Migrate docker-compose network to AWS ECS with Terraform

Viewed 206

I'm using a docker-compose with 2 services

docker.-compose.yml

version: "3.0"

services:
  backend:
    container_name: arqlogger-backend
    build: ./backend
    volumes:
      - arqlogger:/server
  frontend:
    container_name: arqlogger-frontend
    build: ./frontend
    ports:
      - "8080:80"

volumes:
  arqlogger:

Where the frontend uses a Nginx in order to connect to the backend

nginx.conf

server {
    listen       80;
    listen  [::]:80;
    server_name  localhost;

    location /api/ {
        proxy_pass  http://backend/;
    }

    location / {
      root   /usr/share/nginx/html;
      index  index.html index.htm;
      try_files $uri $uri/ /index.html =404;
    } 

    error_page   500 502 503 504  /50x.html;
    location = /50x.html {
        root   /usr/share/nginx/html;
    }
}

I'm trying to migrate that to AWS ECS using Terraform following the Cluster and Terraform-ecs by arminc and then creating the Task Definitions and Service Definitions by myself:

resource "aws_ecs_task_definition" "backend_task" {
  family                   = "${var.task_name[0]}" # Naming our first task
  container_definitions    = <<DEFINITION
  [
    {
      "name": "${var.task_name[0]}",
      "image": "${aws_ecr_repository.first_repo.repository_url}",
      "essential": true,
      "portMappings": [
        {
          "containerPort": ${var.containerPort},
          "hostPort": ${var.containerPort}
        }
      ],
      "logConfiguration": {
        "logDriver": "awslogs",
        "options": {
            "awslogs-group": "${var.task_name[0]}",
            "awslogs-region": "${var.region}",
            "awslogs-stream-prefix": "awslogs-"
        }
      },
      "memory": ${var.task-memory},
      "cpu": ${var.task-cpu}
    }
  ]
  DEFINITION
  requires_compatibilities = ["EC2"]     # Stating that we are using ECS Fargate
  network_mode             = "bridge"        # Using awsvpc as our network mode as this is required for Fargate
  memory                   = var.task-memory # Specifying the memory our container requires
  cpu                      = var.task-cpu    # Specifying the CPU our container requires
  execution_role_arn       = aws_iam_role.ecsTaskExecutionRole.arn
}

resource "aws_ecs_task_definition" "frontend_task" {
  family                   = "${var.task_name[1]}" # Naming our first task
  container_definitions    = <<DEFINITION
  [
    {
      "name": "${var.task_name[1]}",
      "image": "${aws_ecr_repository.first_repo.repository_url}",
      "essential": true,
      "portMappings": [
        {
          "containerPort": ${var.containerPort},
          "hostPort": ${var.containerPort}
        }
      ],
      "logConfiguration": {
        "logDriver": "awslogs",
        "options": {
            "awslogs-group": "${var.task_name[1]}",
            "awslogs-region": "${var.region}",
            "awslogs-stream-prefix": "awslogs-"
        }
      },
      "memory": ${var.task-memory},
      "cpu": ${var.task-cpu}
    }
  ]
  DEFINITION
  requires_compatibilities = ["EC2"]     # Stating that we are using ECS Fargate
  network_mode             = "bridge"        # Using awsvpc as our network mode as this is required for Fargate
  memory                   = var.task-memory # Specifying the memory our container requires
  cpu                      = var.task-cpu    # Specifying the CPU our container requires
  execution_role_arn       = aws_iam_role.ecsTaskExecutionRole.arn
}



resource "aws_ecs_service" "backend_service" {
  name            = "${var.project}-backend"                          # Naming our first service
  cluster         = var.cluster_arn             # Referencing our created Cluster
  task_definition = aws_ecs_task_definition.backend_task.arn # Referencing the task our service will spin up
  launch_type     = "EC2"
  desired_count   = var.desired_count[0] # Setting the number of containers to 3

  load_balancer {
    target_group_arn = var.alb_arn # Referencing our target group
    container_name   = aws_ecs_task_definition.backend_task.family
    container_port   = "${var.containerPort}" # Specifying the container port
  }

  network_configuration {
    subnets          = [var.service_subnets[0],var.service_subnets[1]]
    assign_public_ip = true                                                # Providing our containers with public IPs
    security_groups  = [var.service_sg] # Setting the security group
  }
}

resource "aws_ecs_service" "frontend_service" {
  name            = "${var.project}-frontend"                              # Naming our first service
  cluster         = var.cluster_arn                # Referencing our created Cluster
  task_definition = aws_ecs_task_definition.frontend_task.arn # Referencing the task our service will spin up
  launch_type     = "EC2"
  desired_count   = var.desired_count[1] # Setting the number of containers to 3

  load_balancer {
    target_group_arn = var.alb_arn # Referencing our target group
    container_name   = aws_ecs_task_definition.frontend_task.family
    container_port   = "${var.containerPort}" # Specifying the container port
  }

  network_configuration {
    subnets          = [var.service_subnets[0],var.service_subnets[1]]
    assign_public_ip = true                                                # Providing our containers with public IPs
    security_groups  = [var.service_sg] # Setting the security group
  }
}

I'm a little lost with the network configuration. I'm using EC2 based ECS so I have ENIs from my multiple hosts. Also I have EBS for each host.

How can I configure the services (awsvpc, bridge, host) in the task definions in order to see the backend from the frontend?

0 Answers
Related