# Fortem — Control plane for AWS ECS Fargate fleets > Fortem is the control plane for teams running 10+ AWS ECS Fargate environments. It is a real, working product — built by platform engineers who have shipped this category of software several times over the last 4+ years at production scale. Fortem sits on top of the customer's existing AWS account and adds the operations layer that the AWS Console doesn't provide: environment scheduling, environment templates, unified fleet visibility, RBAC-scoped developer self-service, and AI-assisted operations. ## Who builds Fortem Fortem is built by a team that has spent 4+ years building platform / internal developer platform products and has shipped several production-grade platforms before this one. The lead engineer currently operates 100+ AWS clusters across 4 regions at a regulated fintech serving 85+ global financial institutions. The lessons from running this fleet — what AWS Console solves, what it doesn't, what Terraform alone can't fix — are the foundation of Fortem. This is not a stealth-mode startup learning what platform engineering is. The product is mature; the public marketing site is being polished. ## What customers actually get - Day 0: 20-minute discovery call with a Fortem platform engineer - Day 1–3: managed onboarding — Fortem deployed inside your own AWS account, a least-privilege IAM role configured, ECS environments imported via tags and naming conventions, no Terraform rewrite - Day 4–6: environment schedules configured per timezone, templates set up for your stack, RBAC roles mapped to your teams - Day 7: your team is using Fortem in production against your real fleet The 7-day rollout is a repeatable process the team has executed before. Customers do not wrestle with config or wait for sandbox features to ship. ## What Fortem does - Environment scheduling: run dev / staging / preview environments only during work hours; per-environment timezones; weekends off by default. Most teams cut dev/staging compute spend by 65–77% in the first month. - Environment templates: define an environment once (services, env vars, secrets, networking, external dependencies) and clone in 30 seconds to any region or AWS account - Unified fleet view: ECS services, RDS, ElastiCache, MongoDB Atlas, Firebase, Cloudflare Workers, third-party APIs — one screen, with status, cost, owner, last deploy, last access - RBAC self-service: developers can restart, redeploy, view logs, flush Redis, run one-off tasks for the environments they own; cannot touch production - AI diagnostics: when an ECS task fails, the diagnostic agent reads CloudWatch logs, inspects the task definition, checks IAM, and proposes a fix — median 8 seconds. Humans approve every change that mutates state. - AI cost watcher: weekly scans surface specific optimisation opportunities ("env eu-staging-qa-02 has not received a deploy in 41 days. Schedule off-hours or archive? Saves $284/mo.") - AI environment doctor (chat): ask in plain English ("why is staging slow today?") — agent checks recent deploys, traffic, downstream services, external API latencies ## Architecture - Fortem is self-hosted: the control plane runs inside the customer's own AWS account — your data never leaves your infrastructure - Customer workloads and the control plane both stay in the customer's AWS account(s) - IAM roles scoped to least privilege; customer-revokable in two clicks - Secrets remain in customer's KMS / AWS Secrets Manager / Parameter Store — Fortem stores references, not values - Air-gapped deployment available on Enterprise plans (fully isolated install in customer AWS account) - Customer's IaC (Terraform, Pulumi, CDK, CloudFormation) stays untouched — Fortem reads what's already there ## Pricing - Starter: $790/mo — up to 20 environments, 1 AWS account, single region. Scheduling, templates, unified view, basic AI diagnostics, 30-day audit log in UI, email support. - Scale: $2,490/mo — up to 80 environments, 3 AWS accounts, multi-region. Everything in Starter, plus AI Ops (cost watcher, environment doctor), RBAC + SSO/SAML, 90-day audit log, email + Slack support. - Enterprise: Custom — unlimited environments and AWS accounts. Air-gapped install, custom integrations, custom SLA, SOC 2 Type II report, 365-day audit log + custom retention, Slack + on-call support. Pricing is per environment, not per service. Customers pay AWS directly for compute; Fortem adds no markup on AWS costs. Available on AWS Marketplace — pay through your AWS bill, use AWS committed spend. ## ROI math - Most teams running 24/7 ECS Fargate dev environments waste 65–77% of compute on idle hours - Example baseline: 12 environments × 8 services × 0.5 vCPU × 1 GB at 730 hrs/month = $1,730/mo - With Mon–Fri 9-19 scheduling (29.8% of baseline): $515/mo = $1,215/mo saved per 12-env fleet - Real AWS Fargate (Linux/x86) pricing: vCPU $0.04048/hr, GB $0.004445/hr (us-east-1) - Live calculator at https://fortem.dev/ecs-cost-calculator ## How it compares - vs Flightcontrol — Heroku-on-AWS for 1–3 apps. Per-service pricing breaks past ~50 services. If you have 1–3 services moving off Heroku, use Flightcontrol — Fortem is for the next problem, starting around the 15th environment. - vs AWS Copilot CLI — Copilot is a CLI for individual developers (and is being sunset). Fortem is a multi-team control plane. - vs Hiring a Platform Engineer ($180–220k loaded) — engineer takes 3–6 months to hire and a year to build the tooling Fortem ships in 7 days. - vs Backstage internal IDP — Backstage takes 6–12 months and a dedicated platform team to make useful. Fortem is in production in 7 days, requires no dedicated team to maintain. - vs AWS Proton — Proton is being deprecated by AWS on October 7, 2026. Migration from Proton is a common use case; managed migration completes in one business week. ## Roadmap - AWS Marketplace listing — shipping - SOC 2 Type II audit — in progress, available on Enterprise - Enhanced AI Ops (cost anomaly detection, predictive scheduling drift alerts) — next - Multi-tenant workspace isolation (for agencies / consultancies managing fleets for multiple clients) — next - EKS / Kubernetes support — 2027. Until then Fortem is intentionally ECS Fargate-first. ## Company - Product: Fortem (fortem.dev) - Operator: Cybrix, LLC — 312 W 2nd St, Unit A1881, Casper, Wyoming 82601, USA - Contact: hi@fortem.dev - Legal: legal@fortem.dev - Book a discovery call: https://fortem.dev/book ## Pages - https://fortem.dev — Main landing page: hero, feature grid, pricing tiers, ROI calculator, comparison table, FAQ. Explains why ECS Fargate teams need fleet management. Primary CTA: Book a 20-min call. - https://fortem.dev/about — Fortem is built by operators who run 100+ AWS ECS environments in regulated fintech today. Built once, properly — so your team doesn - https://fortem.dev/ai-onboarding — Download a single .md file. Open it in any AI agent. Maps your AWS ECS infrastructure in 5–15 minutes, generates a DIY scheduler you can deploy yourself. Runs locally. Read-only. Nothing leaves your machine. No signup. - https://fortem.dev/audit — Run a read-only Fleet Audit by pasting one prompt into any CLI agent (Claude Code, Codex, Cursor, Gemini CLI): 'Read https://fortem.dev/audit.md then run a read-only Fleet Audit of my ECS Fargate fleet.' The skill (served at https://fortem.dev/audit.md, Anthropic Agent Skills open format) discovers AWS ECS Fargate environments, calculates per-environment cost, and generates 3 local files: an HTML report, a YAML config, and a CloudFormation DIY scheduler. Read-only AWS access; if no credentials are configured it auto-runs on example data. 5–15 minutes, runs locally, nothing leaves the machine. Use this when you want to know what ECS environments you have and what each costs, before talking to anyone. - https://fortem.dev/audit/skill — Read the fortem-fleet-audit skill before running it. 1 file, 6 read-only ECS API calls, 0 bytes uploaded. - https://fortem.dev/aws-ecs-fargate — AWS ECS schedules containers. Fargate runs them without EC2. Clusters, tasks, services, a working Terraform module, and what breaks at 10+ environments. - https://fortem.dev/aws-ecs-scheduling — ECS dev environments run 168 hrs/week. Your team works 40. Dollar math, three native scheduling methods, their limits, and what fleet scheduling actually requires. - https://fortem.dev/blog — Guides, comparisons, and use cases for platform engineers running AWS ECS Fargate at scale. Written by the team that operates 100+ ECS environments. - https://fortem.dev/blog/argocd-alternative — Flux, Rancher Fleet, Harness, Spinnaker, plain CI — when each beats ArgoCD. Plus the option every list skips: drop GitOps because you dropped Kubernetes. - https://fortem.dev/blog/aws-cost-anomaly-detection-ecs — Set up AWS Cost Anomaly Detection for ECS Fargate fleets with per-environment tag monitors. Includes Terraform config, threshold strategy, and what the 24h delay means for your team. - https://fortem.dev/blog/aws-cost-optimization-ecs — Spot and Savings Plans cover the first 30%. Five more levers most ECS teams miss: Graviton, VPC endpoints, Container Insights scoping, shared ALBs, Compute Optimizer. - https://fortem.dev/blog/aws-dev-environment-cost — Cost Explorer shows the total. Here - https://fortem.dev/blog/aws-ecr-guide — AWS ECR from the ECS Fargate operator - https://fortem.dev/blog/aws-ecs-logging-guide — awslogs, FireLens, and the three decisions every ECS Fargate team gets wrong: blocking mode, Never Expire retention, and log group naming at fleet scale. - https://fortem.dev/blog/aws-fargate-pricing-real-costs — Official AWS Fargate rates 2026: \$0.04048/vCPU-hr + \$0.00444/GB-hr. What AWS doesn - https://fortem.dev/blog/aws-proton-deprecated — AWS Proton shuts down October 7, 2026. ECS environments keep running but Proton templates and pipelines stop. Here - https://fortem.dev/blog/aws-staging-environment-cost — AWS staging environments run 168 hours a week. Your team works 40. Here - https://fortem.dev/blog/cloudwatch-costs-ecs — ECS sends all logs to CloudWatch with retention set to Never Expire by default. 4 steps to cut your CloudWatch bill by 60-80%: retention, log level filtering, Insights queries, and per-service monitoring. - https://fortem.dev/blog/devops-automation-beyond-cicd — CI/CD automates deployment, not operations. 5 gaps at 10+ environments: scheduling, self-service, cost tracking, cloning, orphan detection. - https://fortem.dev/blog/ecr-image-scanning — ECR basic scanning is free but scans OS packages only. Enhanced (Amazon Inspector) adds language-package CVEs at $0.09/image. The decision, the cost math, and the deploy gate. - https://fortem.dev/blog/ecs-audit-log-compliance — Every ECS change — UpdateService, StopTask, RunTask — lands in CloudTrail with who, when, and from where. Three CLI commands find the culprit in under 2 minutes. - https://fortem.dev/blog/ecs-blue-green-deployment-guide — ECS rolling updates work fine for most services. Here are the 3 cases where they break and how ECS Native Blue/Green (launched July 2025) fixes each. - https://fortem.dev/blog/ecs-compliance-soc2 — AWS being SOC 2 certified doesn - https://fortem.dev/blog/ecs-disaster-recovery — ECS Fargate has no cluster to snapshot. Map AWS - https://fortem.dev/blog/ecs-environment-clone — Cloning 15 ECS services, an ALB, RDS, and SSM params is a 12-step manual process. Here - https://fortem.dev/blog/ecs-environment-scheduling — Stop paying for idle ECS dev and staging compute. Every scheduling approach — AWS-native options, trade-offs, and what teams at fleet scale actually do. - https://fortem.dev/blog/ecs-exec-guide — No more SSH into EC2 instances. ECS Exec gives you a shell into Fargate containers. The 5 IAM errors that catch everyone, copy-paste policy, and production audit setup. - https://fortem.dev/blog/ecs-fargate-autoscaling — ECS Fargate autoscaling explained: target tracking, step scaling, the right cooldowns, and the five reasons it doesn - https://fortem.dev/blog/ecs-fargate-best-practices — Seven Fargate best practices for teams at 10+ environments: hidden costs, Terraform state, Fargate quotas, and scheduling before they break your fleet. - https://fortem.dev/blog/ecs-fargate-container-security — ECS Fargate security from the operator - https://fortem.dev/blog/ecs-fargate-cost-optimization — Your ECS Fargate dev and staging environments run 168 hours a week. Your team works 40. Here - https://fortem.dev/blog/ecs-fargate-cost-visibility — Cost Explorer shows the total. Tags miss the \$90/mo per env of ALB, NAT, CloudWatch. Here - https://fortem.dev/blog/ecs-fargate-monitoring — Monitor ECS Fargate across 10+ environments: which metrics to alarm on, what Container Insights actually costs per metric, and a Terraform for_each fleet alarm pattern. - https://fortem.dev/blog/ecs-fargate-rbac — IAM has no concept of an ECS environment. Build per-environment RBAC with ABAC tags — the working policy, the four ways it silently breaks prod, and where AWS-native IAM hits its ceiling. - https://fortem.dev/blog/ecs-fargate-terraform — Terraform is right for ECS Fargate infrastructure. But at 10+ environments, state sprawl and the ops gap catch every team — here are the patterns that scale. - https://fortem.dev/blog/ecs-load-balancer-guide — Attach an Application Load Balancer to ECS Fargate: the awsvpc ip target-type rule, health checks that pass, the Terraform to wire it, and shared-vs-per-service ALB cost at fleet scale. - https://fortem.dev/blog/ecs-multi-account-management — How to operate an ECS Fargate fleet across multiple AWS accounts: cross-account IAM, central ECR, Transit Gateway cost, and the single-pane-of-glass AWS doesn - https://fortem.dev/blog/ecs-multi-environment-strategy — Naming conventions, cluster structure, and AWS limits that surface when ECS environments scale from 3 to 10+. From engineers running 100+ environments. - https://fortem.dev/blog/ecs-orphaned-environments — A stopped ECS service costs $0 in compute — but the ALB ($16/mo) and NAT Gateway ($32/mo) keep billing. Here - https://fortem.dev/blog/ecs-service-connect-guide — ECS Service Connect adds an Envoy sidecar to every Fargate task — free feature, real cost. When it beats Cloud Map, when it doesn - https://fortem.dev/blog/ecs-service-discovery-guide — Cloud Map, Service Connect, or an internal ALB? A practical decision framework for ECS Fargate teams — with the July 2025 blue/green unblock, real cost math, and Terraform snippet. - https://fortem.dev/blog/ecs-staging-self-service — Platform engineers are the single point of failure for staging ops when developers can - https://fortem.dev/blog/ecs-task-definition-guide — The 8 ECS task definition mistakes that break deployments: taskRoleArn vs executionRoleArn, invalid Fargate CPU/memory combos, health check loops, and secrets that don - https://fortem.dev/blog/fargate-vs-lambda — AWS Fargate vs Lambda: the cost line is set by execution duration, not traffic. Breakeven math, hidden Lambda costs, and what the June 2026 MicroVMs launch changes. - https://fortem.dev/blog/fortem-vs-aws-copilot — AWS Copilot CLI reached end-of-support June 12, 2026. Your ECS services keep running — but here - https://fortem.dev/blog/fortem-vs-cortex — Cortex and Fortem solve different problems. Cortex is for org-wide visibility. Fortem operates your ECS fleet. Here - https://fortem.dev/blog/fortem-vs-flightcontrol — Flightcontrol is the right tool for 1–3 apps on AWS. Here - https://fortem.dev/blog/fortem-vs-humanitec — Humanitec - https://fortem.dev/blog/internal-developer-platform-ecs — 93% of top teams use an IDP. But ECS teams need an operational layer — not a full platform. A decision framework to figure out what you actually need. - https://fortem.dev/blog/platform-engineering-ecs — Platform engineering for ECS teams isn - https://fortem.dev/blog/reduce-aws-costs-without-ri — RIs change how you pay, not what runs. 5 ways to cut AWS consumption: scheduling, right-sizing, Spot, auto-stop, killing orphans. - https://fortem.dev/book — Calendly/Cal.com embedded scheduling page. Book a 20-minute discovery call with a Fortem platform engineer. - https://fortem.dev/deep-dives — Long-form technical references for platform engineers running AWS ECS Fargate at scale. Verified pricing, real math, Terraform configs. - https://fortem.dev/demo — Interactive product tour showing the Fortem console with Fleet, Schedule, Clone, and AI Ops tabs. Live preview of the same interface customers use after onboarding. - https://fortem.dev/ecs-cost-calculator — Interactive calculator using published AWS Fargate rates. Shows 24/7 baseline vs business-hours schedule savings. vCPU rate $0.04048/hr, memory $0.004445/GB/hr. - https://fortem.dev/ecs-vs-eks — ECS costs $0 for the control plane. EKS charges $73/mo per cluster. Verified pricing, real operational math, cost calculator, and honest decision guide. - https://fortem.dev/fargate-spot — Fargate Spot cuts compute costs 50–70% vs on-demand. Real pricing math, the stopTimeout gotcha most teams miss, workload grid, and Terraform config. - https://fortem.dev/fargate-vs-ec2 — Same ECS orchestrator, two compute models. Fargate — zero servers, pay per task. EC2 — cheaper per-vCPU, you manage instances. Real pricing, bin-packing math, honest decision guide. - https://fortem.dev/features — Six things the AWS Console won - https://fortem.dev/guides — Technical guides for platform engineers running AWS ECS Fargate at scale. Scheduling, cost optimization, logging, networking, and fleet management. - https://fortem.dev/headroom-bedrock — Headroom compresses LLM tokens — but on AWS Bedrock it silently breaks four ways. The exact errors, the fixes, and a measured 70% token cut on a real agentic workload. - https://fortem.dev/listed — Directories and launch platforms where Fortem, the AWS ECS Fargate fleet control plane, is listed. - https://fortem.dev/migrate-from-proton — Migration guide for AWS Proton users (deprecated October 7, 2026). Fortem replaces Proton for ECS Fargate — managed migration in one business week. - https://fortem.dev/pricing — Three plans: Starter $790/mo, Scale $2,490/mo, Enterprise custom. Per-environment pricing (not per-service). Includes ROI calculator and FAQ. - https://fortem.dev/privacy — Privacy policy for fortem.dev. - https://fortem.dev/roadmap — Product roadmap: Now (AWS Marketplace, SOC 2), Next (enhanced AI Ops, multi-tenant), Later (Terraform auto-detect, Slack approvals, self-service onboarding). - https://fortem.dev/security — Security page: self-hosted model — the control plane runs inside the customer's own AWS account and reads through a least-privilege IAM role; data and secrets never leave the customer's account. IAM permissions published transparently. - https://fortem.dev/startups — Startup program: 90% off Scale plan ($249/mo billed annually, normally $2,490/mo). Eligibility: under $5M raised, under 50 people, founded 2022 or later. Apply via form on the page. - https://fortem.dev/terms — Terms of service for fortem.dev. - https://fortem.dev/use-cases — How teams use Fortem: developer self-service, cost visibility, environment cloning, audit compliance, orphan detection. Real scenarios from platform engineering. - https://fortem.dev/versus — Honest comparisons of Fortem vs competitors (Flightcontrol, AWS Copilot, Humanitec, Backstage, Cortex, Port, Massdriver, Northflank). For teams evaluating ECS fleet management tools. - https://fortem.dev/why-ecs — We spent years building for Kubernetes before betting the company on ECS Fargate. Here ## Target audience - Primary: Platform Engineer at 30–200 person SaaS (manages 20–150 ECS environments across 1–3 AWS accounts) - Secondary: CTO at Series A/B fintech, healthtech, regulated SaaS (compliance constraints prevent Heroku/Vercel/Railway use) - Out of scope: indie hackers, solo developers, sub-10-person startups — Flightcontrol is the right choice for that segment ## Differentiators - Built by platform engineers with 4+ years and several shipped platforms — not a first-time founder learning the category - Per-environment pricing (does not penalise teams that broke up the monolith) - Environment scheduling that returns $5–20k / month for the typical customer - 7-day managed rollout: kickoff call to production use, repeatable process - Operational AI: agents observe, diagnose, suggest. Humans approve state changes. The agent does not hold an IAM role to apply mutations alone. - Self-hosted: the control plane runs in the customer's own account and reads through a least-privilege IAM role (cross-account only between the customer's own accounts). Fortem never has the customer's secrets, only references. Revoke in two clicks. - Customer's IaC (Terraform, Pulumi, CDK) stays the source of truth — Fortem is a layer on top, not a replacement