Why does AWS ECS allows inbound traffic to ALL ports by default?

Viewed 64

I am deploying the following relatively simple docker-compose.yml file on AWS ECS via the Docker CLI. It uses tomcat server image which can be also replaced by any other container which does not exits of startup.

services:
  tomcat:
    image: tomcat:9.0
    command: catalina.sh run
    ports:
     - target: 8080
       published: 8080
       x-aws-protocol: http

Commands used

docker context use mycontextforecs
docker compose up

The cluster, services, task, target, security groups and application load balancer are automatically created as expected.

But, the security group created by AWS ECS allows inbound traffic on ALL ports by default instead of only the exposed 8080. Following is a screenshot of the security group, which also has a comment -

"tomcat:8080/ on default network" 

But port range is "All" instead of 8080

enter image description here

I've read the following and some other stackoverflow links but could not get an answer.

https://docs.docker.com/cloud/ecs-compose-features/
https://docs.docker.com/cloud/ecs-architecture/
https://docs.docker.com/cloud/ecs-integration/

I understand that the default "Fargate" instance type gets a public ip assigned. But why does ECS allow traffic on all ports?

If I add another service in the docker-compose file, the default security group gets shared between both of them. As a result, anyone can telnet into the port exposed by the service due to this security group rule.

0 Answers
Related