Files
acdl/modules/l2/microservice
Jon Chery a03c01932f
acdl-ci / Lint (pull_request) Successful in 7s
acdl-ci / Test (pull_request) Successful in 4m37s
acdl-ci / Platform check-only (offline) (pull_request) Successful in 21s
acdl-modules-lifecycle / CI VPC apply (pull_request) Successful in 40s
acdl-modules-lifecycle / L1 lifecycle (alb) (pull_request) Failing after 4m56s
acdl-modules-lifecycle / L1 lifecycle (ecr) (pull_request) Successful in 2m48s
acdl-modules-lifecycle / L1 lifecycle (cloudfront) (pull_request) Successful in 9m17s
acdl-modules-lifecycle / L1 lifecycle (ecs-cluster) (pull_request) Successful in 3m5s
acdl-modules-lifecycle / L1 lifecycle (iam-role) (pull_request) Successful in 2m52s
acdl-modules-lifecycle / L1 lifecycle (ecs-service) (pull_request) Successful in 4m9s
acdl-modules-lifecycle / L1 lifecycle (kms-key) (pull_request) Successful in 2m58s
acdl-modules-lifecycle / L1 lifecycle (s3) (pull_request) Successful in 2m59s
acdl-modules-lifecycle / L1 lifecycle (uptime) (pull_request) Successful in 4m7s
acdl-modules-lifecycle / L1 lifecycle (vpc) (pull_request) Successful in 3m9s
acdl-modules-lifecycle / L1 lifecycle (waf) (pull_request) Successful in 3m26s
acdl-modules-lifecycle / L2 lifecycle (microservice) (pull_request) Failing after 1m7s
acdl-modules-lifecycle / L2 lifecycle (static-assets) (pull_request) Failing after 1m27s
acdl-modules-lifecycle / L1 lifecycle (rds) (pull_request) Successful in 32m48s
acdl-modules-lifecycle / CI VPC destroy (pull_request) Failing after 20m42s
fix(P60/P62): ALB name_prefix + adapter dedup + L2 composition wiring
Three fixes from CI run 3027 (06f4fc7):

1. ALB name_prefix too long: AWS limits target group name_prefix to 6
   chars. Changed from "acdl-ci-alb-" (12) to "tg-ci-" (6).

2. Adapter deduplication: multi-resource L1s (cloudfront with
   distribution + OAC) expand to multiple stack resources sharing the
   same terraform dir. The adapter was emitting TWO module blocks for
   the same dir, the second missing required inputs. Now deduplicates
   by terraform dir, merging inputs from all resources that point to
   it. Adapter stays under 200 lines (194).

3. L2 microservice composition: ECR module requires "name" input but
   the composition didn't wire it. Added wires for ecr.inputs.name
   (default "app-repo") and roles.inputs.role_name (default "app-role").

Note: the ecs-service/uptime/rds failures in run 3027 were caused by
the P64 teardown destroying the CI VPC while the pipeline was still
running (timing issue). The next CI run after this push will have a
fresh CI VPC.

Regression: 485 passed, 5 deselected.

---ci---
project: acdl
phase: P60
milestone: v1.11
status: execute
---/ci---
2026-07-29 12:22:00 +00:00
..

microservice — ECS Fargate microservice

Module kind: module pattern | Version: 1.0.0

A pattern that references multiple primitives to deploy an ECS Fargate microservice end-to-end (VPC, cluster, ECR, IAM role, ALB, ECS service).

Resources

The pattern references these primitives:

Primitive Purpose README
vpc VPC, subnets, routing README
ecs-cluster ECS Fargate cluster README
ecr ECR image repository README
iam-role IAM task execution role README
alb Application Load Balancer README
ecs-service ECS task definition + service README

Inputs

Name Type Required Description
image string yes ECR image URL for the task container
port number yes Container port the service listens on
region string yes AWS region
cidr string no VPC CIDR block (default 10.0.0.0/16)
azs string no Comma-separated availability zones

Outputs

Name Type Description
lb_arn arn The load balancer ARN
service_arn arn The ECS service ARN

Usage

Define a contract referencing this module:

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      image: 581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest
      port: 8080
      region: us-east-1
    version: 1.0.0
name: microservice

Compliance extension points

The pattern can wire compliance resources across primitives when the compliance milestone (GDPR, SOX, SOC2, DORA) lands:

  • KMS key — shared encryption key referenced by S3, ECR, CloudWatch Logs, and Secrets Manager.
  • CloudTrail — management-plane audit trail for the entire stack.
  • VPC Flow Logs — network audit trail.
  • Security groups — proper network segmentation between ALB, service, and data tiers.
  • Private subnets — ECS tasks in private subnets with NAT egress.

See each primitive's README for per-module compliance extension points.

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment (minimal Fargate, no ALB):

examples/simple.yml

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      bucket_name: my-microservice-demo
      image: public.ecr.aws/docker/library/nginx:latest
      port: 80
      region: us-east-1
    version: 1.0.0
name: microservice

Complex

A production deployment with optional inputs (ALB + env vars + health check):

examples/complex.yml

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      bucket_name: my-production-microservice
      env:
        ENVIRONMENT: production
        LOG_LEVEL: info
      image: public.ecr.aws/docker/library/nginx:latest
      port: 8080
      region: us-east-1
    version: 1.0.0
name: microservice

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.