Files
acdl/modules/l1/ecs-service
Jon Chery de91a4bb76 feat(P31): encryption-by-default + per-stack CMK (REQ-83, REQ-84, REQ-85)
---ci---
project: acdl
phase: 31
milestone: v1.8
status: execute
---/ci---

- New kms-key L1 primitive (aws:kms:key) with enable_key_rotation=true
  (AWS-managed annual rotation, D-075). Registered in registry.json.
- Adapter TYPE_MAP expanded for aws:kms:key + aws:kms:alias.
- Adapter emits enable_key_rotation from NFR.
- S3 adapter emits server_side_encryption_configuration with KMS when
  kms_key_arn provided; managed KMS fallback with stderr warning when not.
- All 10 existing L1 primitives now have encryption_enabled NFR (default true).
- s3, rds, ecr, ecs-service, ecs-cluster have kms_key_arn input.
- Both L2 compositions (static-assets, microservice) now include a kms-key
  child + wires connecting kms_key_arn to children.
- L2 stack outputs include kms_key_arn.

Tests: +7 (300 -> 307). All pass. run_platform.sh --check-only green
(static-assets now resolves to 5 resources with the CMK).
2026-07-22 22:11:03 +00:00
..

ecs-service — ECS Fargate service (task definition + service)

Module kind: primitive | Version: 1.0.0

An ECS Fargate service with its task definition. Runs a container image on Fargate, optionally behind an ALB target group. This is a multi-resource module: it creates a task definition and a service that runs it.

Resources

Resource Type Purpose
task_definition aws_ecs_task_definition Fargate task definition with container image, CPU, memory, port, env
service aws_ecs_service Fargate service running the task definition in a cluster + subnets

Inputs

Name Type Required Default Description
image string yes ECR image URL for the task container
port number yes Container port the service listens on
cpu number no 256 Task CPU units (Fargate)
memory number no 512 Task memory in MiB (Fargate)
env string no Environment variables as a JSON map string
cluster_arn arn yes ECS cluster ARN (from ecs-cluster)
subnets string yes Comma-separated subnet ids (from vpc)
security_group string yes Security group id for the service ENIs
lb_target_group_arn arn no Optional ALB target group ARN (from alb)
region string yes AWS region the service is created in

Outputs

Name Type Description
service_arn arn The ECS service ARN
task_def_arn arn The ECS task definition ARN

Usage

{
  "id": "service",
  "type": "aws:ecs:task_definition",
  "module": "ecs-service@1.0.0",
  "inputs": {
    "image": "581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest",
    "port": 8080,
    "cpu": 256,
    "memory": 512,
    "cluster_arn": "ref:cluster.cluster_arn",
    "subnets": "ref:vpc.subnet_ids",
    "security_group": "ref:roles.role_arn",
    "region": "us-east-1"
  }
}

The image, port, and env inputs are compiled into a container_definitions JSON block by the adapter. The service is placed in the cluster with the given subnets and security group, and optionally wired to the ALB target group if lb_target_group_arn is provided.

Compliance extension points

  • CloudWatch Logs — add logConfiguration to the container definition with a log group + retention policy (SOX, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT incident logging).
  • Task execution role separation — add a separate aws_iam_role for execution vs. the task role (SOC2 CC6.3 segregation of duties at runtime).
  • Secrets injection — add secrets block referencing AWS Secrets Manager / SSM Parameter Store with KMS encryption (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv)).
  • Execute command — add enable_execute_command with KMS encryption for session audit (SOC2 CC7.2).
  • Deployment circuit breaker — add deployment_circuit_breaker block for resilience (SOC2 CC9.1, DORA operational resilience).
  • Health check — add a health_check block to the target group (currently missing despite the contract schema having a healthcheck field).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: ecs-service
environment: dev
inputs:
  name: my-service
  region: us-east-1
  image: public.ecr.aws/docker/library/nginx:latest
  port: 80

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex ECS service with env vars + health check
uses: acdl/pipelines/deploy.yaml@v1.6
module: ecs-service
environment: dev
inputs:
  name: my-production-service
  region: us-east-1
  image: public.ecr.aws/docker/library/nginx:latest
  port: 8080
  env:
    LOG_LEVEL: info
    ENVIRONMENT: production

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.