feat(P58): single platform VPC + deterministic env-aware state keys
EXECUTE stage. Fixes the 4-VPC bug: adds a single shared VPC to
terraform/platform, drops the vpc child from the microservice composition
(references the platform VPC via data source), and makes state keys
env-aware (spike/{id}/{env}/terraform.tfstate — stable across lifecycle).
Platform VPC (terraform/platform/main.tf):
- aws_vpc.acdl_shared (10.0.0.0/16) + 2 subnets + IGW + route table + SG
- Outputs: vpc_id, subnet_ids, ecs_security_group_id
Microservice composition (modules/l2/microservice/composition.json):
- Dropped the vpc child (no per-contract VPC ever again).
- Added data_sources block: platform_vpc → terraform_remote_state (platform).
- Wires: vpc.outputs.subnet_ids → platform_vpc.outputs.subnet_ids.
- Wires: platform_vpc.outputs.vpc_id → alb.inputs.vpc_id.
- Wires: platform_vpc.outputs.ecs_security_group_id → service.inputs.security_group.
Contract resolver (core/contract_resolver.py):
- Added environment to the stack instance (stack.environment).
- Added data_sources handling: pseudo-children with outputs but no resources.
- data_sources propagated through fragment merge to the final stack instance.
Adapter (adapters/terraform/adapter.py):
- State key: spike/{stack_name}/{environment}/terraform.tfstate (env-aware).
- Emits data "terraform_remote_state" "platform" block when data_sources present.
- ref:platform_vpc.<output> → data.terraform_remote_state.platform.outputs.<output>.
Tests (tests/test_adapter.py):
- test_adapt_env_aware_state_key: spike/msvc/prod/terraform.tfstate.
- test_adapt_emits_data_source_block: data.terraform_remote_state.platform.
- test_adapt_no_vpc_for_microservice: no resource "aws_vpc" in microservice output.
- Updated existing state key assertion (spike/s3/dev/terraform.tfstate).
Regression: 467 passed, 0 skipped, 5 deselected. run_platform.sh --check-only
passes for both microservice (9 resources, no VPC) and static-assets (5 resources).
---ci---
project: acdl
phase: P58
milestone: v1.11
status: execute
---/ci---
This commit is contained in:
+42
-1
@@ -88,7 +88,7 @@ class TestModuleAssembly:
|
||||
assert 'region = "us-east-1"' in providers_tf
|
||||
assert 'required_providers' in terraform_tf
|
||||
assert 'backend "s3"' in terraform_tf
|
||||
assert 'spike/s3/terraform.tfstate' in terraform_tf
|
||||
assert 'spike/s3/dev/terraform.tfstate' in terraform_tf
|
||||
|
||||
def test_adapt_emits_root_outputs(self, tmp_path):
|
||||
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
|
||||
@@ -122,6 +122,47 @@ class TestModuleAssembly:
|
||||
main_tf = (tmp_path / "main.tf").read_text()
|
||||
assert "kms_key_arn = module.src.bucket_arn" in main_tf
|
||||
|
||||
def test_adapt_env_aware_state_key(self, tmp_path):
|
||||
"""P58: state key includes environment — spike/{name}/{env}/terraform.tfstate."""
|
||||
instance = {
|
||||
"version": "1.0.0",
|
||||
"stack": {"name": "msvc", "kind": "l2", "depth": 1, "environment": "prod"},
|
||||
"resources": [
|
||||
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0",
|
||||
"inputs": {"bucket_name": "test", "region": "us-east-1"}}
|
||||
],
|
||||
}
|
||||
adapt(instance, str(tmp_path))
|
||||
terraform_tf = (tmp_path / "terraform.tf").read_text()
|
||||
assert "spike/msvc/prod/terraform.tfstate" in terraform_tf
|
||||
|
||||
def test_adapt_emits_data_source_block(self, tmp_path):
|
||||
"""P58: when data_sources is present, emit terraform_remote_state block."""
|
||||
instance = {
|
||||
"version": "1.0.0",
|
||||
"stack": {"name": "msvc", "kind": "l2", "depth": 1, "environment": "dev"},
|
||||
"resources": [
|
||||
{"id": "alb", "type": "aws:elbv2:loadbalancer", "module": "alb@1.0.0",
|
||||
"inputs": {"subnets": "ref:platform_vpc.subnet_ids", "region": "us-east-1"}}
|
||||
],
|
||||
"data_sources": ["platform_vpc"],
|
||||
}
|
||||
adapt(instance, str(tmp_path))
|
||||
main_tf = (tmp_path / "main.tf").read_text()
|
||||
assert 'data "terraform_remote_state" "platform"' in main_tf
|
||||
assert "data.terraform_remote_state.platform.outputs.subnet_ids" in main_tf
|
||||
|
||||
def test_adapt_no_vpc_for_microservice(self, tmp_path):
|
||||
"""P58: microservice contract resolves without inline VPC resources."""
|
||||
import sys
|
||||
sys.path.insert(0, str(ROOT))
|
||||
from core.contract_resolver import resolve
|
||||
stack = resolve(str(ROOT / "contracts/microservice.yml"))
|
||||
adapt(stack, str(tmp_path))
|
||||
main_tf = (tmp_path / "main.tf").read_text()
|
||||
assert 'resource "aws_vpc"' not in main_tf
|
||||
assert 'data "terraform_remote_state" "platform"' in main_tf
|
||||
|
||||
|
||||
class TestRefExpr:
|
||||
def test_ref_translates_to_module_output(self):
|
||||
|
||||
Reference in New Issue
Block a user