Description
When AssignPublicIp is ENABLED in an ECS service’s AwsvpcConfiguration, tasks receive public IP addresses. Internet reachability also depends on routing and security groups.
Potential impact
An internet route combined with permissive rules can allow unintended external connections.
Remediation
If direct exposure is unnecessary, set AssignPublicIp: DISABLED and restrict subnet routes and security groups. Provide NAT or VPC endpoints for required outbound traffic, such as image pulls.
Examples
The examples only disable public IP assignment. This setting does not turn the subnet into a private subnet.
Before
yaml
Resources:
ECSService:
Type: AWS::ECS::Service
Properties:
NetworkConfiguration:
AwsvpcConfiguration:
AssignPublicIp: ENABLED
Subnets:
- subnet-021345abcdef67890
After
yaml
Resources:
ECSService:
Type: AWS::ECS::Service
Properties:
NetworkConfiguration:
AwsvpcConfiguration:
AssignPublicIp: DISABLED
Subnets:
- subnet-021345abcdef67890