---ci--- project: acdl phase: 39 milestone: v1.9 status: execute ---/ci--- Phase 39 — design-doc-refresh-and-p1-1-parameterization: Design docs (REQ-100, REQ-101): - hitl_matrix_design.md: 'dev-only spike'/'v1.2 wires the gates' framing replaced with v1.9 wired-gates reality; 8-concern matrix marked implemented (offline-testable subset + signed evidence artifacts, D-084); v1.9 wiring section cross-references hitl_gates.py + attestation_matrix.py; approver_dr noted. - audit_ledger_design.md: outbox marked shipped+production since v1.8; S3 Object Lock + JWS + async worker + DLQ + daily checkpoints clearly labeled 'Deferred to a future milestone (D-083)'; RPO/RTO table updated; approver fields note v1.9 hitl_gates.attest. P1-1 adapter parameterization (REQ-102, D-085): - ecs-service interface.json: desired_count (default 1), launch_type (FARGATE), family (app) inputs added. - alb interface.json: load_balancer_type (application), target_type (ip). - adapter.py: hardcoded defaults replaced with inputs.get(<name>, <default>); hardcoded 'acdl-microservice-rt'/'acdl-microservice-igw' Name tags derive from the VPC name input. - contract_resolver.py: child_input_map routes wires to the sub-resource that declares the input (desired_count → aws:ecs:service, family → aws:ecs:task_definition, target_type → targetgroup, etc.). - microservice composition.json: wires added for the new inputs. Tests: +21 (test_p1_1_adapter_parameterization.py, test_design_docs_current.py). 371 passed; run_ci.sh green; run_platform.sh --check-only green; v1.1 S3 regression preserved.
microservice — ECS Fargate microservice
Module kind: module pattern | Version: 1.0.0
A pattern that references multiple primitives to deploy an ECS Fargate microservice end-to-end (VPC, cluster, ECR, IAM role, ALB, ECS service).
Resources
The pattern references these primitives:
| Primitive | Purpose | README |
|---|---|---|
vpc |
VPC, subnets, routing | README |
ecs-cluster |
ECS Fargate cluster | README |
ecr |
ECR image repository | README |
iam-role |
IAM task execution role | README |
alb |
Application Load Balancer | README |
ecs-service |
ECS task definition + service | README |
Inputs
| Name | Type | Required | Description |
|---|---|---|---|
image |
string | yes | ECR image URL for the task container |
port |
number | yes | Container port the service listens on |
region |
string | yes | AWS region |
cidr |
string | no | VPC CIDR block (default 10.0.0.0/16) |
azs |
string | no | Comma-separated availability zones |
Outputs
| Name | Type | Description |
|---|---|---|
lb_arn |
arn | The load balancer ARN |
service_arn |
arn | The ECS service ARN |
Usage
Define a contract referencing this module:
uses: acdl/pipelines/deploy.yaml@v1.6
module: microservice
environment: dev
inputs:
image: 581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest
port: 8080
region: us-east-1
Compliance extension points
The pattern can wire compliance resources across primitives when the compliance milestone (GDPR, SOX, SOC2, HIPAA, DORA) lands:
- KMS key — shared encryption key referenced by S3, ECR, CloudWatch Logs, and Secrets Manager.
- CloudTrail — management-plane audit trail for the entire stack.
- VPC Flow Logs — network audit trail.
- Security groups — proper network segmentation between ALB, service, and data tiers.
- Private subnets — ECS tasks in private subnets with NAT egress.
See each primitive's README for per-module compliance extension points.
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment (minimal Fargate, no ALB):
# Simple microservice deployment (minimal Fargate, no ALB)
uses: acdl/pipelines/deploy.yaml@v1.6
module: microservice
environment: dev
inputs:
bucket_name: my-microservice-demo
region: us-east-1
image: public.ecr.aws/docker/library/nginx:latest
port: 80
Complex
A production deployment with optional inputs (ALB + env vars + health check):
# Complex microservice with ALB + env vars + health check
uses: acdl/pipelines/deploy.yaml@v1.6
module: microservice
environment: dev
inputs:
bucket_name: my-production-microservice
region: us-east-1
image: public.ecr.aws/docker/library/nginx:latest
port: 8080
env:
LOG_LEVEL: info
ENVIRONMENT: production
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.