-
Couldn't load subscription status.
- Fork 4.3k
feat(batch): ecs execute command #35341
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Feature and tests look good, but please remove the Kiro instructions haha
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks like this was committed by mistake? Along with the other files in cckiro.
|
@iankhou Thank you for your review and I'm sorry for adding some docs. I've removed them. |
|
@iankhou Could you please confirm this PR again ? |
| private addEcsExecPermissions(role: iam.IRole): void { | ||
| role.addToPrincipalPolicy(new iam.PolicyStatement({ | ||
| effect: iam.Effect.ALLOW, | ||
| actions: [ | ||
| 'ssmmessages:CreateControlChannel', | ||
| 'ssmmessages:CreateDataChannel', | ||
| 'ssmmessages:OpenControlChannel', | ||
| 'ssmmessages:OpenDataChannel', | ||
| ], | ||
| resources: ['*'], |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, validated against docs: https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-iam-roles.html#ecs-exec-required-iam-permissions
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
This pull request has been removed from the queue for the following reason: The pull request can't be updated. You should update or rebase your pull request manually. If you do, this pull request will automatically be requeued once the queue conditions match again. |
Pull request has been modified.
|
@iankhou Could you please approve again? |
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
Comments on closed issues and PRs are hard for our team to see. |
Issue # (if applicable)
None
Reason for this change
AWS Batch now supports for ECS execute command(ECS exec) to access to the job container.
https://aws.amazon.com/about-aws/whats-new/2025/04/aws-batch-amazon-elastic-container-service-exec-firelens-log-router/?nc1=h_ls
Description of changes
enableExecuteCommandprop roEcsContainerDefinitionPropsDescribe any new or updated permissions being added
Description of how you validated changes
Add both unit and integ tests.
Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license