OpenSearch
A managed search and analytics engine, compatible with Elasticsearch. Use OpenSearch when your application needs full-text search or aggregations beyond what a relational database provides. Byks grants your Fargate services network access to the domain automatically, and passes its URL to them through an environment variable.
Terraform configuration
Setting opensearch_config deploys one OpenSearch domain for the application. Set it to null or omit it to skip creating a domain.
main.tf
module "application" {
source = "git@github.com:BYM-IKT/terraform-byks-module.git?ref=v12"
# ...
opensearch_config = {
version = "OpenSearch_2.19"
cluster_instance_count = 1
cluster_instance_type = "t3.small.search"
ebs_volume_size = 10
# options go here
}
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
version |
string |
required | Version of the OpenSearch engine to run, for example OpenSearch_2.19. |
cluster_instance_count |
number |
required | Number of data nodes in the cluster. |
cluster_instance_type |
string |
required | Instance type for the cluster's data nodes, for example t3.small.search. |
ebs_volume_size |
number |
required | Size, in GiB, of the EBS volume attached to each data node. |
ebs_volume_type |
string |
"gp3" |
EBS volume type attached to each data node. |
ebs_iops |
number |
3000 |
Baseline IOPS for the EBS volume. Only applies when ebs_volume_type is gp3. |
domain_endpoint_policy |
string |
"Policy-Min-TLS-1-2-2019-07" |
TLS security policy enforced on the HTTPS endpoint. Either Policy-Min-TLS-1-0-2019-07 or Policy-Min-TLS-1-2-2019-07. |
enable_index_slow_logs |
bool |
true |
Publish index slow logs to CloudWatch. |
enable_search_slow_logs |
bool |
true |
Publish search slow logs to CloudWatch. |
enable_es_application_logs |
bool |
true |
Publish application logs to CloudWatch. |
enable_audit_logs |
bool |
false |
Publish audit logs to CloudWatch. Requires advanced_security_options.enabled. AWS enforces this for audit logging. |
log_retention_in_days |
number |
30 |
Days CloudWatch retains each enabled log group. |
allow_additional_iam_role_arns |
list(string) |
[] |
Extra IAM role ARNs granted es:ESHttpGet, es:ESHttpPut, and es:ESHttpPost access, alongside the application's Fargate task roles. |
allow_additional_security_group_ids |
list(string) |
[] |
Extra security group IDs granted network access to the domain, alongside the application's Fargate services. |
override_domain_name |
string |
null |
Custom domain name, instead of the generated default, the application name in lowercase. |
override_log_group_name_prefix |
string |
null |
Custom prefix for the CloudWatch log group names, instead of the generated default, /aws/opensearch/<environment>/<application_name>. |
Resources
-
AWS documentation
Official AWS documentation for OpenSearch