Description
Excessive IAM permissions on an ECS service role may allow operations beyond the required load-balancer integration. Inspect its policies and trust relationship rather than inferring administrator access from its name. The service role is separate from the task role used by containers to call AWS APIs and the task execution role used for operations such as pulling images.
Potential impact
- Unnecessary service permissions can broaden the resources affected by misconfiguration or role misuse.
- Removing required permissions or selecting the wrong role can break target registration and service deployment.
Remediation
- Check the network mode and load-balancer setup. An
awsvpcservice uses the ECS service-linked role and must not specify thisRoleproperty. - Where an explicit service role is required, allow only necessary actions and resources. Review task-role and task-execution-role permissions separately.
- After changes, verify actual policies, target registration, health checks and required service operations.
Examples
These alternatives describe an EC2-based service with a load balancer. Supply the target group ARN and actual role ARNs, and prepare cluster capacity and networking. Policies are not included; changing a role name alone does not reduce permissions.
Before
AWSTemplateFormatVersion: 2010-09-09
Description: Creating ECS service
Parameters:
TargetGroupArn:
Type: String
Resources:
cluster:
Type: AWS::ECS::Cluster
taskdefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: simple-app
Image: amazon/amazon-ecs-sample
Memory: 128
PortMappings:
- ContainerPort: 80
Volumes:
- Host:
SourcePath: /var/lib/docker/vfs/dir/
Name: my-vol
service:
Type: AWS::ECS::Service
Properties:
Cluster: !Ref cluster
Role: arn:aws:iam::123456789012:role/Admin
TaskDefinition: !Ref taskdefinition
LoadBalancers:
- TargetGroupArn: !Ref TargetGroupArn
ContainerName: simple-app
ContainerPort: 80
The service specifies a role named Admin. Check its attached policies for unnecessary administrative permissions.
After
AWSTemplateFormatVersion: 2010-09-09
Description: Creating ECS service
Parameters:
TargetGroupArn:
Type: String
Resources:
cluster:
Type: AWS::ECS::Cluster
taskdefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: simple-app
Image: amazon/amazon-ecs-sample
Memory: 128
PortMappings:
- ContainerPort: 80
Volumes:
- Host:
SourcePath: /var/lib/docker/vfs/dir/
Name: my-vol
service:
Type: AWS::ECS::Service
Properties:
Cluster: !Ref cluster
Role: arn:aws:iam::123456789012:role/EcsServiceRole
TaskDefinition: !Ref taskdefinition
LoadBalancers:
- TargetGroupArn: !Ref TargetGroupArn
ContainerName: simple-app
ContainerPort: 80
A service-specific role is selected. Verify that its policies are limited to the permissions required for the load-balancer integration.