Skip to main content

Overview

Standard is the recommended starting point for production workloads. It runs on-demand Fargate tasks across 3 availability zones behind an Application Load Balancer, backed by a Multi-AZ RDS PostgreSQL instance, with CPU auto-scaling and CloudWatch alarms already wired. Everything below is scaffolded into fjall/myapp/infrastructure.ts, which you own and edit like any other TypeScript file.

Create a Standard application

In a terminal the flags seed the prompts rather than skip them, so you still confirm the name, database and services. Add --non-interactive to run it straight through. Omit --type to pick Standard from the tier list, where it is the pre-highlighted option. You get:

Architecture

Generated infrastructure

This is what the Standard tier scaffolds into fjall/myapp/infrastructure.ts.
getConfig().environment comes from the target account’s recorded stage, not from a flag. Deploying into an account stamped production wires the shared alarm topic and switches removal policies to retain.

Specifications

Compute (ECS Fargate)

Database (RDS Instance)

Automated backups and AWS Backup are different protections. Standard gets 14 days of RDS automated backups and point-in-time recovery, plus a daily vault snapshot kept for 90 days. What Standard does not get is a copy anywhere else: continuous (second-level) recovery — for the resource types AWS supports it on — and a cross-region copy start at the Resilient tier, and a cross-account copy at Enterprise. S3 buckets are not enrolled at Standard either — AWS Backup requires bucket versioning, which this tier leaves off; set versioned: true on a bucket to enrol it, or move the app to Resilient. Enrolment at every tier also depends on a setting Fjall does not own: AWS Backup’s per-Region service opt-in must admit the resource type, or a tagged resource is in no plan at all while the plan still reports healthy. Check AWS Backup console → Settings → Service opt-in in each account and Region you deploy into.

Networking

The ECR interface endpoints let tasks pull images without traversing the NAT gateway. They cost roughly $0.01 per AZ per hour each, so 2 endpoints across 3 AZs is the second-largest fixed line item after the database.

Customisation

Change scaling

Omitting scaling keeps auto-scaling on with minCapacity tracking desiredCount and maxCapacity defaulting to Math.max(desiredCount + 1, 3). Setting scaling: false disables auto-scaling entirely.

Resize the database

Turn Multi-AZ off

Multi-AZ is on unless you set it to false. Single-AZ roughly halves the database bill and gives up automatic failover, so it suits development accounts rather than production.
Or edit it from the CLI, then deploy:
Change the database through infrastructure.ts or fjall modify, never with aws rds modify-db-instance. An out-of-band change creates CloudFormation drift that the next fjall deploy reverts. Run fjall drift detect if you suspect a resource has been changed outside Fjall.

Add a background worker

A worker belongs in the same cluster as the API, so add a second entry to services. A worker declares no port, so it gets no ALB target group.
To scaffold a separate cluster instead, fjall add compute requires --type and --needsConnection on a first add:
See Add Resources for the full property list.

Monitoring

Standard writes container logs to CloudWatch Logs and publishes ECS, RDS and ALB metrics. Alarms are declared on the factory, not with raw CDK.

Alarm thresholds

Per-service alarms materialise once an alertsTopic is set on the compute. The generated file wires the shared organisation topic automatically in production accounts.
Every alarm treats missing data as not breaching and notifies on both ALARM and OK transitions. Set alarms: false on a service to opt it out.

Cost

Indicative us-east-1 on-demand list prices for the tier defaults, excluding data transfer and request-based charges. The database dominates. Dropping to single-AZ saves roughly $105 a month, and the Lightweight tier trades HA for a much smaller bill. Run fjall costs --app myapp for your actual spend once the application is deployed.

When to use

Choose Standard for:
  • Production web applications and APIs
  • Business applications and SaaS products
  • Mobile app backends
  • Anything that needs automatic database failover from day one
Choose something else if:

Production checklist

Standard already ships Multi-AZ, encryption at rest, deletion protection and 14-day backups. What is left to you:
  • Attach a custom domain and TLS certificate
  • Set alarm thresholds that match your traffic, and confirm the alerts topic is receiving them
  • Add containerInsights: true if you want the running-tasks alarm
  • Load-test and confirm 2 to 5 tasks covers your peak
  • Review generated security groups against your own rules
  • Store application secrets with fjall secret, not in environment
  • Wire up CI/CD so deploys are reproducible
  • Run fjall drift detect on a schedule

Security

Customer-managed KMS keys, RDS Proxy with requireTLS, and advanced Database Insights start at Resilient.

Upgrade paths

To Resilient

Resilient swaps the RDS Instance for Aurora with a reader, adds CMK encryption on storage and Database Insights, adds RDS Proxy with TLS required, and enrols the application in an AWS Backup vault. Scaffold a new application at that tier and port your resources, or edit infrastructure.ts directly.

Add a CDN

--defaultOriginRef names the resource the distribution fronts, which is the compute resource in a Standard application.

Add storage or messaging

Troubleshooting

Container fails to start

  1. Read the service logs in CloudWatch Logs under the application’s log group.
  2. Check the container port matches the port in infrastructure.ts (3000 by default).
  3. Confirm the image built and pushed: fjall build myapp.
  4. Check the task has enough memory. A task killed at 1024 MiB shows as OutOfMemoryError in the stopped-task reason.

Database connection failures

  1. Confirm the service declares the database in connections. That array is what generates the security-group rule.
  2. Check DATABASE_HOST, DATABASE_PORT and DATABASE_NAME in the task definition.
  3. Confirm the credentials import resolved. secretsImport pulls from Secrets Manager at task start.
  4. For interactive access, open a tunnel: fjall tunnel myapp.

Costs higher than expected

  1. Run fjall costs --mode attribution --app myapp.
  2. Check whether auto-scaling is sitting at maxCapacity. A 50% CPU target on a bursty service holds more tasks than you might expect.
  3. Consider single-AZ for non-production accounts.
  4. Drop vpcEndpoints.interface.ecr if image pulls are infrequent and NAT egress is cheaper for your volume.

Breaking out the pattern

Standard is a starting scaffold, not a lock-in. The generated file is ordinary factory calls, so you can add, replace or delete any of them.

Next Steps

Deploy Application

Ship your Standard application to AWS

Add Resources

Extend with storage, messaging, or a CDN

Resilient Pattern

Step up to Aurora, CMK encryption, and backup vaults

Enterprise Pattern

Every capability enabled, multi-region ready

Compute Factory

Tune ECS services, scaling, and alarms

Configure CI/CD

Automate deploys from your pipeline