ECS service assigned public IP addresses

Do not assign public IP addresses to ECS tasks that do not need direct public access.

Description

Assigning public IP addresses to a Fargate ECS service can make its tasks reachable from the internet when routing and security groups allow it. Choose public IP assignment according to the service’s connectivity needs.

Potential impact

An unintended direct access path can expose tasks to external scanning and attacks.

Remediation

If direct public access is unnecessary, set assign_public_ip = false and use private subnets. Expose required services through an ALB/NLB, and configure NAT or VPC endpoints for outbound traffic such as image downloads.

Examples

The examples disable public IP assignment for the same service. Replace the subnet and security group IDs with actual values and configure routing separately.

Before

hcl
resource "aws_ecs_service" "example" {
  name            = "example_service_dev"
  cluster         = aws_ecs_cluster.example_cluster.id
  task_definition = aws_ecs_task_definition.example_task.arn
  desired_count   = 2
  launch_type     = "FARGATE"

  network_configuration {
    assign_public_ip = true
    subnets          = ["subnet-0123456789abcdef0", "subnet-0fedcba9876543210"]
    security_groups  = ["sg-0123456789abcdef0"]
  }
}

After

hcl
resource "aws_ecs_service" "example" {
  name            = "example_service_dev"
  cluster         = aws_ecs_cluster.example_cluster.id
  task_definition = aws_ecs_task_definition.example_task.arn
  desired_count   = 2
  launch_type     = "FARGATE"

  network_configuration {
    assign_public_ip = false
    subnets          = ["subnet-0123456789abcdef0", "subnet-0fedcba9876543210"]
    security_groups  = ["sg-0123456789abcdef0"]
  }
}

References