The Amazon ECS container agent makes calls to the Amazon ECS API actions on your behalf, so it requires an IAM policy and role for the service to know that the agent belongs to you
Only relevant for FARGATE.
See ECS Task Execution IAM Role for more details about task execution roles.