherwise authorized users.
Examples
These are alternative EC2-based task definitions mounting an existing EFS file system. Supply EfsFileSystemId, mount targets, ECS capacity and security groups for the environment. A service that actually runs the task is not included.
Transport encryption disabled
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
AppName:
Type: String
Default: simple-app
EfsFileSystemId:
Type: String
Resources:
cluster:
Type: AWS::ECS::Cluster
taskdefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: !Ref AppName
MountPoints:
- SourceVolume: my-vol
ContainerPath: /var/www/my-vol
Image: amazon/amazon-ecs-sample
Memory: 128
Volumes:
- Name: my-vol
EFSVolumeConfiguration:
FilesystemId: !Ref EfsFileSystemId
TransitEncryption: DISABLED
Encryption in transit between ECS and EFS is disabled. This example does not determine the file system's encryption at rest.
Transport encryption enabled
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
AppName:
Type: String
Default: simple-app
EfsFileSystemId:
Type: String
Resources:
cluster:
Type: AWS::ECS::Cluster
taskdefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: !Ref AppName
MountPoints:
- SourceVolume: my-vol
ContainerPath: /var/www/my-vol
Image: amazon/amazon-ecs-sample
Memory: 128
Volumes:
- Name: my-vol
EFSVolumeConfiguration:
FilesystemId: !Ref EfsFileSystemId
TransitEncryption: ENABLED
The EFS connection uses encryption in transit. Deploy the new revision and verify required file access.