ECS service role references a policy

Specify a valid role instead of a policy in an ECS service’s Role.

Description

Role in AWS::ECS::Service identifies the IAM role used by the service to access its load balancer. Referencing an AWS::IAM::Policy resource does not specify a role.

Potential impact

Using a policy as a role can cause service creation or load-balancer integration to fail.

Remediation

Use the appropriate service-linked role, or an actual IAM role where the configuration permits a separate role. With awsvpc networking, use the service-linked role and omit Role.

Examples

These excerpts remove the invalid policy reference and use a service-linked role. Required roles, cluster, listener, target group, and task definition are omitted. Do not use the broad policy in the first example.

Before

yaml
Resources:
  InlinePolicy:
    Type: AWS::ECS::Service
    DependsOn:
    - Listener
    Properties:
      Role:
        Ref: IAMPolicy
      LoadBalancers:
      - TargetGroupArn:
          Ref: TargetGroup
        ContainerPort: 80
        ContainerName: sample-app
      Cluster:
        Ref: ECSCluster
  IAMPolicy:
    Type: 'AWS::IAM::Policy'
    Properties:
      PolicyName: root
      Roles:
        - !Ref ECSServiceRole
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: '*'
            Resource: '*'

After

yaml
Resources:
  InlinePolicy:
    Type: AWS::ECS::Service
    DependsOn:
    - Listener
    Properties:
      LoadBalancers:
      - TargetGroupArn:
          Ref: TargetGroup
        ContainerPort: 80
        ContainerName: sample-app
      Cluster:
        Ref: ECSCluster

References