Files
acdl/modules/l2/microservice
Jon Chery cec34abc22 fix(P04 W1): ecs-service execution_role_arn + task_role_arn wiring (live apply gap)
The live terraform apply (P4) uncovered a P2 module-completeness gap: the
ecs-service L1 aws_ecs_task_definition was missing execution_role_arn +
task_role_arn, and the microservice L2 composition did not wire
roles.outputs.role_arn to the service. Fargate requires an execution role
for ECR image pull. Fixed: interface.json + variables.tf + main.tf +
composition.json wires. The iam-role assume-policy trusts ecs-tasks +
the inline policy grants ECR pull + CW logs.

A second live gap surfaced once the task definition applied: the ALB
aws_lb had no security group (AWS rejects an ALB with an empty SG list).
The platform VPC only outputs an ECS SG; the composition now wires
platform_vpc.outputs.ecs_security_group_id to alb.inputs.security_group
(the ECS SG opens port 80 to 0.0.0.0/0 — acceptable for an internet-facing
ALB + dev pilot per D-020). No iam-role module changes were needed — its
locals.tf already trusts ecs-tasks.amazonaws.com and grants ECR pull +
CloudWatch logs by default.

Live apply now succeeds: Apply complete! Resources: 0 added, 1 changed, 0
destroyed (task def + ECS service created on the first re-apply; ALB SG
updated in-place on the second). Full suite: 844 passed.

---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W1
---
2026-08-19 03:01:47 +00:00
..

microservice — ECS Fargate microservice

Module kind: module pattern | Version: 1.0.0

A pattern that references multiple primitives to deploy an ECS Fargate microservice end-to-end (VPC, cluster, ECR, IAM role, ALB, ECS service).

Resources

The pattern references these primitives:

Primitive Purpose README
vpc VPC, subnets, routing README
ecs-cluster ECS Fargate cluster README
ecr ECR image repository README
iam-role IAM task execution role README
alb Application Load Balancer README
ecs-service ECS task definition + service README

Inputs

Name Type Required Description
image string yes ECR image URL for the task container
port number yes Container port the service listens on
region string yes AWS region
cidr string no VPC CIDR block (default 10.0.0.0/16)
azs string no Comma-separated availability zones

Outputs

Name Type Description
lb_arn arn The load balancer ARN
service_arn arn The ECS service ARN

Usage

Define a contract referencing this module:

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      image: 581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest
      port: 8080
      region: us-east-1
    version: 1.0.0
name: microservice

Compliance extension points

The pattern can wire compliance resources across primitives when the compliance milestone (GDPR, SOX, SOC2, DORA) lands:

  • KMS key — shared encryption key referenced by S3, ECR, CloudWatch Logs, and Secrets Manager.
  • CloudTrail — management-plane audit trail for the entire stack.
  • VPC Flow Logs — network audit trail.
  • Security groups — proper network segmentation between ALB, service, and data tiers.
  • Private subnets — ECS tasks in private subnets with NAT egress.

See each primitive's README for per-module compliance extension points.

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment (minimal Fargate, no ALB):

examples/simple.yml

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      bucket_name: my-microservice-demo
      image: public.ecr.aws/docker/library/nginx:latest
      port: 80
      region: us-east-1
    version: 1.0.0
name: microservice

Complex

A production deployment with optional inputs (ALB + env vars + health check):

examples/complex.yml

environment: dev
id: msvc
infrastructure:
  microservice:
    inputs:
      bucket_name: my-production-microservice
      env:
        ENVIRONMENT: production
        LOG_LEVEL: info
      image: public.ecr.aws/docker/library/nginx:latest
      port: 8080
      region: us-east-1
    version: 1.0.0
name: microservice

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.