ciaran
03/25/2021, 1:48 PMZanie
ciaran
03/25/2021, 2:18 PMciaran
03/25/2021, 2:18 PMciaran
03/25/2021, 2:18 PMZanie
Zanie
Here are the permissions that we use for ESC/Fargate. Our agent (0.14.6) has the following permissions to use boto3 for submitting tasks - AmazonS3FullAccess and AmazonECSFull Access. Our task_run_arn has the following permissions: AmazonS3FullAccess and AmazonEC2ContainerRegistryFullAccess. Our execution_run_arn has AmazonEcsTaskExecutionRole.
It could be that weβre too lenient on permissions and could scale them back - its on our todo list but this got us unblocked. HTH.
ciaran
03/25/2021, 2:20 PMZanie
ciaran
03/25/2021, 2:20 PMZanie
ciaran
03/25/2021, 2:20 PMZanie
Zanie
ciaran
03/25/2021, 2:21 PMciaran
03/25/2021, 2:23 PMZanie