Description
ExecutionRoleArn is used for ECS agent operations such as image pulls and log delivery; TaskRoleArn lets the application inside the container call AWS APIs. Required roles depend on the features the task uses.
Potential impact
A missing required role can prevent task startup or access to AWS resources. Working around this with long-term access keys increases the risk of credential exposure.
Remediation
Assign an execution role for the features in use, and add a least-privilege task role if the application calls AWS APIs. Execution role permissions are not automatically available to the application.
Examples
The excerpts attach both roles to a task that needs them. Role trust policies and permission definitions are omitted.
Before
Resources:
ECSService:
Type: AWS::ECS::Service
Properties:
TaskDefinition: !Ref ECSTaskDefinition
ECSTaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
Family: app
NetworkMode: awsvpc
ContainerDefinitions:
- Name: app
Image: example/app:latest
After
Resources:
ECSService:
Type: AWS::ECS::Service
Properties:
TaskDefinition: !Ref ECSTaskDefinition
ECSTaskDefinition:
Type: AWS::ECS::TaskDefinition
Properties:
Family: app
NetworkMode: awsvpc
ExecutionRoleArn: !Ref TaskExecutionRole
TaskRoleArn: !Ref AppTaskRole
ContainerDefinitions:
- Name: app
Image: example/app:latest