Description
Without a container HealthCheck in the ECS task definition, this mechanism cannot assess application responsiveness. A running process alone does not guarantee a working response.
Potential impact
Without another check, discovering and replacing an unresponsive container can take longer.
Remediation
Set an appropriate HealthCheck command, interval, and timeout for essential containers. Include the required tools in the image and verify startup timing and failure behavior.
Examples
AppImage must contain curl and respond to the health check at / on port 8080. These container excerpts omit the remaining task properties.
Before
yaml
Resources:
TaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: app
Image: !Ref AppImage
Essential: true
After
yaml
Resources:
TaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
ContainerDefinitions:
- Name: app
Image: !Ref AppImage
Essential: true
HealthCheck:
Command:
- CMD-SHELL
- curl -f http://localhost:8080/ || exit 1
Interval: 30
Retries: 3
Timeout: 5