import json import os import sys from pathlib import Path import jsonschema import pytest sys.path.insert(0, str(Path(__file__).resolve().parent.parent)) from adapters.terraform.adapter import ( TYPE_MAP, INPUT_MAP, OUTPUT_MAP, adapt, _tf_value, _ref_expr, ) ROOT = Path(__file__).resolve().parent.parent class TestInstance: def test_instance_validates_against_stack_schema(self, stack_instance, stack_schema): jsonschema.validate(stack_instance, stack_schema) def test_instance_has_one_resource(self, stack_instance): assert len(stack_instance["resources"]) == 1 r = stack_instance["resources"][0] assert r["id"] == "s3" assert r["type"] == "aws:s3:bucket" def test_instance_stack_is_s3(self, stack_instance): assert stack_instance["stack"]["name"] == "s3" assert stack_instance["stack"]["kind"] == "l1" class TestRegistry: EXPECTED_L1_KEYS = {"s3", "vpc", "ecs-cluster", "ecs-service", "iam-role", "alb", "ecr", "cloudfront", "waf"} EXPECTED_L2_KEYS = {"static-assets", "microservice"} def test_registry_has_11_entries(self, registry): assert len(registry) == 11 assert set(registry.keys()) == (self.EXPECTED_L1_KEYS | self.EXPECTED_L2_KEYS) def test_registry_has_9_l1_entries(self, registry): l1 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l1/")} assert l1 == self.EXPECTED_L1_KEYS def test_registry_has_2_l2_entries(self, registry): l2 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l2/")} assert l2 == self.EXPECTED_L2_KEYS def test_all_l1_interfaces_exist(self, registry, repo_root): for name in self.EXPECTED_L1_KEYS: entry = registry[name]["1.0.0"] iface_path = os.path.join(repo_root, entry["interface"]) assert os.path.isfile(iface_path), f"{iface_path} missing" iface = json.load(open(iface_path)) assert iface["name"] == name class TestTypeMap: def test_s3_in_type_map(self): assert TYPE_MAP["aws:s3:bucket"] == "aws_s3_bucket" def test_vpc_types_in_type_map(self): assert TYPE_MAP["aws:ec2:vpc"] == "aws_vpc" assert TYPE_MAP["aws:ec2:subnet"] == "aws_subnet" assert TYPE_MAP["aws:ec2:routetable"] == "aws_route_table" def test_ecs_types_in_type_map(self): assert TYPE_MAP["aws:ecs:cluster"] == "aws_ecs_cluster" assert TYPE_MAP["aws:ecs:task_definition"] == "aws_ecs_task_definition" assert TYPE_MAP["aws:ecs:service"] == "aws_ecs_service" def test_alb_types_in_type_map(self): assert TYPE_MAP["aws:elbv2:loadbalancer"] == "aws_lb" assert TYPE_MAP["aws:elbv2:listener"] == "aws_lb_listener" assert TYPE_MAP["aws:elbv2:targetgroup"] == "aws_lb_target_group" def test_iam_and_ecr_in_type_map(self): assert TYPE_MAP["aws:iam:role"] == "aws_iam_role" assert TYPE_MAP["aws:ecr:repository"] == "aws_ecr_repository" def test_cloudfront_types_in_type_map(self): assert TYPE_MAP["aws:cloudfront:distribution"] == "aws_cloudfront_distribution" assert TYPE_MAP["aws:cloudfront:originaccesscontrol"] == "aws_cloudfront_origin_access_control" def test_waf_type_in_type_map(self): assert TYPE_MAP["aws:wafv2:webacl"] == "aws_wafv2_web_acl" class TestTfValue: def test_string_quoted(self): assert _tf_value("hello") == '"hello"' def test_bool_true(self): assert _tf_value(True) == "true" def test_bool_false(self): assert _tf_value(False) == "false" def test_int(self): assert _tf_value(42) == "42" def test_float(self): assert _tf_value(3.14) == "3.14" def test_dict_jsonencoded(self): result = _tf_value({"key": "val"}) assert "jsonencode" in result assert '"key"' in result def test_list_jsonencoded(self): result = _tf_value([1, 2]) assert "jsonencode" in result def test_json_string_jsonencoded(self): result = _tf_value('{"k":"v"}') assert "jsonencode" in result def test_ref_raises(self): with pytest.raises(ValueError, match="ref: values"): _tf_value("ref:s3.bucket_arn") class TestRefExpr: def test_basic_ref(self): type_by_id = {"s3": "aws:s3:bucket"} result = _ref_expr("ref:s3.bucket_arn", type_by_id) assert result == "aws_s3_bucket.s3.arn" def test_vpc_ref(self): type_by_id = {"vpc": "aws:ec2:vpc"} result = _ref_expr("ref:vpc.vpc_id", type_by_id) assert result == "aws_vpc.vpc.id" def test_unknown_id_raises(self): with pytest.raises(ValueError, match="unknown stack resource id"): _ref_expr("ref:nonexistent.output", {"s3": "aws:s3:bucket"}) class TestAdapt: def test_adapt_emits_three_files(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) assert os.path.isfile(os.path.join(out_dir, "main.tf")) assert os.path.isfile(os.path.join(out_dir, "terraform.tf")) assert os.path.isfile(os.path.join(out_dir, "providers.tf")) def test_main_tf_has_s3_bucket(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert 'resource "aws_s3_bucket" "s3"' in main_tf assert 'bucket = "acdl-spike-bucket"' in main_tf def test_main_tf_has_versioning(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert "versioning" in main_tf assert "enabled = true" in main_tf def test_main_tf_has_outputs(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert 'output "bucket_arn"' in main_tf assert 'output "bucket_name"' in main_tf def test_terraform_tf_has_backend(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) terraform_tf = open(os.path.join(out_dir, "terraform.tf")).read() assert 'backend "s3"' in terraform_tf assert 'required_version' in terraform_tf assert ">= 1.9" in terraform_tf def test_providers_tf_has_aws(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) providers_tf = open(os.path.join(out_dir, "providers.tf")).read() assert 'provider "aws"' in providers_tf assert "us-east-1" in providers_tf def test_backend_key_uses_stack_name(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) terraform_tf = open(os.path.join(out_dir, "terraform.tf")).read() assert "spike/s3/terraform.tfstate" in terraform_tf class TestS3Output: def test_s3_instance_has_bucket_regional_domain_name_output(self, stack_instance, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(stack_instance, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert 'output "bucket_regional_domain_name"' in main_tf assert "aws_s3_bucket.s3.bucket_regional_domain_name" in main_tf class TestStaticAssetsStack: @pytest.fixture def static_assets_stack(self): from core.contract_resolver import resolve return resolve(str(ROOT / "contracts/static-assets.yaml"), str(ROOT)) def test_static_assets_resolves_to_4_resources(self, static_assets_stack): types = [r["type"] for r in static_assets_stack["resources"]] assert "aws:s3:bucket" in types assert "aws:cloudfront:distribution" in types assert "aws:cloudfront:originaccesscontrol" in types assert "aws:wafv2:webacl" in types def test_static_assets_adapter_emits_all_resources(self, static_assets_stack, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(static_assets_stack, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert 'resource "aws_s3_bucket" "s3"' in main_tf assert 'resource "aws_cloudfront_distribution" "cloudfront-distribution"' in main_tf assert 'resource "aws_cloudfront_origin_access_control" "cloudfront-originaccesscontrol"' in main_tf assert 'resource "aws_wafv2_web_acl" "waf"' in main_tf def test_static_assets_adapter_wires_s3_origin_to_cloudfront(self, static_assets_stack, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(static_assets_stack, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert "aws_s3_bucket.s3.bucket_regional_domain_name" in main_tf assert "aws_cloudfront_origin_access_control.cloudfront-originaccesscontrol.id" in main_tf def test_static_assets_adapter_wires_waf_to_cloudfront(self, static_assets_stack, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(static_assets_stack, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert "aws_wafv2_web_acl.waf.arn" in main_tf assert "web_acl_id = aws_wafv2_web_acl.waf.arn" in main_tf def test_static_assets_adapter_emits_distribution_outputs(self, static_assets_stack, tmp_path): out_dir = str(tmp_path / "tf_out") adapt(static_assets_stack, out_dir) main_tf = open(os.path.join(out_dir, "main.tf")).read() assert 'output "distribution_domain_name"' in main_tf assert 'output "web_acl_arn"' in main_tf