Description
awsvpc gives each ECS task a network interface and supports task-level security groups. Fargate requires this mode, but other modes can be valid on EC2 depending on the workload. none provides no external connectivity.
Potential impact
A network mode that does not fit the workload can block required communication or make task-level access control harder.
Remediation
Use NetworkMode: awsvpc when task-level network control is needed, and specify subnets and security groups when creating the service or running the task. Do not change none indiscriminately for tasks that need no external connectivity.
Examples
The examples change none to awsvpc for a task that needs external connectivity. Task sizing and launch-time network settings are omitted.
Before
Resources:
TaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
NetworkMode: none
ContainerDefinitions:
- Name: app
Image: amazon/amazon-ecs-sample
After
Resources:
TaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
NetworkMode: awsvpc
ContainerDefinitions:
- Name: app
Image: amazon/amazon-ecs-sample