Files
acdl/modules/l1/ecs-service
Jon Chery e1be05287b feat(P39): refresh design docs + parameterize adapter (P1-1)
---ci---
project: acdl
phase: 39
milestone: v1.9
status: execute
---/ci---

Phase 39 — design-doc-refresh-and-p1-1-parameterization:

Design docs (REQ-100, REQ-101):
- hitl_matrix_design.md: 'dev-only spike'/'v1.2 wires the gates' framing
  replaced with v1.9 wired-gates reality; 8-concern matrix marked
  implemented (offline-testable subset + signed evidence artifacts,
  D-084); v1.9 wiring section cross-references hitl_gates.py +
  attestation_matrix.py; approver_dr noted.
- audit_ledger_design.md: outbox marked shipped+production since v1.8;
  S3 Object Lock + JWS + async worker + DLQ + daily checkpoints clearly
  labeled 'Deferred to a future milestone (D-083)'; RPO/RTO table updated;
  approver fields note v1.9 hitl_gates.attest.

P1-1 adapter parameterization (REQ-102, D-085):
- ecs-service interface.json: desired_count (default 1), launch_type
  (FARGATE), family (app) inputs added.
- alb interface.json: load_balancer_type (application), target_type (ip).
- adapter.py: hardcoded defaults replaced with inputs.get(<name>, <default>);
  hardcoded 'acdl-microservice-rt'/'acdl-microservice-igw' Name tags
  derive from the VPC name input.
- contract_resolver.py: child_input_map routes wires to the sub-resource
  that declares the input (desired_count → aws:ecs:service, family →
  aws:ecs:task_definition, target_type → targetgroup, etc.).
- microservice composition.json: wires added for the new inputs.

Tests: +21 (test_p1_1_adapter_parameterization.py, test_design_docs_current.py).
371 passed; run_ci.sh green; run_platform.sh --check-only green; v1.1 S3
regression preserved.
2026-07-23 04:24:25 +00:00
..

ecs-service — ECS Fargate service (task definition + service)

Module kind: primitive | Version: 1.0.0

An ECS Fargate service with its task definition. Runs a container image on Fargate, optionally behind an ALB target group. This is a multi-resource module: it creates a task definition and a service that runs it.

Resources

Resource Type Purpose
task_definition aws_ecs_task_definition Fargate task definition with container image, CPU, memory, port, env
service aws_ecs_service Fargate service running the task definition in a cluster + subnets

Inputs

Name Type Required Default Description
image string yes ECR image URL for the task container
port number yes Container port the service listens on
cpu number no 256 Task CPU units (Fargate)
memory number no 512 Task memory in MiB (Fargate)
env string no Environment variables as a JSON map string
cluster_arn arn yes ECS cluster ARN (from ecs-cluster)
subnets string yes Comma-separated subnet ids (from vpc)
security_group string yes Security group id for the service ENIs
lb_target_group_arn arn no Optional ALB target group ARN (from alb)
region string yes AWS region the service is created in

Outputs

Name Type Description
service_arn arn The ECS service ARN
task_def_arn arn The ECS task definition ARN

Usage

{
  "id": "service",
  "type": "aws:ecs:task_definition",
  "module": "ecs-service@1.0.0",
  "inputs": {
    "image": "581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest",
    "port": 8080,
    "cpu": 256,
    "memory": 512,
    "cluster_arn": "ref:cluster.cluster_arn",
    "subnets": "ref:vpc.subnet_ids",
    "security_group": "ref:roles.role_arn",
    "region": "us-east-1"
  }
}

The image, port, and env inputs are compiled into a container_definitions JSON block by the adapter. The service is placed in the cluster with the given subnets and security group, and optionally wired to the ALB target group if lb_target_group_arn is provided.

Compliance extension points

  • CloudWatch Logs — add logConfiguration to the container definition with a log group + retention policy (SOX, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT incident logging).
  • Task execution role separation — add a separate aws_iam_role for execution vs. the task role (SOC2 CC6.3 segregation of duties at runtime).
  • Secrets injection — add secrets block referencing AWS Secrets Manager / SSM Parameter Store with KMS encryption (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv)).
  • Execute command — add enable_execute_command with KMS encryption for session audit (SOC2 CC7.2).
  • Deployment circuit breaker — add deployment_circuit_breaker block for resilience (SOC2 CC9.1, DORA operational resilience).
  • Health check — add a health_check block to the target group (currently missing despite the contract schema having a healthcheck field).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: ecs-service
environment: dev
inputs:
  name: my-service
  region: us-east-1
  image: public.ecr.aws/docker/library/nginx:latest
  port: 80

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex ECS service with env vars + health check
uses: acdl/pipelines/deploy.yaml@v1.6
module: ecs-service
environment: dev
inputs:
  name: my-production-service
  region: us-east-1
  image: public.ecr.aws/docker/library/nginx:latest
  port: 8080
  env:
    LOG_LEVEL: info
    ENVIRONMENT: production

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.