Files
acdl/modules/l1/ecs-service
Jon Chery c80060878a feat(P56b): author 11 L1 module terraform subdirs + fix adapter output format
EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with
the full versions/variables/locals/main/outputs split. Defaults previously
hardcoded in the adapter move into locals.tf.

Simple single-resource modules (7):
- kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults)
- ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning)
- ecs-cluster: aws_ecs_cluster (name default)
- iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf)
- rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults)
- waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules)
- uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf)

Multi-resource modules with intra-refs (4):
- vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf)
- ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf)
- alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf)
- cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf)

Registry: terraform_dir added to all 11 remaining entries.

Adapter fix: stack output format uses separate 'from' + 'output' fields
(not 'from': 'rid.output'). Fixed _emit_root_output to read both fields.

6 previously-skipped tests unblocked (run_platform.sh --check-only now
resolves static-assets.yml through the new module-assembled adapter).
Removed skip markers. Fixed test assertion (aws_s3_bucket → module).

Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules
pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass
terraform init + validate standalone.

---ci---
project: acdl
phase: P56b
milestone: v1.11
status: execute
---/ci---
2026-07-28 16:07:57 +00:00
..

ecs-service — ECS Fargate service (task definition + service)

Module kind: primitive | Version: 1.0.0

An ECS Fargate service with its task definition. Runs a container image on Fargate, optionally behind an ALB target group. This is a multi-resource module: it creates a task definition and a service that runs it.

Resources

Resource Type Purpose
task_definition aws_ecs_task_definition Fargate task definition with container image, CPU, memory, port, env
service aws_ecs_service Fargate service running the task definition in a cluster + subnets

Inputs

Name Type Required Default Description
image string yes ECR image URL for the task container
port number yes Container port the service listens on
cpu number no 256 Task CPU units (Fargate)
memory number no 512 Task memory in MiB (Fargate)
env string no Environment variables as a JSON map string
cluster_arn arn yes ECS cluster ARN (from ecs-cluster)
subnets string yes Comma-separated subnet ids (from vpc)
security_group string yes Security group id for the service ENIs
lb_target_group_arn arn no Optional ALB target group ARN (from alb)
region string yes AWS region the service is created in

Outputs

Name Type Description
service_arn arn The ECS service ARN
task_def_arn arn The ECS task definition ARN

Usage

{
  "id": "service",
  "type": "aws:ecs:task_definition",
  "module": "ecs-service@1.0.0",
  "inputs": {
    "image": "581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest",
    "port": 8080,
    "cpu": 256,
    "memory": 512,
    "cluster_arn": "ref:cluster.cluster_arn",
    "subnets": "ref:vpc.subnet_ids",
    "security_group": "ref:roles.role_arn",
    "region": "us-east-1"
  }
}

The image, port, and env inputs are compiled into a container_definitions JSON block by the adapter. The service is placed in the cluster with the given subnets and security group, and optionally wired to the ALB target group if lb_target_group_arn is provided.

Compliance extension points

  • CloudWatch Logs — add logConfiguration to the container definition with a log group + retention policy (SOX, SOC2 CC7.2, DORA ICT incident logging).
  • Task execution role separation — add a separate aws_iam_role for execution vs. the task role (SOC2 CC6.3 segregation of duties at runtime).
  • Secrets injection — add secrets block referencing AWS Secrets Manager / SSM Parameter Store with KMS encryption (SOC2 CC6.1.
  • Execute command — add enable_execute_command with KMS encryption for session audit (SOC2 CC7.2).
  • Deployment circuit breaker — add deployment_circuit_breaker block for resilience (SOC2 CC9.1, DORA operational resilience).
  • Health check — add a health_check block to the target group (currently missing despite the contract schema having a healthcheck field).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: svc
infrastructure:
  ecs-service:
    inputs:
      image: public.ecr.aws/docker/library/nginx:latest
      name: my-service
      port: 80
      region: us-east-1
    version: 1.0.0
name: ecs-service

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: svc
infrastructure:
  ecs-service:
    inputs:
      env:
        ENVIRONMENT: production
        LOG_LEVEL: info
      image: public.ecr.aws/docker/library/nginx:latest
      name: my-production-service
      port: 8080
      region: us-east-1
    version: 1.0.0
name: ecs-service

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.