aws-fargate-opensearch
| Reference Documentation: | https://docs.aws.amazon.com/solutions/latest/constructs/ |
| Language | Package |
|---|---|
|
|
|
|
|
|
|
|
|
Overview
This AWS Solutions Construct implements an AWS Fargate service that can write/read to an Amazon OpenSearch Service domain.
Here is a minimal deployable pattern definition:
Example
Pattern Construct Props
| Name | Type | Description |
|---|---|---|
|
publicApi |
|
Whether the construct is deploying a private or public API. This has implications for the VPC. |
|
vpcProps? |
Optional custom properties for a VPC the construct will create. This VPC will be used by any Private Hosted Zone the construct creates (that’s why loadBalancerProps and privateHostedZoneProps can’t include a VPC). Providing both this and existingVpc causes an error. |
|
|
existingVpc? |
An existing VPC in which to deploy the construct. Providing both this and vpcProps causes an error. If the client provides an existing load balancer and/or existing Private Hosted Zone, those constructs must exist in this VPC. |
|
|
clusterProps? |
Optional properties to create a new ECS cluster. To provide an existing cluster, use the cluster attribute of fargateServiceProps. |
|
|
ecrRepositoryArn? |
|
The arn of an ECR Repository containing the image to use to generate the containers. Either this or the image property of containerDefinitionProps must be provided. format: arn:aws:ecr:_region_:_account number_:repository/Repository Name |
|
ecrImageVersion? |
|
The version of the image to use from the repository. Defaults to "Latest". |
|
containerDefinitionProps? |
Optional props to define the container created for the Fargate Service (defaults found in fargate-defaults.ts). |
|
|
fargateTaskDefinitionProps? |
Optional props to define the Fargate Task Definition for this construct (defaults found in fargate-defaults.ts). |
|
|
fargateServiceProps? |
|
Optional values to override default Fargate Task definition properties (fargate-defaults.ts). The construct will default to launching the service is the most isolated subnets available (precedence: Isolated, Private and Public). Override those and other defaults here. |
|
existingFargateServiceObject? |
A Fargate Service already instantiated (probably by another Solutions Construct). If this is specified, then no props defining a new service can be provided, including: ecrImageVersion, containerDefinitionProps, fargateTaskDefinitionProps, ecrRepositoryArn, fargateServiceProps, clusterProps. |
|
|
existingContainerDefinitionObject? |
A container definition already instantiated as part of a Fargate service. This must be the container in the existingFargateServiceObject. |
|
|
openSearchDomainProps? |
Optional user provided props to override the default props for the OpenSearch Service. |
|
|
openSearchDomainName |
|
Domain name for the OpenSearch Service. |
|
cognitoDomainName? |
|
Optional Amazon Cognito domain name. If omitted the Amazon Cognito domain will default to the OpenSearch Service domain name. |
|
createCloudWatchAlarms? |
|
Whether to create the recommended CloudWatch alarms. |
|
domainEndpointEnvironmentVariableName? |
|
Optional name for the
OpenSearch Service domain endpoint environment variable set for the
Lambda function. Default is |
Pattern Properties
| Name | Type | Description |
|---|---|---|
|
vpc |
The VPC used by the construct (whether created by the construct or provided by the client). |
|
|
service |
The AWS Fargate service used by this construct (whether created by this construct or passed to this construct at initialization). |
|
|
container |
The container associated with the AWS Fargate service in the service property. |
|
|
userPool |
Returns an instance of |
|
|
userPoolClient |
Returns an instance of |
|
|
identityPool |
Returns an instance of |
|
|
openSearchDomain |
Returns an instance of |
|
|
openSearchRole |
Returns an instance of |
|
|
cloudWatchAlarms? |
Returns a list of |
Default settings
Out of the box implementation of the Construct without any override will set the following defaults:
AWS Fargate Service
-
Sets up an AWS Fargate service
-
Uses the existing service if provided
-
Creates a new service if none provided
-
Service will run in isolated subnets if available, then private subnets if available and finally public subnets
-
-
Adds environment variables to the container with the OpenSearch Service domain endpoint
-
Add permissions to the container IAM role allowing it to write/read to the OpenSearch Service domain endpoint
-
Amazon Cognito
-
Set password policy for User Pools
-
Enforce the advanced security mode for User Pools
Amazon OpenSearch Service
-
Deploy best practices CloudWatch Alarms for the OpenSearch Service domain
-
Secure the OpenSearch Service dashboard access with Cognito User Pools
-
Enable server-side encryption for OpenSearch Service domain using AWS managed KMS Key
-
Enable node-to-node encryption for the OpenSearch Service domain
-
Configure the cluster for the OpenSearch Service domain
Architecture
Github
Go to the Github repo