Build1 publisherNot yet confirmed elsewhere3 min readPublished
Express Mode builds the ALB you skipped, and owns the knobs you used to write
AWS's November release provisions the load balancer, scaling policies and alarms that a hands-on Terraform comparison admits it never configured. The control points go with them.
The Engineer · Build desk
What happened
- AWS introduced ECS Express Mode on November 21, 2025, offering containerised apps behind secure HTTPS endpoints within minutes.
- Express Mode adds no charge of its own; the bill is for the AWS resources it provisions and the application uses.
- A dev.to author who built both stacks in Terraform says the traditional one is bare minimum, with no balancer, HTTPS, monitoring, alarms or scaling policies.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Health check and scaling behaviour stop being lines a reviewer can argue about in a pull request, and the writeup never establishes which of the generated parameters remain reachable.
- exposure Your listener rules can end up on a balancer nobody on the team declared and up to two dozen other services depend on, outside whatever change control you run.
- decision Least privilege now has to be written for a role permitted to build networks, security groups and balancers, which is why the demonstration reached for AdministratorAccess and apologised for it.
- cost Spend moves from resources you sized to resources the defaults size: a balancer, alarms and scaling exist for every service, whether that service needed them.
Line up the two lists in the dev.to walkthrough and they match almost item for item. The author says the Terraform stack never got an Application Load Balancer, HTTPS, production-grade monitoring, alarms or scaling policies [7]. AWS says Express Mode creates a load balancer with listener rules, HTTPS configuration, auto-scaling policies, metrics, alarms and health checks on your behalf [3]. Each of the five gaps has a counterpart in what Express Mode provisions, with metrics standing in for monitoring [14]. That is a genuine result for a Flask portfolio site with three versions [11]. It is also why the comparison cannot answer the question a team with a running service is asking.
What is being traded away is not typing. AWS's own framing names load balancers, target groups and scaling policies as the manual configuration Express Mode removes [2]. Those are the objects whose settings decide how a deployment drains connections and when a service adds capacity. The walkthrough does not say whether the generated versions can be adjusted afterwards, or from where [13]. Anything the service stands up itself is, by construction, not a resource block an operator wrote and can read in a diff [12].
The shared balancer is the sharpest version of this. Up to 25 Express Mode services can sit behind one ALB, which AWS presents as a way to reduce the cost of running several services [5], and it is: the feature carries no charge of its own, so the balancer's hourly cost is the thing being spread [4]. It also means the listener rules your service depends on live on an object with as many as two dozen other tenants and no entry in your own change process [3][5].
The control point that remains is the input: a container image and an infrastructure role [2]. That role has to be permitted to create VPCs, subnets, security groups, balancers, alarms and scaling policies [3], which is not a permission set that scopes down neatly. The walkthrough runs on an IAM account with AdministratorAccess, and says outright that this is for the blog rather than production and that least privilege applies [8].
One edge is already visible. The author built for AMD64 and stayed there, noting that getting ARM64 working with Express Mode can be more complicated depending on the configuration [9]. On the traditional side, shipping a new version meant changing the Docker image in the task definition [10], and reaching the site at all meant running a script to find the task's public IP and appending port 5000 [6]. Neither stack here is one you would put in front of customers. The difference is that on the Express path, the parts you would need to fix are no longer yours to declare.
What to watch
- Whether AWS documents which Express Mode generated settings (health check timing, scaling thresholds, listener rules) are editable, and through what interface.
- Whether the limit of 25 services per shared Application Load Balancer arrives with documented isolation between the services sharing it.
- Whether there is a supported route to adopt Express Mode created resources into your own Terraform state, or to move a service off Express Mode without rebuilding it.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence38
- Adoption24
- Hype gap+22
- Incentives58
- Confidence42
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On November 21, 2025, AWS introduced ECS Express Mode, allowing developers to launch containerized applications with secure HTTPS endpoints within minutes; AWS launched it in late 2025.
- [2]
Express Mode is similar to traditional ECS but without a lot of the manual configuration required for things like load balancers, target groups, scaling policies and more; by providing a container image and an infrastructure role you can create a complete ECS Fargate-based deployment.
- [3]
Express Mode automatically creates resources such as a VPC, subnets, security groups, a load balancer with listener rules, HTTPS configuration, auto-scaling policies, metrics, alarms and health checks.
- [4]
There is no additional charge for using ECS Express Mode itself; you pay for the AWS resources provisioned and used by your application.
- [5]
A single Application Load Balancer can be shared by up to 25 Express Mode services, which can help reduce the cost of running multiple services.
- [6]
In the walkthrough's traditional directory, main.tf sets the AWS provider, values.tf gets the default VPC and its subnets plus a security group with port 5000 open, ecs.tf creates the ECS cluster, IAM roles and policy attachments, task definition and service, and get_ip.sh uses AWS CLI commands to retrieve the task network interface's public IP and generate the URL with port 5000.
- [7]
The author notes that the traditional approach creates quite a few resources but yields bare-minimum infrastructure rather than a recommended production-grade setup, with no Application Load Balancer, HTTPS, production-grade monitoring, alarms or scaling policies configured.
- [8]
The walkthrough requires Terraform configured with an AWS IAM account that has AdministratorAccess, which the author states is just for the sake of the blog, is not recommended in a production environment, and that the principle of least privilege should always be followed.
- [9]
The author's Docker image is built for AMD64; using an ARM64 image requires the ECS task configuration to support that architecture, and the author says getting ARM64 working with ECS Express Mode can be more complicated depending on the configuration, so AMD64 was used for the demonstration.
- [10]
Updating the application in the traditional path is done by updating the Docker image version inside the ECS task definition; for the demonstration the author deployed v2 and then switched the application back to v1.
- [11]
The comparison uses a basic Flask portfolio website with three versions (v1 Foundation, v2 Advanced, v3 Production), deployed with both a traditional ECS architecture and ECS Express Mode using Terraform.
- [12]
Resources that Express Mode provisions on the user's behalf are not resources the operator declared, so their settings are not part of the configuration the operator writes and reviews.
- [13]
The article does not state whether or how the automatically provisioned load balancer listener rules, auto-scaling policies, alarms or health checks can be adjusted after Express Mode creates them.
- [14]
All five capabilities the author lists as absent from the traditional Terraform stack (ALB, HTTPS, production-grade monitoring, alarms, scaling policies) have counterparts in the resource set Express Mode creates automatically (load balancer with listener rules, HTTPS configuration, metrics, alarms, auto-scaling policies).
Sources
1 independent publisher whose own reporting we read for this story.
- dev.to🧐 ECS Express Mode vs Traditional ECS: A Hands-on Comparison with Terraform
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.