Description
Setting container_properties.privileged to true in a Batch job definition gives the container broader host access and weakens ordinary container isolation. Compromise of the job code or image can extend the impact to the host and other jobs.
Privileged mode is different from merely running as root inside a container. Jobs running on AWS Fargate cannot use this mode.
Potential impact
- Excessive access to host resources can weaken isolation between jobs.
- Malicious code or images can misuse elevated permissions with a wider impact.
Remediation
Set container_properties.privileged to false or omit it. Grant only the permissions needed by the job and review host mounts and special capabilities. Test normal operation with the new job definition revision before updating job submission settings.
Examples
This changes the privileged setting for the same EC2-based job definition.
Before
resource "aws_batch_job_definition" "batch_job" {
name = "tf_test_batch_job_definition"
type = "container"
container_properties = <<CONTAINER_PROPERTIES
{
"command": ["ls", "-la"],
"image": "busybox",
"memory": 1024,
"vcpus": 1,
"privileged": true
}
CONTAINER_PROPERTIES
}
This enables privileged mode.
After
resource "aws_batch_job_definition" "batch_job" {
name = "tf_test_batch_job_definition"
type = "container"
container_properties = <<CONTAINER_PROPERTIES
{
"command": ["ls", "-la"],
"image": "busybox",
"memory": 1024,
"vcpus": 1,
"privileged": false
}
CONTAINER_PROPERTIES
}
This disables privileged mode. Review other execution settings too, because the change alone does not remove every path to host resources.