The Amazon ECS container agent makes calls to the Amazon ECS API actions on your behalf, so it requires an IAM policy and role for the service to know that the agent belongs to you

Only relevant for FARGATE. If not specified, the plugin will try to use the default ecsTaskExecutionRole role

See ECS Task Execution IAM Role for more details about task execution roles.