AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A developer is deploying a containerized application to Amazon ECS Fargate. The application needs to interact with other AWS services, such as DynamoDB and SQS. The developer wants to ensure that the application has only the necessary permissions and that credentials are not hardcoded. How should the developer securely grant permissions to the Fargate tasks?
- ACreate an IAM role for the Fargate task and associate it with the task definition.
- BUse environment variables in the task definition to store AWS access keys.
- CEmbed an IAM user's access key and secret key directly into the container image.
- DAttach an IAM policy directly to the ECS cluster.
Show answer & explanationAnswer & explanation
Correct answer: A. Create an IAM role for the Fargate task and associate it with the task definition.
Creating an IAM role for the Fargate task and associating it with the task definition is the recommended and most secure way to grant permissions. This allows the task to assume the role and obtain temporary, regularly rotated credentials, eliminating the need to hardcode or manage long-term credentials.
Why the other options are wrong
- B. Storing AWS access keys in environment variables is insecure, as they are still long-term credentials and can be easily exposed.
- C. Embedding long-term credentials is a major security vulnerability.
- D. Attaching an IAM policy directly to the ECS cluster would grant permissions to the cluster, not granularly to individual tasks, and tasks would still need a mechanism to assume those permissions.
ECS Task IAM Roles
IAM roles for Amazon ECS tasks allow you to assign specific permissions to your tasks, ensuring that only necessary AWS resources can be accessed.
- Provides temporary, auto-rotated credentials.
- Follows the principle of least privilege.
- Eliminates the need for hardcoded credentials.
Memory trick: Task roles grant temporary, specific access.