Define trust boundaries
Separate the public API, scheduler, credential broker, artifact service, and execution runtime. The control plane should never mount a tenant workspace or execute tenant commands. Sandboxes should communicate through narrow authenticated APIs or queues. Use one Fargate task, microVM, or VM per tenant session boundary. Fargate isolates tasks from each other, but containers within one task share compute, network, and ephemeral storage.Minimize identity
Give each task a session-scoped IAM role whenever architecture permits. Deny all by default. Scope access to exact S3 prefixes, queues, model endpoints, and KMS keys. Do not expose the control-plane role, AWS account credentials, or another tenant’s secret path. Short-lived credentials reduce exposure but do not replace least privilege. A credential valid for ten minutes can still cause significant damage in ten seconds.Restrict the runtime
Run as non-root. Use a read-only root filesystem and explicit writable mounts. Drop unnecessary Linux capabilities. Disallow privileged containers. Pin the image digest, scan dependencies, and rebuild after base-image security updates. Set hard CPU, memory, storage, process, log, and time limits. Stop tasks that miss heartbeats or exceed idle limits.Enforce egress policy
Block metadata, link-local, private networks, control-plane services, and unrelated customer resources. Use a proxy or firewall for allowlisted public destinations. Resolve and validate redirects to reduce SSRF and DNS-rebinding paths. Network policy should be tied to the session’s purpose. A coding agent may need a package mirror and GitHub. A private data-analysis job may need no public internet.Protect logs and artifacts
Logs can contain source code, prompts, credentials, and personal data. Redact known secret formats, cap output, encrypt at rest, scope read access, and set retention. Treat generated archives, binaries, HTML, notebooks, and office files as untrusted downloads.Detect abuse
Rate-limit task creation, cap concurrent sessions, detect cryptocurrency mining and scanning patterns, and preserve enough audit data to investigate incidents. Build a kill switch that stops sessions and revokes credentials independently of the agent.Frequently asked questions
Does Fargate isolate different agent sessions?
Does Fargate isolate different agent sessions?
Each Fargate task has a dedicated isolation boundary for kernel, CPU, memory, network interface, and ephemeral storage. Application identity, egress, credentials, browser security, and data scope still require explicit design.
Is a read-only filesystem enough?
Is a read-only filesystem enough?
No. Agents need some writable workspace, and they can still misuse network or credentials. Read-only roots reduce persistence and tampering but are one defense among many.