Skip to main content
ECS containers produce logs through the log driver configured in the container definition. This module’s container-definition sub-module supports two logging backends: CloudWatch Logs and FireLens (FluentBit/Fluentd).

How log groups are managed

When CloudWatch logging is enabled, ECS will create a log group automatically if one does not exist. The problem with this approach is that the log group is created outside of Terraform: it cannot be tagged, its retention period cannot be set, it will not be deleted when you destroy the stack, and it cannot be encrypted with a customer-managed KMS key. To address this, the container-definition module creates the CloudWatch log group on your behalf by default. This means you get full Terraform control over the log group lifecycle.
The default retention period for log groups created by the container-definition module is 14 days. The cluster-level log group defaults to 90 days. Override both with cloudwatch_log_group_retention_in_days.

The four logging scenarios

Set enable_cloudwatch_logging = false to disable all logging for the container. No log group is created and no log driver is configured.
Use this when:
  • The container writes logs to a file or stdout that another sidecar collects.
  • You want zero logging overhead for non-critical containers.

Log group configuration options

When the module manages the CloudWatch log group (create_cloudwatch_log_group = true), you can control its configuration through container definition inputs:

KMS encryption example

If you provide a KMS key, ensure the key policy grants CloudWatch Logs the kms:GenerateDataKey* and kms:Decrypt permissions. Without the correct key policy, log group creation will fail.

FireLens with Kinesis Firehose

The service module README shows a complete FireLens example forwarding to Kinesis Firehose:
Retrieve the latest stable FluentBit image from SSM Parameter Store rather than hardcoding the image tag:
Then reference it as nonsensitive(data.aws_ssm_parameter.fluentbit.value) in the container definition.
For more FireLens configuration examples, see the FireLens examples repository.