Description
Without transit encryption on an EFS volume mounted by ECS, file data can travel in plaintext. Encryption at rest does not protect this network connection.
Potential impact
- An attacker with access to the communication path has a greater opportunity to intercept or alter file data.
- Services handling sensitive files may fail to meet transport-encryption requirements.
Remediation
- Set
TransitEncryptiontoENABLEDfor the EFS volume. - Deploy the workload with a new task-definition revision and verify mounting, reads and writes. Transit encryption is also required with IAM authorization or an EFS access point.
- Manage network access, file permissions and encryption at rest separately.
Examples
These excerpts show only the EFS volume settings in an ECS task definition. Replace the example file system ID and configure container mount points and the required task and network settings.
Before
json
{
"Resources": {
"TaskDefinition": {
"Type": "AWS::ECS::TaskDefinition",
"Properties": {
"Volumes": [
{
"Name": "myEfsVolume",
"EFSVolumeConfiguration": {
"FileSystemId": "fs-1234",
"TransitEncryption": "DISABLED"
}
}
]
}
}
}
}
Transit encryption is disabled for the EFS mount. Encryption at rest would not protect this connection.
After
json
{
"Resources": {
"TaskDefinition": {
"Type": "AWS::ECS::TaskDefinition",
"Properties": {
"Volumes": [
{
"Name": "myEfsVolume",
"EFSVolumeConfiguration": {
"FileSystemId": "fs-1234",
"TransitEncryption": "ENABLED"
}
}
]
}
}
}
}
The EFS mount uses transit encryption. This does not automatically configure file access permissions or encryption at rest.