Skip to main content
This module provides a set of composable Terraform sub-modules for provisioning Amazon ECS infrastructure. Understanding how the pieces fit together will help you choose the right module structure for your use case.

Module structure

Root module

Combines the cluster and service sub-modules into a single integrated entrypoint. One module block provisions a cluster and any number of services together.

Cluster sub-module

Creates an ECS cluster, capacity providers, CloudWatch log group, task execution IAM role, and — for ECS Managed Instances — the infrastructure IAM role, node IAM role, and security group.

Service sub-module

Creates one ECS service, its task definition, container definitions, autoscaling resources, security group, service IAM role, task execution IAM role (optionally), and tasks IAM role.

Container definition sub-module

A building block invoked internally by the service sub-module for each container entry. Produces the JSON-encoded container definition and optionally manages the CloudWatch log group.

Express service sub-module

Creates an aws_ecs_express_gateway_service — a simplified, fully-managed ECS service type with built-in autoscaling. Use this when you want a minimal configuration surface without managing task definitions directly.

Construct hierarchy

Amazon ECS resources follow a strict parent-child hierarchy. The module mirrors this hierarchy exactly:
  • A cluster may contain one or more services.
  • A service manages one task definition or task set (this module assumes one per service).
  • A task wraps one to ten container definitions. Think of a task as a Kubernetes pod and the task definition as a pod spec.

Root module vs. separate sub-modules

Use the root module when you want to manage the cluster and all of its services in a single Terraform configuration. The root module accepts a services map and iterates over it with for_each, passing the cluster ARN and the cluster-level task execution role ARN to each service automatically.
Best for: Single-team clusters where one Terraform workspace owns the cluster and all services.

Capacity provider types

The cluster sub-module supports four capacity provider types. You cannot mix Fargate-based providers with EC2-based providers on the same cluster.
You cannot mix EC2-based capacity providers (Auto Scaling Group or Managed Instances) with Fargate capacity providers on the same ECS cluster.

Resources created by each module

The sub-module’s primary output is the container_definition local — a map that is JSON-encoded by the service sub-module and passed to aws_ecs_task_definition.container_definitions.