UNPKG

@aws-cdk/aws-ecs

Version:

The CDK Construct Library for AWS::ECS

599 lines 96.5 kB
"use strict"; var _a; Object.defineProperty(exports, "__esModule", { value: true }); exports.isExternalCompatible = exports.isFargateCompatible = exports.isEc2Compatible = exports.Compatibility = exports.Scope = exports.PidMode = exports.IpcMode = exports.NetworkMode = exports.TaskDefinition = void 0; const jsiiDeprecationWarnings = require("../../.warnings.jsii.js"); const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti"); const ec2 = require("@aws-cdk/aws-ec2"); const iam = require("@aws-cdk/aws-iam"); const core_1 = require("@aws-cdk/core"); const container_definition_1 = require("../container-definition"); const ecs_generated_1 = require("../ecs.generated"); const firelens_log_router_1 = require("../firelens-log-router"); const aws_log_driver_1 = require("../log-drivers/aws-log-driver"); const _imported_task_definition_1 = require("./_imported-task-definition"); class TaskDefinitionBase extends core_1.Resource { /** * Return true if the task definition can be run on an EC2 cluster */ get isEc2Compatible() { return isEc2Compatible(this.compatibility); } /** * Return true if the task definition can be run on a Fargate cluster */ get isFargateCompatible() { return isFargateCompatible(this.compatibility); } /** * Return true if the task definition can be run on a ECS anywhere cluster */ get isExternalCompatible() { return isExternalCompatible(this.compatibility); } } /** * The base class for all task definitions. */ class TaskDefinition extends TaskDefinitionBase { /** * Constructs a new instance of the TaskDefinition class. */ constructor(scope, id, props) { super(scope, id); /** * The container definitions. */ this.containers = new Array(); /** * All volumes */ this.volumes = []; /** * Placement constraints for task instances */ this.placementConstraints = new Array(); /** * Inference accelerators for task instances */ this._inferenceAccelerators = []; try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_TaskDefinitionProps(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, TaskDefinition); } throw error; } this.family = props.family || core_1.Names.uniqueId(this); this.compatibility = props.compatibility; if (props.volumes) { props.volumes.forEach(v => this.addVolume(v)); } this.networkMode = props.networkMode ?? (this.isFargateCompatible ? NetworkMode.AWS_VPC : NetworkMode.BRIDGE); if (this.isFargateCompatible && this.networkMode !== NetworkMode.AWS_VPC) { throw new Error(`Fargate tasks can only have AwsVpc network mode, got: ${this.networkMode}`); } if (props.proxyConfiguration && this.networkMode !== NetworkMode.AWS_VPC) { throw new Error(`ProxyConfiguration can only be used with AwsVpc network mode, got: ${this.networkMode}`); } if (props.placementConstraints && props.placementConstraints.length > 0 && this.isFargateCompatible) { throw new Error('Cannot set placement constraints on tasks that run on Fargate'); } if (this.isFargateCompatible && (!props.cpu || !props.memoryMiB)) { throw new Error(`Fargate-compatible tasks require both CPU (${props.cpu}) and memory (${props.memoryMiB}) specifications`); } if (props.inferenceAccelerators && props.inferenceAccelerators.length > 0 && this.isFargateCompatible) { throw new Error('Cannot use inference accelerators on tasks that run on Fargate'); } if (this.isExternalCompatible && this.networkMode !== NetworkMode.BRIDGE) { throw new Error(`External tasks can only have Bridge network mode, got: ${this.networkMode}`); } if (!this.isFargateCompatible && props.runtimePlatform) { throw new Error('Cannot specify runtimePlatform in non-Fargate compatible tasks'); } this._executionRole = props.executionRole; this.taskRole = props.taskRole || new iam.Role(this, 'TaskRole', { assumedBy: new iam.ServicePrincipal('ecs-tasks.amazonaws.com'), }); if (props.inferenceAccelerators) { props.inferenceAccelerators.forEach(ia => this.addInferenceAccelerator(ia)); } this.ephemeralStorageGiB = props.ephemeralStorageGiB; // validate the cpu and memory size for the Windows operation system family. if (props.runtimePlatform?.operatingSystemFamily?._operatingSystemFamily.includes('WINDOWS')) { // We know that props.cpu and props.memoryMiB are defined because an error would have been thrown previously if they were not. // But, typescript is not able to figure this out, so using the `!` operator here to let the type-checker know they are defined. this.checkFargateWindowsBasedTasksSize(props.cpu, props.memoryMiB, props.runtimePlatform); } this.runtimePlatform = props.runtimePlatform; const taskDef = new ecs_generated_1.CfnTaskDefinition(this, 'Resource', { containerDefinitions: core_1.Lazy.any({ produce: () => this.renderContainers() }, { omitEmptyArray: true }), volumes: core_1.Lazy.any({ produce: () => this.renderVolumes() }, { omitEmptyArray: true }), executionRoleArn: core_1.Lazy.string({ produce: () => this.executionRole && this.executionRole.roleArn }), family: this.family, taskRoleArn: this.taskRole.roleArn, requiresCompatibilities: [ ...(isEc2Compatible(props.compatibility) ? ['EC2'] : []), ...(isFargateCompatible(props.compatibility) ? ['FARGATE'] : []), ...(isExternalCompatible(props.compatibility) ? ['EXTERNAL'] : []), ], networkMode: this.renderNetworkMode(this.networkMode), placementConstraints: core_1.Lazy.any({ produce: () => !isFargateCompatible(this.compatibility) ? this.placementConstraints : undefined, }, { omitEmptyArray: true }), proxyConfiguration: props.proxyConfiguration ? props.proxyConfiguration.bind(this.stack, this) : undefined, cpu: props.cpu, memory: props.memoryMiB, ipcMode: props.ipcMode, pidMode: props.pidMode, inferenceAccelerators: core_1.Lazy.any({ produce: () => !isFargateCompatible(this.compatibility) ? this.renderInferenceAccelerators() : undefined, }, { omitEmptyArray: true }), ephemeralStorage: this.ephemeralStorageGiB ? { sizeInGiB: this.ephemeralStorageGiB, } : undefined, runtimePlatform: this.isFargateCompatible && this.runtimePlatform ? { cpuArchitecture: this.runtimePlatform?.cpuArchitecture?._cpuArchitecture, operatingSystemFamily: this.runtimePlatform?.operatingSystemFamily?._operatingSystemFamily, } : undefined, }); if (props.placementConstraints) { props.placementConstraints.forEach(pc => this.addPlacementConstraint(pc)); } this.taskDefinitionArn = taskDef.ref; } /** * Imports a task definition from the specified task definition ARN. * * The task will have a compatibility of EC2+Fargate. */ static fromTaskDefinitionArn(scope, id, taskDefinitionArn) { return new _imported_task_definition_1.ImportedTaskDefinition(scope, id, { taskDefinitionArn: taskDefinitionArn }); } /** * Create a task definition from a task definition reference */ static fromTaskDefinitionAttributes(scope, id, attrs) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_TaskDefinitionAttributes(attrs); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.fromTaskDefinitionAttributes); } throw error; } return new _imported_task_definition_1.ImportedTaskDefinition(scope, id, { taskDefinitionArn: attrs.taskDefinitionArn, compatibility: attrs.compatibility, networkMode: attrs.networkMode, taskRole: attrs.taskRole, }); } get executionRole() { return this._executionRole; } /** * Public getter method to access list of inference accelerators attached to the instance. */ get inferenceAccelerators() { return this._inferenceAccelerators; } renderVolumes() { return this.volumes.map(renderVolume); function renderVolume(spec) { return { host: spec.host, name: spec.name, dockerVolumeConfiguration: spec.dockerVolumeConfiguration && { autoprovision: spec.dockerVolumeConfiguration.autoprovision, driver: spec.dockerVolumeConfiguration.driver, driverOpts: spec.dockerVolumeConfiguration.driverOpts, labels: spec.dockerVolumeConfiguration.labels, scope: spec.dockerVolumeConfiguration.scope, }, efsVolumeConfiguration: spec.efsVolumeConfiguration && { filesystemId: spec.efsVolumeConfiguration.fileSystemId, authorizationConfig: spec.efsVolumeConfiguration.authorizationConfig, rootDirectory: spec.efsVolumeConfiguration.rootDirectory, transitEncryption: spec.efsVolumeConfiguration.transitEncryption, transitEncryptionPort: spec.efsVolumeConfiguration.transitEncryptionPort, }, }; } } renderInferenceAccelerators() { return this._inferenceAccelerators.map(renderInferenceAccelerator); function renderInferenceAccelerator(inferenceAccelerator) { return { deviceName: inferenceAccelerator.deviceName, deviceType: inferenceAccelerator.deviceType, }; } } /** * Validate the existence of the input target and set default values. * * @internal */ _validateTarget(options) { const targetContainer = this.findContainer(options.containerName); if (targetContainer === undefined) { throw new Error(`No container named '${options.containerName}'. Did you call "addContainer()"?`); } const targetProtocol = options.protocol || container_definition_1.Protocol.TCP; const targetContainerPort = options.containerPort || targetContainer.containerPort; const portMapping = targetContainer.findPortMapping(targetContainerPort, targetProtocol); if (portMapping === undefined) { // eslint-disable-next-line max-len throw new Error(`Container '${targetContainer}' has no mapping for port ${options.containerPort} and protocol ${targetProtocol}. Did you call "container.addPortMappings()"?`); } return { containerName: options.containerName, portMapping, }; } /** * Returns the port range to be opened that match the provided container name and container port. * * @internal */ _portRangeFromPortMapping(portMapping) { if (portMapping.hostPort !== undefined && portMapping.hostPort !== 0) { return portMapping.protocol === container_definition_1.Protocol.UDP ? ec2.Port.udp(portMapping.hostPort) : ec2.Port.tcp(portMapping.hostPort); } if (this.networkMode === NetworkMode.BRIDGE || this.networkMode === NetworkMode.NAT) { return EPHEMERAL_PORT_RANGE; } return portMapping.protocol === container_definition_1.Protocol.UDP ? ec2.Port.udp(portMapping.containerPort) : ec2.Port.tcp(portMapping.containerPort); } /** * Adds a policy statement to the task IAM role. */ addToTaskRolePolicy(statement) { this.taskRole.addToPrincipalPolicy(statement); } /** * Adds a policy statement to the task execution IAM role. */ addToExecutionRolePolicy(statement) { this.obtainExecutionRole().addToPrincipalPolicy(statement); } /** * Adds a new container to the task definition. */ addContainer(id, props) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_ContainerDefinitionOptions(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addContainer); } throw error; } return new container_definition_1.ContainerDefinition(this, id, { taskDefinition: this, ...props }); } /** * Adds a firelens log router to the task definition. */ addFirelensLogRouter(id, props) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_FirelensLogRouterDefinitionOptions(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addFirelensLogRouter); } throw error; } // only one firelens log router is allowed in each task. if (this.containers.find(x => x instanceof firelens_log_router_1.FirelensLogRouter)) { throw new Error('Firelens log router is already added in this task.'); } return new firelens_log_router_1.FirelensLogRouter(this, id, { taskDefinition: this, ...props }); } /** * Links a container to this task definition. * @internal */ _linkContainer(container) { this.containers.push(container); if (this.defaultContainer === undefined && container.essential) { this.defaultContainer = container; } if (container.referencesSecretJsonField) { this._referencesSecretJsonField = true; } } /** * Adds a volume to the task definition. */ addVolume(volume) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_Volume(volume); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addVolume); } throw error; } this.volumes.push(volume); } /** * Adds the specified placement constraint to the task definition. */ addPlacementConstraint(constraint) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_PlacementConstraint(constraint); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addPlacementConstraint); } throw error; } if (isFargateCompatible(this.compatibility)) { throw new Error('Cannot set placement constraints on tasks that run on Fargate'); } this.placementConstraints.push(...constraint.toJson()); } /** * Adds the specified extension to the task definition. * * Extension can be used to apply a packaged modification to * a task definition. */ addExtension(extension) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_ITaskDefinitionExtension(extension); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addExtension); } throw error; } extension.extend(this); } /** * Adds an inference accelerator to the task definition. */ addInferenceAccelerator(inferenceAccelerator) { try { jsiiDeprecationWarnings._aws_cdk_aws_ecs_InferenceAccelerator(inferenceAccelerator); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addInferenceAccelerator); } throw error; } if (isFargateCompatible(this.compatibility)) { throw new Error('Cannot use inference accelerators on tasks that run on Fargate'); } this._inferenceAccelerators.push(inferenceAccelerator); } /** * Creates the task execution IAM role if it doesn't already exist. */ obtainExecutionRole() { if (!this._executionRole) { this._executionRole = new iam.Role(this, 'ExecutionRole', { assumedBy: new iam.ServicePrincipal('ecs-tasks.amazonaws.com'), // needed for cross-account access with TagParameterContainerImage roleName: core_1.PhysicalName.GENERATE_IF_NEEDED, }); } return this._executionRole; } /** * Whether this task definition has at least a container that references a * specific JSON field of a secret stored in Secrets Manager. */ get referencesSecretJsonField() { return this._referencesSecretJsonField; } /** * Validates the task definition. */ validate() { const ret = super.validate(); if (isEc2Compatible(this.compatibility)) { // EC2 mode validations // Container sizes for (const container of this.containers) { if (!container.memoryLimitSpecified) { ret.push(`ECS Container ${container.containerName} must have at least one of 'memoryLimitMiB' or 'memoryReservationMiB' specified`); } } } return ret; } /** * Returns the container that match the provided containerName. */ findContainer(containerName) { return this.containers.find(c => c.containerName === containerName); } renderNetworkMode(networkMode) { return (networkMode === NetworkMode.NAT) ? undefined : networkMode; } renderContainers() { // add firelens log router container if any application container is using firelens log driver, // also check if already created log router container for (const container of this.containers) { if (container.logDriverConfig && container.logDriverConfig.logDriver === 'awsfirelens' && !this.containers.find(x => x instanceof firelens_log_router_1.FirelensLogRouter)) { this.addFirelensLogRouter('log-router', { image: firelens_log_router_1.obtainDefaultFluentBitECRImage(this, container.logDriverConfig), firelensConfig: { type: firelens_log_router_1.FirelensLogRouterType.FLUENTBIT, }, logging: new aws_log_driver_1.AwsLogDriver({ streamPrefix: 'firelens' }), memoryReservationMiB: 50, }); break; } } return this.containers.map(x => x.renderContainerDefinition()); } checkFargateWindowsBasedTasksSize(cpu, memory, runtimePlatform) { if (Number(cpu) === 1024) { if (Number(memory) < 1024 || Number(memory) > 8192 || (Number(memory) % 1024 !== 0)) { throw new Error(`If provided cpu is ${cpu}, then memoryMiB must have a min of 1024 and a max of 8192, in 1024 increments. Provided memoryMiB was ${Number(memory)}.`); } } else if (Number(cpu) === 2048) { if (Number(memory) < 4096 || Number(memory) > 16384 || (Number(memory) % 1024 !== 0)) { throw new Error(`If provided cpu is ${cpu}, then memoryMiB must have a min of 4096 and max of 16384, in 1024 increments. Provided memoryMiB ${Number(memory)}.`); } } else if (Number(cpu) === 4096) { if (Number(memory) < 8192 || Number(memory) > 30720 || (Number(memory) % 1024 !== 0)) { throw new Error(`If provided cpu is ${cpu}, then memoryMiB must have a min of 8192 and a max of 30720, in 1024 increments.Provided memoryMiB was ${Number(memory)}.`); } } else { throw new Error(`If operatingSystemFamily is ${runtimePlatform.operatingSystemFamily._operatingSystemFamily}, then cpu must be in 1024 (1 vCPU), 2048 (2 vCPU), or 4096 (4 vCPU). Provided value was: ${cpu}`); } } ; } exports.TaskDefinition = TaskDefinition; _a = JSII_RTTI_SYMBOL_1; TaskDefinition[_a] = { fqn: "@aws-cdk/aws-ecs.TaskDefinition", version: "1.204.0" }; /** * The port range to open up for dynamic port mapping */ const EPHEMERAL_PORT_RANGE = ec2.Port.tcpRange(32768, 65535); /** * The networking mode to use for the containers in the task. */ var NetworkMode; (function (NetworkMode) { /** * The task's containers do not have external connectivity and port mappings can't be specified in the container definition. */ NetworkMode["NONE"] = "none"; /** * The task utilizes Docker's built-in virtual network which runs inside each container instance. */ NetworkMode["BRIDGE"] = "bridge"; /** * The task is allocated an elastic network interface. */ NetworkMode["AWS_VPC"] = "awsvpc"; /** * The task bypasses Docker's built-in virtual network and maps container ports directly to the EC2 instance's network interface directly. * * In this mode, you can't run multiple instantiations of the same task on a * single container instance when port mappings are used. */ NetworkMode["HOST"] = "host"; /** * The task utilizes NAT network mode required by Windows containers. * * This is the only supported network mode for Windows containers. For more information, see * [Task Definition Parameters](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definition_parameters.html#network_mode). */ NetworkMode["NAT"] = "nat"; })(NetworkMode = exports.NetworkMode || (exports.NetworkMode = {})); /** * The IPC resource namespace to use for the containers in the task. */ var IpcMode; (function (IpcMode) { /** * If none is specified, then IPC resources within the containers of a task are private and not * shared with other containers in a task or on the container instance */ IpcMode["NONE"] = "none"; /** * If host is specified, then all containers within the tasks that specified the host IPC mode on * the same container instance share the same IPC resources with the host Amazon EC2 instance. */ IpcMode["HOST"] = "host"; /** * If task is specified, all containers within the specified task share the same IPC resources. */ IpcMode["TASK"] = "task"; })(IpcMode = exports.IpcMode || (exports.IpcMode = {})); /** * The process namespace to use for the containers in the task. */ var PidMode; (function (PidMode) { /** * If host is specified, then all containers within the tasks that specified the host PID mode * on the same container instance share the same process namespace with the host Amazon EC2 instance. */ PidMode["HOST"] = "host"; /** * If task is specified, all containers within the specified task share the same process namespace. */ PidMode["TASK"] = "task"; })(PidMode = exports.PidMode || (exports.PidMode = {})); /** * The scope for the Docker volume that determines its lifecycle. * Docker volumes that are scoped to a task are automatically provisioned when the task starts and destroyed when the task stops. * Docker volumes that are scoped as shared persist after the task stops. */ var Scope; (function (Scope) { /** * Docker volumes that are scoped to a task are automatically provisioned when the task starts and destroyed when the task stops. */ Scope["TASK"] = "task"; /** * Docker volumes that are scoped as shared persist after the task stops. */ Scope["SHARED"] = "shared"; })(Scope = exports.Scope || (exports.Scope = {})); /** * The task launch type compatibility requirement. */ var Compatibility; (function (Compatibility) { /** * The task should specify the EC2 launch type. */ Compatibility[Compatibility["EC2"] = 0] = "EC2"; /** * The task should specify the Fargate launch type. */ Compatibility[Compatibility["FARGATE"] = 1] = "FARGATE"; /** * The task can specify either the EC2 or Fargate launch types. */ Compatibility[Compatibility["EC2_AND_FARGATE"] = 2] = "EC2_AND_FARGATE"; /** * The task should specify the External launch type. */ Compatibility[Compatibility["EXTERNAL"] = 3] = "EXTERNAL"; })(Compatibility = exports.Compatibility || (exports.Compatibility = {})); /** * Return true if the given task definition can be run on an EC2 cluster */ function isEc2Compatible(compatibility) { return [Compatibility.EC2, Compatibility.EC2_AND_FARGATE].includes(compatibility); } exports.isEc2Compatible = isEc2Compatible; /** * Return true if the given task definition can be run on a Fargate cluster */ function isFargateCompatible(compatibility) { return [Compatibility.FARGATE, Compatibility.EC2_AND_FARGATE].includes(compatibility); } exports.isFargateCompatible = isFargateCompatible; /** * Return true if the given task definition can be run on a ECS Anywhere cluster */ function isExternalCompatible(compatibility) { return [Compatibility.EXTERNAL].includes(compatibility); } exports.isExternalCompatible = isExternalCompatible; //# sourceMappingURL=data:application/json;base64,