Description
Assigning public IP addresses to a Fargate ECS service can make its tasks reachable from the internet when routing and security groups allow it. Choose public IP assignment according to the service’s connectivity needs.
Potential impact
An unintended direct access path can expose tasks to external scanning and attacks.
Remediation
If direct public access is unnecessary, set assign_public_ip = false and use private subnets. Expose required services through an ALB/NLB, and configure NAT or VPC endpoints for outbound traffic such as image downloads.
Examples
The examples disable public IP assignment for the same service. Replace the subnet and security group IDs with actual values and configure routing separately.
Before
resource "aws_ecs_service" "example" {
name = "example_service_dev"
cluster = aws_ecs_cluster.example_cluster.id
task_definition = aws_ecs_task_definition.example_task.arn
desired_count = 2
launch_type = "FARGATE"
network_configuration {
assign_public_ip = true
subnets = ["subnet-0123456789abcdef0", "subnet-0fedcba9876543210"]
security_groups = ["sg-0123456789abcdef0"]
}
}
After
resource "aws_ecs_service" "example" {
name = "example_service_dev"
cluster = aws_ecs_cluster.example_cluster.id
task_definition = aws_ecs_task_definition.example_task.arn
desired_count = 2
launch_type = "FARGATE"
network_configuration {
assign_public_ip = false
subnets = ["subnet-0123456789abcdef0", "subnet-0fedcba9876543210"]
security_groups = ["sg-0123456789abcdef0"]
}
}