---ci---
project: acdl
phase: 32
milestone: v1.8
status: execute
---/ci---
- All 11 L1 primitives now have deletion_protection NFR (boolean, default true).
- Adapter emits `lifecycle { prevent_destroy = true }` when NFR is true;
omits it when false. Default is true when NFR is absent.
- L2 composition resolver propagates inputs.deletion_protection to all
children NFRs. When false, all resources get deletion_protection=false.
- Stack schema updated with optional features object (deletion_protection,
uptime_enabled).
- Contract schema description updated to document deletion_protection
and uptime_enabled inputs.
Tests: +5 (307 -> 312). All pass.
vpc — VPC with subnets and routing
Module kind: primitive | Version: 1.0.0
A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids.
Resources
| Resource | Type | Purpose |
|---|---|---|
| vpc | aws_vpc |
The VPC itself |
| subnet | aws_subnet |
One subnet per availability zone |
| route_table | aws_route_table |
Route table with default route 0.0.0.0/0 |
| internet_gateway | aws_internet_gateway |
IGW for public internet access |
| route_table_association | aws_route_table_association |
Binds subnet to route table |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
cidr |
string | yes | — | VPC CIDR block, e.g. 10.0.0.0/16 |
azs |
string | yes | — | Comma-separated availability zones, e.g. us-east-1a,us-east-1b |
name |
string | yes | — | Name tag for the VPC and child resources |
region |
string | yes | — | AWS region the VPC is created in |
Outputs
| Name | Type | Description |
|---|---|---|
vpc_id |
string | The VPC id |
subnet_ids |
string | Comma-separated subnet ids |
Usage
{
"id": "vpc",
"type": "aws:ec2:vpc",
"module": "vpc@1.0.0",
"inputs": {
"cidr": "10.0.0.0/16",
"azs": "us-east-1a,us-east-1b",
"name": "acdl-microservice",
"region": "us-east-1"
}
}
The azs input is split on comma; one subnet is created per zone. The
route table gets a default route 0.0.0.0/0 → internet gateway. Other
modules reference subnet_ids for their network placement.
Compliance extension points
- VPC Flow Logs — add
aws_flow_log+ CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT risk logging). - Private subnets + NAT gateway — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, HIPAA network isolation).
- VPC endpoints — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk).
- Security groups — add
aws_security_groupas a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2). - Network ACLs — add
aws_network_aclfor subnet-level segmentation (PCI-DSS 1.3).
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment:
uses: acdl/pipelines/deploy.yaml@v1.6
module: vpc
environment: dev
inputs:
cidr: 10.0.0.0/16
azs: us-east-1a,us-east-1b
name: my-vpc
region: us-east-1
Complex
A production deployment with optional inputs:
# Complex VPC with 3 AZs and a custom CIDR
uses: acdl/pipelines/deploy.yaml@v1.6
module: vpc
environment: dev
inputs:
cidr: 10.50.0.0/16
azs: us-east-1a,us-east-1b,us-east-1c
name: my-production-vpc
region: us-east-1
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.