Skip to main content
Use the cluster sub-module when you want to manage the ECS cluster separately from services.

Resource Creation Controls

bool
Determines whether resources will be created (affects all resources). Default: true.

Cluster

string
Name of the ECS cluster (up to 255 letters, numbers, hyphens, and underscores). Default: "".
object
The execute command configuration for the cluster.Default: sets cloud_watch_log_group_name = "placeholder".
object
Default Service Connect namespace for the cluster.Default: null.
list(object)
Cluster settings. Used to enable Container Insights. Default: [{ name = "containerInsights", value = "enabled" }].

Capacity Providers

list(string)
List of capacity provider names (e.g., ["FARGATE", "FARGATE_SPOT"]) to associate with the cluster. Providers created by this module are automatically added. Default: [].
string
Duration to wait after the cluster becomes active before attaching capacity providers. Default: "20s".
map(object)
Default capacity provider strategy for the cluster.Default: {}.
map(object)
Map of capacity provider definitions to create.Default: {}.

CloudWatch Logging

bool
Create a CloudWatch log group for cluster logs. Default: true.
string
Custom CloudWatch Log Group name. Default: null.
number
Log retention in days. Default: 90.
string
KMS Key ARN for log group encryption. Default: null.
string
Log class: STANDARD or INFREQUENT_ACCESS. Default: null.
map(string)
Additional tags for the log group. Default: {}.

IAM — Infrastructure Role

bool
Create the ECS infrastructure IAM role. Default: true.
string
Name for the infrastructure IAM role. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: null.
string
Permissions boundary ARN. Default: null.
list(string)
Policy documents merged into role (unique sids). Default: [].
list(string)
Policy documents that override matching statements. Default: [].
map(object)
Custom IAM policy statements. Default: null.
map(string)
Additional tags. Default: {}.

IAM — Task Execution Role

bool
Create a cluster-level task execution IAM role. Default: false.
string
Name for the task execution role. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: null.
string
Permissions boundary ARN. Default: null.
map(string)
Policy ARNs to attach. Default: {}.
map(string)
Additional tags. Default: {}.
bool
Create the task execution policy with ECR pull, CloudWatch logging, Secrets Manager, and SSM access. Default: true.
list(string)
Secrets Manager ARNs the execution role can read. Default: [].
list(string)
SSM parameter ARNs the execution role can read. Default: [].
map(object)
Custom IAM statements for the execution role. Default: null.

IAM — Node Role (Managed Instances)

bool
Create an IAM instance profile for Managed Instances nodes. Default: true.
string
Name for the node IAM role/instance profile. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: "ECS Managed Instances node IAM role".
string
Permissions boundary ARN. Default: null.
map(string)
Additional policy ARNs to attach. Default: {}.
list(string)
Policy documents merged into node role. Default: [].
list(string)
Policy documents that override matching statements. Default: [].
map(object)
Custom IAM statements for the node role. Default: null.
map(string)
Additional tags. Default: {}.

Security Group (Managed Instances)

bool
Create a security group for Managed Instances. Default: true.
string
Security group name. Default: null.
bool
Use name as prefix. Default: true.
string
Security group description. Default: null.
map(object)
Ingress rules for the security group. Default: {}.
map(object)
Egress rules. Default includes allow-all IPv4 and IPv6.
map(string)
Additional tags. Default: {}.
string
VPC ID for the security group. Default: null.

Misc

string
AWS region. Defaults to provider region. Default: null.
map(string)
Tags for all resources. Default: {}.
bool
Deprecated — will be removed in v8.0. Disables v7.0 name/description postfixes. Default: false.