699aa542df
---ci---
project: acdl
phase: 15
milestone: v1.2
status: verify
verdict: PARTIAL
requirements:
covered: [REQ-34]
partial: [REQ-33]
blocker:
- id: P0-IAM
description: terraform apply fails with AccessDenied on ECS/ECR/IAM/EC2 — live spike_runner_policy.json not pushed (root key deactivated per D-034)
unblock: operator runs create_iam_user.py with root/admin creds to push the expanded policy, then terraform apply succeeds (plan valid, 13 to add)
---/ci---
Phase 15 plan-as-execute + verify. PARTIAL: terraform apply blocked by IAM.
- Consumer microservice content authored (app.py + Dockerfile + README.md).
- Docker image acdl-microservice:latest built.
- Adapter fixed: ref emission (bare), JSON-string jsonencode, ECS service
network_configuration/load_balancer/desired_count/launch_type/task_definition,
listener default_action/load_balancer_arn, target group target_type/vpc_id/protocol,
VPC tags (not name), IGW + route table association, managed_policy_arns list.
- L1 fixes: l1-ecs-service (removed port from service sub-resource),
l1-vpc (added intra_refs, removed igw_id output).
- Resolver: intra_refs resolution (refs between sub-resources of same L1).
- terraform validate + plan succeed (13 to add).
- terraform apply BLOCKED (AccessDenied — live IAM policy not updated).
- Evidence event TERRAFORM_APPLY_BLOCKED written to DynamoDB outbox.
- v1.1 S3 regression: byte-identical.
Ready to ship v1.2.5 (partial).
64 lines
1.7 KiB
JSON
64 lines
1.7 KiB
JSON
{
|
|
"name": "l1-vpc",
|
|
"version": "1.0.0",
|
|
"kind": "l1",
|
|
"type": "aws:ec2:vpc",
|
|
"description": "VPC primitive (substrate-agnostic IR types aws:ec2:vpc + aws:ec2:subnet + aws:ec2:routetable; the Terraform adapter translates to aws_vpc/aws_subnet/aws_route_table).",
|
|
"inputs": {
|
|
"cidr": {
|
|
"type": "string",
|
|
"description": "VPC CIDR block, e.g. 10.0.0.0/16.",
|
|
"required": true
|
|
},
|
|
"azs": {
|
|
"type": "string",
|
|
"description": "Comma-separated availability zones, e.g. us-east-1a,us-east-1b.",
|
|
"required": true
|
|
},
|
|
"name": {
|
|
"type": "string",
|
|
"description": "Name tag for the VPC and child resources.",
|
|
"required": true
|
|
},
|
|
"region": {
|
|
"type": "string",
|
|
"description": "AWS region the VPC is created in.",
|
|
"required": true
|
|
}
|
|
},
|
|
"outputs": {
|
|
"vpc_id": {
|
|
"type": "string",
|
|
"description": "The VPC id."
|
|
},
|
|
"subnet_ids": {
|
|
"type": "string",
|
|
"description": "Comma-separated subnet ids."
|
|
}
|
|
},
|
|
"nfrs": {},
|
|
"resources": [
|
|
{
|
|
"type": "aws:ec2:vpc",
|
|
"description": "The VPC itself.",
|
|
"inputs": ["cidr", "name"],
|
|
"outputs": ["vpc_id"]
|
|
},
|
|
{
|
|
"type": "aws:ec2:subnet",
|
|
"description": "One subnet per availability zone (azs split on comma).",
|
|
"inputs": ["cidr", "az", "vpc_id", "name"],
|
|
"outputs": ["subnet_id"]
|
|
},
|
|
{
|
|
"type": "aws:ec2:routetable",
|
|
"description": "Route table bound to the VPC with an internet gateway + default route.",
|
|
"inputs": ["vpc_id"],
|
|
"outputs": []
|
|
}
|
|
],
|
|
"intra_refs": [
|
|
{"from": "aws:ec2:subnet.vpc_id", "to": "aws:ec2:vpc.vpc_id"},
|
|
{"from": "aws:ec2:routetable.vpc_id", "to": "aws:ec2:vpc.vpc_id"}
|
|
]
|
|
} |