Skip to content

OpenSearch

A managed search and analytics engine, compatible with Elasticsearch. Use OpenSearch when your application needs full-text search or aggregations beyond what a relational database provides. Byks grants your Fargate services network access to the domain automatically, and passes its URL to them through an environment variable.

Terraform configuration

Setting opensearch_config deploys one OpenSearch domain for the application. Set it to null or omit it to skip creating a domain.

main.tf
module "application" {
  source = "git@github.com:BYM-IKT/terraform-byks-module.git?ref=v12"
  # ...

  opensearch_config = {
    version                = "OpenSearch_2.19"
    cluster_instance_count = 1
    cluster_instance_type  = "t3.small.search"
    ebs_volume_size        = 10
    # options go here
  }
}

Options

Option Type Default Description
version string required Version of the OpenSearch engine to run, for example OpenSearch_2.19.
cluster_instance_count number required Number of data nodes in the cluster.
cluster_instance_type string required Instance type for the cluster's data nodes, for example t3.small.search.
ebs_volume_size number required Size, in GiB, of the EBS volume attached to each data node.
ebs_volume_type string "gp3" EBS volume type attached to each data node.
ebs_iops number 3000 Baseline IOPS for the EBS volume. Only applies when ebs_volume_type is gp3.
domain_endpoint_policy string "Policy-Min-TLS-1-2-2019-07" TLS security policy enforced on the HTTPS endpoint. Either Policy-Min-TLS-1-0-2019-07 or Policy-Min-TLS-1-2-2019-07.
enable_index_slow_logs bool true Publish index slow logs to CloudWatch.
enable_search_slow_logs bool true Publish search slow logs to CloudWatch.
enable_es_application_logs bool true Publish application logs to CloudWatch.
enable_audit_logs bool false Publish audit logs to CloudWatch. Requires advanced_security_options.enabled. AWS enforces this for audit logging.
log_retention_in_days number 30 Days CloudWatch retains each enabled log group.
allow_additional_iam_role_arns list(string) [] Extra IAM role ARNs granted es:ESHttpGet, es:ESHttpPut, and es:ESHttpPost access, alongside the application's Fargate task roles.
allow_additional_security_group_ids list(string) [] Extra security group IDs granted network access to the domain, alongside the application's Fargate services.
override_domain_name string null Custom domain name, instead of the generated default, the application name in lowercase.
override_log_group_name_prefix string null Custom prefix for the CloudWatch log group names, instead of the generated default, /aws/opensearch/<environment>/<application_name>.

Resources