finds.dev← search

// the find

arminc/terraform-ecs

★ 810 · HCL · MIT · updated Jun 2021

AWS ECS terraform module

A Terraform module set for standing up a production-style ECS cluster on EC2 (VPC, ALB, autoscaling instances, IAM roles) in one shot. Aimed at teams who want a working multi-AZ ECS baseline to start from rather than wiring VPC/ALB/ASG/ECS together from scratch.

Genuinely modular — vpc, subnet, alb, nat_gateway, ecs_instances, ecs_roles, and ecs_events are separate composable modules, not one giant main.tf, so you can lift out just the alb or subnet module if that's all you need. The README goes past the happy path: it covers draining instances before termination, CloudWatch log group collisions when running two clusters in one account, and why SSH access should go through a bastion rather than directly to nodes. The ecs_events module wires up EventBridge/CloudWatch events to detect a task getting stuck in a start/stop loop, which most quick-start ECS templates skip entirely.

Last commit is from mid-2021 and the README still says Terraform CLI 0.9.5+, meaning this predates HCL2 and years of AWS provider changes — expect it to need real rework before it applies cleanly today. EC2 launch type only, no Fargate support anywhere in the module, which is a significant gap for anything written in the Fargate era. The repo ships a Terraform-generated private key committed at the root (ecs_fake_private) for 'quick' SSH access — exactly the kind of shortcut that ends up copy-pasted into a real environment. Replacing EC2 nodes after an AMI update is manual and one-by-one; there's no automated draining/cycling, just an open, unresolved GitHub issue acknowledging it.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →