Review the ECS task network mode

Choose an ECS task network mode that fits its connectivity needs.

Description

The awsvpc mode gives each task a dedicated network interface so that security groups can be applied per task. Fargate requires this mode. For EC2 tasks, choose a mode appropriate for the workload.

Potential impact

Unlike awsvpc, host and bridge do not support security groups applied directly to individual tasks. In contrast, none provides no external network connectivity and does not itself imply public exposure.

Remediation

If you need per-task network controls, set network_mode = "awsvpc" and configure the service’s subnets and security groups. Check port mappings and connectivity requirements before changing modes.

Examples

These partial EC2 task definitions compare only network modes and omit the required container definitions. Switching from none to awsvpc enables network connectivity.

Before

hcl
resource "aws_ecs_task_definition" "example" {
  family       = "service"
  network_mode = "none"

  volume {
    name      = "service-storage"
    host_path = "/ecs/service-storage"
  }
}

After

hcl
resource "aws_ecs_task_definition" "example" {
  family       = "service"
  network_mode = "awsvpc"

  volume {
    name      = "service-storage"
    host_path = "/ecs/service-storage"
  }
}

References