feat(P56b): author 11 L1 module terraform subdirs + fix adapter output format

EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with
the full versions/variables/locals/main/outputs split. Defaults previously
hardcoded in the adapter move into locals.tf.

Simple single-resource modules (7):
- kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults)
- ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning)
- ecs-cluster: aws_ecs_cluster (name default)
- iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf)
- rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults)
- waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules)
- uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf)

Multi-resource modules with intra-refs (4):
- vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf)
- ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf)
- alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf)
- cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf)

Registry: terraform_dir added to all 11 remaining entries.

Adapter fix: stack output format uses separate 'from' + 'output' fields
(not 'from': 'rid.output'). Fixed _emit_root_output to read both fields.

6 previously-skipped tests unblocked (run_platform.sh --check-only now
resolves static-assets.yml through the new module-assembled adapter).
Removed skip markers. Fixed test assertion (aws_s3_bucket → module).

Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules
pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass
terraform init + validate standalone.

---ci---
project: acdl
phase: P56b
milestone: v1.11
status: execute
---/ci---
This commit is contained in:
Jon Chery
2026-07-28 15:28:57 +00:00
parent 8218734957
commit c80060878a
56 changed files with 1007 additions and 20 deletions
@@ -0,0 +1,23 @@
locals {
# Fargate compat defaults (adapter previously hardcoded these).
requires_compatibilities = var.launch_type == "FARGATE" ? ["FARGATE"] : ["EC2"]
network_mode = var.launch_type == "FARGATE" ? "awsvpc" : "bridge"
# Container definitions from image/port/env (adapter previously hardcoded this).
container_definitions = jsonencode([{
name = "app"
image = var.image
essential = true
portMappings = [{
containerPort = var.port
hostPort = var.port
protocol = "tcp"
}]
}])
# Subnet list from comma-separated string.
subnet_list = split(",", var.subnets)
# Security groups list.
security_groups = var.security_group != null ? [var.security_group] : []
}
+31
View File
@@ -0,0 +1,31 @@
resource "aws_ecs_task_definition" "this" {
family = var.family
cpu = tostring(var.cpu)
memory = tostring(var.memory)
requires_compatibilities = local.requires_compatibilities
network_mode = local.network_mode
container_definitions = local.container_definitions
}
resource "aws_ecs_service" "this" {
name = "acdl-microservice"
cluster = var.cluster_arn
task_definition = aws_ecs_task_definition.this.arn
desired_count = var.desired_count
launch_type = var.launch_type
network_configuration {
subnets = local.subnet_list
security_groups = local.security_groups
assign_public_ip = var.launch_type == "FARGATE"
}
dynamic "load_balancer" {
for_each = var.lb_target_group_arn != null ? [1] : []
content {
target_group_arn = var.lb_target_group_arn
container_name = "app"
container_port = var.port
}
}
}
@@ -0,0 +1,9 @@
output "service_arn" {
value = aws_ecs_service.this.id
description = "The ECS service ARN."
}
output "task_def_arn" {
value = aws_ecs_task_definition.this.arn
description = "The ECS task definition ARN."
}
@@ -0,0 +1,80 @@
variable "image" {
type = string
description = "ECR image URL for the task container."
}
variable "port" {
type = number
description = "Container port the service listens on."
default = 80
}
variable "cpu" {
type = number
description = "Task CPU units (Fargate)."
default = 256
}
variable "memory" {
type = number
description = "Task memory (MiB, Fargate)."
default = 512
}
variable "env" {
type = string
description = "Environment variables as a JSON map string (optional)."
default = null
}
variable "cluster_arn" {
type = string
description = "ECS cluster ARN (ref to ecs-cluster)."
}
variable "subnets" {
type = string
description = "Comma-separated subnet ids (ref to vpc)."
}
variable "security_group" {
type = string
description = "Security group id for the service ENIs."
default = null
}
variable "lb_target_group_arn" {
type = string
description = "Optional ALB target group ARN (ref to alb)."
default = null
}
variable "region" {
type = string
description = "AWS region (provider-level; not a resource arg)."
default = null
}
variable "kms_key_arn" {
type = string
description = "ARN of the CMK for CloudWatch log group encryption; if absent, uses managed key."
default = null
}
variable "desired_count" {
type = number
description = "Desired number of ECS task replicas (Fargate)."
default = 1
}
variable "launch_type" {
type = string
description = "ECS launch type (FARGATE or EC2)."
default = "FARGATE"
}
variable "family" {
type = string
description = "ECS task definition family name."
default = "app"
}
@@ -0,0 +1,9 @@
terraform {
required_version = ">= 1.9, < 1.10"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}