Description
The awsvpc mode gives each task a dedicated network interface so that security groups can be applied per task. Fargate requires this mode. For EC2 tasks, choose a mode appropriate for the workload.
Potential impact
Unlike awsvpc, host and bridge do not support security groups applied directly to individual tasks. In contrast, none provides no external network connectivity and does not itself imply public exposure.
Remediation
If you need per-task network controls, set network_mode = "awsvpc" and configure the service’s subnets and security groups. Check port mappings and connectivity requirements before changing modes.
Examples
These partial EC2 task definitions compare only network modes and omit the required container definitions. Switching from none to awsvpc enables network connectivity.
Before
resource "aws_ecs_task_definition" "example" {
family = "service"
network_mode = "none"
volume {
name = "service-storage"
host_path = "/ecs/service-storage"
}
}
After
resource "aws_ecs_task_definition" "example" {
family = "service"
network_mode = "awsvpc"
volume {
name = "service-storage"
host_path = "/ecs/service-storage"
}
}