Review IAM roles for an ECS task

Assign the ECS execution role and application task role according to their purposes.

Description

ExecutionRoleArn is used for ECS agent operations such as image pulls and log delivery; TaskRoleArn lets the application inside the container call AWS APIs. Required roles depend on the features the task uses.

Potential impact

A missing required role can prevent task startup or access to AWS resources. Working around this with long-term access keys increases the risk of credential exposure.

Remediation

Assign an execution role for the features in use, and add a least-privilege task role if the application calls AWS APIs. Execution role permissions are not automatically available to the application.

Examples

The excerpts attach both roles to a task that needs them. Role trust policies and permission definitions are omitted.

Before

yaml
Resources:
  ECSService:
    Type: AWS::ECS::Service
    Properties:
      TaskDefinition: !Ref ECSTaskDefinition

  ECSTaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      Family: app
      NetworkMode: awsvpc
      ContainerDefinitions:
        - Name: app
          Image: example/app:latest

After

yaml
Resources:
  ECSService:
    Type: AWS::ECS::Service
    Properties:
      TaskDefinition: !Ref ECSTaskDefinition

  ECSTaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      Family: app
      NetworkMode: awsvpc
      ExecutionRoleArn: !Ref TaskExecutionRole
      TaskRoleArn: !Ref AppTaskRole
      ContainerDefinitions:
        - Name: app
          Image: example/app:latest

References