AWS ECS service role permissions need review

Grant only the permissions ECS needs to manage the load balancer.

Description

Excessive administrative permissions on an ECS service’s iam_role can allow service operations beyond their required scope. Review the actual permission and trust policies rather than merely changing the role name.

This service role lets ECS make calls to the load balancer; it is separate from the application’s task role and the task execution role. With awsvpc network mode, omit iam_role and use the service-linked role.

Potential impact

  • Incorrect service configuration or unauthorized role use can permit unnecessary administrative operations.
  • Excessive policies can increase the impact of role misuse.

Remediation

Remove unnecessary administrative permissions from the service role and allow only the actions and resources ECS needs. Check its trust policy too. Use the ECS service-linked role in supported configurations and test load-balancer registration and service health after changes. Review application task-role permissions separately.

Examples

These excerpts show role settings for a non-awsvpc service using a load balancer. The cluster, task definition, load_balancer block and role policies are omitted.

Before

hcl
resource "aws_ecs_service" "ecs_service" {
  name            = "mongodb"
  cluster         = aws_ecs_cluster.foo.id
  task_definition = aws_ecs_task_definition.mongo.arn
  desired_count   = 3
  iam_role        = "admin"
}

This references a role named admin. Check its policies to determine the actual administrative permissions.

After

hcl
resource "aws_ecs_service" "ecs_service" {
  name            = "mongodb"
  cluster         = aws_ecs_cluster.foo.id
  task_definition = aws_ecs_task_definition.mongo.arn
  desired_count   = 3
  iam_role        = aws_iam_role.foo.arn
}

This switches to a role ARN reference. Verify that the foo role’s policies grant only the permissions required.

References