Resource Creation Controls
bool
Determines whether resources will be created (affects all resources). Default:
true.bool
Determines whether the ECS service resource will be created. Set to
false to create only the task definition. Default: true.bool
Determines whether to create a task definition or use an existing one. Default:
true.bool
Determines whether the ECS service IAM role should be created (for load balancer management). Default:
true.bool
Create a service-level task execution IAM role. Default:
true.bool
Create the task execution IAM policy with ECR, CloudWatch, Secrets Manager, and SSM permissions. Default:
true.bool
Create the tasks runtime IAM role. Default:
true.bool
Create a security group for the service. Default:
true.bool
Create the infrastructure IAM role. Default:
true.Service
string
Name of the service (up to 255 letters, numbers, hyphens, and underscores). Default:
"".string
ARN of the ECS cluster where the service will be provisioned. Default:
"".string
Launch type for the service:
EC2, FARGATE, or EXTERNAL. Default: "FARGATE".string
Scheduling strategy:
REPLICA or DAEMON. Default: null (REPLICA).number
Number of task instances to run. Note: this value is always ignored after initial creation — autoscaling manages the count. Default:
1.bool
Whether changes to task definition, and load_balancer should be ignored. Set to
true for CodeDeploy blue/green deployments.Default: false.string
Enable ECS automatic task rebalancing across AZs:
ENABLED or DISABLED. Default: null.bool
Enable Amazon ECS managed tags for tasks. Default:
true.bool
Enable Amazon ECS Exec for interactive debugging. Default:
false.bool
Enable fault injection requests from task containers. Default:
null.bool
Force a new task deployment. Default:
true.bool
Delete service even if not scaled to zero (REPLICA strategy only). Default:
null.number
Seconds to ignore failing load balancer health checks on new tasks. Default:
null.string
Propagate tags from
SERVICE or TASK_DEFINITION. Default: null.bool
Wait for the service to reach steady state before completing. Default:
null.bool
Enable graceful termination using SIGINT signals (requires
wait_for_steady_state = true). Default: null.map(string)
Map of values that trigger in-place redeployments when changed. Useful with
timestamp(). Default: null.object
Create, update, and delete timeout configurations.Default:
null.map(string)
Additional tags for the service. Default:
{}.Deployment
object
Deployment controller type.Default:
null.object
Deployment circuit breaker configuration.Default:
null.object
Advanced deployment configuration (rolling, canary, linear strategies).Default:
null.number
Upper limit of running tasks during deployment (as % of desired count). Default:
200.number
Lower limit of healthy tasks during deployment (as % of desired count). Default:
66.object
CloudWatch alarms configuration for deployment monitoring.Default:
null.map(object)
Capacity provider strategy overrides for the service.Default:
null.map(object)
Task placement constraints (up to 10). Default:
null.list(object)
Ordered task placement strategies. Default:
null.Load Balancer
map(object)
Load balancer configuration.Default:
null.VPC Lattice
object
VPC Lattice configuration for cross-account service connectivity.Default:
null.Service Connect
object
ECS Service Connect configuration for service discovery.Default:
null.object
Service discovery registries (Cloud Map).Default:
null.Task Definition
number
CPU units for the task (required for FARGATE). Default:
1024.number
Memory in MiB for the task (required for FARGATE). Default:
2048.string
Unique name for the task definition family. Default:
null (uses service name).string
Docker networking mode:
none, bridge, awsvpc, or host. Default: "awsvpc".list(string)
Launch types required:
EC2, FARGATE, EXTERNAL, MANAGED_INSTANCES. Default: ["FARGATE"].object
CPU architecture and OS family.
string
Existing task definition ARN. Required when
create_task_definition = false. Default: null.map(object)
Task-level placement constraints (up to 10). Default:
null.bool
Track the latest ACTIVE task definition revision on AWS. Default:
true.bool
Don’t delete the task definition when the service is deleted. Default:
null.string
IPC namespace:
host, task, or none. Default: null.string
PID namespace:
host or task. Default: null.object
App Mesh proxy configuration. Default:
null.object
Additional ephemeral storage beyond default (Fargate only).Default:
null.map(object)
Volume configurations for the task (EFS, Docker, FSx, host bind mounts). Default:
null.object
EBS volume configuration for volumes attached at launch time. Default:
null.map(string)
Additional tags for the task definition/set. Default:
{}.Container Definitions
map(object)
Map of container definitions. Each key is the container name. Supports all ECS container definition parameters.Key module-specific additions:
enable_cloudwatch_logging(bool) — creates a CloudWatch log group. Default:truecloudwatch_log_group_name— custom log group namecloudwatch_log_group_retention_in_days— log retention dayscreate_cloudwatch_log_group— whether the module manages the log group
{}.Task Set
string
External ID associated with the task set. Default:
null.object
Desired percentage of tasks to run in the task set (always ignored after creation). Default:
null.bool
Wait until the task set reaches
STEADY_STATE. Default: null.Autoscaling
bool
Enable autoscaling for the service. Default:
true.number
Minimum number of tasks. Default:
1.number
Maximum number of tasks. Default:
10.map(object)
Map of autoscaling policies. Supports
TargetTrackingScaling and StepScaling policy types. Default includes CPU and Memory target tracking policies.map(object)
Map of scheduled scaling actions.Default:
null.object
Suspend scaling activities.Default:
null.Networking
list(string)
Subnets to associate with the task or service. Default:
[].bool
Assign a public IP to the task ENI (Fargate only). Default:
false.list(string)
Additional security groups to associate with the task. Default:
[].string
Security group name. Default:
null.bool
Use security group name as prefix. Default:
true.string
Security group description. Default:
null.map(object)
Ingress rules for the service security group. Default:
{}.map(object)
Egress rules for the service security group. Default:
{}.map(string)
Additional security group tags. Default:
{}.string
VPC ID for the service. Derived from subnets if not provided. Default:
null.IAM — Service Role
string
Existing service IAM role ARN. Default:
null.string
Service IAM role name. Default:
null.bool
Use role name as prefix. Default:
true.string
IAM role path. Default:
null.string
Role description. Default:
null.string
Permissions boundary ARN. Default:
null.list(object)
Custom IAM statements for the service role. Default:
null.map(string)
Additional tags. Default:
{}.IAM — Task Execution Role
string
Existing task execution IAM role ARN. Default:
null.string
Task execution IAM role name. Default:
null.bool
Use name as prefix. Default:
true.string
IAM role path. Default:
null.string
Role description. Default:
null.string
Permissions boundary ARN. Default:
null.map(string)
Policy ARNs to attach. Default:
{}.map(string)
Additional tags. Default:
{}.number
Maximum session duration in seconds. Default:
null.string
Path for the task execution IAM policy. Default:
null.list(string)
Secrets Manager ARNs the execution role can read. Default:
[].list(string)
SSM parameter ARNs the execution role can read. Default:
[].list(object)
Custom IAM statements for the execution role. Default:
null.IAM — Tasks Role (Runtime)
string
Existing tasks IAM role ARN. Default:
null.string
Tasks IAM role name. Default:
null.bool
Use name as prefix. Default:
true.string
IAM role path. Default:
null.string
Role description. Default:
null.string
Permissions boundary ARN. Default:
null.map(string)
Additional policy ARNs to attach. Default:
{}.list(object)
Custom IAM statements for the tasks role. Default:
null.map(string)
Additional tags. Default:
{}.number
Maximum session duration in seconds. Default:
null.IAM — Infrastructure Role
bool
Create the infrastructure IAM role. Default:
true.string
Existing infrastructure IAM role ARN. Default:
null.string
Infrastructure IAM role name. Default:
null.bool
Use name as prefix. Default:
true.string
IAM role path. Default:
null.string
Role description. Default:
null.string
Permissions boundary ARN. Default:
null.map(string)
Additional tags. Default:
{}.Misc
string
AWS region. Defaults to provider region. Default:
null.map(string)
Tags for all resources. Default:
{}.bool
Deprecated — will be removed in v8.0. Disables v7.0 name/description postfixes. Default:
false.
