a4b17d0f26
---ci---
project: acdl
phase: 26
milestone: v1.7
status: execute
---/ci---
The microservice pattern (and any L2 referencing multi-resource L1s like
vpc) failed at the adapter stage because the resolver emitted refs using
the child id (e.g. 'vpc') instead of the expanded sub-resource id (e.g.
'vpc-subnet'). The adapter's type_by_id table only knows the sub-resource
ids, so ref:vpc.subnet_ids was an unknown resource id.
Fix:
- contract_resolver.py: child_outputs now maps {outputName -> resourceId}
instead of just the interface outputs dict. For multi-resource L1s, the
ref uses the sub-resource id that produces the output. For single-resource
L1s, the resourceId == childId (unchanged behavior).
- vpc interface.json: the subnet sub-resource output is 'subnet_ids'
(matching the interface-level output name) instead of 'subnet_id'.
- adapter.py OUTPUT_MAP: aws:ec2:subnet now maps both 'subnet_ids' and
'subnet_id' to 'id'.
Verification:
- microservice pattern check-only: PASS (11 resources)
- static-assets pattern check-only: PASS (4 resources)
- platform check-only: PASS
- full test suite: 266 passed
vpc — VPC with subnets and routing
Module kind: primitive | Version: 1.0.0
A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids.
Resources
| Resource | Type | Purpose |
|---|---|---|
| vpc | aws_vpc |
The VPC itself |
| subnet | aws_subnet |
One subnet per availability zone |
| route_table | aws_route_table |
Route table with default route 0.0.0.0/0 |
| internet_gateway | aws_internet_gateway |
IGW for public internet access |
| route_table_association | aws_route_table_association |
Binds subnet to route table |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
cidr |
string | yes | — | VPC CIDR block, e.g. 10.0.0.0/16 |
azs |
string | yes | — | Comma-separated availability zones, e.g. us-east-1a,us-east-1b |
name |
string | yes | — | Name tag for the VPC and child resources |
region |
string | yes | — | AWS region the VPC is created in |
Outputs
| Name | Type | Description |
|---|---|---|
vpc_id |
string | The VPC id |
subnet_ids |
string | Comma-separated subnet ids |
Usage
{
"id": "vpc",
"type": "aws:ec2:vpc",
"module": "vpc@1.0.0",
"inputs": {
"cidr": "10.0.0.0/16",
"azs": "us-east-1a,us-east-1b",
"name": "acdl-microservice",
"region": "us-east-1"
}
}
The azs input is split on comma; one subnet is created per zone. The
route table gets a default route 0.0.0.0/0 → internet gateway. Other
modules reference subnet_ids for their network placement.
Compliance extension points
- VPC Flow Logs — add
aws_flow_log+ CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT risk logging). - Private subnets + NAT gateway — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, HIPAA network isolation).
- VPC endpoints — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk).
- Security groups — add
aws_security_groupas a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2). - Network ACLs — add
aws_network_aclfor subnet-level segmentation (PCI-DSS 1.3).
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.