Files
acdl/modules/l1/cloudfront
Jon Chery 7585c828f0
acdl-ci / Lint (push) Successful in 7s
acdl-ci / Test (push) Successful in 23s
acdl-ci / Platform check-only (offline) (push) Successful in 8s
docs(P48): vision gaps + badge system + substrate→engine + CR format + agentic tags
9 requirements implemented across presentation decks and project docs:

1. DX closing slide: added 'Infrastructure as a utility, not a craft' bullet
   to convey the full vision (infrastructure consumed, not maintained;
   platform compounds value over time).
2. PW Problem slide: 'moving a merged change' → 'promoting a change'.
3. PW Problem slide: added 'Red tape' and 'Scalability without increasing
   headcount' bullets (4 frictions, not 2).
4. PW Roadmap slide: redesigned with side-by-side HTML table layout
   (Testing | Planned), 16px font, no overflow.
5. PW deck: added new slide 'What This Platform Is — and Isn't' after North
   Star (sovereign boundary, infrastructure as utility, 4 anti-goals).
   PW deck now 16 slides (was 15).
6. Maturity nomenclature: 'Available today'/'shipped' → 'Testing' across
   both decks + source markdown. New .testing badge (blue/teal #DBEAFE).
   Roadmap title: 'Testing vs. Planned'. The platform has 0 consumer
   adoption — 'shipped' was inaccurate.
7. Global: 'substrate' → 'engine' across entire project (88 matches, 30+
   files including .ciagent/, docs/, modules/, adapters/, schemas/, code).
8. Presentation files only: 'forge' → 'VCS' / 'version control system'
   (6 occurrences in 4 files). 'forge' retained in all technical docs and
   code as the industry-standard term.
9. New .agentic badge (purple/violet #EDE9FE) appended to agentic features
   in both decks: confidence signal, autonomous dev, pattern recognition,
   dynamic module creation, citizen developer surface, auto-promotion.

Also: Change Request ID format changed from 'CR-2026-001' to 'CHG0678912'
across presentation files, consumer guide, and test fixtures.

HTML re-rendered. PPTX rendered for release upload.

---ci---
phase: 48
milestone: v1.9
status: complete
requirements:
  covered: []
  partial: []
---/ci---
2026-07-23 14:58:29 +00:00
..

cloudfront — CloudFront distribution

Module kind: primitive | Version: 1.0.0

A CloudFront distribution with an S3 origin via Origin Access Control (OAC). The distribution serves the bucket's static content from the global edge network with HTTPS redirection by default. An optional WAF web ACL can be associated to filter traffic before it reaches the origin.

Resources

Resource Type Purpose
oac aws_cloudfront_origin_access_control Origin Access Control signing the S3 origin
distribution aws_cloudfront_distribution The CloudFront distribution with an S3 origin via OAC

Inputs

Name Type Required Default Description
bucket_regional_domain_name string yes The S3 bucket regional domain name (ref to s3 origin)
price_class string no PriceClass_100 CloudFront price class
viewer_protocol_policy string no redirect-to-https Viewer protocol policy
default_ttl number no 3600 Default TTL in seconds
max_ttl number no 86400 Max TTL in seconds
waf_web_acl_arn string no WAF web ACL ARN to associate (ref to waf)
region string yes AWS region (CloudFront is global but the provider region is used for the OAC)

Outputs

Name Type Description
distribution_arn arn The CloudFront distribution ARN
distribution_domain_name string The CloudFront distribution domain name (e.g. d111111abcdef8.cloudfront.net)
oac_id string The Origin Access Control ID

Usage

{
  "id": "cloudfront",
  "type": "aws:cloudfront:distribution",
  "module": "cloudfront@1.0.0",
  "inputs": {
    "bucket_regional_domain_name": "ref:s3.bucket_regional_domain_name",
    "price_class": "PriceClass_100",
    "viewer_protocol_policy": "redirect-to-https",
    "default_ttl": 3600,
    "max_ttl": 86400,
    "waf_web_acl_arn": "ref:waf.web_acl_arn",
    "region": "us-east-1"
  }
}

The bucket_regional_domain_name and waf_web_acl_arn inputs are typically wired as ref: expressions from the s3 and waf primitives inside a module composition (see modules/l2/static-assets).

Compliance extension points

  • TLS/HTTPS — viewer protocol policy defaults to redirect-to-https; a custom ACM certificate + viewer_certificate block can pin TLS to a customer domain (SOC2 CC6.1, GDPR Art.32).
  • Geo restriction — the restrictions.geo_restriction block can whitelist/blacklist countries for data-residency compliance (GDPR Art.44, SOC2 CC6.1).
  • Logging — CloudFront access logs to an S3 bucket for auditability (SOC2 CC7.2, DORA audit trail).
  • Field-level encryption — add field-level encryption for PII fields in POST bodies (GDPR Art.32).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

# Simple CloudFront distribution (S3 origin, no WAF)
uses: acdl/pipelines/deploy.yaml@v1.6
module: cloudfront
environment: dev
inputs:
  bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
  region: us-east-1

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex CloudFront with WAF + custom TTL + viewer protocol redirect
uses: acdl/pipelines/deploy.yaml@v1.6
module: cloudfront
environment: dev
inputs:
  bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
  price_class: PriceClass_100
  viewer_protocol_policy: redirect-to-https
  default_ttl: 3600
  max_ttl: 86400
  waf_web_acl_arn: arn:aws:wafv2:us-east-1:000000000000:webacl/my-waf
  region: us-east-1

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.