feat: Enable ECS "SSH" - #2940
Draft
akash1810 wants to merge 1 commit into
Draft
Conversation
🦋 Changeset detectedLatest commit: 93b3196 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
akash1810
force-pushed
the
aa/ecs-execute-command
branch
from
August 6, 2026 13:49
75f9c79 to
93b3196
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this change?
This change enables AWS ECS Exec to enable "ssh" to the running container. Once connected to a container, there's a limited number of things we can do. For example, if the image doesn't have
curlthen we won't be able tocurlan endpoint without first installing it.The change follows the requirements listed on https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-exec.html#ecs-exec-considerations. Specifically, it sets
readonlyRootFilesystemtofalse, which is a direct violation of FSBP ECS.5.How to test
See guardian/cdk-playground#1171.
How can we measure success?
We're able to "ssh" to a running container.
Have we considered potential risks?
When enabled, the ECS cluster would actively violate FSBP EC2.5 and CloudBuster would alert us to this, for example:
For this reason, I don't think this should ever be enabled on PROD.
Checklist
Footnotes
Consider whether this is something that will mean changes to projects that have already been migrated, or to the CDK CLI tool. If changes are required, consider adding a checklist here and/or linking to related PRs. ↩
If you are adding a new construct or pattern, has new documentation been added? If you are amending defaults or changing behaviour, are the existing docs still valid? ↩