The amazon ecs container agent provides an api operation for gathering details about the container instance on which the agent is running and the associated tasks running on that instance.
Aws ecs container metadata.
Task metadata endpoint version 2 available for amazon ecs tasks on aws fargate that use platform version 1 1 0 or later and tasks that are launched on amazon ec2 infrastructure that use the awsvpc network mode and are running at least version 1 17 0 of the amazon ecs container agent.
Short description if you run containers in an amazon ec2 instance it s a best practice for security reasons to avoid allowing your applications to assume an instance role.
For reference these are the blog posts in this series.
Previously if an application running in a container managed by amazon ecs required access to information about its environment you needed to manually call this metadata using the docker or amazon ecs.
Welcome to part 3 of this blog post series on how to use amazon efs with amazon ecs and aws fargate.
The task metadata and network rate stats are sent to cloudwatch container insights and can be viewed in the aws management console.
Your container will now be running and will be using temporary credentials obtained from your default aws command line interface profile.
Beginning with version 1 15 0 of the amazon ecs container agent various container metadata is available within your containers or the host container instance.
Beginning with version 1 17 0 of the amazon ecs container agent various task metadata and docker stats are available to tasks that use the awsvpc network mode at an http endpoint that is provided by the amazon ecs container agent.
This blog provides the background about the need for this integration its scope and provides a high level view of the use cases.
The metadata file is created on the host instance and mounted in the.
The amazon ecs container agent injects an environment variable into each container referred to as the task metadata endpoint which provides various task metadata and docker stats to the container.
You should not use your production credentials locally if you provide the ecs local endpoints with an aws profile that has access to your production account then your application will be able to.
By enabling this feature you can query the information about a task container and container instance from within the container or the host container instance.
I want to prevent containers from accessing amazon elastic compute cloud amazon ec2 instance metadata in amazon elastic container service amazon ecs.
All containers belonging to tasks that are launched with the awsvpc network mode receive a local ipv4 address within a predefined link local address range.