Files
acdl/modules-ir/l2/l2-static-asset
Jon Chery 3508671377 refactor(modules): remove thin-composition layer; rewrite all module READMEs
The L2 thin-composition layer (composition.json + contract_resolver.py +
contract schema + sample contracts) has been removed completely. The
implementation was unsatisfactory and is deferred for a later redesign.

- Delete: composition.json x2, contract_resolver.py, contracts/ x2,
  contract.schema.json
- Patch: run_platform.sh now loads a pre-existing IR instance instead of
  resolving a contract (the downstream adapter/checkov/confidence/outbox
  pipeline is unchanged)
- Prune: L2 entries removed from registry.json (L1 entries unchanged)
- Rewrite: all 7 L1 module READMEs in plain language (no jargon), each
  with Resources/Inputs/Outputs/Usage/Compliance-extension-points/Versioning
  sections derived from interface.json
- Add: 2 L2 placeholder READMEs noting the composition is under redesign
- Add: modules-ir/README.md catalog index + README-TEMPLATE.md

---ci---
project: acdl
phase: 17
milestone: v1.3
status: execute
---/ci---
2026-07-22 13:54:40 +00:00
..

l2-static-asset — S3 static asset (composition being redesigned)

Module kind: L2 composition | Version: TBD | Status: Under redesign

A composition that references the l1-s3 primitive to deploy a single S3 bucket for static asset hosting.

The composition layer is being redesigned. The previous thin-composition implementation (a composition.json with children + wires) has been removed. A new composition mechanism will be designed in a later phase.

Resources

TBD — the composition will reference this L1 primitive:

L1 module Purpose README
l1-s3 S3 bucket README

Inputs

TBD — will be defined when the composition mechanism is redesigned.

Outputs

TBD — will be defined when the composition mechanism is redesigned.

Usage

TBD — the composition mechanism is being redesigned. Until then, use l1-s3 directly. See the l1-s3 README for a usage example.

Compliance extension points

The composition will need to wire compliance resources when the compliance milestone (GDPR, SOX, SOC2, HIPAA, DORA) lands:

  • KMS key — shared encryption key for S3 SSE.
  • S3 access logs — access logging to a separate audit bucket.
  • Object Lock — 7-year immutable retention for evidence.
  • Public access block — prevent data exfiltration.

See the l1-s3 README for per-module compliance extension points.

Versioning

Versioning will be defined when the composition mechanism is redesigned.