Skip to content

feat: Enable ECS "SSH" - #2940

Draft
akash1810 wants to merge 1 commit into
mainfrom
aa/ecs-execute-command
Draft

feat: Enable ECS "SSH"#2940
akash1810 wants to merge 1 commit into
mainfrom
aa/ecs-execute-command

Conversation

@akash1810

@akash1810 akash1810 commented Jul 21, 2026

Copy link
Copy Markdown
Member

What does this change?

This change enables AWS ECS Exec to enable "ssh" to the running container. Once connected to a container, there's a limited number of things we can do. For example, if the image doesn't have curl then we won't be able to curl an endpoint without first installing it.

The change follows the requirements listed on https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-exec.html#ecs-exec-considerations. Specifically, it sets readonlyRootFilesystem to false, which is a direct violation of FSBP ECS.5.

How to test

See guardian/cdk-playground#1171.

How can we measure success?

We're able to "ssh" to a running container.

Have we considered potential risks?

When enabled, the ECS cluster would actively violate FSBP EC2.5 and CloudBuster would alert us to this, for example:

image

For this reason, I don't think this should ever be enabled on PROD.

Checklist

  • I have listed any breaking changes, along with a migration path 1
  • I have updated the documentation as required for the described changes 2

Footnotes

  1. Consider whether this is something that will mean changes to projects that have already been migrated, or to the CDK CLI tool. If changes are required, consider adding a checklist here and/or linking to related PRs.

  2. If you are adding a new construct or pattern, has new documentation been added? If you are amending defaults or changing behaviour, are the existing docs still valid?

@akash1810 akash1810 added the feature Departmental tracking: work on a new feature label Jul 21, 2026
@changeset-bot

changeset-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 93b3196

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@guardian/cdk Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@akash1810
akash1810 force-pushed the aa/ecs-execute-command branch from 75f9c79 to 93b3196 Compare August 6, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature Departmental tracking: work on a new feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant