Description
Role in AWS::ECS::Service identifies the IAM role used by the service to access its load balancer. Referencing an AWS::IAM::Policy resource does not specify a role.
Potential impact
Using a policy as a role can cause service creation or load-balancer integration to fail.
Remediation
Use the appropriate service-linked role, or an actual IAM role where the configuration permits a separate role. With awsvpc networking, use the service-linked role and omit Role.
Examples
These excerpts remove the invalid policy reference and use a service-linked role. Required roles, cluster, listener, target group, and task definition are omitted. Do not use the broad policy in the first example.
Before
yaml
Resources:
InlinePolicy:
Type: AWS::ECS::Service
DependsOn:
- Listener
Properties:
Role:
Ref: IAMPolicy
LoadBalancers:
- TargetGroupArn:
Ref: TargetGroup
ContainerPort: 80
ContainerName: sample-app
Cluster:
Ref: ECSCluster
IAMPolicy:
Type: 'AWS::IAM::Policy'
Properties:
PolicyName: root
Roles:
- !Ref ECSServiceRole
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: '*'
Resource: '*'
After
yaml
Resources:
InlinePolicy:
Type: AWS::ECS::Service
DependsOn:
- Listener
Properties:
LoadBalancers:
- TargetGroupArn:
Ref: TargetGroup
ContainerPort: 80
ContainerName: sample-app
Cluster:
Ref: ECSCluster