Files
acdl/modules-ir/l1/l1-ecr/README.md
T
Jon Chery 3508671377 refactor(modules): remove thin-composition layer; rewrite all module READMEs
The L2 thin-composition layer (composition.json + contract_resolver.py +
contract schema + sample contracts) has been removed completely. The
implementation was unsatisfactory and is deferred for a later redesign.

- Delete: composition.json x2, contract_resolver.py, contracts/ x2,
  contract.schema.json
- Patch: run_platform.sh now loads a pre-existing IR instance instead of
  resolving a contract (the downstream adapter/checkov/confidence/outbox
  pipeline is unchanged)
- Prune: L2 entries removed from registry.json (L1 entries unchanged)
- Rewrite: all 7 L1 module READMEs in plain language (no jargon), each
  with Resources/Inputs/Outputs/Usage/Compliance-extension-points/Versioning
  sections derived from interface.json
- Add: 2 L2 placeholder READMEs noting the composition is under redesign
- Add: modules-ir/README.md catalog index + README-TEMPLATE.md

---ci---
project: acdl
phase: 17
milestone: v1.3
status: execute
---/ci---
2026-07-22 13:54:40 +00:00

2.0 KiB

l1-ecr — ECR repository

Module kind: L1 primitive | Version: 1.0.0

A single ECR repository that hosts the container image for the ECS task. The simplest container-registry module — one resource, two inputs, two outputs.

Resources

Resource Type Purpose
repository aws_ecr_repository The ECR repository

Inputs

Name Type Required Default Description
name string yes The ECR repository name
region string yes AWS region the repository is created in

Outputs

Name Type Description
repository_url string The ECR repository URL
repository_arn arn The ECR repository ARN

Usage

{
  "id": "ecr",
  "type": "aws:ecr:repository",
  "module": "l1-ecr@1.0.0",
  "inputs": {
    "name": "acdl-microservice",
    "region": "us-east-1"
  }
}

The repository_url output is used to build the image input for l1-ecs-service (e.g. <repository_url>:latest).

Compliance extension points

  • Image scanning — add image_scanning_configuration { scan_on_push = true } for vulnerability scanning (SOC2 CC7.6, DORA ICT risk testing, HIPAA security monitoring).
  • Encryption — add encryption_configuration { encryption_type = "KMS", kms_key = ... } with a customer-managed key (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv), GDPR Art.32).
  • Image tag immutability — add image_tag_mutability = "IMMUTABLE" to prevent tag overwriting (SOX §802, SOC2 CC6.1 integrity, DORA audit integrity).
  • Lifecycle policy — add aws_ecr_lifecycle_policy to enforce image retention / cleanup (GDPR Art.5(2) data minimization, SOC2 CC5.2).
  • Access policy — add a repository policy restricting pull/push to known roles (SOC2 CC6.1, HIPAA §164.308(a)(4)).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.