Files
acdl/tests/test_adapter.py
Jon Chery 3300ed2557 feat(P03 W3): env-JSON state_backend wiring (REQ-319)
The adapter reads env.state_backend.bucket from the env JSON when present
(fallback to the computed nova-tfstate-{account_id}-{region} pattern for
backwards compat). dev.json bound to the real account 581513795199 +
bucket nova-tfstate-581513795199-us-east-1 (D-203). qa/prod/dr stay
placeholder (account_id 000000000000 — the pilot-readiness policy blocks
apply on placeholder, D-208). dynamodb added to the adapter test
EXPECTED_L1_KEYS + a resolution/emission test.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W3
---
2026-08-18 22:56:39 +00:00

464 lines
21 KiB
Python

import json
import os
import subprocess
import sys
from pathlib import Path
import jsonschema
import pytest
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
from adapters.terraform.adapter import adapt, _tf_value, _ref_expr, _module_name, _child_id
ROOT = Path(__file__).resolve().parent.parent
class TestInstance:
def test_instance_validates_against_stack_schema(self, stack_instance, stack_schema):
jsonschema.validate(stack_instance, stack_schema)
def test_instance_has_one_resource(self, stack_instance):
assert len(stack_instance["resources"]) == 1
r = stack_instance["resources"][0]
assert r["id"] == "s3"
assert r["type"] == "aws:s3:bucket"
def test_instance_stack_is_s3(self, stack_instance):
assert stack_instance["stack"]["name"] == "s3"
assert stack_instance["stack"]["kind"] == "l1"
class TestRegistry:
EXPECTED_L1_KEYS = {"s3", "vpc", "ecs-cluster", "ecs-service", "iam-role", "alb", "ecr", "cloudfront", "waf", "rds", "kms-key", "uptime", "dynamodb"}
EXPECTED_L2_KEYS = {"static-assets", "microservice"}
def test_registry_has_15_entries(self, registry):
assert len(registry) == 15
assert set(registry.keys()) == (self.EXPECTED_L1_KEYS | self.EXPECTED_L2_KEYS)
def test_registry_has_13_l1_entries(self, registry):
l1 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l1/")}
assert l1 == self.EXPECTED_L1_KEYS
def test_registry_has_2_l2_entries(self, registry):
l2 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l2/")}
assert l2 == self.EXPECTED_L2_KEYS
def test_all_l1_interfaces_exist(self, registry, repo_root):
for name in self.EXPECTED_L1_KEYS:
entry = registry[name]["1.0.0"]
iface_path = os.path.join(repo_root, entry["interface"])
assert os.path.isfile(iface_path), f"{iface_path} missing"
iface = json.load(open(iface_path))
assert iface["name"] == name
def test_s3_has_terraform_dir(self, registry):
assert registry["s3"]["1.0.0"]["terraform_dir"] == "modules/l1/s3/terraform"
class TestModuleAssembly:
"""Assert the adapter ASSEMBLES module instantiations, not HCL strings."""
def test_adapt_emits_module_block(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'module "s3" {' in main_tf
assert "source = " in main_tf
def test_adapt_passes_inputs(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'bucket_name = "acdl-spike-bucket"' in main_tf
def test_adapt_skips_region(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert "region" not in main_tf.split("module")[1]
def test_adapt_emits_providers_and_terraform_tf(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
providers_tf = (tmp_path / "providers.tf").read_text()
terraform_tf = (tmp_path / "terraform.tf").read_text()
assert 'provider "aws"' in providers_tf
assert 'region = "us-east-1"' in providers_tf
assert 'required_providers' in terraform_tf
assert 'backend "s3"' in terraform_tf
assert 'spike/s3/dev/terraform.tfstate' in terraform_tf
def test_adapt_emits_nova_state_bucket(self, tmp_path):
"""P1 (REQ-165): the emitted backend references nova-tfstate-*
(not acdl-tfstate-*); the live bucket was renamed in v1.15 P4."""
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
terraform_tf = (tmp_path / "terraform.tf").read_text()
assert "nova-tfstate-" in terraform_tf
assert "acdl-tfstate-" not in terraform_tf
def test_adapt_emits_root_outputs(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
instance["outputs"] = {
"bucket_arn": {"from": "s3.bucket_arn"}
}
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'output "bucket_arn"' in main_tf
assert "module.s3.bucket_arn" in main_tf
def test_adapt_wires_refs(self, tmp_path):
instance = {
"version": "1.0.0",
"stack": {"name": "test-ref", "kind": "l1", "depth": 1},
"resources": [
{
"id": "src", "type": "aws:s3:bucket", "module": "s3@1.0.0",
"inputs": {"bucket_name": "src-bucket", "region": "us-east-1"},
"outputs": {"bucket_arn": {"type": "arn"}}
},
{
"id": "dst", "type": "aws:s3:bucket", "module": "s3@1.0.0",
"inputs": {"bucket_name": "dst-bucket", "region": "us-east-1",
"kms_key_arn": "ref:src.bucket_arn"},
"outputs": {"bucket_arn": {"type": "arn"}}
}
]
}
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert "kms_key_arn = module.src.bucket_arn" in main_tf
def test_adapt_env_aware_state_key(self, tmp_path):
"""P58: state key includes environment — spike/{name}/{env}/terraform.tfstate."""
instance = {
"version": "1.0.0",
"stack": {"name": "msvc", "kind": "l2", "depth": 1, "environment": "prod"},
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0",
"inputs": {"bucket_name": "test", "region": "us-east-1"}}
],
}
adapt(instance, str(tmp_path))
terraform_tf = (tmp_path / "terraform.tf").read_text()
assert "spike/msvc/prod/terraform.tfstate" in terraform_tf
def test_adapt_emits_data_source_block(self, tmp_path):
"""P58: when data_sources is present, emit terraform_remote_state block."""
instance = {
"version": "1.0.0",
"stack": {"name": "msvc", "kind": "l2", "depth": 1, "environment": "dev"},
"resources": [
{"id": "alb", "type": "aws:elbv2:loadbalancer", "module": "alb@1.0.0",
"inputs": {"subnets": "ref:platform_vpc.subnet_ids", "region": "us-east-1"}}
],
"data_sources": ["platform_vpc"],
}
adapt(instance, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'data "terraform_remote_state" "platform"' in main_tf
assert "data.terraform_remote_state.platform.outputs.subnet_ids" in main_tf
def test_adapt_no_vpc_for_microservice(self, tmp_path):
"""P58: microservice contract resolves without inline VPC resources."""
import sys
sys.path.insert(0, str(ROOT))
from core.contract_resolver import resolve
stack = resolve(str(ROOT / "contracts/microservice.yml"))
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'resource "aws_vpc"' not in main_tf
assert 'data "terraform_remote_state" "platform"' in main_tf
class TestRefExpr:
def test_ref_translates_to_module_output(self):
assert _ref_expr("ref:kms.kms_key_arn") == "module.kms.kms_key_arn"
def test_non_ref_returns_none(self):
assert _ref_expr("plain-string") is None
assert _ref_expr(42) is None
def test_module_name_extracts_from_versioned(self):
assert _module_name({"module": "s3@1.0.0"}) == "s3"
assert _module_name({"module": "vpc@1.0.0"}) == "vpc"
class TestTfValue:
def test_string(self):
assert _tf_value("hello") == '"hello"'
def test_bool(self):
assert _tf_value(True) == "true"
assert _tf_value(False) == "false"
def test_number(self):
assert _tf_value(42) == "42"
def test_ref(self):
assert _tf_value("ref:kms.kms_key_arn") == "module.kms.kms_key_arn"
def test_dict(self):
result = _tf_value({"key": "val"})
assert result.startswith("jsonencode(")
assert "key" in result
def test_list(self):
result = _tf_value(["a", "b"])
assert result.startswith("jsonencode(")
class TestAdapterStatelessness:
"""Assert the adapter has no type-specific logic or constant tables."""
def test_no_type_map(self):
adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text()
assert "TYPE_MAP" not in adapter_src
def test_no_input_map(self):
adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text()
assert "INPUT_MAP" not in adapter_src
def test_no_output_map(self):
adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text()
assert "OUTPUT_MAP" not in adapter_src
def test_no_rtype_branches(self):
adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text()
assert 'rtype ==' not in adapter_src
def test_adapter_under_250_lines(self):
# P03 W3 (REQ-319): the adapter now loads the env onboarding JSON to
# source env.state_backend.bucket + env.account_id + env.region for
# the S3 backend block (two small helpers). The bound is 250 (was
# 200) — still a tight statelessness guardrail against type-specific
# logic / constant tables creeping back in.
adapter_path = ROOT / "adapters/terraform/adapter.py"
line_count = len(adapter_path.read_text().splitlines())
assert line_count < 250, f"adapter is {line_count} lines, expected < 250"
class TestAdapterEmitsValidTerraform:
"""The adapter-emitted root main.tf must pass terraform validate."""
def test_s3_instance_emits_valid_terraform(self, tmp_path):
instance = json.load(open(ROOT / "modules/l1/s3/instance.json"))
adapt(instance, str(tmp_path))
result = subprocess.run(
["terraform", "init", "-backend=false", "-input=false"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform init failed: {result.stderr}"
result = subprocess.run(
["terraform", "validate"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform validate failed: {result.stderr}"
class TestAdapterDedupMultiResourceL1:
"""CAP-013 (v1.12, REQ-129): multi-resource L1s (ecs-service, alb) with
stack outputs + cross-module refs must dedup to ONE module block named by
the composition child id, with all expanded sub-ids rewritten. This is the
regression test that locks in the fix — a future refactor that re-breaks
the dedup must turn this red."""
def test_microservice_dedup_names_modules_by_child_id(self, tmp_path):
import sys
sys.path.insert(0, str(ROOT))
from core.contract_resolver import resolve
stack = resolve(str(ROOT / "contracts/microservice.yml"))
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
# The merged modules are named by the child id (alb, service), not the
# expanded sub-ids (alb-loadbalancer, service-service, ...).
assert 'module "alb" {' in main_tf
assert 'module "service" {' in main_tf
# Expanded sub-ids must NOT appear as module names.
assert 'module "alb-loadbalancer"' not in main_tf
assert 'module "alb-targetgroup"' not in main_tf
assert 'module "alb-listener"' not in main_tf
assert 'module "service-task-definition"' not in main_tf
assert 'module "service-service"' not in main_tf
def test_microservice_dedup_rewrites_stack_outputs(self, tmp_path):
"""Stack outputs reference the expanded sub-ids; after dedup they
must resolve to the child-id module name."""
import sys
sys.path.insert(0, str(ROOT))
from core.contract_resolver import resolve
stack = resolve(str(ROOT / "contracts/microservice.yml"))
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
# service_arn output references service-service -> module.service
assert 'output "service_arn" {\n value = module.service.service_arn' in main_tf
# lb_arn output references alb-loadbalancer -> module.alb
assert 'output "lb_arn" {\n value = module.alb.lb_arn' in main_tf
def test_microservice_dedup_rewrites_cross_module_refs(self, tmp_path):
"""A ref: input that targets an expanded sub-id (e.g.
ref:alb-targetgroup.target_group_arn) must be rewritten to the
child-id module (module.alb.target_group_arn)."""
import sys
sys.path.insert(0, str(ROOT))
from core.contract_resolver import resolve
stack = resolve(str(ROOT / "contracts/microservice.yml"))
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert "lb_target_group_arn = module.alb.target_group_arn" in main_tf
# The un-rewritten expanded form must NOT appear.
assert "module.alb-targetgroup" not in main_tf
assert "module.service-service" not in main_tf
def test_microservice_emits_valid_terraform(self, tmp_path):
"""CAP-013 end-to-end: the microservice (multi-resource L1s) main.tf
passes terraform init + validate. This is the real regression — the
v1.11 dedup produced 'No module call name' here."""
import sys
sys.path.insert(0, str(ROOT))
from core.contract_resolver import resolve
stack = resolve(str(ROOT / "contracts/microservice.yml"))
adapt(stack, str(tmp_path))
result = subprocess.run(
["terraform", "init", "-backend=false", "-input=false"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform init failed: {result.stderr}"
result = subprocess.run(
["terraform", "validate"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform validate failed (CAP-013 regression): {result.stderr}"
class TestChildIdHelper:
"""Unit tests for _child_id (the common-prefix heuristic)."""
def test_single_resource_returns_id_verbatim(self):
assert _child_id(["cluster"]) == "cluster"
assert _child_id(["kms-key"]) == "kms-key"
def test_multi_resource_returns_common_prefix(self):
# ecs-service expands to service-task-definition + service-service
assert _child_id(["service-task-definition", "service-service"]) == "service"
# alb expands to alb-loadbalancer + alb-targetgroup + alb-listener
assert _child_id(["alb-loadbalancer", "alb-targetgroup", "alb-listener"]) == "alb"
class TestAdapterDedupRejectsUnregisteredModule:
"""P1-1 (v1.14, REQ-135): a resource whose module is not in the
registry must raise ValueError, not be silently dropped from the
dedup merge. A typo'd module field (e.g. 'iam-role' vs 'iam_roles')
must surface as a diagnostic, not vanish."""
def test_unregistered_module_raises_valueerror(self, tmp_path):
stack = {
"resources": [
{"id": "bad", "type": "aws:bogus:thing", "module": "nonexistent@1.0.0", "inputs": {}}
],
"outputs": {},
"data_sources": [],
}
with pytest.raises(ValueError, match="no terraform_dir for module 'nonexistent'"):
adapt(stack, str(tmp_path))
def test_registered_module_still_works(self, tmp_path):
"""A registered module (s3) must still emit valid terraform — the
ValueError guard must not break the happy path."""
stack = {
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0", "inputs": {"bucket_name": "test"}}
],
"outputs": {},
"data_sources": [],
}
adapt(stack, str(tmp_path))
assert (tmp_path / "main.tf").exists()
class TestAdapterDedupMergesSameModule:
"""P2-2 (v1.14, REQ-139): two resources with the same module collapse
to one module block named by the child id, with merged inputs. This
locks in the dedup-merge behavior at the unit level."""
def test_two_resources_same_module_collapse_to_one_block(self, tmp_path):
"""Two resources sharing the same terraform dir (e.g. cloudfront
distribution + OAC) must produce ONE module block, not two."""
stack = {
"resources": [
{"id": "cloudfront-distribution", "type": "aws:cloudfront:distribution", "module": "cloudfront@1.0.0", "inputs": {"price_class": "PriceClass_100"}},
{"id": "cloudfront-originaccesscontrol", "type": "aws:cloudfront:originaccesscontrol", "module": "cloudfront@1.0.0", "inputs": {"viewer_protocol_policy": "redirect-to-https"}},
],
"outputs": {},
"data_sources": [],
}
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
# Exactly one module block for cloudfront (deduped to child id "cloudfront")
assert main_tf.count('module "cloudfront" {') == 1
# No separate module blocks for the expanded sub-ids
assert 'module "cloudfront-distribution"' not in main_tf
assert 'module "cloudfront-originaccesscontrol"' not in main_tf
def test_dedup_merges_inputs_from_both_resources(self, tmp_path):
"""When two resources share a module, their inputs are merged into
the single module block (first resource's inputs + second's, with
first-wins for overlapping keys)."""
stack = {
"resources": [
{"id": "cloudfront-distribution", "type": "aws:cloudfront:distribution", "module": "cloudfront@1.0.0", "inputs": {"price_class": "PriceClass_100", "region": "us-east-1"}},
{"id": "cloudfront-originaccesscontrol", "type": "aws:cloudfront:originaccesscontrol", "module": "cloudfront@1.0.0", "inputs": {"viewer_protocol_policy": "redirect-to-https"}},
],
"outputs": {},
"data_sources": [],
}
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
# Both inputs present in the merged module block
assert "PriceClass_100" in main_tf
assert "redirect-to-https" in main_tf
class TestAdapterRemoteStateKeyOverride:
"""P2-2 (v1.14, REQ-139): NOVA_REMOTE_STATE_KEY env var (P2 renamed from
NOVA_REMOTE_STATE_KEY; dual-read NOVA_* preferred, ACDL_* fallback until
P5) overrides the default 'platform/terraform.tfstate' key in the emitted
data terraform_remote_state block. This is the load-bearing correctness
mechanism for the microservice L2 lifecycle (remote state points at the
CI VPC, not the platform VPC)."""
def test_default_remote_state_key(self, tmp_path, monkeypatch):
"""When NOVA_REMOTE_STATE_KEY is unset, the default key is used."""
# P5 (REQ-164): ACDL_* fallback removed — NOVA_* only.
monkeypatch.delenv("NOVA_REMOTE_STATE_KEY", raising=False)
stack = {
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0", "inputs": {"bucket_name": "test", "region": "us-east-1"}}
],
"outputs": {},
"data_sources": ["platform"],
}
adapt(stack, str(tmp_path))
terraform_tf = (tmp_path / "terraform.tf").read_text()
main_tf = (tmp_path / "main.tf").read_text()
# The remote state data block uses the default key
assert "platform/terraform.tfstate" in main_tf
def test_env_override_remote_state_key(self, tmp_path, monkeypatch):
"""When NOVA_REMOTE_STATE_KEY is set, the emitted data block uses
the overridden key (e.g. 'spike/ci-vpc/terraform.tfstate')."""
monkeypatch.setenv("NOVA_REMOTE_STATE_KEY", "spike/ci-vpc/terraform.tfstate")
stack = {
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0", "inputs": {"bucket_name": "test", "region": "us-east-1"}}
],
"outputs": {},
"data_sources": ["platform"],
}
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
# The remote state data block uses the overridden key
assert "spike/ci-vpc/terraform.tfstate" in main_tf
assert "platform/terraform.tfstate" not in main_tf