Presentation changes (both Marp decks + source markdown): 1. Title slide: deck title as H1 (slightly bigger), 'Agentic Cloud Delivery Platform' as H3 subtitle — cleaner title hierarchy 2. DX deck: removed Local Reproducibility slide (not beneficial for DX) 3. DX deck: Safe Promotion Path slide redesigned with side-by-side layout for Approaches A and B (HTML table, two columns) 4. DX deck: 'an agent' → 'an AI agent' (slide 2 + Citizen Developer slide) 5. DX deck: What a Developer Does — diagram floated to the right side 6. Header simplified to just the deck name (subtitle now on title slide) HIPAA removal (25 files): - Completely removed all HIPAA references from all markdown documentation, presentation source files, module READMEs, and rendered HTML - Removed HIPAA from compliance milestone lists (GDPR, SOX, SOC2, DORA remain) - Removed HIPAA section references (§164.xxx) from compliance annotations - Cleaned up empty parentheses and broken commas left by removal - Re-rendered both HTML decks from updated Marp source ---ci--- phase: 47 milestone: v1.9 status: complete requirements: covered: [] partial: [] ---/ci---
vpc — VPC with subnets and routing
Module kind: primitive | Version: 1.0.0
A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids.
Resources
| Resource | Type | Purpose |
|---|---|---|
| vpc | aws_vpc |
The VPC itself |
| subnet | aws_subnet |
One subnet per availability zone |
| route_table | aws_route_table |
Route table with default route 0.0.0.0/0 |
| internet_gateway | aws_internet_gateway |
IGW for public internet access |
| route_table_association | aws_route_table_association |
Binds subnet to route table |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
cidr |
string | yes | — | VPC CIDR block, e.g. 10.0.0.0/16 |
azs |
string | yes | — | Comma-separated availability zones, e.g. us-east-1a,us-east-1b |
name |
string | yes | — | Name tag for the VPC and child resources |
region |
string | yes | — | AWS region the VPC is created in |
Outputs
| Name | Type | Description |
|---|---|---|
vpc_id |
string | The VPC id |
subnet_ids |
string | Comma-separated subnet ids |
Usage
{
"id": "vpc",
"type": "aws:ec2:vpc",
"module": "vpc@1.0.0",
"inputs": {
"cidr": "10.0.0.0/16",
"azs": "us-east-1a,us-east-1b",
"name": "acdl-microservice",
"region": "us-east-1"
}
}
The azs input is split on comma; one subnet is created per zone. The
route table gets a default route 0.0.0.0/0 → internet gateway. Other
modules reference subnet_ids for their network placement.
Compliance extension points
- VPC Flow Logs — add
aws_flow_log+ CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, DORA ICT risk logging). - Private subnets + NAT gateway — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, network isolation).
- VPC endpoints — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk).
- Security groups — add
aws_security_groupas a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2). - Network ACLs — add
aws_network_aclfor subnet-level segmentation (PCI-DSS 1.3).
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment:
uses: acdl/pipelines/deploy.yaml@v1.6
module: vpc
environment: dev
inputs:
cidr: 10.0.0.0/16
azs: us-east-1a,us-east-1b
name: my-vpc
region: us-east-1
Complex
A production deployment with optional inputs:
# Complex VPC with 3 AZs and a custom CIDR
uses: acdl/pipelines/deploy.yaml@v1.6
module: vpc
environment: dev
inputs:
cidr: 10.50.0.0/16
azs: us-east-1a,us-east-1b,us-east-1c
name: my-production-vpc
region: us-east-1
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.