Naming constraints
These values are used in AWS resource names (ElastiCache replication group IDs, secrets, IAM, etc.) and are validated by the module:
Generated names follow
<project>-<environment>-…. Example: project = "acme", environment = "staging" → Redis replication group acme-staging-redis.
Database Configuration
Managed Aurora is always PostgreSQL Serverless v2 (db.serverless). There is no provisioned instance-class input (db.r6g.large, etc.). Size the cluster with Aurora Capacity Units (ACUs):
external_database instead.
Bring Your Own Database / Cache
Skip Aurora and/or ElastiCache when you operate PostgreSQL and Redis/Valkey yourself. Postgres and Redis can be configured independently.POSTGRES_* env vars and Secrets Manager entries for PLATFORM_DB_PASSWORD and REDIS_URL. Ensure private subnets can reach your endpoints. For Kubernetes, see the Runlayer Operator database and Redis contract.
Redis / ElastiCache
Managed Redis (skipped whenexternal_redis is set):
Service Scaling
Defaults already set production-ready CPU/memory. To override, replace the fullservices_configurations map (partial maps are not merged):
min_capacity / max_capacity control the running fleet: Application Auto Scaling owns each service’s live desired_count, and Terraform ignores it after the service is created, so desired_count only seeds a brand-new service. To change the floor of an existing service, raise min_capacity (or backend_min_capacity).
Reserve backend.priority + 1 for the /mcp alias listener rule (module validation enforces this).
ECS services, workers, and migrations
Monitoring & Alerting
redis_connections_per_backend_task_threshold. For the deployment guide’s v33.1.0, omit that input and use redis_curr_connections_threshold = 2000 instead.
Resource tags
Theadditional_tags input accepts a string map and defaults to {}. It applies
deployment metadata to directly managed workload resources. Resource identity tags
take precedence. No partner attribution is enabled by default. Verify product code,
resource eligibility and existing tag ownership before opt-in. See the module README
for the coverage available in your published module version.
Secrets management
All application secrets live in AWS Secrets Manager in your account. The module creates two primary secrets (plus an optional LLM gateway secret):
Design notes:
SECRET_KEYandMASTER_SALTare isolated in the restricted secret so only privileged task roles can read them.- The app secret and restricted secret share the same random name suffix to avoid recreate collisions during Secrets Manager recovery windows.
- Prefer
TF_VAR_*/ a secrets backend for sensitive inputs — do not commit API keys to git. - Rotate
DISTRIBUTION_API_KEYthrough the Terraform input and coordinate registration with Runlayer; follow the Distribution key rotation procedure so the new key is accepted before tasks use it. - After deploy, rotate other non-key values with Secrets Manager (then force a new ECS deployment so tasks pick up the new version). Rotate
SECRET_KEY/MASTER_SALTviasecret_key/master_saltinstead — Terraform reverts out-of-band edits to the restricted secret on the next apply.
ecs_cluster_name. To inspect secret names with Terraform, also add these root outputs:
terraform output -raw app_secrets_name or terraform output -raw restricted_app_keys_secret_name. These outputs contain names, not secret values.
Use your approved secret-management workflow to update non-key values. Preserve all other keys in the JSON secret. Restart every service that consumes the changed value; for the core services:
Module outputs (attributes)
These are child-module attributes.terraform output reads only outputs declared in your root configuration; export an attribute there before using it from the CLI. Useful attributes include: