AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A development team is building a new microservice that runs on AWS Fargate. This microservice needs to securely access credentials stored in AWS Secrets Manager and temporary tokens for AWS services. The team wants to ensure that the microservice has only the necessary permissions and that these permissions are not hardcoded into the container image. How should the developer assign these permissions?

  1. AEmbed an IAM user's access keys directly into the container image.
  2. BAttach an IAM role to the Fargate task definition.
  3. CCreate an IAM policy and attach it directly to the Fargate service.
  4. DUse environment variables in the task definition to store access keys.
Show answer & explanation

Correct answer: B. Attach an IAM role to the Fargate task definition.

Attaching an IAM role to the Fargate task definition allows the microservice to assume the role's permissions, providing secure and temporary credentials without hardcoding them, aligning with AWS best practices for least privilege.

Why the other options are wrong

  • A. Embedding access keys is an anti-pattern as it introduces security risks and violates the principle of least privilege.
  • C. IAM policies are attached to roles or users, not directly to services. While a policy is needed, it must be part of a role assumed by the task.
  • D. Using environment variables for access keys is insecure and not recommended for sensitive credentials.

ECS Task IAM Roles

ECS Task IAM roles provide a mechanism to grant permissions to applications running in an Amazon ECS task. The task assumes the role, obtaining temporary credentials for AWS service access.

  • Grants temporary permissions to ECS tasks.
  • Avoids embedding static credentials.
  • Follows the principle of least privilege.
  • Attached to the task definition.

Memory trick: Fargate tasks use IAM roles to safely access secrets and services.

More Security questions