ECS EFS transport encryption needs review

Verify encryption in transit between ECS tasks and EFS. This setting is separate from encryption of data stored in the EFS file system.

Description

An ECS task's EFSVolumeConfiguration.TransitEncryption protects data in transit between the ECS host and the EFS server. DISABLED does not use transport encryption for that connection. It does not enable or disable encryption at rest on the EFS file system.

Potential impact

  • Without encryption in transit, file contents lack this additional protection against an attacker with access to the communication path.
  • A configuration that conflicts with a policy requiring encrypted transport can prevent volume mounting or application startup.

Remediation

  • Check the task definition and EFS volume actually used by the service and set TransitEncryption: ENABLED. EFS IAM authorization and access points require encryption in transit.
  • Prepare a supported ECS environment, EFS mount targets, network paths and permissions. Update the service to a new task-definition revision, then verify mounts and application reads and writes.
  • Check file-system encryption at rest and access policies separately. Transport encryption does not restrict excessive file access by otherwise authorized users.

Examples

These are alternative EC2-based task definitions mounting an existing EFS file system. Supply EfsFileSystemId, mount targets, ECS capacity and security groups for the environment. A service that actually runs the task is not included.

Transport encryption disabled

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  AppName:
    Type: String
    Default: simple-app
  EfsFileSystemId:
    Type: String
Resources:
  cluster:
    Type: AWS::ECS::Cluster
  taskdefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: !Ref AppName
          MountPoints:
            - SourceVolume: my-vol
              ContainerPath: /var/www/my-vol
          Image: amazon/amazon-ecs-sample
          Memory: 128
      Volumes:
        - Name: my-vol
          EFSVolumeConfiguration:
            FilesystemId: !Ref EfsFileSystemId
            TransitEncryption: DISABLED

Encryption in transit between ECS and EFS is disabled. This example does not determine the file system's encryption at rest.

Transport encryption enabled

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  AppName:
    Type: String
    Default: simple-app
  EfsFileSystemId:
    Type: String
Resources:
  cluster:
    Type: AWS::ECS::Cluster
  taskdefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: !Ref AppName
          MountPoints:
            - SourceVolume: my-vol
              ContainerPath: /var/www/my-vol
          Image: amazon/amazon-ecs-sample
          Memory: 128
      Volumes:
        - Name: my-vol
          EFSVolumeConfiguration:
            FilesystemId: !Ref EfsFileSystemId
            TransitEncryption: ENABLED

The EFS connection uses encryption in transit. Deploy the new revision and verify required file access.

References