c80060878a
EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with the full versions/variables/locals/main/outputs split. Defaults previously hardcoded in the adapter move into locals.tf. Simple single-resource modules (7): - kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults) - ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning) - ecs-cluster: aws_ecs_cluster (name default) - iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf) - rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults) - waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules) - uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf) Multi-resource modules with intra-refs (4): - vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf) - ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf) - alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf) - cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf) Registry: terraform_dir added to all 11 remaining entries. Adapter fix: stack output format uses separate 'from' + 'output' fields (not 'from': 'rid.output'). Fixed _emit_root_output to read both fields. 6 previously-skipped tests unblocked (run_platform.sh --check-only now resolves static-assets.yml through the new module-assembled adapter). Removed skip markers. Fixed test assertion (aws_s3_bucket → module). Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass terraform init + validate standalone. ---ci--- project: acdl phase: P56b milestone: v1.11 status: execute ---/ci---
24 lines
745 B
Terraform
24 lines
745 B
Terraform
locals {
|
|
# Fargate compat defaults (adapter previously hardcoded these).
|
|
requires_compatibilities = var.launch_type == "FARGATE" ? ["FARGATE"] : ["EC2"]
|
|
network_mode = var.launch_type == "FARGATE" ? "awsvpc" : "bridge"
|
|
|
|
# Container definitions from image/port/env (adapter previously hardcoded this).
|
|
container_definitions = jsonencode([{
|
|
name = "app"
|
|
image = var.image
|
|
essential = true
|
|
portMappings = [{
|
|
containerPort = var.port
|
|
hostPort = var.port
|
|
protocol = "tcp"
|
|
}]
|
|
}])
|
|
|
|
# Subnet list from comma-separated string.
|
|
subnet_list = split(",", var.subnets)
|
|
|
|
# Security groups list.
|
|
security_groups = var.security_group != null ? [var.security_group] : []
|
|
}
|