container-definition sub-module supports two logging backends: CloudWatch Logs and FireLens (FluentBit/Fluentd).
How log groups are managed
When CloudWatch logging is enabled, ECS will create a log group automatically if one does not exist. The problem with this approach is that the log group is created outside of Terraform: it cannot be tagged, its retention period cannot be set, it will not be deleted when you destroy the stack, and it cannot be encrypted with a customer-managed KMS key. To address this, thecontainer-definition module creates the CloudWatch log group on your behalf by default. This means you get full Terraform control over the log group lifecycle.
The default retention period for log groups created by the
container-definition module is 14 days. The cluster-level log group defaults to 90 days. Override both with cloudwatch_log_group_retention_in_days.The four logging scenarios
- Disable logging
- CloudWatch (ECS-managed group)
- CloudWatch (Terraform-managed group)
- FireLens (FluentBit)
Set Use this when:
enable_cloudwatch_logging = false to disable all logging for the container. No log group is created and no log driver is configured.- The container writes logs to a file or stdout that another sidecar collects.
- You want zero logging overhead for non-critical containers.
Log group configuration options
When the module manages the CloudWatch log group (create_cloudwatch_log_group = true), you can control its configuration through container definition inputs:

