ECS service role permissions need review

Inspect the actual ECS service-role policies and grant only the permissions needed for service operations.

Description

Excessive IAM permissions on an ECS service role may allow operations beyond the required load-balancer integration. Inspect its policies and trust relationship rather than inferring administrator access from its name. The service role is separate from the task role used by containers to call AWS APIs and the task execution role used for operations such as pulling images.

Potential impact

  • Unnecessary service permissions can broaden the resources affected by misconfiguration or role misuse.
  • Removing required permissions or selecting the wrong role can break target registration and service deployment.

Remediation

  • Check the network mode and load-balancer setup. An awsvpc service uses the ECS service-linked role and must not specify this Role property.
  • Where an explicit service role is required, allow only necessary actions and resources. Review task-role and task-execution-role permissions separately.
  • After changes, verify actual policies, target registration, health checks and required service operations.

Examples

These alternatives describe an EC2-based service with a load balancer. Supply the target group ARN and actual role ARNs, and prepare cluster capacity and networking. Policies are not included; changing a role name alone does not reduce permissions.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: Creating ECS service
Parameters:
  TargetGroupArn:
    Type: String
Resources:
  cluster:
    Type: AWS::ECS::Cluster
  taskdefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: simple-app
          Image: amazon/amazon-ecs-sample
          Memory: 128
          PortMappings:
            - ContainerPort: 80
      Volumes:
        - Host:
            SourcePath: /var/lib/docker/vfs/dir/
          Name: my-vol
  service:
    Type: AWS::ECS::Service
    Properties:
      Cluster: !Ref cluster
      Role: arn:aws:iam::123456789012:role/Admin
      TaskDefinition: !Ref taskdefinition
      LoadBalancers:
        - TargetGroupArn: !Ref TargetGroupArn
          ContainerName: simple-app
          ContainerPort: 80

The service specifies a role named Admin. Check its attached policies for unnecessary administrative permissions.

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: Creating ECS service
Parameters:
  TargetGroupArn:
    Type: String
Resources:
  cluster:
    Type: AWS::ECS::Cluster
  taskdefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: simple-app
          Image: amazon/amazon-ecs-sample
          Memory: 128
          PortMappings:
            - ContainerPort: 80
      Volumes:
        - Host:
            SourcePath: /var/lib/docker/vfs/dir/
          Name: my-vol
  service:
    Type: AWS::ECS::Service
    Properties:
      Cluster: !Ref cluster
      Role: arn:aws:iam::123456789012:role/EcsServiceRole
      TaskDefinition: !Ref taskdefinition
      LoadBalancers:
        - TargetGroupArn: !Ref TargetGroupArn
          ContainerName: simple-app
          ContainerPort: 80

A service-specific role is selected. Verify that its policies are limited to the permissions required for the load-balancer integration.

References