EFS volume with transit encryption disabled

Protect communication between ECS tasks and EFS file systems with encryption in transit.

Description

When ECS tasks use EFS, traffic between the host and file system also needs protection. With transit encryption disabled, file contents and metadata can be exposed along the network path.

Setting efs_volume_configuration.transit_encryption to ENABLED in the ECS task definition enables transit encryption for that EFS connection. Encryption at rest and file-access permissions require separate controls.

Potential impact

A party able to intercept unencrypted traffic on the connection path could obtain application files or operational data. An internal network alone does not protect data in transit.

Remediation

  • Set transit_encryption = "ENABLED" for volumes that use EFS.
  • Deploy tasks using the new task-definition revision and verify actual file access.
  • Review IAM, access points and security groups alongside transit encryption.

Examples

These task-definition excerpts require the referenced container-definition file and EFS file system. Configure the container's volume mount separately.

Before

hcl
resource "aws_ecs_task_definition" "example" {
  family                = "service"
  container_definitions = file("task-definitions/service.json")

  volume {
    name = "service-storage"

    efs_volume_configuration {
      file_system_id          = aws_efs_file_system.fs.id
      root_directory          = "/opt/data"
      transit_encryption      = "DISABLED"
      transit_encryption_port = 2999
    }
  }
}

This disables transit encryption for the EFS connection.

After

hcl
resource "aws_ecs_task_definition" "example" {
  family                = "service"
  container_definitions = file("task-definitions/service.json")

  volume {
    name = "service-storage"

    efs_volume_configuration {
      file_system_id          = aws_efs_file_system.fs.id
      root_directory          = "/opt/data"
      transit_encryption      = "ENABLED"
      transit_encryption_port = 2999
    }
  }
}

This enables transit encryption for the same connection. Running tasks must be moved to the new definition.

References