feat(P56b): author 11 L1 module terraform subdirs + fix adapter output format

EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with
the full versions/variables/locals/main/outputs split. Defaults previously
hardcoded in the adapter move into locals.tf.

Simple single-resource modules (7):
- kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults)
- ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning)
- ecs-cluster: aws_ecs_cluster (name default)
- iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf)
- rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults)
- waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules)
- uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf)

Multi-resource modules with intra-refs (4):
- vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf)
- ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf)
- alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf)
- cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf)

Registry: terraform_dir added to all 11 remaining entries.

Adapter fix: stack output format uses separate 'from' + 'output' fields
(not 'from': 'rid.output'). Fixed _emit_root_output to read both fields.

6 previously-skipped tests unblocked (run_platform.sh --check-only now
resolves static-assets.yml through the new module-assembled adapter).
Removed skip markers. Fixed test assertion (aws_s3_bucket → module).

Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules
pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass
terraform init + validate standalone.

---ci---
project: acdl
phase: P56b
milestone: v1.11
status: execute
---/ci---
This commit is contained in:
Jon Chery
2026-07-28 15:28:57 +00:00
parent 8218734957
commit c80060878a
56 changed files with 1007 additions and 20 deletions
@@ -0,0 +1,7 @@
locals {
# OAC defaults (adapter previously hardcoded these).
oac_name = "acdl-oac"
oac_origin_type = "s3"
oac_signing_behavior = "always"
oac_signing_protocol = "sigv4"
}
+47
View File
@@ -0,0 +1,47 @@
resource "aws_cloudfront_origin_access_control" "this" {
name = local.oac_name
origin_access_control_origin_type = local.oac_origin_type
signing_behavior = local.oac_signing_behavior
signing_protocol = local.oac_signing_protocol
}
resource "aws_cloudfront_distribution" "this" {
origin {
origin_id = "s3-origin"
domain_name = var.bucket_regional_domain_name
origin_access_control_id = aws_cloudfront_origin_access_control.this.id
s3_origin_config {
origin_access_identity = ""
}
}
enabled = true
price_class = var.price_class
default_cache_behavior {
viewer_protocol_policy = var.viewer_protocol_policy
target_origin_id = "s3-origin"
min_ttl = 0
default_ttl = var.default_ttl
max_ttl = var.max_ttl
allowed_methods = ["GET", "HEAD"]
cached_methods = ["GET", "HEAD"]
forwarded_values {
query_string = false
cookies {
forward = "none"
}
}
}
restrictions {
geo_restriction {
restriction_type = "none"
}
}
viewer_certificate {
cloudfront_default_certificate = true
}
web_acl_id = var.waf_web_acl_arn
}
@@ -0,0 +1,14 @@
output "distribution_arn" {
value = aws_cloudfront_distribution.this.arn
description = "The CloudFront distribution ARN."
}
output "distribution_domain_name" {
value = aws_cloudfront_distribution.this.domain_name
description = "The CloudFront distribution domain name."
}
output "oac_id" {
value = aws_cloudfront_origin_access_control.this.id
description = "The Origin Access Control ID."
}
@@ -0,0 +1,40 @@
variable "bucket_regional_domain_name" {
type = string
description = "The S3 bucket regional domain name (ref to s3 origin)."
}
variable "price_class" {
type = string
description = "CloudFront price class (default PriceClass_100)."
default = "PriceClass_100"
}
variable "viewer_protocol_policy" {
type = string
description = "Viewer protocol policy (default redirect-to-https)."
default = "redirect-to-https"
}
variable "default_ttl" {
type = number
description = "Default TTL in seconds (default 3600)."
default = 3600
}
variable "max_ttl" {
type = number
description = "Max TTL in seconds (default 86400)."
default = 86400
}
variable "waf_web_acl_arn" {
type = string
description = "WAF web ACL ARN to associate (optional, ref to waf)."
default = null
}
variable "region" {
type = string
description = "AWS region (CloudFront is global but the provider region is used for the OAC)."
default = null
}
@@ -0,0 +1,9 @@
terraform {
required_version = ">= 1.9, < 1.10"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}