# ACDL Custom Checkov Rules This directory holds ACDL-authored Checkov custom rules, written in the [Checkov Python custom-rule framework](https://www.checkov.io/4.Contributing/Custom%20Policies.html). ## Files - `acdl_tagging.py` — `ACDL_TAG_NAMING` (D-054): ensures every taggable AWS resource carries the four required ACDL tags (`acdl:owner`, `acdl:contract`, `acdl:environment`, `acdl:cost-center`). This rule replaces the synthetic SKIPPED `ACDL_TAG_NAMING` record that the Checkov adapter previously emitted (D-043 closure). The canonical tag set is declared in [`schemas/tagging-standard.json`](../../../schemas/tagging-standard.json). ## How Checkov loads them Checkov custom rules are discovered via the `--external-checks-dir` flag. `scripts/run_platform.sh` invokes Checkov with: ``` checkov -f terraform/spike/main.tf --framework terraform -o json --soft-fail \ --external-checks-dir adapters/terraform/policy/custom_rules/ ``` Checkov imports each `*.py` file in the directory and instantiates the module-level `check` object (see the `check = AcdlTaggingStandard()` line at the bottom of `acdl_tagging.py`). ## Severity / result mapping The Checkov adapter (`adapters/terraform/policy/checkov_adapter.py`) maps `ACDL_TAG_NAMING` to `(tagging-standard, medium)` in `RULE_MAP`. The custom rule therefore produces real `PASS`/`FAIL` PolicyCheckResult records, feeding the confidence signal instead of the old SKIPPED placeholder.