Repository navigation
Releases: ottojs/devops-aws
Releases · ottojs/devops-aws
Release list
v0.9.0
2025-08-26 v0.9.0
It is still not recommended to use this in production (yet).
Consider this a "beta" version, but you can use and test it to see if it meets your needs.
- Removed: Redis module, use Valkey instead (license fork)
- Removed: Resource Explorer in module "security" (create in console instead)
- Breaking: Moving Valkey password to Secrets Manager
- Breaking: Moving OpenSearch password to Secrets Manager
- Fix: Output ordering of VPC subnets
- Edit: Improve module sns
- Edit: Default log retention changed from 365 days to 400 days
- Edit: Refine VPC Flow Logs IAM Role/Policy
- Edit: EC2 Monitoring enabled, EBS Optimization enabled, Dev Mode, remove AZ, Add Recovery Alarm
- Edit: ASG EBS Optimized, Dynamic AMI Lookup, Encrypted Disk, Health Check, KMS Encryption, Dev Mode, Alarms
- Edit: ECS Cluster to better utilize resources, Dev Mode, CloudWatch Log Group, CloudWatch alarms
- Edit: Load Balancer, more restrictive TLS/ciphers, cross-zone load balancing, CloudWatch alarms, encrypted WAF logs
- Edit: WAF: rate limits, SQLi/Unix/Linux rule sets, Geo Blocking
- Edit: SSM now uses its own KMS key, and has CloudTrail alarms
- Edit: Bucket Private Logging Bucket, Allow CloudWatch Logs (BucketOwnerPreferred)
- Add: Module Bucket Public with CloudFront
- Add: Module Kafka_MSK (experimental)
- Add: Aurora MySQL (primary with optional readers)
- Add: ECS Service option: additional_hosts
- Add: Load Balancer option: waf_enabled
- Add: VPC Endpoints to modules/vpc (S3/DynamoDB are free and enabled by default)
- Add: Module for AMI Lookup
- Add: Enable switches for IGW/NAT to modules/vpc (default: false)
- Add: Module security_global
- Add: Example for Debian ARM64 bastion instances
- Add: Rocky Linux 10
- Add: RHEL 10
- Add: Valkey cluster mode switch selection
- Add: Example for allowing only Cloudflare IP traffic on public Load Balancer
- Dependencies: Upgrade provider aws to 6.10.0
- Dependencies: Upgrade OpenTofu minimum from v1.9 to v1.10
- Dependencies: Upgrade golang to v1.25.0
- Dependencies: Upgrade PostgreSQL default version from v17.4 to v17.6
- Dependencies: Upgrade Valkey default version from v8.0 to v8.1
- Dependencies: Upgrade OpenSearch default version from v2.17 to v2.19
- Dependencies: Upgrade MariaDB default version from v11.4.5 to v11.8.3
v0.8.0
2025-05-21 v0.8.0
It is still not recommended to use this in production (yet)
- Breaking: Module ecs_service now passes secrets as a list/array
- Fix: Upgrade EC2 SSM policy from AmazonEC2RoleforSSM to AmazonSSMManagedInstanceCore
- Fix: Refine Debian AMI name filter to avoid backports
- Add: Module db_mariadb for MariaDB instance
- Add: Support for Debian 11 (bullseye) and 12 (bookworm)
- Add: Security Module - ResourceExplorer
- Add: Module bucket_private log bucket can now receive CloudWatch logs
- Add: Module ecs_service supports skeleton creation
- Add: Module ecs_service supports use_registry to re-use another container registry
- Add: Module ecs_service supports replicas (default 1)
- Add: Database tools to the bastion hosts init scripts (debian/al2023)
- Add: Common tools to the bastion hosts init scripts (debian/al2023)
- Add: Tags to VPC Flow Logs, VPC IAM Roles, and SSM IAM Roles
- Add: Variable for container command to execute in ECS
- Add: VPC outputs NAT EIP
- Add: Valkey module outputs endpoint address
- Add: Load Balancer now accepts security group IDs
- Add: Bastion RHEL9 Golang
- Add: Bastion RHEL9 Docker Compose Plugin
- Add: Bastion Debian 11/12 Golang 1.24.3 and Node.js v22.x
- Add: Bastion Rocky Linux 9 (RHEL9 base)
- Edit: Always adding private DNS record for ECS service
- Edit: Moving SSM settings out of VPC to its own module to prevent conflicts
- Edit: Terraform State Bucket Name tag and deletion protection
- Edit: Changing default Bastion machine type from "t3" to "t3a" for small cost savings
- Dependencies: Upgrade provider aws to v5.97.0
v0.7.0
2025-04-06 v0.7.0
It is still not recommended to use this in production (yet).
- Fix: Module "bucket_private" to stay current
- Add: Module "security" with AWS Config, Security Hub, GuardDuty, Inspector, Detective, etc.
- Add: Cloudflare Security Group for HTTP/HTTPS
- Edit: Switching default region from us-east-2 to us-east-1
- Edit: Upgrading RHEL9 AMI from v9.4.x to v9.5.x
- Dependencies: Upgrade provider aws to v5.94.1
v0.6.0
2025-03-09 v0.6.0
It is still not recommended to use this in production (yet).
- New: WAF on Public Load Balancer(s)
- New: RHEL 9 Support (v9.4)
- New: APP_VERSION environment variable for ECS to match container image tag
- New: EC2 Machine parameter AMI
- New: EC2 Machine parameter disk_size
- New: EC2 Machine dynamic AMI
- New: AWS Certificate Manager automatic wildcard certificate (incl DNS validation in Route53)
- New: DNS Record for DMARC
- New: DNS Record for Valkey (internal/private)
- New: DNS Record for PostgreSQL (internal/private)
- New: Account High Password Requirements
- New: ECS Example Service Worker
- New: ECS Service parameter to specify inline IAM policy
- New: ECS Service parameter "create_registry"
- New: IAM Policy to block non-US regions (not attached)
- New: Self-signed TLS/SSL Certificate Script
- Edit: EC2 Machine Naming Pattern
- Edit: EC2 Machine "access" ("private"/"public") has been changed to "public" (true/false)
- Upgrade: Provider aws to v5.90.0
- Remove: ECS EC2 Example (Commented Out)
v0.5.0
2025-02-23 v0.5.0
Fourth release for testing!
It is still not recommended to use this in production (yet).
- New: 03_apps directory
- New: ECS Service option fault_injection
- New: VPC Endpoints option (experimental, untested)
- Edit: VPC Default Network ACL to have individual rules (idempotency)
- Edit: Merge module ecs_cron into ecs_service
- Edit: Security Group names
- Upgrade: PostgreSQL default version to v17.4
- Upgrade: Amazon Linux 2023 AMI to v20250218
- Upgrade: Container image node to v22.14.0
- Upgrade: Provider aws to v5.88.0
v0.4.0
2025-02-16 v0.4.0
Third release for testing!
It is still not recommended to use this in production (yet).
- Fix: ECS Execution and Task Role (same)
- Fix: OpenSearch now uses private subnets in the example
- Fix: Provider aws upgraded to v5.87.0 (v5.86.0 was removed)
- New: OpenSearch Audit Logs are now enabled by default
- New: Load Balancer dynamic health check path
- New: Module Route 53 for Root Domain
- New: Tags on Subnets "Public" => true/false
- Edit: Upgraded AL2023 AMI for EC2 Hosts
- Edit: NACLs and Security Groups to be more secure
- Edit: OpenSearch password now uses variable
- Edit: Simplifying tags on SNS module
- Edit: Move
userdatato root for use in multiple accounts - Removed: Node.js Code for SQS (another repo)
- Removed: Route 53 Subdomain Zone
v0.3.0
2025-02-09 v0.3.0
Second release for testing!
It is still not recommended to use this in production (yet).
- Fix: ECS Cron Tasks
- New: CloudWatch Alerts for RDS PostgreSQL
- New: ECS can use dynamic envvars/secrets provided
- New: Module for SES
- New: Module for SQS
- New: Module for Valkey ElastiCache Cluster
- New: Module for OpenSearch
- New: Node.js Code for SQS
- New: Load Balancer Access and Connection logs
- New: Route 53 Zones
- Edit: Load Balancer option: Public/Private
- Edit: Move from tag_app to tag map
- Edit: Remove most instances of hard-coded region
- Edit: Upgraded AL2023 AMI for EC2 Hosts
Full Changelog: 0.2.0...0.3.0
v0.2.0
2025-02-02 v0.2.0
First release for testing!
It is still not recommended to use this in production (yet).
Supports the high-level features below:
- VPC Core Networks
- S3 Buckets
- EC2 Machines for Web SSH (SSM)
- EC2 AutoScaling Groups
- Load Balancers
- ECS Provider Fargate
- ECS Provider EC2
- ECS Cron Schedules
- Database PostgreSQL
- Database Redis/Valkey (Valkey not yet supported by provider)
- VPN (optional, disabled by default)
- SNS Topics