AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is deploying a containerized application to Amazon ECS Fargate. The application needs to perform operations on an Amazon S3 bucket and publish messages to an Amazon SNS topic. The security team has mandated that the application should not use static AWS credentials and must adhere to the principle of least privilege. How can the developer provide the necessary permissions to the Fargate task securely?

  1. AEmbed IAM user access keys and secret keys directly into the container image.
  2. BUse an EC2 instance profile attached to the underlying Fargate infrastructure.
  3. CAssign an IAM role to the Fargate task definition, granting only S3 and SNS permissions.
  4. DStore IAM user credentials in AWS Secrets Manager and retrieve them at runtime.
Show answer & explanation

Correct answer: C. Assign an IAM role to the Fargate task definition, granting only S3 and SNS permissions.

Assigning an IAM role directly to the Fargate task definition is the recommended and most secure way. This creates a Task IAM Role, which provides temporary, frequently rotated credentials to the running container, eliminating the need to manage static credentials and adhering to least privilege by granting only necessary S3 and SNS permissions.

Why the other options are wrong

  • A. Embedding credentials in the container image is a severe security vulnerability and violates best practices.
  • B. Fargate tasks do not run on EC2 instances you manage, so an EC2 instance profile is not applicable. Fargate manages the underlying infrastructure.
  • D. While Secrets Manager is for secrets, using it for *task* credentials is less ideal than a Task IAM Role, as the task would still need permissions to access Secrets Manager, creating a bootstrap problem or requiring a role anyway.

ECS Task IAM Roles

ECS Task IAM Roles allow you to specify an IAM role that a task can use to make API requests to authorized AWS services. This provides temporary, frequently rotated credentials to the container, eliminating the need to embed or distribute static credentials.

  • Provides temporary credentials to individual tasks.
  • Eliminates static credential management.
  • Adheres to the principle of least privilege.
  • Configured in the ECS task definition.

Memory trick: Fargate Tasks get their own Role, no keys in the container's soul.

More Security questions