ECS cluster must have Container Insights enabled
Medium
AWS
General
aws-ecs-cluster-ecs-cluster-container-insights
Applies to
AWS::ECS::Cluster
What CGPulse checks
A resource passes this rule when settings.containerInsights must equal enabled. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Enable Container Insights to collect metrics and logs for monitoring. In AWS Console: ECS > Clusters > select cluster > Update > enable Container Insights. See: https://docs.aws.amazon.com/AmazonECS/latest/developerguide/cloudwatch-container-insights.html
CLI
aws ecs update-cluster-settings --cluster "{id}" --settings name=containerInsights,value=enabledTerraform
resource "aws_ecs_cluster" "{name}" {
setting {
name = "containerInsights"
value = "enabled"
}
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related AWS rules
- ACM certificate must be eligible for renewal
- ACM certificate must be in issued status
- Amplify app should have basic auth disabled for production
- API Gateway REST API must have an endpoint configuration
- API Gateway V2 API must be properly configured
- App Runner service must have encryption enabled
- AppSync API must have logging configured
- AppSync API must have X-Ray tracing enabled