AWS ECS/EKS container security scanner with compliance mapping for CIS, PCI-DSS, HIPAA, SOC 2, ISO
482
A comprehensive AWS ECS and EKS container security scanner with multi-framework compliance mapping. It audits ECS clusters, services, and task definitions, EKS clusters and node groups, IAM/IRSA configuration, and ECR repositories for security misconfigurations and compliance gaps. The scanner is read-only and never modifies AWS resources.
~/.aws is readable (see Credentials).docker pull tarekcheikh/ecs-eks-security-scanner:latest
# Show help
docker run --rm tarekcheikh/ecs-eks-security-scanner --help
# Run a scan with mounted AWS credentials, writing reports to ./output
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v "$(pwd)/output:/app/output" \
tarekcheikh/ecs-eks-security-scanner security -r us-east-1
The image ENTRYPOINT is ecs-eks-security-scanner, so arguments after the image
name are passed straight to the CLI (for example security, --help).
The container reads AWS credentials either from a mounted profile directory or
from environment variables. The image intentionally runs as root so that a host
~/.aws/credentials file (mode 0600, owned by your user) is readable inside the
container.
Mounted profile (supports -p/--profile):
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v "$(pwd)/output:/app/output" \
tarekcheikh/ecs-eks-security-scanner security -p production -r us-east-1
Environment variables (including temporary/assumed-role credentials):
docker run --rm \
-e AWS_ACCESS_KEY_ID \
-e AWS_SECRET_ACCESS_KEY \
-e AWS_SESSION_TOKEN \
-e AWS_DEFAULT_REGION=us-east-1 \
-v "$(pwd)/output:/app/output" \
tarekcheikh/ecs-eks-security-scanner security
Note: IAM Identity Center (SSO) sessions do not resolve inside the container.
Export process credentials first (for example
aws configure export-credentials --format env) and pass them as environment
variables.
Checks span 8 categories across ECS and EKS:
The ECS scanner evaluates task definitions referenced by services. CIS Kubernetes in-cluster sections (kubelet, RBAC, Pod Security) require kubectl access and are out of scope for an AWS-API-only scanner.
Controls mapped across 11 frameworks:
Mapping API-layer container checks to broad governance frameworks is partial technical evidence, not a compliance attestation.
Each scan produces a per-cluster 0-100 security score and reports in the mounted
output directory (default /app/output in the container, mapped to ./output):
Select the format with -f json|csv|html|all (default all).
The scanner needs read-only access only: ecs:Describe* and ecs:List*,
eks:Describe* and eks:List*, ec2:Describe*, iam:Get* and iam:List*,
ecr:Describe*, guardduty:List* and guardduty:Get*, and
sts:GetCallerIdentity. The full minimal policy is in the repository README.
The scanner performs no write or delete actions.
latest: most recent release1.0.0: pinned versionImages are published for linux/amd64 and linux/arm64.
Content type
Image
Digest
sha256:93e87ac46…
Size
127.5 MB
Last updated
3 months ago
docker pull tarekcheikh/ecs-eks-security-scanner