Skip to main content
The Express Service module creates an ECS Express Gateway Service — a simplified deployment model with opinionated defaults.

Resource Creation Controls

bool
Determines whether resources will be created. Default: true.

Service

string
Name or ARN of the ECS cluster. Defaults to the default cluster. Default: null.
string
Name of the service. If not specified, a name is generated. Changing this forces re-creation. Default: "".
string
CPU units for the task. Valid values are powers of 2 between 256 and 4096. Default: null.
string
Memory in MiB for the task. Valid values are between 512 and 8192. Default: null.
string
Path for health check requests. Default: null (/ping).
object
Network configuration for the service revision.Default: null.
object
Primary container configuration for the service revision.Default: null.
object
Auto-scaling configuration for the service revision.Default: null.

Security Group

bool
Create a security group for the service. Default: true.
string
Security group name. Default: null.
bool
Use security group name as prefix. Default: true.
string
Security group description. Default: null.
map(object)
Ingress rules for the security group. Default: {}.
map(object)
Egress rules for the security group. Default: {}.
map(string)
Additional security group tags. Default: {}.
string
VPC ID for the security group. Default: null.

IAM — Execution Role

bool
Create the task execution IAM role. Default: true.
string
Existing execution IAM role ARN. Default: null.
string
Execution IAM role name. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: null.
string
Permissions boundary ARN. Default: null.
map(string)
Policy ARNs to attach. Default: {}.
map(string)
Additional tags. Default: {}.
number
Maximum session duration in seconds. Default: null.
bool
Create the execution IAM policy with ECR, CloudWatch, Secrets Manager, and SSM permissions. Default: true.
list(string)
SSM parameter ARNs the execution role can read. Default: [].
list(string)
Secrets Manager ARNs the execution role can read. Default: [].
map(object)
Custom IAM statements for the execution role. Default: null.
string
Path for the execution IAM policy. Default: null.

IAM — Infrastructure Role

bool
Create the infrastructure IAM role. Default: true.
string
Existing infrastructure IAM role ARN. Default: null.
string
Infrastructure IAM role name. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: null.
string
Permissions boundary ARN. Default: null.
map(string)
Additional tags. Default: {}.

IAM — Task Role

bool
Create the task runtime IAM role. Default: true.
string
Existing task IAM role ARN. Default: null.
string
Task IAM role name. Default: null.
bool
Use name as prefix. Default: true.
string
IAM role path. Default: null.
string
Role description. Default: null.
string
Permissions boundary ARN. Default: null.
map(string)
Additional policy ARNs to attach. Default: {}.
map(object)
Custom IAM statements for the task role. Default: null.
map(string)
Additional tags. Default: {}.
number
Maximum session duration in seconds. Default: null.

CloudWatch Log Group

bool
Create a CloudWatch log group for the service. Default: true.
string
Custom log group name. Default: null.
number
Log retention in days. Default: 14.
string
KMS Key ARN for log encryption. Default: null.
string
Log class: STANDARD or INFREQUENT_ACCESS. Default: null.
map(string)
Additional log group tags. Default: {}.

Misc

string
AWS region. Defaults to provider region. Default: null.
map(string)
Tags for all resources. Default: {}.