Skip to content

Shared Platforms ​

A platform is one VPC and one ECS cluster shared by several Keel applications. Each tenant keeps its own load balancer, security groups, task roles, state, deployments, and teardown.

bash
keel platform init --name acme --platform-region us-west-2
keel platform up --platform acme
keel platform show --platform acme

Join from an application's keel.yml:

yaml
platform: acme

The definition lives in the account registry rather than in a repository. platform export and platform apply -f provide a reviewable file form without creating a second source of truth. platform lock (Pro) refuses ad-hoc set changes until unlocked, while lock --off remains available regardless of licence state.

Ownership boundaries ​

The platform owns the VPC CIDR, availability zones, NAT strategy, private AWS endpoints, Container Insights setting, cluster, and any EC2 capacity fleet. A tenant that declares one of those keys is refused instead of having it silently ignored.

Tenants still decide where their own Fargate task interfaces go with networking.public_tasks, and they own application-level resources. A tenant's cluster name and capacity-provider name are always resolved from the platform record rather than derived from the app name.

Fargate and EC2 together ​

One ECS cluster can hold Fargate, Fargate Spot, and an EC2 capacity provider at the same time. Add a fleet to the platform:

bash
keel platform set capacity.ec2.instance_types g5.xlarge,g5.2xlarge --platform acme
keel platform set capacity.ec2.max 8 --platform acme
keel platform up --platform acme

Then select it in a tenant without a top-level capacity: block:

yaml
services:
  gpu-worker:
    type: worker
    cpu: 4096
    memory: 16384
    gpu: 1
    capacity:
      fleet: ec2

The platform publishes the provider name, its subnet placement, and network mode. Bridge networking is refused for tenants because every task on an instance shares the host security group; on a multi-tenant fleet that would collapse network identity across applications.

Teardown safety ​

keel platform destroy refuses while any tenant remains. --force skips confirmation, not the tenant check. Once the platform is empty and the named VPC and cluster are confirmed, Keel generates teardown configuration without the ordinary prevent_destroy guards and removes the infrastructure.

A platform's own VPC and cluster keep those guards during every normal apply, so a CIDR edit or targeted apply cannot replace shared infrastructure accidentally.

Keel — the missing platform layer for AWS.