ECS container health check not configured

Configure a container health check that tests actual application health.

Description

Without a container HealthCheck in the ECS task definition, this mechanism cannot assess application responsiveness. A running process alone does not guarantee a working response.

Potential impact

Without another check, discovering and replacing an unresponsive container can take longer.

Remediation

Set an appropriate HealthCheck command, interval, and timeout for essential containers. Include the required tools in the image and verify startup timing and failure behavior.

Examples

AppImage must contain curl and respond to the health check at / on port 8080. These container excerpts omit the remaining task properties.

Before

yaml
Resources:
  TaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: app
          Image: !Ref AppImage
          Essential: true

After

yaml
Resources:
  TaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      ContainerDefinitions:
        - Name: app
          Image: !Ref AppImage
          Essential: true
          HealthCheck:
            Command:
              - CMD-SHELL
              - curl -f http://localhost:8080/ || exit 1
            Interval: 30
            Retries: 3
            Timeout: 5

References