Skip to main content
Use these examples when preparing your ECS deployment, or when updating an existing installation. All input snippets belong inside the module block unless marked as root outputs. Merge examples into your existing configuration. The inputs reference is the full variable contract. Networking and optional features have their own guides.

Naming constraints

These values are used in AWS resource names (ElastiCache replication group IDs, secrets, IAM, etc.) and are validated by the module: Generated names follow <project>-<environment>-…. Example: project = "acme", environment = "staging" → Redis replication group acme-staging-redis.

Database Configuration

Managed Aurora is always PostgreSQL Serverless v2 (db.serverless). There is no provisioned instance-class input (db.r6g.large, etc.). Size the cluster with Aurora Capacity Units (ACUs):
Pick ACU values supported for Aurora PostgreSQL Serverless v2 in your region. For a database you operate yourself (any size or engine), use external_database instead.

Bring Your Own Database / Cache

Skip Aurora and/or ElastiCache when you operate PostgreSQL and Redis/Valkey yourself. Postgres and Redis can be configured independently.
ECS tasks receive POSTGRES_* env vars and Secrets Manager entries for PLATFORM_DB_PASSWORD and REDIS_URL. Ensure private subnets can reach your endpoints. For Kubernetes, see the Runlayer Operator database and Redis contract.

Redis / ElastiCache

Managed Redis (skipped when external_redis is set):

Service Scaling

Defaults already set production-ready CPU/memory. To override, replace the full services_configurations map (partial maps are not merged):
min_capacity / max_capacity control the running fleet: Application Auto Scaling owns each service’s live desired_count, and Terraform ignores it after the service is created, so desired_count only seeds a brand-new service. To change the floor of an existing service, raise min_capacity (or backend_min_capacity). Reserve backend.priority + 1 for the /mcp alias listener rule (module validation enforces this).

ECS services, workers, and migrations

Monitoring & Alerting

Automatic CloudWatch alarms cover: ECS CPU/memory, RDS, Redis, ALB latency/unhealthy targets/5XX, and VPC flow logs. The Redis per-task connection alarm below requires a module release that includes redis_connections_per_backend_task_threshold. For the deployment guide’s v33.1.0, omit that input and use redis_curr_connections_threshold = 2000 instead.

Resource tags

The additional_tags input accepts a string map and defaults to {}. It applies deployment metadata to directly managed workload resources. Resource identity tags take precedence. No partner attribution is enabled by default. Verify product code, resource eligibility and existing tag ownership before opt-in. See the module README for the coverage available in your published module version.

Secrets management

All application secrets live in AWS Secrets Manager in your account. The module creates two primary secrets (plus an optional LLM gateway secret): Design notes:
  • SECRET_KEY and MASTER_SALT are isolated in the restricted secret so only privileged task roles can read them.
  • The app secret and restricted secret share the same random name suffix to avoid recreate collisions during Secrets Manager recovery windows.
  • Prefer TF_VAR_* / a secrets backend for sensitive inputs — do not commit API keys to git.
  • Rotate DISTRIBUTION_API_KEY through the Terraform input and coordinate registration with Runlayer; follow the Distribution key rotation procedure so the new key is accepted before tasks use it.
  • After deploy, rotate other non-key values with Secrets Manager (then force a new ECS deployment so tasks pick up the new version). Rotate SECRET_KEY/MASTER_SALT via secret_key/master_salt instead — Terraform reverts out-of-band edits to the restricted secret on the next apply.
The deployment guide exports ecs_cluster_name. To inspect secret names with Terraform, also add these root outputs:
Apply the output-only change, then inspect names with terraform output -raw app_secrets_name or terraform output -raw restricted_app_keys_secret_name. These outputs contain names, not secret values. Use your approved secret-management workflow to update non-key values. Preserve all other keys in the JSON secret. Restart every service that consumes the changed value; for the core services:
Also restart any enabled optional consumers using that secret, then repeat the deployment verification.

Module outputs (attributes)

These are child-module attributes. terraform output reads only outputs declared in your root configuration; export an attribute there before using it from the CLI. Useful attributes include:

Common use cases

Private enterprise deployment

High availability production

Development environment