Amazon Elastic Container Service
Educational simulation No cloud connection
0 of 9 objectives completeScore: 0 / 100
RCW guided deployment

Secure and resilient container service

Plan, deploy, validate, monitor, and approve a production-shaped web application on Amazon ECS with AWS Fargate.

Intermediate · 75–100 min
This is an interactive console simulation.

No AWS account, credentials, internet calls, cloud resources, or charges are used. Product names teach the workflow; no vendor logo is used.

Scenario

Deploy the RCW Orders service

A business-critical containerized web API must be reachable through HTTPS while its tasks remain private. Security, platform, and operations teams require traceable controls before a limited release.

  • Scan and pin an immutable container image
  • Separate build, execution, and runtime permissions
  • Run two non-root Fargate tasks across Availability Zones
  • Terminate TLS at an Application Load Balancer
  • Prove health, rollback, scaling, logging, and cleanup
Reference architecture

Private multi-AZ Fargate service

Simulated
Amazon ECS Fargate reference architectureA user reaches an HTTPS application load balancer in public subnets. The load balancer sends traffic to two ECS Fargate tasks in private subnets. Tasks pull a pinned image from ECR, retrieve a secret, and send logs to CloudWatch through private endpoints. CloudTrail and security services collect evidence. USERClient HTTPSPublic ALB ECSFargate servicePrivate subnets TASK AAZ-a · private TASK BAZ-b · private ECR + SECRETSPrivate endpoints OBSERVELogs and metrics CloudTrail · Config · Security Hub · GuardDuty · KMS · evidence owner
Objective 1 · 10 points

Authorize the workload boundary

Required
Required guardrails
Mandatory control gates

Release readiness

GovernanceOwner, classification, scopePending
Supply chainImmutable, scanned imagePending
Runtime hardeningNon-root, read-only, logsPending
Operational proofHealth, rollback, scalePending
Human approvalEvidence and release decisionPending
Start with the workload boundary before creating resources.
RCW IT Training

Amazon ECS GUI lab guide

Goal

Deploy a production-shaped, secure Fargate service while collecting auditable evidence. Complete all nine objectives in order.

  1. Authorize scopeName the owner, data class, IaC obligation, and limited release.
  2. Prepare ECRUse KMS, immutable digest, continuous scanning, lifecycle, SBOM, and trusted build evidence.
  3. Separate IAM rolesUse distinct build, execution, and task permissions plus a referenced secret.
  4. Create clusterSelect Fargate, enhanced observability, encryption, tags, budget, and break-glass policy.
  5. Register taskPin the image and enforce non-root, read-only, non-privileged, health, logging, and secret controls.
  6. Protect networkPlace only the HTTPS ALB in public subnets; keep tasks private in two AZs with endpoints.
  7. Create serviceRun two tasks with rolling safety, automatic rollback, AZ rebalancing, and bounded scaling.
  8. Validate operationsRun all checks and the deliberately failed deployment rollback drill.
  9. Approve pilotMap evidence, own residual risk, set review date, and download evidence/certificate.
!
Production caution

Confirm current Region support, quotas, pricing, organization policies, threat model, recovery objectives, legal duties, and control applicability. Use reviewed IaC and a separated delivery pipeline.

Open the complete step-by-step lab guide

Lab complete

Amazon ECS End-to-End Lab Champion

You completed every mandatory control gate and approved only a limited monitored pilot.

100/ 100 points

Issued by RCW IT Training · Signed by Pradeep Raju · Educational achievement certificate

Reset simulation

Delete local lab progress?

This clears the simulated resources, score, validation evidence, and learner name from this browser.