Compare commits

...

2 Commits

Author SHA1 Message Date
Jon Chery df1b004a46 docs(P20): complete platform-vpc-parameterization phase (v1.13.22)
---ci---
project: acdl
phase: 20
milestone: v1.14
status: complete
requirements:
  covered: [REQ-154]
  partial: []
---/ci---
2026-07-29 21:27:02 +00:00
Jon Chery 64b2ba5076 docs(P18): complete module-standards-consistency phase (v1.13.21)
---ci---
project: acdl
phase: 18
milestone: v1.14
status: complete
requirements:
  covered: [REQ-152]
  partial: []
---/ci---
2026-07-29 21:23:54 +00:00
2 changed files with 23 additions and 7 deletions
+10 -5
View File
@@ -207,9 +207,12 @@ declares intra-refs from the subnet and route table to the VPC's
- `aws:wafv2:webacl`
- `aws:rds:instance`
- `aws:kms:key`, `aws:kms:alias`
- The engine adapter's `TYPE_MAP` is the registry of stack types the
adapter can compile (see §8). A new stack type requires a `TYPE_MAP`
entry before the primitive can be deployed.
- The engine adapter is a **stateless assembler** (v1.11, D-098): it reads
the registry, emits a root `main.tf` instantiating each L1 as
`module "x" { source = "..." }` with resolved inputs and wired refs. There
is no `TYPE_MAP` (deleted in the v1.11 stateless rewrite). A new stack
type requires a `terraform/` dir in the L1 module + a registry entry with
a `terraform_dir` field.
## 3. L2 Module Standards
@@ -580,8 +583,10 @@ must be checked before the module is registered and published.
### 9.4 Adapter (stateless assembler)
- [ ] The new primitive's `terraform/` subdir exists with
`versions.tf`/`variables.tf`/`locals.tf`/`main.tf`/`outputs.tf` and
passes `terraform init + validate` standalone.
`versions.tf`/`variables.tf`/`main.tf`/`outputs.tf` and
passes `terraform init + validate` standalone. `locals.tf` is required
for multi-resource modules; trivial single-resource modules (e.g.
`kms-key`, `ecr`, `ecs-cluster`) may inline locals in `main.tf`.
- [ ] `registry.json` has a `terraform_dir` field for the new primitive.
- [ ] No adapter code changes are needed (the adapter is generic; it
assembles any module with a `terraform_dir` in the registry).
+13 -2
View File
@@ -29,6 +29,13 @@ provider "aws" {
region = "us-east-1"
}
# v1.14 (REQ-154): VPC CIDR is parameterized (default 10.0.0.0/16).
variable "vpc_cidr" {
description = "CIDR block for the shared platform VPC (default 10.0.0.0/16)."
type = string
default = "10.0.0.0/16"
}
# KMS customer-managed key for DynamoDB SSE + SSM Parameter Store encryption
resource "aws_kms_key" "acdl_platform" {
description = "ACDL platform KMS key (DynamoDB SSE + SSM + Secrets Manager)"
@@ -252,7 +259,7 @@ output "acdl_sod_halt_topic_arn" {
# ---------------------------------------------------------------------------
resource "aws_vpc" "acdl_shared" {
cidr_block = "10.0.0.0/16"
cidr_block = var.vpc_cidr
tags = {
Name = "acdl-shared"
"acdl:owner" = "acdl"
@@ -263,7 +270,7 @@ resource "aws_vpc" "acdl_shared" {
}
resource "aws_subnet" "acdl_shared" {
count = 2
count = length(data.aws_availability_zones.available.names)
vpc_id = aws_vpc.acdl_shared.id
cidr_block = cidrsubnet(aws_vpc.acdl_shared.cidr_block, 8, count.index + 1)
availability_zone = data.aws_availability_zones.available.names[count.index]
@@ -317,6 +324,10 @@ resource "aws_security_group" "ecs" {
description = "Security group for ECS Fargate services (platform VPC)"
vpc_id = aws_vpc.acdl_shared.id
# Ingress on port 80 is open to 0.0.0.0/0 — this is acceptable because
# the ECS service is fronted by a public-facing ALB (the ALB terminates
# TLS + routes to the target group). The ECS SG should not be attached
# directly to resources without an ALB in front. v1.14 (REQ-154).
ingress {
from_port = 80
to_port = 80