[ECS] [Fargate]: Report Container Hardening Compliance Information
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
What do you want us to build?
I want information about containers and their compliance status for [CIS Docker Benchmark 1.2.0](https://success.docker.com/api/asset/.%2Frefarch%2Fsecurity-best-practices%2FCIS_Docker_Benchmark_v1.2.0.pdf) and potentially relevant operating system controls from [DISA STIGS](https://public.cyber.mil/stigs/downloads/).
**Which service(s) is this request for?**
Fargate, ECS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
What outcome are you trying to achieve, ultimately, and why is it hard/impossible to do right now? What is the impact of not having this problem solved? The more details you can provide, the better we'll be able to understand and solve the problem.
There are now a variety of community tools, such as [docker-bench](https://github.com/aquasecurity/docker-bench) and [docker-bench-security](github.com/docker/docker-bench-security), as well as managed solutions for Docker deployments like [Twistlock/Prsima](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/compliance/host_scanning.html) and [a small part of AquaSec's microenforcer compoonents](https://www.aquasec.com/solutions/aws-container-security/) that provide information about whether or not a container's runtime configuration is hardened with proper configuration items. Common choices are the CIS Docker Benchmark 1.2.0. Other US government customers maybe interested in full DISA STIG RedHat/Ubuntu/Other compliance with more stringent hardening baselines, such as what [oscap-docker](https://www.open-scap.org/resources/documentation/security-compliance-of-rhel7-docker-containers/) does.
Now that [ECR supports image _vulnerability scanning_](https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html), I work with fellow AWS engineers with systems where related compliance statuses for _containers deployed in Fargate_ would be ideal.
The lack of this information and tools being readily available requires more spend and risk in supporting additional infrastructure, ad hoc or long-term for point-in-time auditing checks as requested by auditors.
**Are you currently working around this issue?**
How are you currently solving this problem?
Yes, I will have to build and/or augment my own solutions.
**Additional context**
Anything else we should know?
I know the CIS benchmark compromises security controls for the Docker host and daemon and its configuration that are not applicable for Fargate users; I am interested in 5.x controls runtime configuration at this time; I would appreciate knowing compliance with these other control families in CIS Docker Benchmark, but that, for Fargate, I understand AWS may reserve the right to not disclose this information.
**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
Contributor guide
Research direction
Start with the requested Fargate and ECS runtime-compliance scope and the cited CIS Docker Benchmark 1.2.0 and DISA STIG references. No repository files, tests, or implementation entry point are identified; done would require a defined way to report compliance for deployed Fargate containers.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100