7585c828f0
9 requirements implemented across presentation decks and project docs: 1. DX closing slide: added 'Infrastructure as a utility, not a craft' bullet to convey the full vision (infrastructure consumed, not maintained; platform compounds value over time). 2. PW Problem slide: 'moving a merged change' → 'promoting a change'. 3. PW Problem slide: added 'Red tape' and 'Scalability without increasing headcount' bullets (4 frictions, not 2). 4. PW Roadmap slide: redesigned with side-by-side HTML table layout (Testing | Planned), 16px font, no overflow. 5. PW deck: added new slide 'What This Platform Is — and Isn't' after North Star (sovereign boundary, infrastructure as utility, 4 anti-goals). PW deck now 16 slides (was 15). 6. Maturity nomenclature: 'Available today'/'shipped' → 'Testing' across both decks + source markdown. New .testing badge (blue/teal #DBEAFE). Roadmap title: 'Testing vs. Planned'. The platform has 0 consumer adoption — 'shipped' was inaccurate. 7. Global: 'substrate' → 'engine' across entire project (88 matches, 30+ files including .ciagent/, docs/, modules/, adapters/, schemas/, code). 8. Presentation files only: 'forge' → 'VCS' / 'version control system' (6 occurrences in 4 files). 'forge' retained in all technical docs and code as the industry-standard term. 9. New .agentic badge (purple/violet #EDE9FE) appended to agentic features in both decks: confidence signal, autonomous dev, pattern recognition, dynamic module creation, citizen developer surface, auto-promotion. Also: Change Request ID format changed from 'CR-2026-001' to 'CHG0678912' across presentation files, consumer guide, and test fixtures. HTML re-rendered. PPTX rendered for release upload. ---ci--- phase: 48 milestone: v1.9 status: complete requirements: covered: [] partial: [] ---/ci---
4.3 KiB
4.3 KiB
ACDL — Agentic Cloud Delivery Platform
Consumers declare intent; the platform delivers safe production deployment through an agentic stack — automatically, safely, and with a complete audit trail. A merged change progresses through lower environments end-to-end without a platform engineer joining a thread; a non-technical consumer ships a production deployment by declaring intent, without authoring a workflow, a configuration file, or an infrastructure module.
Two repositories
There are two kinds of repository in the ACDL model:
- Platform repo (this one). The source code of the platform. It owns
modules/,adapters/,core/,schemas/,pipelines/,scripts/, and the reusable workflow files. Platform engineers work here. A consumer never clones it. - Consumer repo (yours). A consumer repo contains only its application
code, one or more contracts (
.acdl/contract.yaml), and one or more CI definitions (a thin.github/workflows/deploy.ymlthatuses:the central reusable workflow, pointing at the appropriate environment + contract). The consumer does not write infrastructure modules, workflow YAML, or adapter code.
Documentation
| Section | Audience | What it covers |
|---|---|---|
| Consumer Guide | Consumers | Step-by-step: create a repo, write a contract, reference the central pipeline, ship a deployment. |
| Modules | Consumers + platform engineers | The module catalog — primitives and modules, their inputs/outputs, and usage. |
| Contracts | Consumers | The contract schema, fields, and a worked sample. |
| Pipeline | Consumers + platform engineers | The central CI + deployment pipeline and its stages. |
| Versioning | Consumers + platform engineers | Module versioning + deploy-pipeline versioning (the uses: tag). |
| Environments | Consumers | Platform-managed environments and the first-run onboarding flow. |
| Architecture | Platform engineers | The current architecture — layers, cross-cutting concerns, the engine abstraction. |
| Vision | All | The why — the friction the platform absorbs and the north star. |
Features
- Contract-driven deploys — a consumer writes a YAML contract; the platform resolves it to a stack, compiles it, and deploys it.
- Reusable versioned deploy workflow — consumer repos
uses:a versioned central workflow; no platform code is cloned by the consumer. - Module catalog — primitives (single resources) and modules (patterns of primitives) with self-documented inputs/outputs.
- Zero-trust credentials — OIDC federation + attribute-based authorization (ABAC) by default; no long-lived keys in consumer repos.
- Security + policy checks — a security-check stage and a policy-check stage run before any infrastructure is created.
- Confidence signal — a computed, explainable score gates promotion.
- Evidence outbox — every deployment writes a hash-chained evidence event to an audit outbox.
- Shell reproducibility —
scripts/run_ci.shmirrors the CI pipeline locally;scripts/run_platform.sh --check-onlyruns offline. - Platform-managed environments — consumers provide no AWS account, VPC, subnet, or state bucket; the platform manages environments.
Roadmap
Planned future features (no dates; tracked in the internal roadmap):
- Dynamic module creation from a contract — an agentic flow where a consumer creates a module directly from the contract file (the "composition" mechanism, redesigned).
- Compliance milestone — per-module compliance extension points (GDPR, SOX, SOC2, DORA) wired into the pipeline.
- Additional engine adapters — beyond the Terraform adapter.
- Environment self-service — a consumer-facing flow to request and provision a new platform-managed environment.
- HITL gates for qa / prod / dr — human attestation + higher confidence thresholds for higher environments.
- OIDC for all platform runners — zero-trust credentials everywhere.
Quick links
- Consumer Guide — start here if you are a consumer.
- Architecture — start here if you are a platform engineer.
- The README describes the platform repo.