shiichan

AWS Network Firewall Now Speaks Container!

Heya, it's me, Shiichan! Today I found a fun little update for network security, so let me tell you about it!

AWS What's New aws.amazon.com

What was announced?

Over on AWS's What's New, they announced that AWS Network Firewall now supports container attribute-based inspection! It covers Amazon EKS and Amazon ECS. Instead of writing firewall rules around IP addresses like before, you can now write them using the container's own native constructs. You can see the big picture on the product page too.

The story so far

Containers keep changing their IP addresses every time they scale out or get rescheduled. So building firewall rules around IPs tended to get really complex. A simple intent like "let only this Pod reach this domain" would end up buried under IP management.

What changes

From now on, you can write policies using the native container structure instead of IPs!

  • For Amazon EKS: Namespace / Cluster Name / Labels
  • For Amazon ECS: Cluster Name / Container Instance Attributes

And even when your containers scale, the rules follow along automatically. Not having to chase IPs around is a big relief for anyone running these workloads!

Dive Deep

Once you match on container attributes, you can combine inspections like these:

  • TLS decryption for deep packet inspection
  • FQDN-based filtering to restrict pods to approved domains
  • URL category filtering
  • GeoIP filtering

These adapt automatically as your containers scale. For the finer details on URL filtering, check the documentation when you build your rule groups.

As for the price you might be wondering about, this feature is available at no additional cost as part of AWS Network Firewall. For supported Regions, take a look at the AWS Capabilities by Region page.

Wrap-up

  • AWS Network Firewall now supports container attribute-based inspection (for EKS and ECS)
  • Write rules with container structure like Namespaces and Labels instead of IPs
  • Combine it with TLS decryption, FQDN, URL category, and GeoIP filtering
  • Follows scaling automatically, and at no additional cost

This one's for all you EKS / ECS folks who want to keep a tight grip on network traffic in your container environments!