> ## Documentation Index
> Fetch the complete documentation index at: https://docs.runlayer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ECS Prerequisites

> Prepare AWS access, Terraform state, credentials, networking, and model access before deploying Runlayer

Complete these steps before the [ECS deployment guide](/deployment/terraform).

## Tools and AWS identity

Install [Terraform](https://developer.hashicorp.com/terraform/install) and [AWS CLI v2](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) on the machine or runner that will execute Terraform. The module requires Terraform or OpenTofu **1.11.0+**; prefer Terraform **1.12+** for boolean short-circuit evaluation. Required providers are `hashicorp/aws >= 6.64.0, < 7.0.0` and `hashicorp/random ~> 3.9`.

Use one authenticated AWS identity for Terraform, module downloads, and the migration runner. For a named profile:

```bash theme={null}
export AWS_PROFILE=your-deployment-profile
export AWS_REGION=us-east-1
# For an IAM Identity Center profile, authenticate first:
# aws sso login --profile "$AWS_PROFILE"
aws sts get-caller-identity
terraform version
aws --version
```

Confirm the returned account matches the deployment account. Run all subsequent commands in this shell. Setting `profile` only inside the Terraform provider or backend does **not** configure the AWS CLI subprocess used to start database migrations. CI can supply temporary credentials through its normal AWS credential chain instead.

The deployment identity needs permissions for the selected VPC, ECS, RDS, ElastiCache, load balancer, ACM, Route 53, IAM, Secrets Manager, S3, CloudWatch, and Lambda resources. It also needs `ecs:RunTask`, `ecs:DescribeTasks`, `ecs:StopTask`, and `iam:PassRole` for migrations. Optional features require additional services, such as AgentCore and EC2.

Check regional quotas before deployment: Fargate vCPUs, VPCs, elastic IPs/NAT gateways, RDS, and GPU capacity when enabling ToolGuard or other GPU features.

## Runlayer onboarding

Obtain the [shared inputs](/deployment/runlayer-provided-inputs):

* WorkOS `auth_client_id` and secret `auth_api_key`.
* `mcp_catalog_api_key`, required for catalog and onboarding even though the Terraform variable has an empty default.
* `distribution_api_key`, registered by Runlayer for this deployment, plus its Distribution API URL. The deployment guide selects `openfeature_provider = "flagd"`, which requires both values. Confirm the key is active and the API is reachable before applying; supplying an arbitrary new key is insufficient.
* The approved module release and application version. The example pins module `v33.1.0`; confirm its compatibility with your tenant.
* S3 module download access and Customer Distribution ECR image-pull access.
* Registration of your application hostname and authentication redirects with Runlayer.
* Credentials and entitlements for any optional features you select.

## Network, domain, and data services

Decide these before creating the root module:

| Decision | Standard deployment | Alternatives |
| - | - | - |
| VPC | Module creates a multi-AZ VPC | Supply an existing VPC and subnets |
| Application access | Public HTTPS ALB | Private ALB, dual ALBs, or inbound PrivateLink |
| DNS and TLS | Existing public Route 53 zone; module creates ACM certificate and DNS records | Cross-account Route 53 or externally managed DNS/TLS |
| Database | Module creates Aurora PostgreSQL | Supply external PostgreSQL and credentials |
| Cache | Module creates ElastiCache Redis | Supply external Redis/Valkey and credentials |

For `ai.example.com`, the parent hosted zone is typically `example.com`. The zone must already exist and be publicly delegated for ACM DNS validation. Configure [networking](/deployment/ecs-networking) and [database/cache alternatives](/deployment/ecs-configuration) now.

Private subnets need ECR and S3 access for image pulls, plus outbound HTTPS to [required external hosts](/deployment/egress-requirements). AWS VPC endpoints alone do not reach WorkOS, AuthKit, or the hosted catalog. If enabling WAF allowlisting with AgentCore, prepare [AgentCore VPC mode and PrivateLink](/deployment/ecs-networking#security-configuration).

## Terraform state storage

The S3 backend bucket must exist **before `terraform init`**. Use an existing approved state bucket or create one separately from this deployment, with versioning, encryption, public access blocked, and access limited to deployment operators.

Example bootstrap for **us-east-1** (replace the globally unique bucket name):

```bash theme={null}
export RUNLAYER_TF_STATE_BUCKET=replace-with-your-unique-state-bucket
aws s3api create-bucket --bucket "$RUNLAYER_TF_STATE_BUCKET" --region us-east-1
aws s3api put-bucket-versioning --bucket "$RUNLAYER_TF_STATE_BUCKET" \
  --versioning-configuration Status=Enabled
aws s3api put-bucket-encryption --bucket "$RUNLAYER_TF_STATE_BUCKET" \
  --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'
aws s3api put-public-access-block --bucket "$RUNLAYER_TF_STATE_BUCKET" \
  --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
```

For other regions, `create-bucket` also needs `--create-bucket-configuration LocationConstraint=<region>`. Match the backend region to the bucket region. The deployment identity needs bucket listing and state-object read/write access, plus read/write/delete access to the `.tflock` object for S3 locking.

Use a distinct state key per environment. Terraform state and saved plans can contain sensitive values; keep both out of Git and restrict access. Keep `.terraform.lock.hcl` in Git to record provider selections.

## Bedrock access before first startup

The ECS module enables Bedrock for Runlayer Assistant. By default the backend submits Anthropic's use-case form and accepts the model agreement automatically. **The form is submitted once per AWS account, and the default company identity is Runlayer.** For your self-hosted installation, set these values to your organization before the first apply:

```hcl theme={null}
bedrock_auto_model_access            = true
bedrock_model_access_company_name    = "Example Corp"
bedrock_model_access_company_website = "https://example.com"
bedrock_model_access_industry        = "Technology"
bedrock_model_access_intended_users  = 100
```

Alternatively, set `bedrock_auto_model_access = false` and complete the use-case details and model agreement in the Bedrock console before using Assistant. Confirm your SCPs and permission boundaries allow model access and invocation. Access can take up to 15 minutes to propagate.

Select a supported region/inference profile for your deployment. See [Bedrock configuration](/deployment/ecs-features#bedrock-and-anthropic) and [model-access troubleshooting](/operations/troubleshooting#runlayer-assistant-anthropic-bedrock-model-access).

## Ready to deploy

Choose any [optional features](/deployment/ecs-features), collect their credentials, and provision the required network paths and quotas. Then continue to the [deployment guide](/deployment/terraform).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.