# ecs-service — ECS Fargate service (task definition + service) > **Module kind:** primitive | **Version:** 1.0.0 An ECS Fargate service with its task definition. Runs a container image on Fargate, optionally behind an ALB target group. This is a multi-resource module: it creates a task definition and a service that runs it. ## Resources | Resource | Type | Purpose | |----------|------|---------| | task_definition | `aws_ecs_task_definition` | Fargate task definition with container image, CPU, memory, port, env | | service | `aws_ecs_service` | Fargate service running the task definition in a cluster + subnets | ## Inputs | Name | Type | Required | Default | Description | |------|------|----------|---------|-------------| | `image` | string | yes | — | ECR image URL for the task container | | `port` | number | yes | — | Container port the service listens on | | `cpu` | number | no | 256 | Task CPU units (Fargate) | | `memory` | number | no | 512 | Task memory in MiB (Fargate) | | `env` | string | no | — | Environment variables as a JSON map string | | `cluster_arn` | arn | yes | — | ECS cluster ARN (from `ecs-cluster`) | | `subnets` | string | yes | — | Comma-separated subnet ids (from `vpc`) | | `security_group` | string | yes | — | Security group id for the service ENIs | | `lb_target_group_arn` | arn | no | — | Optional ALB target group ARN (from `alb`) | | `region` | string | yes | — | AWS region the service is created in | ## Outputs | Name | Type | Description | |------|------|-------------| | `service_arn` | arn | The ECS service ARN | | `task_def_arn` | arn | The ECS task definition ARN | ## Usage ```json { "id": "service", "type": "aws:ecs:task_definition", "module": "ecs-service@1.0.0", "inputs": { "image": "581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest", "port": 8080, "cpu": 256, "memory": 512, "cluster_arn": "ref:cluster.cluster_arn", "subnets": "ref:vpc.subnet_ids", "security_group": "ref:roles.role_arn", "region": "us-east-1" } } ``` The `image`, `port`, and `env` inputs are compiled into a `container_definitions` JSON block by the adapter. The service is placed in the cluster with the given subnets and security group, and optionally wired to the ALB target group if `lb_target_group_arn` is provided. ## Compliance extension points - **CloudWatch Logs** — add `logConfiguration` to the container definition with a log group + retention policy (SOX, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT incident logging). - **Task execution role separation** — add a separate `aws_iam_role` for execution vs. the task role (SOC2 CC6.3 segregation of duties at runtime). - **Secrets injection** — add `secrets` block referencing AWS Secrets Manager / SSM Parameter Store with KMS encryption (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv)). - **Execute command** — add `enable_execute_command` with KMS encryption for session audit (SOC2 CC7.2). - **Deployment circuit breaker** — add `deployment_circuit_breaker` block for resilience (SOC2 CC9.1, DORA operational resilience). - **Health check** — add a `health_check` block to the target group (currently missing despite the contract schema having a healthcheck field). ## Versioning `1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.