Review the ECS task network mode

Choose a network mode that meets the task’s connectivity and isolation needs.

Description

awsvpc gives each ECS task a network interface and supports task-level security groups. Fargate requires this mode, but other modes can be valid on EC2 depending on the workload. none provides no external connectivity.

Potential impact

A network mode that does not fit the workload can block required communication or make task-level access control harder.

Remediation

Use NetworkMode: awsvpc when task-level network control is needed, and specify subnets and security groups when creating the service or running the task. Do not change none indiscriminately for tasks that need no external connectivity.

Examples

The examples change none to awsvpc for a task that needs external connectivity. Task sizing and launch-time network settings are omitted.

Before

yaml
Resources:
  TaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      NetworkMode: none
      ContainerDefinitions:
        - Name: app
          Image: amazon/amazon-ecs-sample

After

yaml
Resources:
  TaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      NetworkMode: awsvpc
      ContainerDefinitions:
        - Name: app
          Image: amazon/amazon-ecs-sample

References