|
Feature
|
Description
|
||
|
Runtime Security
|
Provides visibility into any activity of your running containers
that violates a customizable set of rules.
|
||
|
Runtime Scanning
|
Provides visibility of operating system and open source code
vulnerabilities that are part of containers running in
clusters.
|
Procedure
- Go to .
- In the tree, click Amazon ECS, locate and click the cluster in the list.
- Turn on Runtime Security.
- Turn on Runtime Scanning.
- Click Save.
ImportantIf the ECS cluster has the
trendmicro:patch-exclude=true AWS tag
applied, enabling Runtime Security marks the cluster as enabled in the console
but does not trigger patching of task definitions. No Container Security
containers will be injected into the cluster's Fargate tasks until the tag is
removed. For more information, see Exclude an Amazon ECS cluster from patching. |
NoteIf your ECS cluster uses Bottlerocket AMI, additional configuration is required
before Container Security can be deployed. See Enable Container
Security on Amazon ECS Bottlerocket instances for more information.
|
