feat(P4): transparent terraform + feature flags + run_platform.sh split (REQ-233..238)

Create run_codegen.sh (pre-TF: env check, validate, resolve, adapt).
Create run_postapply.sh (post-TF: Checkov, confidence, HITL, outbox, SSM, uptime).
Add variable 'enabled' (bool, default true) + count=var.enabled?1:0 to all 12
L1 modules (alb, cloudfront, ecr, ecs-cluster, ecs-service, iam-role, kms-key,
rds, s3, uptime, vpc, waf). Fix all cross-resource references with [0] indexing.
Update interface.json for all modules to declare 'enabled' input.
Fix stale artifact path /tmp/acdl_platform_run_v18 → /tmp/nova_platform_run (REQ-238).
run_platform.sh remains as backward-compat shim for local-dev usage.

---ci---
project: acdl
phase: 4
milestone: v1.20
status: execute
requirements: [REQ-233, REQ-234, REQ-235, REQ-236, REQ-237, REQ-238]
---/ci---
This commit is contained in:
Jon Chery
2026-08-07 18:49:56 +00:00
parent ed5ea90654
commit 0ca383dae6
52 changed files with 667 additions and 79 deletions
+34 -7
View File
@@ -48,6 +48,11 @@
"description": "Target group target type (ip or instance).",
"required": false,
"default": "ip"
},
"enabled": {
"type": "boolean",
"default": true,
"description": "Feature flag: enable/disable this module. Set to false to skip resource creation."
}
},
"outputs": {
@@ -85,20 +90,42 @@
{
"type": "aws:elbv2:loadbalancer",
"description": "Application load balancer in the VPC subnets.",
"inputs": ["name", "subnets", "security_group", "load_balancer_type"],
"outputs": ["lb_arn"]
"inputs": [
"name",
"subnets",
"security_group",
"load_balancer_type"
],
"outputs": [
"lb_arn"
]
},
{
"type": "aws:elbv2:targetgroup",
"description": "Target group for the ECS service tasks.",
"inputs": ["name", "port", "protocol", "vpc_id", "target_type"],
"outputs": ["target_group_arn"]
"inputs": [
"name",
"port",
"protocol",
"vpc_id",
"target_type"
],
"outputs": [
"target_group_arn"
]
},
{
"type": "aws:elbv2:listener",
"description": "Listener forwarding the LB port to the target group.",
"inputs": ["lb_arn", "port", "protocol", "target_group_arn"],
"outputs": ["listener_arn"]
"inputs": [
"lb_arn",
"port",
"protocol",
"target_group_arn"
],
"outputs": [
"listener_arn"
]
}
]
}
}
+5 -2
View File
@@ -1,4 +1,5 @@
resource "aws_lb" "this" {
count = var.enabled ? 1 : 0
name = var.name
load_balancer_type = var.load_balancer_type
subnets = local.subnet_list
@@ -6,6 +7,7 @@ resource "aws_lb" "this" {
}
resource "aws_lb_target_group" "this" {
count = var.enabled ? 1 : 0
name_prefix = "${var.name}-"
port = var.port
protocol = var.protocol
@@ -18,13 +20,14 @@ resource "aws_lb_target_group" "this" {
}
resource "aws_lb_listener" "this" {
load_balancer_arn = aws_lb.this.id
count = var.enabled ? 1 : 0
load_balancer_arn = aws_lb.this[0].id
port = var.port
protocol = var.protocol
default_action {
type = "forward"
target_group_arn = aws_lb_target_group.this.arn
target_group_arn = aws_lb_target_group.this[0].arn
}
depends_on = [aws_lb_target_group.this]
+3 -3
View File
@@ -1,14 +1,14 @@
output "lb_arn" {
value = aws_lb.this.id
value = aws_lb.this[0].id
description = "The load balancer ARN."
}
output "listener_arn" {
value = aws_lb_listener.this.arn
value = aws_lb_listener.this[0].arn
description = "The listener ARN."
}
output "target_group_arn" {
value = aws_lb_target_group.this.arn
value = aws_lb_target_group.this[0].arn
description = "The target group ARN."
}
+6
View File
@@ -50,3 +50,9 @@ variable "vpc_id" {
description = "VPC ID for the target group (ref to vpc or platform VPC)."
default = null
}
variable "enabled" {
type = bool
description = "Feature flag: enable/disable this module. Set to false to skip resource creation."
default = true
}