# Nova Modules Reusable building blocks for cloud infrastructure. Each module is self-documented with a `README.md` following the [template](README-TEMPLATE.md). ## How the modules work There are two kinds of module: - **Primitives** — a single cloud resource or a small group of related resources (e.g. a VPC with subnets and routing). Each primitive has an `interface.json` declaring its inputs and outputs, and a `README.md` in plain language. - **Modules** — a pattern that references multiple primitives to deploy a complete stack (e.g. an ECS Fargate microservice). Each module has a `composition.json` declaring its children and wires. The engine adapter (`adapters/terraform/adapter.py`) compiles a module instance to infrastructure. Each module's README documents which resources it creates. ## Primitives | Module | What it creates | README | |--------|----------------|--------| | `s3` | `aws_s3_bucket` — a single S3 bucket | [README](l1/s3/README.md) | | `vpc` | `aws_vpc` + `aws_subnet` + `aws_route_table` + `aws_internet_gateway` — VPC with subnets and routing | [README](l1/vpc/README.md) | | `ecs-cluster` | `aws_ecs_cluster` — ECS Fargate cluster | [README](l1/ecs-cluster/README.md) | | `ecs-service` | `aws_ecs_task_definition` + `aws_ecs_service` — Fargate service with task definition | [README](l1/ecs-service/README.md) | | `iam-role` | `aws_iam_role` — IAM role with assume-role policy | [README](l1/iam-role/README.md) | | `alb` | `aws_lb` + `aws_lb_target_group` + `aws_lb_listener` — Application Load Balancer | [README](l1/alb/README.md) | | `ecr` | `aws_ecr_repository` — ECR container image repository | [README](l1/ecr/README.md) | | `cloudfront` | `aws_cloudfront_distribution` + `aws_cloudfront_origin_access_control` — CloudFront distribution with S3 origin via OAC | [README](l1/cloudfront/README.md) | | `waf` | `aws_wafv2_web_acl` — WAFv2 Web ACL (CloudFront-scoped) | [README](l1/waf/README.md) | | `rds` | `aws_db_instance` — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support | [README](l1/rds/README.md) | | `kms-key` | `aws_kms_key` — Customer-managed KMS key with rotation enabled (per-stack CMK) | [README](l1/kms-key/README.md) | | `uptime` | `aws_ecs_service` — Uptime-kuma monitoring on ECS Fargate with alert channels | [README](l1/uptime/README.md) | | `dynamodb` | `aws_dynamodb_table` — DynamoDB table with encryption + PITR (v1.8 NFR defaults) | [README](l1/dynamodb/README.md) | ## Modules | Module | What it references | README | |--------|--------------------|--------| | `microservice` | 6 primitives (vpc, cluster, ecr, iam-role, alb, ecs-service) | [README](l2/microservice/README.md) | | `static-assets` | 3 primitives (s3, cloudfront, waf) | [README](l2/static-assets/README.md) | ## Registry Module versions are tracked in `registry.json`. Both primitives and modules are registered. ## Template New modules should use [README-TEMPLATE.md](README-TEMPLATE.md) as their starting point. ## Module patterns (roadmap) The current `composition.json` mechanism is a thin pattern layer. A future redesign will let a consumer dynamically create a module directly from the contract file (an agentic "composition" flow). That is on the roadmap, not implemented today.