#!/usr/bin/env bash # scripts/run_lifecycle_destroy.sh — destroy an L1 module after lifecycle testing. # # Usage: run_lifecycle_destroy.sh [ci-vpc-outputs.json] # # For VPC-dependent modules, injects CI VPC outputs into the complex contract # before destroy (so terraform can find the resources in the right VPC). # # Lifecycle mode (REQ-134): ACDL_LIFECYCLE_MODE default "plan" = no-op # (plan mode never applies resources, so there is nothing to destroy; the # script exits 0 so the pipeline matrix cell stays green). Set to "full" # for the real `--destroy` against live AWS. set -euo pipefail ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" cd "$ROOT" MODULE="$1" CI_VPC_OUTPUTS="${2:-}" # Lifecycle mode: "plan" (default) skips destroy (nothing was applied); # "full" runs the real terraform destroy. LIFECYCLE_MODE="${ACDL_LIFECYCLE_MODE:-plan}" if [ "$LIFECYCLE_MODE" != "full" ]; then echo "lifecycle mode=$LIFECYCLE_MODE — nothing to destroy (plan-only run), exiting 0" exit 0 fi CONTRACT="modules/l1/${MODULE}/examples/complex.yml" VPC_DEPENDENT="alb ecs-service rds uptime" if echo "$VPC_DEPENDENT" | grep -qw "$MODULE" && [ -n "$CI_VPC_OUTPUTS" ] && [ -f "$CI_VPC_OUTPUTS" ]; then TMP_CONTRACT="/tmp/acdl-lifecycle-${MODULE}-complex.yml" python3 -c " import yaml, json with open('$CONTRACT') as f: contract = yaml.safe_load(f) with open('$CI_VPC_OUTPUTS') as f: raw = json.load(f) vpc = {k: v['value'] if isinstance(v, dict) and 'value' in v else v for k, v in raw.items()} m = '$MODULE' inputs = contract['infrastructure'][m]['inputs'] if m == 'alb': inputs['subnets'] = vpc.get('subnet_ids', '') inputs['vpc_id'] = vpc.get('vpc_id', '') inputs['security_group'] = vpc.get('ecs_security_group_id', '') elif m == 'ecs-service': inputs['subnets'] = vpc.get('subnet_ids', '') inputs['security_group'] = vpc.get('ecs_security_group_id', '') inputs['cluster_arn'] = vpc.get('cluster_arn', '') elif m == 'rds': inputs['subnet_ids'] = vpc.get('subnet_ids', '') elif m == 'uptime': inputs['subnets'] = vpc.get('subnet_ids', '') inputs['security_group'] = vpc.get('ecs_security_group_id', '') inputs['cluster_arn'] = vpc.get('cluster_arn', '') with open('$TMP_CONTRACT', 'w') as f: yaml.dump(contract, f) " CONTRACT="$TMP_CONTRACT" fi bash scripts/run_platform.sh --destroy "$CONTRACT"