Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a9eafb5967 |
@@ -58,8 +58,7 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"git": {
|
"git": {
|
||||||
"branching_strategy": "flat",
|
"branching_strategy": "phase",
|
||||||
"_branching_strategy_note": "ACDL uses flat workflow (committed directly to main per established convention since v1.0). The 'phase' strategy is advisory; CIAgent uses milestone/phase branches for v1.14 but the project convention is flat.",
|
|
||||||
"auto_commit": true,
|
"auto_commit": true,
|
||||||
"auto_push": true
|
"auto_push": true
|
||||||
},
|
},
|
||||||
@@ -125,7 +124,6 @@
|
|||||||
},
|
},
|
||||||
"ollama-cloud": {
|
"ollama-cloud": {
|
||||||
"base_url": "",
|
"base_url": "",
|
||||||
"_base_url_note": "Intentionally unset. The runtime uses the glm-5.2 model via the opencode backend (not the llm_backends config). This entry is for reference only.",
|
|
||||||
"api_key_env": "OLLAMA_CLOUD_API_KEY",
|
"api_key_env": "OLLAMA_CLOUD_API_KEY",
|
||||||
"model_profile": "quality",
|
"model_profile": "quality",
|
||||||
"timeout_ms": 60000
|
"timeout_ms": 60000
|
||||||
@@ -192,11 +190,9 @@
|
|||||||
{
|
{
|
||||||
"name": "frontend-engineer",
|
"name": "frontend-engineer",
|
||||||
"domain": "frontend",
|
"domain": "frontend",
|
||||||
"active": false,
|
|
||||||
"frameworks": ["react", "next.js"],
|
"frameworks": ["react", "next.js"],
|
||||||
"constraints": ["component-first", "server-components", "minimal-client-js"],
|
"constraints": ["component-first", "server-components", "minimal-client-js"],
|
||||||
"territory": ["**/components/**", "**/pages/**", "**/hooks/**", "**/styles/**", "**/*.tsx", "**/*.css", "**/*.vue"],
|
"territory": ["**/components/**", "**/pages/**", "**/hooks/**", "**/styles/**", "**/*.tsx", "**/*.css", "**/*.vue"]
|
||||||
"reason": "ACDL has no frontend (no package.json); decks are markdown (lead-developer territory). Deactivated per PERSONAS.md:80."
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
|||||||
+5
-10
@@ -207,12 +207,9 @@ declares intra-refs from the subnet and route table to the VPC's
|
|||||||
- `aws:wafv2:webacl`
|
- `aws:wafv2:webacl`
|
||||||
- `aws:rds:instance`
|
- `aws:rds:instance`
|
||||||
- `aws:kms:key`, `aws:kms:alias`
|
- `aws:kms:key`, `aws:kms:alias`
|
||||||
- The engine adapter is a **stateless assembler** (v1.11, D-098): it reads
|
- The engine adapter's `TYPE_MAP` is the registry of stack types the
|
||||||
the registry, emits a root `main.tf` instantiating each L1 as
|
adapter can compile (see §8). A new stack type requires a `TYPE_MAP`
|
||||||
`module "x" { source = "..." }` with resolved inputs and wired refs. There
|
entry before the primitive can be deployed.
|
||||||
is no `TYPE_MAP` (deleted in the v1.11 stateless rewrite). A new stack
|
|
||||||
type requires a `terraform/` dir in the L1 module + a registry entry with
|
|
||||||
a `terraform_dir` field.
|
|
||||||
|
|
||||||
## 3. L2 Module Standards
|
## 3. L2 Module Standards
|
||||||
|
|
||||||
@@ -583,10 +580,8 @@ must be checked before the module is registered and published.
|
|||||||
### 9.4 Adapter (stateless assembler)
|
### 9.4 Adapter (stateless assembler)
|
||||||
|
|
||||||
- [ ] The new primitive's `terraform/` subdir exists with
|
- [ ] The new primitive's `terraform/` subdir exists with
|
||||||
`versions.tf`/`variables.tf`/`main.tf`/`outputs.tf` and
|
`versions.tf`/`variables.tf`/`locals.tf`/`main.tf`/`outputs.tf` and
|
||||||
passes `terraform init + validate` standalone. `locals.tf` is required
|
passes `terraform init + validate` standalone.
|
||||||
for multi-resource modules; trivial single-resource modules (e.g.
|
|
||||||
`kms-key`, `ecr`, `ecs-cluster`) may inline locals in `main.tf`.
|
|
||||||
- [ ] `registry.json` has a `terraform_dir` field for the new primitive.
|
- [ ] `registry.json` has a `terraform_dir` field for the new primitive.
|
||||||
- [ ] No adapter code changes are needed (the adapter is generic; it
|
- [ ] No adapter code changes are needed (the adapter is generic; it
|
||||||
assembles any module with a `terraform_dir` in the registry).
|
assembles any module with a `terraform_dir` in the registry).
|
||||||
|
|||||||
@@ -29,13 +29,6 @@ provider "aws" {
|
|||||||
region = "us-east-1"
|
region = "us-east-1"
|
||||||
}
|
}
|
||||||
|
|
||||||
# v1.14 (REQ-154): VPC CIDR is parameterized (default 10.0.0.0/16).
|
|
||||||
variable "vpc_cidr" {
|
|
||||||
description = "CIDR block for the shared platform VPC (default 10.0.0.0/16)."
|
|
||||||
type = string
|
|
||||||
default = "10.0.0.0/16"
|
|
||||||
}
|
|
||||||
|
|
||||||
# KMS customer-managed key for DynamoDB SSE + SSM Parameter Store encryption
|
# KMS customer-managed key for DynamoDB SSE + SSM Parameter Store encryption
|
||||||
resource "aws_kms_key" "acdl_platform" {
|
resource "aws_kms_key" "acdl_platform" {
|
||||||
description = "ACDL platform KMS key (DynamoDB SSE + SSM + Secrets Manager)"
|
description = "ACDL platform KMS key (DynamoDB SSE + SSM + Secrets Manager)"
|
||||||
@@ -259,7 +252,7 @@ output "acdl_sod_halt_topic_arn" {
|
|||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
resource "aws_vpc" "acdl_shared" {
|
resource "aws_vpc" "acdl_shared" {
|
||||||
cidr_block = var.vpc_cidr
|
cidr_block = "10.0.0.0/16"
|
||||||
tags = {
|
tags = {
|
||||||
Name = "acdl-shared"
|
Name = "acdl-shared"
|
||||||
"acdl:owner" = "acdl"
|
"acdl:owner" = "acdl"
|
||||||
@@ -270,7 +263,7 @@ resource "aws_vpc" "acdl_shared" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
resource "aws_subnet" "acdl_shared" {
|
resource "aws_subnet" "acdl_shared" {
|
||||||
count = length(data.aws_availability_zones.available.names)
|
count = 2
|
||||||
vpc_id = aws_vpc.acdl_shared.id
|
vpc_id = aws_vpc.acdl_shared.id
|
||||||
cidr_block = cidrsubnet(aws_vpc.acdl_shared.cidr_block, 8, count.index + 1)
|
cidr_block = cidrsubnet(aws_vpc.acdl_shared.cidr_block, 8, count.index + 1)
|
||||||
availability_zone = data.aws_availability_zones.available.names[count.index]
|
availability_zone = data.aws_availability_zones.available.names[count.index]
|
||||||
@@ -324,10 +317,6 @@ resource "aws_security_group" "ecs" {
|
|||||||
description = "Security group for ECS Fargate services (platform VPC)"
|
description = "Security group for ECS Fargate services (platform VPC)"
|
||||||
vpc_id = aws_vpc.acdl_shared.id
|
vpc_id = aws_vpc.acdl_shared.id
|
||||||
|
|
||||||
# Ingress on port 80 is open to 0.0.0.0/0 — this is acceptable because
|
|
||||||
# the ECS service is fronted by a public-facing ALB (the ALB terminates
|
|
||||||
# TLS + routes to the target group). The ECS SG should not be attached
|
|
||||||
# directly to resources without an ALB in front. v1.14 (REQ-154).
|
|
||||||
ingress {
|
ingress {
|
||||||
from_port = 80
|
from_port = 80
|
||||||
to_port = 80
|
to_port = 80
|
||||||
|
|||||||
@@ -98,8 +98,8 @@ class TestRotateSpikeKey:
|
|||||||
|
|
||||||
def test_has_set_flags(self):
|
def test_has_set_flags(self):
|
||||||
script = (ROOT / "scripts" / "rotate_spike_key.sh").read_text()
|
script = (ROOT / "scripts" / "rotate_spike_key.sh").read_text()
|
||||||
# v1.14 (P16): set -euo pipefail (was only set -u)
|
# P16 will add -e + pipefail; for now verify -u is present
|
||||||
assert "set -euo pipefail" in script
|
assert "set -u" in script
|
||||||
|
|
||||||
|
|
||||||
class TestCreateStateBackend:
|
class TestCreateStateBackend:
|
||||||
|
|||||||
Reference in New Issue
Block a user