UNPKG

105 kBJavaScriptView Raw
1"use strict";
2var _a, _b;
3Object.defineProperty(exports, "__esModule", { value: true });
4exports.AsgCapacityProvider = exports.ExecuteCommandLogging = exports.Cluster = exports.MachineImageType = void 0;
5const jsiiDeprecationWarnings = require("../.warnings.jsii.js");
6const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti");
7const autoscaling = require("@aws-cdk/aws-autoscaling");
8const cloudwatch = require("@aws-cdk/aws-cloudwatch");
9const ec2 = require("@aws-cdk/aws-ec2");
10const iam = require("@aws-cdk/aws-iam");
11const cloudmap = require("@aws-cdk/aws-servicediscovery");
12const core_1 = require("@aws-cdk/core");
13const amis_1 = require("./amis");
14const instance_drain_hook_1 = require("./drain-hook/instance-drain-hook");
15const ecs_canned_metrics_generated_1 = require("./ecs-canned-metrics.generated");
16const ecs_generated_1 = require("./ecs.generated");
17// v2 - keep this import as a separate section to reduce merge conflict when forward merging with the v2 branch.
18// eslint-disable-next-line
19const core_2 = require("@aws-cdk/core");
20/**
21 * The machine image type
22 */
23var MachineImageType;
24(function (MachineImageType) {
25 /**
26 * Amazon ECS-optimized Amazon Linux 2 AMI
27 */
28 MachineImageType[MachineImageType["AMAZON_LINUX_2"] = 0] = "AMAZON_LINUX_2";
29 /**
30 * Bottlerocket AMI
31 */
32 MachineImageType[MachineImageType["BOTTLEROCKET"] = 1] = "BOTTLEROCKET";
33})(MachineImageType = exports.MachineImageType || (exports.MachineImageType = {}));
34/**
35 * A regional grouping of one or more container instances on which you can run tasks and services.
36 */
37class Cluster extends core_1.Resource {
38 /**
39 * Constructs a new instance of the Cluster class.
40 */
41 constructor(scope, id, props = {}) {
42 super(scope, id, {
43 physicalName: props.clusterName,
44 });
45 /**
46 * Manage the allowed network connections for the cluster with Security Groups.
47 */
48 this.connections = new ec2.Connections();
49 /**
50 * The names of both ASG and Fargate capacity providers associated with the cluster.
51 */
52 this._capacityProviderNames = [];
53 /**
54 * Specifies whether the cluster has EC2 instance capacity.
55 */
56 this._hasEc2Capacity = false;
57 try {
58 jsiiDeprecationWarnings._aws_cdk_aws_ecs_ClusterProps(props);
59 }
60 catch (error) {
61 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
62 Error.captureStackTrace(error, Cluster);
63 }
64 throw error;
65 }
66 /**
67 * clusterSettings needs to be undefined if containerInsights is not explicitly set in order to allow any
68 * containerInsights settings on the account to apply. See:
69 * https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-ecs-cluster-clustersettings.html#cfn-ecs-cluster-clustersettings-value
70 */
71 let clusterSettings = undefined;
72 if (props.containerInsights !== undefined) {
73 clusterSettings = [{ name: 'containerInsights', value: props.containerInsights ? ContainerInsights.ENABLED : ContainerInsights.DISABLED }];
74 }
75 this._capacityProviderNames = props.capacityProviders ?? [];
76 if (props.enableFargateCapacityProviders) {
77 this.enableFargateCapacityProviders();
78 }
79 if (props.executeCommandConfiguration) {
80 if ((props.executeCommandConfiguration.logging === ExecuteCommandLogging.OVERRIDE) !==
81 (props.executeCommandConfiguration.logConfiguration !== undefined)) {
82 throw new Error('Execute command log configuration must only be specified when logging is OVERRIDE.');
83 }
84 this._executeCommandConfiguration = props.executeCommandConfiguration;
85 }
86 const cluster = new ecs_generated_1.CfnCluster(this, 'Resource', {
87 clusterName: this.physicalName,
88 clusterSettings,
89 configuration: this._executeCommandConfiguration && this.renderExecuteCommandConfiguration(),
90 });
91 this.clusterArn = this.getResourceArnAttribute(cluster.attrArn, {
92 service: 'ecs',
93 resource: 'cluster',
94 resourceName: this.physicalName,
95 });
96 this.clusterName = this.getResourceNameAttribute(cluster.ref);
97 this.vpc = props.vpc || new ec2.Vpc(this, 'Vpc', { maxAzs: 2 });
98 this._defaultCloudMapNamespace = props.defaultCloudMapNamespace !== undefined
99 ? this.addDefaultCloudMapNamespace(props.defaultCloudMapNamespace)
100 : undefined;
101 this._autoscalingGroup = props.capacity !== undefined
102 ? this.addCapacity('DefaultAutoScalingGroup', props.capacity)
103 : undefined;
104 // Only create cluster capacity provider associations if there are any EC2
105 // capacity providers. Ordinarily we'd just add the construct to the tree
106 // since it's harmless, but we'd prefer not to add unexpected new
107 // resources to the stack which could surprise users working with
108 // brown-field CDK apps and stacks.
109 core_1.Aspects.of(this).add(new MaybeCreateCapacityProviderAssociations(this, id, this._capacityProviderNames));
110 }
111 /**
112 * Import an existing cluster to the stack from its attributes.
113 */
114 static fromClusterAttributes(scope, id, attrs) {
115 try {
116 jsiiDeprecationWarnings._aws_cdk_aws_ecs_ClusterAttributes(attrs);
117 }
118 catch (error) {
119 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
120 Error.captureStackTrace(error, this.fromClusterAttributes);
121 }
122 throw error;
123 }
124 return new ImportedCluster(scope, id, attrs);
125 }
126 /**
127 * Import an existing cluster to the stack from the cluster ARN.
128 * This does not provide access to the vpc, hasEc2Capacity, or connections -
129 * use the `fromClusterAttributes` method to access those properties.
130 */
131 static fromClusterArn(scope, id, clusterArn) {
132 const stack = core_1.Stack.of(scope);
133 const arn = stack.splitArn(clusterArn, core_1.ArnFormat.SLASH_RESOURCE_NAME);
134 const clusterName = arn.resourceName;
135 if (!clusterName) {
136 throw new Error(`Missing required Cluster Name from Cluster ARN: ${clusterArn}`);
137 }
138 const errorSuffix = 'is not available for a Cluster imported using fromClusterArn(), please use fromClusterAttributes() instead.';
139 class Import extends core_1.Resource {
140 constructor() {
141 super(...arguments);
142 this.clusterArn = clusterArn;
143 this.clusterName = clusterName;
144 }
145 get hasEc2Capacity() {
146 throw new Error(`hasEc2Capacity ${errorSuffix}`);
147 }
148 get connections() {
149 throw new Error(`connections ${errorSuffix}`);
150 }
151 get vpc() {
152 throw new Error(`vpc ${errorSuffix}`);
153 }
154 }
155 return new Import(scope, id, {
156 environmentFromArn: clusterArn,
157 });
158 }
159 /**
160 * Enable the Fargate capacity providers for this cluster.
161 */
162 enableFargateCapacityProviders() {
163 for (const provider of ['FARGATE', 'FARGATE_SPOT']) {
164 if (!this._capacityProviderNames.includes(provider)) {
165 this._capacityProviderNames.push(provider);
166 }
167 }
168 }
169 renderExecuteCommandConfiguration() {
170 return {
171 executeCommandConfiguration: {
172 kmsKeyId: this._executeCommandConfiguration?.kmsKey?.keyArn,
173 logConfiguration: this._executeCommandConfiguration?.logConfiguration && this.renderExecuteCommandLogConfiguration(),
174 logging: this._executeCommandConfiguration?.logging,
175 },
176 };
177 }
178 renderExecuteCommandLogConfiguration() {
179 const logConfiguration = this._executeCommandConfiguration?.logConfiguration;
180 if (logConfiguration?.s3EncryptionEnabled && !logConfiguration?.s3Bucket) {
181 throw new Error('You must specify an S3 bucket name in the execute command log configuration to enable S3 encryption.');
182 }
183 if (logConfiguration?.cloudWatchEncryptionEnabled && !logConfiguration?.cloudWatchLogGroup) {
184 throw new Error('You must specify a CloudWatch log group in the execute command log configuration to enable CloudWatch encryption.');
185 }
186 return {
187 cloudWatchEncryptionEnabled: logConfiguration?.cloudWatchEncryptionEnabled,
188 cloudWatchLogGroupName: logConfiguration?.cloudWatchLogGroup?.logGroupName,
189 s3BucketName: logConfiguration?.s3Bucket?.bucketName,
190 s3EncryptionEnabled: logConfiguration?.s3EncryptionEnabled,
191 s3KeyPrefix: logConfiguration?.s3KeyPrefix,
192 };
193 }
194 /**
195 * Add an AWS Cloud Map DNS namespace for this cluster.
196 * NOTE: HttpNamespaces are not supported, as ECS always requires a DNSConfig when registering an instance to a Cloud
197 * Map service.
198 */
199 addDefaultCloudMapNamespace(options) {
200 try {
201 jsiiDeprecationWarnings._aws_cdk_aws_ecs_CloudMapNamespaceOptions(options);
202 }
203 catch (error) {
204 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
205 Error.captureStackTrace(error, this.addDefaultCloudMapNamespace);
206 }
207 throw error;
208 }
209 if (this._defaultCloudMapNamespace !== undefined) {
210 throw new Error('Can only add default namespace once.');
211 }
212 const namespaceType = options.type !== undefined
213 ? options.type
214 : cloudmap.NamespaceType.DNS_PRIVATE;
215 const sdNamespace = namespaceType === cloudmap.NamespaceType.DNS_PRIVATE ?
216 new cloudmap.PrivateDnsNamespace(this, 'DefaultServiceDiscoveryNamespace', {
217 name: options.name,
218 vpc: this.vpc,
219 }) :
220 new cloudmap.PublicDnsNamespace(this, 'DefaultServiceDiscoveryNamespace', {
221 name: options.name,
222 });
223 this._defaultCloudMapNamespace = sdNamespace;
224 return sdNamespace;
225 }
226 /**
227 * Getter for namespace added to cluster
228 */
229 get defaultCloudMapNamespace() {
230 return this._defaultCloudMapNamespace;
231 }
232 /**
233 * It is highly recommended to use {@link Cluster.addAsgCapacityProvider} instead of this method.
234 *
235 * This method adds compute capacity to a cluster by creating an AutoScalingGroup with the specified options.
236 *
237 * Returns the AutoScalingGroup so you can add autoscaling settings to it.
238 */
239 addCapacity(id, options) {
240 try {
241 jsiiDeprecationWarnings._aws_cdk_aws_ecs_AddCapacityOptions(options);
242 }
243 catch (error) {
244 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
245 Error.captureStackTrace(error, this.addCapacity);
246 }
247 throw error;
248 }
249 // Do 2-way defaulting here: if the machineImageType is BOTTLEROCKET, pick the right AMI.
250 // Otherwise, determine the machineImageType from the given AMI.
251 const machineImage = options.machineImage ??
252 (options.machineImageType === MachineImageType.BOTTLEROCKET ? new amis_1.BottleRocketImage({
253 architecture: options.instanceType.architecture,
254 }) : new amis_1.EcsOptimizedAmi());
255 const machineImageType = options.machineImageType ??
256 (isBottleRocketImage(machineImage) ? MachineImageType.BOTTLEROCKET : MachineImageType.AMAZON_LINUX_2);
257 const autoScalingGroup = new autoscaling.AutoScalingGroup(this, id, {
258 vpc: this.vpc,
259 machineImage,
260 updateType: options.updateType || autoscaling.UpdateType.REPLACING_UPDATE,
261 ...options,
262 });
263 this.addAutoScalingGroup(autoScalingGroup, {
264 machineImageType: machineImageType,
265 ...options,
266 });
267 return autoScalingGroup;
268 }
269 /**
270 * This method adds an Auto Scaling Group Capacity Provider to a cluster.
271 *
272 * @param provider the capacity provider to add to this cluster.
273 */
274 addAsgCapacityProvider(provider, options = {}) {
275 try {
276 jsiiDeprecationWarnings._aws_cdk_aws_ecs_AsgCapacityProvider(provider);
277 jsiiDeprecationWarnings._aws_cdk_aws_ecs_AddAutoScalingGroupCapacityOptions(options);
278 }
279 catch (error) {
280 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
281 Error.captureStackTrace(error, this.addAsgCapacityProvider);
282 }
283 throw error;
284 }
285 // Don't add the same capacity provider more than once.
286 if (this._capacityProviderNames.includes(provider.capacityProviderName)) {
287 return;
288 }
289 this._hasEc2Capacity = true;
290 this.configureAutoScalingGroup(provider.autoScalingGroup, {
291 ...options,
292 machineImageType: provider.machineImageType,
293 // Don't enable the instance-draining lifecycle hook if managed termination protection is enabled
294 taskDrainTime: provider.enableManagedTerminationProtection ? core_1.Duration.seconds(0) : options.taskDrainTime,
295 canContainersAccessInstanceRole: options.canContainersAccessInstanceRole ?? provider.canContainersAccessInstanceRole,
296 });
297 this._capacityProviderNames.push(provider.capacityProviderName);
298 }
299 /**
300 * This method adds compute capacity to a cluster using the specified AutoScalingGroup.
301 *
302 * @deprecated Use {@link Cluster.addAsgCapacityProvider} instead.
303 * @param autoScalingGroup the ASG to add to this cluster.
304 * [disable-awslint:ref-via-interface] is needed in order to install the ECS
305 * agent by updating the ASGs user data.
306 */
307 addAutoScalingGroup(autoScalingGroup, options = {}) {
308 try {
309 jsiiDeprecationWarnings.print("@aws-cdk/aws-ecs.Cluster#addAutoScalingGroup", "Use {@link Cluster.addAsgCapacityProvider} instead.");
310 jsiiDeprecationWarnings._aws_cdk_aws_ecs_AddAutoScalingGroupCapacityOptions(options);
311 }
312 catch (error) {
313 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
314 Error.captureStackTrace(error, this.addAutoScalingGroup);
315 }
316 throw error;
317 }
318 this._hasEc2Capacity = true;
319 this.connections.connections.addSecurityGroup(...autoScalingGroup.connections.securityGroups);
320 this.configureAutoScalingGroup(autoScalingGroup, options);
321 }
322 configureAutoScalingGroup(autoScalingGroup, options = {}) {
323 if (autoScalingGroup.osType === ec2.OperatingSystemType.WINDOWS) {
324 this.configureWindowsAutoScalingGroup(autoScalingGroup, options);
325 }
326 else {
327 // Tie instances to cluster
328 switch (options.machineImageType) {
329 // Bottlerocket AMI
330 case MachineImageType.BOTTLEROCKET: {
331 autoScalingGroup.addUserData(
332 // Connect to the cluster
333 // Source: https://github.com/bottlerocket-os/bottlerocket/blob/develop/QUICKSTART-ECS.md#connecting-to-your-cluster
334 '[settings.ecs]', `cluster = "${this.clusterName}"`);
335 // Enabling SSM
336 // Source: https://github.com/bottlerocket-os/bottlerocket/blob/develop/QUICKSTART-ECS.md#enabling-ssm
337 autoScalingGroup.role.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName('AmazonSSMManagedInstanceCore'));
338 // required managed policy
339 autoScalingGroup.role.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName('service-role/AmazonEC2ContainerServiceforEC2Role'));
340 break;
341 }
342 default:
343 // Amazon ECS-optimized AMI for Amazon Linux 2
344 autoScalingGroup.addUserData(`echo ECS_CLUSTER=${this.clusterName} >> /etc/ecs/ecs.config`);
345 if (!options.canContainersAccessInstanceRole) {
346 // Deny containers access to instance metadata service
347 // Source: https://docs.aws.amazon.com/AmazonECS/latest/developerguide/instance_IAM_role.html
348 autoScalingGroup.addUserData('sudo iptables --insert FORWARD 1 --in-interface docker+ --destination 169.254.169.254/32 --jump DROP');
349 autoScalingGroup.addUserData('sudo service iptables save');
350 // The following is only for AwsVpc networking mode, but doesn't hurt for the other modes.
351 autoScalingGroup.addUserData('echo ECS_AWSVPC_BLOCK_IMDS=true >> /etc/ecs/ecs.config');
352 }
353 if (autoScalingGroup.spotPrice && options.spotInstanceDraining) {
354 autoScalingGroup.addUserData('echo ECS_ENABLE_SPOT_INSTANCE_DRAINING=true >> /etc/ecs/ecs.config');
355 }
356 }
357 }
358 // ECS instances must be able to do these things
359 // Source: https://docs.aws.amazon.com/AmazonECS/latest/developerguide/instance_IAM_role.html
360 // But, scoped down to minimal permissions required.
361 // Notes:
362 // - 'ecs:CreateCluster' removed. The cluster already exists.
363 autoScalingGroup.addToRolePolicy(new iam.PolicyStatement({
364 actions: [
365 'ecs:DeregisterContainerInstance',
366 'ecs:RegisterContainerInstance',
367 'ecs:Submit*',
368 ],
369 resources: [
370 this.clusterArn,
371 ],
372 }));
373 autoScalingGroup.addToRolePolicy(new iam.PolicyStatement({
374 actions: [
375 // These act on a cluster instance, and the instance doesn't exist until the service starts.
376 // Thus, scope to the cluster using a condition.
377 // See: https://docs.aws.amazon.com/IAM/latest/UserGuide/list_amazonelasticcontainerservice.html
378 'ecs:Poll',
379 'ecs:StartTelemetrySession',
380 ],
381 resources: ['*'],
382 conditions: {
383 ArnEquals: { 'ecs:cluster': this.clusterArn },
384 },
385 }));
386 autoScalingGroup.addToRolePolicy(new iam.PolicyStatement({
387 actions: [
388 // These do not support resource constraints, and must be resource '*'
389 'ecs:DiscoverPollEndpoint',
390 'ecr:GetAuthorizationToken',
391 // Preserved for backwards compatibility.
392 // Users are able to enable cloudwatch agent using CDK. Existing
393 // customers might be installing CW agent as part of user-data so if we
394 // remove these permissions we will break that customer use cases.
395 'logs:CreateLogStream',
396 'logs:PutLogEvents',
397 ],
398 resources: ['*'],
399 }));
400 // 0 disables, otherwise forward to underlying implementation which picks the sane default
401 if (!options.taskDrainTime || options.taskDrainTime.toSeconds() !== 0) {
402 new instance_drain_hook_1.InstanceDrainHook(autoScalingGroup, 'DrainECSHook', {
403 autoScalingGroup,
404 cluster: this,
405 drainTime: options.taskDrainTime,
406 topicEncryptionKey: options.topicEncryptionKey,
407 });
408 }
409 }
410 /**
411 * This method enables the Fargate or Fargate Spot capacity providers on the cluster.
412 *
413 * @param provider the capacity provider to add to this cluster.
414 * @deprecated Use {@link enableFargateCapacityProviders} instead.
415 * @see {@link addAsgCapacityProvider} to add an Auto Scaling Group capacity provider to the cluster.
416 */
417 addCapacityProvider(provider) {
418 try {
419 jsiiDeprecationWarnings.print("@aws-cdk/aws-ecs.Cluster#addCapacityProvider", "Use {@link enableFargateCapacityProviders} instead.");
420 }
421 catch (error) {
422 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
423 Error.captureStackTrace(error, this.addCapacityProvider);
424 }
425 throw error;
426 }
427 if (!(provider === 'FARGATE' || provider === 'FARGATE_SPOT')) {
428 throw new Error('CapacityProvider not supported');
429 }
430 if (!this._capacityProviderNames.includes(provider)) {
431 this._capacityProviderNames.push(provider);
432 }
433 }
434 configureWindowsAutoScalingGroup(autoScalingGroup, options = {}) {
435 // clear the cache of the agent
436 autoScalingGroup.addUserData('Remove-Item -Recurse C:\\ProgramData\\Amazon\\ECS\\Cache');
437 // pull the latest ECS Tools
438 autoScalingGroup.addUserData('Import-Module ECSTools');
439 // set the cluster name environment variable
440 autoScalingGroup.addUserData(`[Environment]::SetEnvironmentVariable("ECS_CLUSTER", "${this.clusterName}", "Machine")`);
441 autoScalingGroup.addUserData('[Environment]::SetEnvironmentVariable("ECS_ENABLE_AWSLOGS_EXECUTIONROLE_OVERRIDE", "true", "Machine")');
442 // tslint:disable-next-line: max-line-length
443 autoScalingGroup.addUserData('[Environment]::SetEnvironmentVariable("ECS_AVAILABLE_LOGGING_DRIVERS", \'["json-file","awslogs"]\', "Machine")');
444 // enable instance draining
445 if (autoScalingGroup.spotPrice && options.spotInstanceDraining) {
446 autoScalingGroup.addUserData('[Environment]::SetEnvironmentVariable("ECS_ENABLE_SPOT_INSTANCE_DRAINING", "true", "Machine")');
447 }
448 // enable task iam role
449 if (!options.canContainersAccessInstanceRole) {
450 autoScalingGroup.addUserData('[Environment]::SetEnvironmentVariable("ECS_ENABLE_TASK_IAM_ROLE", "true", "Machine")');
451 autoScalingGroup.addUserData(`Initialize-ECSAgent -Cluster '${this.clusterName}' -EnableTaskIAMRole`);
452 }
453 else {
454 autoScalingGroup.addUserData(`Initialize-ECSAgent -Cluster '${this.clusterName}'`);
455 }
456 }
457 /**
458 * Getter for autoscaling group added to cluster
459 */
460 get autoscalingGroup() {
461 return this._autoscalingGroup;
462 }
463 /**
464 * Whether the cluster has EC2 capacity associated with it
465 */
466 get hasEc2Capacity() {
467 return this._hasEc2Capacity;
468 }
469 /**
470 * Getter for execute command configuration associated with the cluster.
471 */
472 get executeCommandConfiguration() {
473 return this._executeCommandConfiguration;
474 }
475 /**
476 * This method returns the CloudWatch metric for this clusters CPU reservation.
477 *
478 * @default average over 5 minutes
479 */
480 metricCpuReservation(props) {
481 return this.cannedMetric(ecs_canned_metrics_generated_1.ECSMetrics.cpuReservationAverage, props);
482 }
483 /**
484 * This method returns the CloudWatch metric for this clusters CPU utilization.
485 *
486 * @default average over 5 minutes
487 */
488 metricCpuUtilization(props) {
489 return this.cannedMetric(ecs_canned_metrics_generated_1.ECSMetrics.cpuUtilizationAverage, props);
490 }
491 /**
492 * This method returns the CloudWatch metric for this clusters memory reservation.
493 *
494 * @default average over 5 minutes
495 */
496 metricMemoryReservation(props) {
497 return this.cannedMetric(ecs_canned_metrics_generated_1.ECSMetrics.memoryReservationAverage, props);
498 }
499 /**
500 * This method returns the CloudWatch metric for this clusters memory utilization.
501 *
502 * @default average over 5 minutes
503 */
504 metricMemoryUtilization(props) {
505 return this.cannedMetric(ecs_canned_metrics_generated_1.ECSMetrics.memoryUtilizationAverage, props);
506 }
507 /**
508 * This method returns the specifed CloudWatch metric for this cluster.
509 */
510 metric(metricName, props) {
511 return new cloudwatch.Metric({
512 namespace: 'AWS/ECS',
513 metricName,
514 dimensionsMap: { ClusterName: this.clusterName },
515 ...props,
516 }).attachTo(this);
517 }
518 cannedMetric(fn, props) {
519 return new cloudwatch.Metric({
520 ...fn({ ClusterName: this.clusterName }),
521 ...props,
522 }).attachTo(this);
523 }
524}
525exports.Cluster = Cluster;
526_a = JSII_RTTI_SYMBOL_1;
527Cluster[_a] = { fqn: "@aws-cdk/aws-ecs.Cluster", version: "1.197.0" };
528/**
529 * An Cluster that has been imported
530 */
531class ImportedCluster extends core_1.Resource {
532 /**
533 * Constructs a new instance of the ImportedCluster class.
534 */
535 constructor(scope, id, props) {
536 super(scope, id);
537 /**
538 * Security group of the cluster instances
539 */
540 this.connections = new ec2.Connections();
541 this.clusterName = props.clusterName;
542 this.vpc = props.vpc;
543 this.hasEc2Capacity = props.hasEc2Capacity !== false;
544 this._defaultCloudMapNamespace = props.defaultCloudMapNamespace;
545 this._executeCommandConfiguration = props.executeCommandConfiguration;
546 this.clusterArn = props.clusterArn ?? core_1.Stack.of(this).formatArn({
547 service: 'ecs',
548 resource: 'cluster',
549 resourceName: props.clusterName,
550 });
551 this.connections = new ec2.Connections({
552 securityGroups: props.securityGroups,
553 });
554 }
555 get defaultCloudMapNamespace() {
556 return this._defaultCloudMapNamespace;
557 }
558 get executeCommandConfiguration() {
559 return this._executeCommandConfiguration;
560 }
561}
562var ContainerInsights;
563(function (ContainerInsights) {
564 /**
565 * Enable CloudWatch Container Insights for the cluster
566 */
567 ContainerInsights["ENABLED"] = "enabled";
568 /**
569 * Disable CloudWatch Container Insights for the cluster
570 */
571 ContainerInsights["DISABLED"] = "disabled";
572})(ContainerInsights || (ContainerInsights = {}));
573/**
574 * The log settings to use to for logging the execute command session. For more information, see
575 * [Logging] https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-ecs-cluster-executecommandconfiguration.html#cfn-ecs-cluster-executecommandconfiguration-logging
576 */
577var ExecuteCommandLogging;
578(function (ExecuteCommandLogging) {
579 /**
580 * The execute command session is not logged.
581 */
582 ExecuteCommandLogging["NONE"] = "NONE";
583 /**
584 * The awslogs configuration in the task definition is used. If no logging parameter is specified, it defaults to this value. If no awslogs log driver is configured in the task definition, the output won't be logged.
585 */
586 ExecuteCommandLogging["DEFAULT"] = "DEFAULT";
587 /**
588 * Specify the logging details as a part of logConfiguration.
589 */
590 ExecuteCommandLogging["OVERRIDE"] = "OVERRIDE";
591})(ExecuteCommandLogging = exports.ExecuteCommandLogging || (exports.ExecuteCommandLogging = {}));
592/**
593 * An Auto Scaling Group Capacity Provider. This allows an ECS cluster to target
594 * a specific EC2 Auto Scaling Group for the placement of tasks. Optionally (and
595 * recommended), ECS can manage the number of instances in the ASG to fit the
596 * tasks, and can ensure that instances are not prematurely terminated while
597 * there are still tasks running on them.
598 */
599class AsgCapacityProvider extends core_2.Construct {
600 constructor(scope, id, props) {
601 super(scope, id);
602 try {
603 jsiiDeprecationWarnings._aws_cdk_aws_ecs_AsgCapacityProviderProps(props);
604 }
605 catch (error) {
606 if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
607 Error.captureStackTrace(error, AsgCapacityProvider);
608 }
609 throw error;
610 }
611 this.autoScalingGroup = props.autoScalingGroup;
612 this.machineImageType = props.machineImageType ?? MachineImageType.AMAZON_LINUX_2;
613 this.canContainersAccessInstanceRole = props.canContainersAccessInstanceRole;
614 this.enableManagedTerminationProtection =
615 props.enableManagedTerminationProtection === undefined ? true : props.enableManagedTerminationProtection;
616 if (this.enableManagedTerminationProtection) {
617 this.autoScalingGroup.protectNewInstancesFromScaleIn();
618 }
619 if (props.capacityProviderName) {
620 if (!(/^(?!aws|ecs|fargate).+/gm.test(props.capacityProviderName))) {
621 throw new Error(`Invalid Capacity Provider Name: ${props.capacityProviderName}, If a name is specified, it cannot start with aws, ecs, or fargate.`);
622 }
623 }
624 const capacityProvider = new ecs_generated_1.CfnCapacityProvider(this, id, {
625 name: props.capacityProviderName,
626 autoScalingGroupProvider: {
627 autoScalingGroupArn: this.autoScalingGroup.autoScalingGroupName,
628 managedScaling: props.enableManagedScaling === false ? undefined : {
629 status: 'ENABLED',
630 targetCapacity: props.targetCapacityPercent || 100,
631 maximumScalingStepSize: props.maximumScalingStepSize,
632 minimumScalingStepSize: props.minimumScalingStepSize,
633 },
634 managedTerminationProtection: this.enableManagedTerminationProtection ? 'ENABLED' : 'DISABLED',
635 },
636 });
637 this.capacityProviderName = capacityProvider.ref;
638 }
639}
640exports.AsgCapacityProvider = AsgCapacityProvider;
641_b = JSII_RTTI_SYMBOL_1;
642AsgCapacityProvider[_b] = { fqn: "@aws-cdk/aws-ecs.AsgCapacityProvider", version: "1.197.0" };
643/**
644 * A visitor that adds a capacity provider association to a Cluster only if
645 * the caller created any EC2 Capacity Providers.
646 */
647class MaybeCreateCapacityProviderAssociations {
648 constructor(scope, id, capacityProviders) {
649 this.scope = scope;
650 this.id = id;
651 this.capacityProviders = capacityProviders;
652 }
653 visit(node) {
654 if (node instanceof Cluster) {
655 if (this.capacityProviders.length > 0 && !this.resource) {
656 const resource = new ecs_generated_1.CfnClusterCapacityProviderAssociations(this.scope, this.id, {
657 cluster: node.clusterName,
658 defaultCapacityProviderStrategy: [],
659 capacityProviders: core_1.Lazy.list({ produce: () => this.capacityProviders }),
660 });
661 this.resource = resource;
662 }
663 }
664 }
665}
666function isBottleRocketImage(image) {
667 return image instanceof amis_1.BottleRocketImage;
668}
669//# sourceMappingURL=data:application/json;base64,
\No newline at end of file