Jon Chery 3070a68e1d phase: 9, status: plan-as-execute, persona: platform-engineer, task: T-9.5..T-9.7+T-9.9
---ci---
project: acdl
phase: 9
milestone: v1.1
status: plan-as-execute
persona: platform-engineer
task: [T-9.5, T-9.6, T-9.7, T-9.9]
requirements.covered: [REQ-26]
---/ci---

Waves 2+3: Terraform adapter + generated spike TF + run script.

- T-9.5: adapters/terraform/adapter.py - compiles an IR instance to a
  Terraform root module. TYPE_MAP {aws:s3:bucket -> aws_s3_bucket}. Thin
  layer; does not own L1 content. Emits main.tf (resource + outputs) +
  terraform.tf (required_version/providers + S3 backend, NO
  dynamodb_table per D-P09-1) + providers.tf (aws provider region from
  the IR). CLI: adapter.py <ir_instance.json> <out_dir>.

- T-9.6: terraform/spike/{main.tf,terraform.tf,providers.tf} - generated
  by running the adapter against modules-ir/l1/l1-s3/spike_instance.json.
  Committed so verify_phase09.sh can validate/plan without regenerating
  (D-P09-4); the verify script will regenerate + diff to prove
  reproducibility.

- T-9.7: scripts/run_spike_plan.sh - loads rotated spike key from
  gitignored .env.secrets, exports AWS env vars, cd terraform/spike,
  terraform init -lock=false, terraform validate, terraform plan
  -lock=false -out=tfplan. Plan-only; no apply.

- T-9.9: .gitignore - add terraform/spike/.terraform/ + tfplan +
  *.tfstate*.

EXECUTE: ran scripts/run_spike_plan.sh against real AWS via the rotated
spike key (D-039). terraform plan succeeded: 1 to add (the S3 bucket),
outputs computed. One non-blocking deprecation warning (aws_s3_bucket
versioning block -> use aws_s3_bucket_versioning in v1.2). No long-lived
credential in the workflow (key loaded from .env.secrets at runtime).
2026-07-21 19:15:10 +00:00

ACDL — Agentic Cloud Delivery Platform

Consumers declare intent; the platform delivers safe production deployment through an agentic stack — automatically, safely, and with a complete audit trail. A merged change progresses through lower environments end-to-end without a platform engineer joining a thread; a non-technical consumer ships a production deployment by declaring intent, without authoring a workflow, a configuration file, or a Terraform module.

Status

  • v1.1 (active): architecture finalization + v1 spike. Finalize the architecture to v1.0 (resolve the 11 open design decisions) and prove the locked commitments with one end-to-end implementation spike (l1-s3 + l2-static-asset + Terraform adapter → real terraform plan against AWS).
  • v1.0 demo (complete, archived): tag v1.1.0. The 30-minute stub-driven executive demo is preserved under demo/ as the intent reference; it is not the platform.

Repository layout

Path Purpose Populated
acdl_platform/ Platform code: confidence signal, contract resolver, outbox, HITL/ledger designs (renamed from platform/ in Phase 08 to avoid shadowing the stdlib platform module) Phase 07+
schemas/ JSON Schemas: IR, PolicyCheckResult, contract Phase 07
adapters/ Substrate adapters (Terraform adapter in v1; the only substrate-specific code per §12) Phase 09
terraform/ State backend + provider config (S3 state + DynamoDB lock) Phase 08+
modules-ir/ IR-typed L1/L2 modules (l1-s3, l2-static-asset) Phase 0910
scripts/ v1.1 verify scripts (verify_phaseNN.sh) Phase 06+
demo/ Archived v1.0 executive demo (tag v1.1.0); runs locally via demo/scripts/run_demo.sh --no-upload complete
.ciagent/ CIAgent metadata (plans, decisions, personas, roadmap, research) active
docs/ Upstream vision + architecture sources active

Running the archived demo

The v1.0 demo is an archived artifact. To re-run it locally:

bash demo/scripts/run_demo.sh --no-upload

The demo deck is at demo/ACDL_DEMO.md. The demo runs entirely on local stubs — no AWS, no AI — and shows intent and safety behavior rather than provisioning real cloud resources. It is the reference of intent for the real platform; it is not the platform itself.

S
Description
Nova — The New Dawn of DevSecOps. Autonomous infrastructure delivery: consumers declare intent, the platform ships safely with an immutable audit trail.
Readme 69 MiB
Languages
Python 87.2%
Shell 8.6%
HCL 4.2%