Ensure that your Amazon ECS cluster instances are running the latest version of ECS container agent in order to introduce bug fixes and new software features. Updating the Amazon ECS container agent does not interrupt running tasks or services on the container instances.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
excellence
Each Amazon ECS container agent version supports a different set of features and improvements, and provides bug fixes from previous versions, therefore it is strongly recommended to configure your ECS cluster instances to update the Amazon ECS container agent to the latest version.
Audit
To determine if your Amazon ECS cluster instances are using the latest ECS container agent version, perform the following operations:
Remediation / Resolution
To update the Amazon ECS container agent to the latest version supported by Amazon ECS for all your container instances, perform the following operations:
Note: As example, this section demonstrates how to update the Amazon ECS container agent on container instances using ECS-Optimized Amazon Linux AMIs.References
- AWS Documentation
- Amazon Elastic Container Service FAQs
- Amazon ECS Container Agent Versions
- Updating the Amazon ECS Container Agent
- Updating the Amazon ECS Container Agent on an Amazon ECS-optimized AMI
- AWS Command Line Interface (CLI) Documentation
- ecs
- list-clusters
- list-container-instances
- describe-container-instances
- update-container-agent
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Check for ECS Container Instance Agent Version
Risk Level: Medium