Tools and AWS identity
Install Terraform and AWS CLI v2 on the machine or runner that will execute Terraform. The module requires Terraform or OpenTofu 1.11.0+; prefer Terraform 1.12+ for boolean short-circuit evaluation. Required providers arehashicorp/aws >= 6.64.0, < 7.0.0 and hashicorp/random ~> 3.9.
Use one authenticated AWS identity for Terraform, module downloads, and the migration runner. For a named profile:
profile only inside the Terraform provider or backend does not configure the AWS CLI subprocess used to start database migrations. CI can supply temporary credentials through its normal AWS credential chain instead.
The deployment identity needs permissions for the selected VPC, ECS, RDS, ElastiCache, load balancer, ACM, Route 53, IAM, Secrets Manager, S3, CloudWatch, and Lambda resources. It also needs ecs:RunTask, ecs:DescribeTasks, ecs:StopTask, and iam:PassRole for migrations. Optional features require additional services, such as AgentCore and EC2.
Check regional quotas before deployment: Fargate vCPUs, VPCs, elastic IPs/NAT gateways, RDS, and GPU capacity when enabling ToolGuard or other GPU features.
Runlayer onboarding
Obtain the shared inputs:- WorkOS
auth_client_idand secretauth_api_key. mcp_catalog_api_key, required for catalog and onboarding even though the Terraform variable has an empty default.distribution_api_key, registered by Runlayer for this deployment, plus its Distribution API URL. The deployment guide selectsopenfeature_provider = "flagd", which requires both values. Confirm the key is active and the API is reachable before applying; supplying an arbitrary new key is insufficient.- The approved module release and application version. The example pins module
v33.1.0; confirm its compatibility with your tenant. - S3 module download access and Customer Distribution ECR image-pull access.
- Registration of your application hostname and authentication redirects with Runlayer.
- Credentials and entitlements for any optional features you select.
Network, domain, and data services
Decide these before creating the root module:
For
ai.example.com, the parent hosted zone is typically example.com. The zone must already exist and be publicly delegated for ACM DNS validation. Configure networking and database/cache alternatives now.
Private subnets need ECR and S3 access for image pulls, plus outbound HTTPS to required external hosts. AWS VPC endpoints alone do not reach WorkOS, AuthKit, or the hosted catalog. If enabling WAF allowlisting with AgentCore, prepare AgentCore VPC mode and PrivateLink.
Terraform state storage
The S3 backend bucket must exist beforeterraform init. Use an existing approved state bucket or create one separately from this deployment, with versioning, encryption, public access blocked, and access limited to deployment operators.
Example bootstrap for us-east-1 (replace the globally unique bucket name):
create-bucket also needs --create-bucket-configuration LocationConstraint=<region>. Match the backend region to the bucket region. The deployment identity needs bucket listing and state-object read/write access, plus read/write/delete access to the .tflock object for S3 locking.
Use a distinct state key per environment. Terraform state and saved plans can contain sensitive values; keep both out of Git and restrict access. Keep .terraform.lock.hcl in Git to record provider selections.
Bedrock access before first startup
The ECS module enables Bedrock for Runlayer Assistant. By default the backend submits Anthropic’s use-case form and accepts the model agreement automatically. The form is submitted once per AWS account, and the default company identity is Runlayer. For your self-hosted installation, set these values to your organization before the first apply:bedrock_auto_model_access = false and complete the use-case details and model agreement in the Bedrock console before using Assistant. Confirm your SCPs and permission boundaries allow model access and invocation. Access can take up to 15 minutes to propagate.
Select a supported region/inference profile for your deployment. See Bedrock configuration and model-access troubleshooting.