Role summary
Task execution role
The task execution role is assumed by the ECS service (ecs-tasks.amazonaws.com) during task launch — not by the containers themselves. ECS uses this role to:
- Pull container images from Amazon ECR.
- Write log streams to CloudWatch Logs.
- Retrieve SSM Parameter Store values injected as environment variables.
- Retrieve Secrets Manager secrets injected as environment variables.
The task execution role’s permissions are not accessible to the containers at runtime. They are consumed only during the task creation process. Runtime access to AWS services is handled by the tasks IAM role.
Shared vs. per-service patterns
- Service-level (per-service)
Task execution role permissions
Task execution role permissions
The module creates a custom IAM policy (rather than attaching the AWS-managed
AmazonECSTaskExecutionRolePolicy) so that permissions can be scoped precisely. The policy includes:Additional managed policies can be attached via
task_exec_iam_role_policies (a map of policy name to ARN).The GetSSMParams and GetSecrets statements are only included when the respective ARN lists are non-empty, keeping the policy minimal by default.Controlling variables
Tasks IAM role
The tasks IAM role is assumed by the containers within the task at runtime. This is analogous to an EC2 instance profile or a Kubernetes IRSA role. If your application needs to read from S3, connect to RDS using IAM authentication, publish to SQS, or call any AWS API, those permissions belong on the tasks IAM role. The tasks IAM role is created by the service sub-module only. It is scoped to the specific service.Tasks IAM role permissions
Tasks IAM role permissions
The base tasks IAM role has no permissions by default. Permissions are added through:The assume role policy includes two conditions to prevent confused deputy attacks:
When
enable_execute_command = true, the module injects the following statement:aws:SourceArnmust matcharn:*:ecs:<region>:<account>:*aws:SourceAccountmust match the deploying account ID
Controlling variables
Service IAM role
The service IAM role is assumed by the ECS service (ecs.amazonaws.com) and is used to register and deregister task IPs or instances with Elastic Load Balancing target groups or classic load balancers.
This role is only required when the service uses a load balancer and the task network mode is not
awsvpc. For Fargate tasks (which always use awsvpc), the load balancer registers task ENI IPs directly and this role is not needed. The module automatically determines whether to create it based on network_mode and load_balancer.Service IAM role permissions
Service IAM role permissions
The service IAM role receives a policy with the following permissions:
Additional statements can be added via
iam_role_statements.Controlling variables
Infrastructure IAM role
The infrastructure IAM role is used by ECS to manage the underlying EC2 compute fleet when using the ECS Managed Instances capacity provider type. It is assumed by the ECS service principal (ecs.amazonaws.com) and allows ECS to create and manage EC2 launch templates, run EC2 instances, and tag resources.
This role is created by the cluster sub-module and is only created when at least one capacity provider in capacity_providers has a managed_instances_provider block configured.
Infrastructure IAM role permissions
Infrastructure IAM role permissions
The module creates a custom policy (rather than using
AmazonECSInfrastructureRolePolicyForManagedInstances) to avoid a surprising AWS requirement that the role name start with ecsInstanceRole when using the managed policy.Key permission groups:Controlling variables
Node IAM role
The node IAM role is attached to EC2 instances launched by the ECS Managed Instances capacity provider via an instance profile. It is assumed byec2.amazonaws.com and grants the ECS agent running on each node the permissions it needs to register with the cluster, poll for tasks, and report state.
Like the infrastructure role, the node IAM role is created by the cluster sub-module and is only created when Managed Instances is in use.
Node IAM role permissions
Node IAM role permissions
The module creates a custom policy equivalent to
AmazonECSInstanceRolePolicyForManagedInstances:Additional policies can be attached via
node_iam_role_additional_policies. Custom statements can be added via node_iam_role_statements.An aws_iam_instance_profile resource is created alongside the role so that EC2 instances launched by the Managed Instances fleet can use it.
