Three fixes from CI run 3027 (06f4fc7):
1. ALB name_prefix too long: AWS limits target group name_prefix to 6
chars. Changed from "acdl-ci-alb-" (12) to "tg-ci-" (6).
2. Adapter deduplication: multi-resource L1s (cloudfront with
distribution + OAC) expand to multiple stack resources sharing the
same terraform dir. The adapter was emitting TWO module blocks for
the same dir, the second missing required inputs. Now deduplicates
by terraform dir, merging inputs from all resources that point to
it. Adapter stays under 200 lines (194).
3. L2 microservice composition: ECR module requires "name" input but
the composition didn't wire it. Added wires for ecr.inputs.name
(default "app-repo") and roles.inputs.role_name (default "app-role").
Note: the ecs-service/uptime/rds failures in run 3027 were caused by
the P64 teardown destroying the CI VPC while the pipeline was still
running (timing issue). The next CI run after this push will have a
fresh CI VPC.
Regression: 485 passed, 5 deselected.
---ci---
project: acdl
phase: P60
milestone: v1.11
status: execute
---/ci---
microservice — ECS Fargate microservice
Module kind: module pattern | Version: 1.0.0
A pattern that references multiple primitives to deploy an ECS Fargate microservice end-to-end (VPC, cluster, ECR, IAM role, ALB, ECS service).
Resources
The pattern references these primitives:
| Primitive | Purpose | README |
|---|---|---|
vpc |
VPC, subnets, routing | README |
ecs-cluster |
ECS Fargate cluster | README |
ecr |
ECR image repository | README |
iam-role |
IAM task execution role | README |
alb |
Application Load Balancer | README |
ecs-service |
ECS task definition + service | README |
Inputs
| Name | Type | Required | Description |
|---|---|---|---|
image |
string | yes | ECR image URL for the task container |
port |
number | yes | Container port the service listens on |
region |
string | yes | AWS region |
cidr |
string | no | VPC CIDR block (default 10.0.0.0/16) |
azs |
string | no | Comma-separated availability zones |
Outputs
| Name | Type | Description |
|---|---|---|
lb_arn |
arn | The load balancer ARN |
service_arn |
arn | The ECS service ARN |
Usage
Define a contract referencing this module:
environment: dev
id: msvc
infrastructure:
microservice:
inputs:
image: 581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest
port: 8080
region: us-east-1
version: 1.0.0
name: microservice
Compliance extension points
The pattern can wire compliance resources across primitives when the compliance milestone (GDPR, SOX, SOC2, DORA) lands:
- KMS key — shared encryption key referenced by S3, ECR, CloudWatch Logs, and Secrets Manager.
- CloudTrail — management-plane audit trail for the entire stack.
- VPC Flow Logs — network audit trail.
- Security groups — proper network segmentation between ALB, service, and data tiers.
- Private subnets — ECS tasks in private subnets with NAT egress.
See each primitive's README for per-module compliance extension points.
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment (minimal Fargate, no ALB):
environment: dev
id: msvc
infrastructure:
microservice:
inputs:
bucket_name: my-microservice-demo
image: public.ecr.aws/docker/library/nginx:latest
port: 80
region: us-east-1
version: 1.0.0
name: microservice
Complex
A production deployment with optional inputs (ALB + env vars + health check):
environment: dev
id: msvc
infrastructure:
microservice:
inputs:
bucket_name: my-production-microservice
env:
ENVIRONMENT: production
LOG_LEVEL: info
image: public.ecr.aws/docker/library/nginx:latest
port: 8080
region: us-east-1
version: 1.0.0
name: microservice
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.