Skip to main content
The AWS ECS Terraform module creates up to five distinct IAM roles depending on which features you enable. Each role has a specific purpose tied to a different phase of the ECS task lifecycle or a different compute type.

Role summary


Task execution role

The task execution role is assumed by the ECS service (ecs-tasks.amazonaws.com) during task launch — not by the containers themselves. ECS uses this role to:
  • Pull container images from Amazon ECR.
  • Write log streams to CloudWatch Logs.
  • Retrieve SSM Parameter Store values injected as environment variables.
  • Retrieve Secrets Manager secrets injected as environment variables.
The task execution role’s permissions are not accessible to the containers at runtime. They are consumed only during the task creation process. Runtime access to AWS services is handled by the tasks IAM role.

Shared vs. per-service patterns

Create one task execution role in the cluster sub-module and share it across all services in the cluster. This is the simplest pattern and works well when all services in the cluster are owned by the same team.
When using the root module, this is handled automatically: setting create_task_exec_iam_role = true at the top level creates the cluster-level role, and its ARN is forwarded to every service via task_exec_iam_role_arn = try(coalesce(each.value.task_exec_iam_role_arn, module.cluster.task_exec_iam_role_arn), null).
The module creates a custom IAM policy (rather than attaching the AWS-managed AmazonECSTaskExecutionRolePolicy) so that permissions can be scoped precisely. The policy includes:Additional managed policies can be attached via task_exec_iam_role_policies (a map of policy name to ARN).The GetSSMParams and GetSecrets statements are only included when the respective ARN lists are non-empty, keeping the policy minimal by default.

Controlling variables


Tasks IAM role

The tasks IAM role is assumed by the containers within the task at runtime. This is analogous to an EC2 instance profile or a Kubernetes IRSA role. If your application needs to read from S3, connect to RDS using IAM authentication, publish to SQS, or call any AWS API, those permissions belong on the tasks IAM role. The tasks IAM role is created by the service sub-module only. It is scoped to the specific service.
The base tasks IAM role has no permissions by default. Permissions are added through:When enable_execute_command = true, the module injects the following statement:
The assume role policy includes two conditions to prevent confused deputy attacks:
  • aws:SourceArn must match arn:*:ecs:<region>:<account>:*
  • aws:SourceAccount must match the deploying account ID

Controlling variables


Service IAM role

The service IAM role is assumed by the ECS service (ecs.amazonaws.com) and is used to register and deregister task IPs or instances with Elastic Load Balancing target groups or classic load balancers.
This role is only required when the service uses a load balancer and the task network mode is not awsvpc. For Fargate tasks (which always use awsvpc), the load balancer registers task ENI IPs directly and this role is not needed. The module automatically determines whether to create it based on network_mode and load_balancer.
The condition for creation in the service module is:
The service IAM role receives a policy with the following permissions:Additional statements can be added via iam_role_statements.

Controlling variables


Infrastructure IAM role

The infrastructure IAM role is used by ECS to manage the underlying EC2 compute fleet when using the ECS Managed Instances capacity provider type. It is assumed by the ECS service principal (ecs.amazonaws.com) and allows ECS to create and manage EC2 launch templates, run EC2 instances, and tag resources. This role is created by the cluster sub-module and is only created when at least one capacity provider in capacity_providers has a managed_instances_provider block configured.
The module creates a custom policy (rather than using AmazonECSInfrastructureRolePolicyForManagedInstances) to avoid a surprising AWS requirement that the role name start with ecsInstanceRole when using the managed policy.Key permission groups:

Controlling variables


Node IAM role

The node IAM role is attached to EC2 instances launched by the ECS Managed Instances capacity provider via an instance profile. It is assumed by ec2.amazonaws.com and grants the ECS agent running on each node the permissions it needs to register with the cluster, poll for tasks, and report state. Like the infrastructure role, the node IAM role is created by the cluster sub-module and is only created when Managed Instances is in use.
AWS documentation states that when using the AWS-managed AmazonECSInstanceRolePolicyForManagedInstances policy, the instance profile must be named ecsInstanceRole. This module avoids that constraint by creating a custom equivalent policy, allowing any name.
The module creates a custom policy equivalent to AmazonECSInstanceRolePolicyForManagedInstances:Additional policies can be attached via node_iam_role_additional_policies. Custom statements can be added via node_iam_role_statements.An aws_iam_instance_profile resource is created alongside the role so that EC2 instances launched by the Managed Instances fleet can use it.

Controlling variables