c80060878a
EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with the full versions/variables/locals/main/outputs split. Defaults previously hardcoded in the adapter move into locals.tf. Simple single-resource modules (7): - kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults) - ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning) - ecs-cluster: aws_ecs_cluster (name default) - iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf) - rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults) - waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules) - uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf) Multi-resource modules with intra-refs (4): - vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf) - ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf) - alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf) - cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf) Registry: terraform_dir added to all 11 remaining entries. Adapter fix: stack output format uses separate 'from' + 'output' fields (not 'from': 'rid.output'). Fixed _emit_root_output to read both fields. 6 previously-skipped tests unblocked (run_platform.sh --check-only now resolves static-assets.yml through the new module-assembled adapter). Removed skip markers. Fixed test assertion (aws_s3_bucket → module). Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass terraform init + validate standalone. ---ci--- project: acdl phase: P56b milestone: v1.11 status: execute ---/ci---
52 lines
1.3 KiB
Terraform
52 lines
1.3 KiB
Terraform
resource "aws_wafv2_web_acl" "this" {
|
|
name = var.name
|
|
scope = var.scope
|
|
|
|
default_action {
|
|
dynamic "allow" {
|
|
for_each = local.action_type == "allow" ? [1] : []
|
|
content {}
|
|
}
|
|
dynamic "block" {
|
|
for_each = local.action_type == "block" ? [1] : []
|
|
content {}
|
|
}
|
|
}
|
|
|
|
visibility_config {
|
|
cloudwatch_metrics_enabled = true
|
|
metric_name = "acdl-waf-metrics"
|
|
sampled_requests_enabled = true
|
|
}
|
|
|
|
dynamic "rule" {
|
|
for_each = var.rules
|
|
content {
|
|
name = lookup(rule.value, "name", "custom-rule-${rule.key}")
|
|
priority = lookup(rule.value, "priority", rule.key)
|
|
override_action {
|
|
none {}
|
|
}
|
|
statement {
|
|
byte_match_statement {
|
|
search_string = lookup(rule.value, "search_string", "/")
|
|
positional_constraint = "CONTAINS"
|
|
field_to_match {
|
|
single_header {
|
|
name = "user-agent"
|
|
}
|
|
}
|
|
text_transformation {
|
|
priority = 0
|
|
type = "NONE"
|
|
}
|
|
}
|
|
}
|
|
visibility_config {
|
|
cloudwatch_metrics_enabled = true
|
|
metric_name = "${lookup(rule.value, "name", "custom-rule-${rule.key}")}-metrics"
|
|
sampled_requests_enabled = true
|
|
}
|
|
}
|
|
}
|
|
} |