Public IP assignment for ECS tasks

Disable public IP assignment for ECS tasks that do not need direct internet exposure.

Description

When AssignPublicIp is ENABLED in an ECS service’s AwsvpcConfiguration, tasks receive public IP addresses. Internet reachability also depends on routing and security groups.

Potential impact

An internet route combined with permissive rules can allow unintended external connections.

Remediation

If direct exposure is unnecessary, set AssignPublicIp: DISABLED and restrict subnet routes and security groups. Provide NAT or VPC endpoints for required outbound traffic, such as image pulls.

Examples

The examples only disable public IP assignment. This setting does not turn the subnet into a private subnet.

Before

yaml
Resources:
  ECSService:
    Type: AWS::ECS::Service
    Properties:
      NetworkConfiguration:
        AwsvpcConfiguration:
          AssignPublicIp: ENABLED
          Subnets:
            - subnet-021345abcdef67890

After

yaml
Resources:
  ECSService:
    Type: AWS::ECS::Service
    Properties:
      NetworkConfiguration:
        AwsvpcConfiguration:
          AssignPublicIp: DISABLED
          Subnets:
            - subnet-021345abcdef67890

References