feat(P32): deletion-protection-by-default + L2 feature flag (REQ-86, REQ-87)

---ci---
project: acdl
phase: 32
milestone: v1.8
status: execute
---/ci---

- All 11 L1 primitives now have deletion_protection NFR (boolean, default true).
- Adapter emits `lifecycle { prevent_destroy = true }` when NFR is true;
  omits it when false. Default is true when NFR is absent.
- L2 composition resolver propagates inputs.deletion_protection to all
  children NFRs. When false, all resources get deletion_protection=false.
- Stack schema updated with optional features object (deletion_protection,
  uptime_enabled).
- Contract schema description updated to document deletion_protection
  and uptime_enabled inputs.

Tests: +5 (307 -> 312). All pass.
This commit is contained in:
Jon Chery
2026-07-22 22:12:42 +00:00
parent de91a4bb76
commit 8145eee8fc
14 changed files with 174 additions and 2 deletions
+6
View File
@@ -464,6 +464,12 @@ def _emit_resource(resource, type_by_id=None):
body.append(" }")
body.append(" }")
body.append("}")
nfrs = resource.get("nfrs", {})
deletion_protection = nfrs.get("deletion_protection", True)
if deletion_protection:
body.append("lifecycle {")
body.append(" prevent_destroy = true")
body.append("}")
return _resource_block(rid, tf_type, body)