[ECS] [request]: ECS on EC2 in VPC trunking mode - ability to override default account security group
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
When VPC trunking is enabled an AWS account and we launch and ECS cluster using EC2, the EC2 instance has the account default security group attached. This security group is highly permissive. I would like to be able to specify my own least privileged security group similar to existing behavior of launch template.
**Which service(s) is this request for?**
ECS with EC2 (VPC trunking enabled)
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
Default behavior when VPC trunking is enabled. This cannot be overridden. It is not feasible to update the default security group rules across all our accounts.
**Are you currently working around this issue?**
No
Contributor guide
Research direction
Start by reviewing ECS with EC2 in VPC trunking mode and the existing launch template security-group behavior described in the issue. Done means users can specify a least-privileged security group instead of inheriting the account default security group.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, networking, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100