ECS Cluster
An ECS cluster with Container Insights, or a handle on a customer owned cluster.
GovCloudView source
- Module
- ecs-cluster
- Layer
- Compute
- Interface
- 7 inputs, 3 outputs
- Used by
- 13 Kaizen apps
Why it matters
A cluster is the named home where an app's containers run. Most Kaizen apps create their own, but a federal customer often owns the cluster inside an account Kaizen cannot change. One setting switches this module from creating a cluster to adopting the customer's, so the rest of the stack stays the same.
Use it when
- A new app needs a cluster for its ecs-service.
- The customer owns the cluster. Set create_cluster = false and existing_cluster_name.
Reach for something else when
- You want to run containers. The cluster only groups them, so pair it with a service. Use ecs-service.
What it creates
aws_ecs_cluster(when create_cluster = true, Container Insights on)aws_ecs_cluster_capacity_providers(FARGATE and FARGATE_SPOT, only when enable_fargate_capacity_providers = true)data.aws_ecs_cluster(when create_cluster = false, adopts existing_cluster_name)
Secure by default
- CloudWatch Container Insights is on (container_insights_enabled = true).
Commercial and GovCloud
module "ecs_cluster" {
source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//ecs-cluster?ref=v1.7.0"
cluster_name = local.app_name
tags = local.tags
}| Setting | Commercial default | Federal setting | Note |
|---|---|---|---|
create_cluster | true | false, with existing_cluster_name set to the customer's cluster | For accounts where the customer owns the cluster. |
enable_execute_command_logging | false | true | Logs ECS Exec sessions with the DEFAULT logging setting. |
enable_fargate_capacity_providers | false | true |
How it connects
- To ecs-service: cluster_name
- To openobserve: cluster_id (as ecs_cluster_id)
Inputs
| Name | Type | Default | Required | Description |
|---|---|---|---|---|
cluster_name | string | null | no | Name of the ECS cluster to create (used only when create_cluster = true). Required when create_cluster = true. |
container_insights_enabled | bool | true | no | Enable CloudWatch Container Insights |
create_cluster | bool | true | no | Whether to create a new ECS cluster. Set to false to reuse an existing customer-managed cluster passed via existing_cluster_name (common federal pattern where the customer owns the cluster). |
enable_execute_command_logging | bool | false | no | Set execute_command_configuration { logging = "DEFAULT" } on the cluster. Off by default to avoid state changes on existing v1 clusters. |
enable_fargate_capacity_providers | bool | false | no | Attach FARGATE and FARGATE_SPOT capacity providers with FARGATE as the default strategy. Off by default to avoid state changes on existing v1 clusters. |
existing_cluster_name | string | null | no | Name of an existing ECS cluster to reuse. Required when create_cluster = false. |
tags | map(string) | {} | no | Tags to apply to all resources |
Outputs
| Name | Description |
|---|---|
cluster_arn | Value: var.create_cluster ? aws_ecs_cluster.main[0].arn : data.aws_ecs_cluster.existing[0].arn |
cluster_id | Value: var.create_cluster ? aws_ecs_cluster.main[0].id : data.aws_ecs_cluster.existing[0].id |
cluster_name | Value: var.create_cluster ? aws_ecs_cluster.main[0].name : var.existing_cluster_name |
Used by
| App | Pinned ref |
|---|---|
| BidBuddy | v1.0.0 |
| castle | v1.6.0 |
| dust | v1.1.0 |
| evergreen | v1.0.0 |
| forager | v1.1.0 |
| ginkgo | v1.3.0 |
| juniper | v1.1.0 |
| meridian | v1.0.0 |
| oak | v1.1.0 |
| poppy | v1.1.0 |
| saplings | v1.3.0 |
| skeddy | v1.6.0 |
| test-health-dashboard | v1.4.0 |