ECS Fargate Service
Full Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.
Compare Serverless Containers across clouds →
Part of: AWS Production Landing Zone
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-11 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o aws-ecs-fargate-service-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/aws-ecs-fargate-service/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle aws-ecs-fargate-service-1.0.0.sigstore.json \
aws-ecs-fargate-service-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "1087200b6d95b7776393d456d941dde2c0141079aa08dda85e532cc93eb2f4c7 aws-ecs-fargate-service-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "ecs_fargate_service" {
source = "www.iac-bazaar.com/iac-bazaar/aws-ecs-fargate-service/aws"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Premium, so its contract unlocks when you buy it.
Documentation
aws-ecs-fargate-service
Full Fargate stack: cluster, task definition, service with ALB integration,
autoscaling, and Cloud Map discovery. Works with Terraform and OpenTofu
(>= 1.6), AWS provider >= 6.0, < 7.0.
What you get (and why it is worth paying for):
- The container definition is built from typed variables and
jsonencoded once — no hand-rolled JSON, no task-definition drift between plans - Private networking by default (no public IP), scoped security group using modern standalone rule resources, all-egress only where required
- Least-privilege IAM: execution role gets secret-read access to exactly the ARNs you inject; separate task role for application permissions
- Deployment circuit breaker with automatic rollback
- Target-tracking autoscaling (CPU and/or memory) with
desired_counthanded over to the scaler after first deploy (ignore_changes) - Optional Cloud Map (A records) for east-west discovery
- Container Insights + retention-managed, optionally KMS-encrypted logs
Requirements
- Terraform or OpenTofu
>= 1.6 - AWS provider
>= 6.0, < 7.0 - An existing VPC + subnets; an existing ALB target group if you set
load_balancer(pair with theaws-albmodule); an existing Cloud Map private DNS namespace if you setservice_discovery
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
- Notes
Related modules
Lambda Function (Packaged & Wired)
Lambda with execution role, log group, triggers, aliases, and zip/container packaging handled.
Step Functions State Machine
A Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.
Azure Container Apps Environment
Container Apps environment with workload profiles, Dapr, KEDA scale rules, ACR pull identity and custom domain.
Cloud Run Job (v2)
A Cloud Run v2 Job for batch and run-to-completion workloads with a dedicated runtime service account, auto-wired Secret Manager accessor grants, VPC egress, bounded retries and per-task timeout.
Cloud Run Service
Cloud Run v2 service with autoscaling, secret and VPC egress wiring, custom domain and invoker IAM done right.
DigitalOcean App Platform Service
Declarative App Platform deployment with services, workers, domains, and alerts.