aws-fargate-ssmstringparameter
| Reference Documentation: | https://docs.aws.amazon.com/solutions/latest/constructs/ |
| Language | Package |
|---|---|
|
|
|
|
|
|
|
|
|
Overview
This AWS Solutions Construct implements an AWS Fargate service that can read/write to an AWS Systems Manager String Parameter
Here is a minimal deployable pattern definition:
Example
Pattern Construct Props
| Name | Type | Description |
|---|---|---|
|
publicApi |
|
Whether the construct is deploying a private or public API. This has implications for the VPC. |
|
vpcProps? |
Optional custom properties for a VPC the construct will create. This VPC will be used by any Private Hosted Zone the construct creates (that’s why loadBalancerProps and privateHostedZoneProps can’t include a VPC). Providing both this and existingVpc causes an error. |
|
|
existingVpc? |
An existing VPC in which to deploy the construct. Providing both this and vpcProps causes an error. If the client provides an existing load balancer and/or existing Private Hosted Zone, those constructs must exist in this VPC. |
|
|
clusterProps? |
Optional properties to create a new ECS cluster. To provide an existing cluster, use the cluster attribute of fargateServiceProps. |
|
|
ecrRepositoryArn? |
|
The arn of an ECR Repository containing the image to use to generate the containers. Either this or the image property of containerDefinitionProps must be provided. format: arn:aws:ecr:_region_:_account number_:repository/Repository Name |
|
ecrImageVersion? |
|
The version of the image to use from the repository. Defaults to "Latest" |
|
containerDefinitionProps? |
Optional props to define the container created for the Fargate Service (defaults found in fargate-defaults.ts) |
|
|
fargateTaskDefinitionProps? |
Optional props to define the Fargate Task Definition for this construct (defaults found in fargate-defaults.ts) |
|
|
fargateServiceProps? |
|
Optional values to override default Fargate Task definition properties (fargate-defaults.ts). The construct will default to launching the service is the most isolated subnets available (precedence: Isolated, Private and Public). Override those and other defaults here. |
|
existingFargateServiceObject? |
A Fargate Service already instantiated (probably by another Solutions Construct). If this is specified, then no props defining a new service can be provided, including: ecrImageVersion, containerDefinitionProps, fargateTaskDefinitionProps, ecrRepositoryArn, fargateServiceProps, clusterProps |
|
|
existingContainerDefinitionObject? |
A container definition already instantiated as part of a Fargate service. This must be the container in the existingFargateServiceObject |
|
|
existingStringParameterObj? |
Existing instance of SSM String parameter object, providing both this
and |
|
|
stringParameterProps? |
Optional user provided props to override the default props for SSM
String parameter. If existingStringParameterObj is not set
stringParameterProps is required. The only supported
|
|
|
stringParameterPermissions? |
|
Optional SSM String parameter permissions to grant to the Fargate service. One of the following may be specified: "Read", "ReadWrite". |
|
stringParameterEnvironmentVariableName? |
|
Optional Name for the container environment variable set to the SSM parameter name. Default: SSM_STRING_PARAMETER_NAME |
Pattern Properties
| Name | Type | Description |
|---|---|---|
|
vpc |
The VPC used by the construct (whether created by the construct or provided by the client) |
|
|
service |
The AWS Fargate service used by this construct (whether created by this construct or passed to this construct at initialization) |
|
|
container |
The container associated with the AWS Fargate service in the service property. |
|
|
stringParameter |
Returns an instance of |
Default settings
Out of the box implementation of the Construct without any override will set the following defaults:
AWS Fargate Service
-
Sets up an AWS Fargate service
-
Uses the existing service if provided
-
Creates a new service if none provided.
-
Service will run in isolated subnets if available, then private subnets if available and finally public subnets
-
-
Adds environment variables to the container with the ARN and Name of the SSM parameter
-
Add permissions to the container IAM role allowing it to read/write to the SSM parameter
-
AWS SSM String Parameter
-
Sets up an AWS SSM String Parameter
-
Uses an existing parameter if one is provided, otherwise creates a new one
-
-
Adds an Interface Endpoint to the VPC for SSM parameter (the service by default runs in Isolated or Private subnets)
Architecture
Github
Go to the Github repo