4bd07a4fae
Add modules/<name>/examples/ directories with simple.yaml + complex.yaml (+ mysql.yaml for RDS) for every primitive and module pattern. All 25 example contracts validate against schemas/contract.schema.json. Update the contract schema to allow object/array input values (for env vars). Fix the platform-test schema-validation glob to modules/*/*/examples/*.yaml to match the nested l1/l2 path structure. Update the microservice sample contract note (env objects now permitted by the schema). ---ci--- project: acdl phase: 27 milestone: v1.7 status: execute ---/ci---
vpc — VPC with subnets and routing
Module kind: primitive | Version: 1.0.0
A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids.
Resources
| Resource | Type | Purpose |
|---|---|---|
| vpc | aws_vpc |
The VPC itself |
| subnet | aws_subnet |
One subnet per availability zone |
| route_table | aws_route_table |
Route table with default route 0.0.0.0/0 |
| internet_gateway | aws_internet_gateway |
IGW for public internet access |
| route_table_association | aws_route_table_association |
Binds subnet to route table |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
cidr |
string | yes | — | VPC CIDR block, e.g. 10.0.0.0/16 |
azs |
string | yes | — | Comma-separated availability zones, e.g. us-east-1a,us-east-1b |
name |
string | yes | — | Name tag for the VPC and child resources |
region |
string | yes | — | AWS region the VPC is created in |
Outputs
| Name | Type | Description |
|---|---|---|
vpc_id |
string | The VPC id |
subnet_ids |
string | Comma-separated subnet ids |
Usage
{
"id": "vpc",
"type": "aws:ec2:vpc",
"module": "vpc@1.0.0",
"inputs": {
"cidr": "10.0.0.0/16",
"azs": "us-east-1a,us-east-1b",
"name": "acdl-microservice",
"region": "us-east-1"
}
}
The azs input is split on comma; one subnet is created per zone. The
route table gets a default route 0.0.0.0/0 → internet gateway. Other
modules reference subnet_ids for their network placement.
Compliance extension points
- VPC Flow Logs — add
aws_flow_log+ CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT risk logging). - Private subnets + NAT gateway — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, HIPAA network isolation).
- VPC endpoints — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk).
- Security groups — add
aws_security_groupas a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2). - Network ACLs — add
aws_network_aclfor subnet-level segmentation (PCI-DSS 1.3).
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.