Files
acdl/modules/l1/alb
Jon Chery 4dad967910
acdl-ci / Lint (pull_request) Successful in 7s
acdl-ci / Platform check-only (offline) (pull_request) Successful in 21s
acdl-modules-lifecycle / CI VPC apply (pull_request) Successful in 39s
acdl-ci / Test (pull_request) Successful in 4m18s
acdl-modules-lifecycle / L1 lifecycle (alb) (pull_request) Failing after 1m4s
acdl-modules-lifecycle / L1 lifecycle (cloudfront) (pull_request) Successful in 8m51s
acdl-modules-lifecycle / L1 lifecycle (ecr) (pull_request) Successful in 2m37s
acdl-modules-lifecycle / L1 lifecycle (ecs-cluster) (pull_request) Successful in 3m0s
acdl-modules-lifecycle / L1 lifecycle (iam-role) (pull_request) Successful in 2m43s
acdl-modules-lifecycle / L1 lifecycle (ecs-service) (pull_request) Successful in 4m4s
acdl-modules-lifecycle / L1 lifecycle (kms-key) (pull_request) Successful in 2m53s
acdl-modules-lifecycle / L1 lifecycle (s3) (pull_request) Successful in 2m48s
acdl-modules-lifecycle / L1 lifecycle (uptime) (pull_request) Successful in 3m45s
acdl-modules-lifecycle / L1 lifecycle (vpc) (pull_request) Successful in 2m46s
acdl-modules-lifecycle / L1 lifecycle (waf) (pull_request) Successful in 3m8s
acdl-modules-lifecycle / L2 lifecycle (microservice) (pull_request) Failing after 54s
acdl-modules-lifecycle / L2 lifecycle (static-assets) (pull_request) Failing after 55s
acdl-modules-lifecycle / L1 lifecycle (rds) (pull_request) Successful in 32m32s
acdl-modules-lifecycle / CI VPC destroy (pull_request) Failing after 20m33s
fix(P60): ALB target group name_prefix — avoid orphaned resource conflicts
The ALB lifecycle test was failing with "ELBv2 Target Group (acdl-ci-alb)
already exists" because a prior failed run left an orphaned target group
in AWS. The deterministic state key means terraform reuses the same state,
but create_before_destroy tries to create a new target group with the same
name before destroying the old one → conflict.

Fix: use name_prefix instead of name for the target group. AWS auto-generates
a unique name (e.g. acdl-ci-alb-2026072812001234567), so create_before_destroy
can create the new target group without conflicting with the orphaned one.
The old orphaned target group is eventually garbage-collected by AWS (or
cleaned up by a future run's destroy step).

This is the standard terraform pattern for create_before_destroy resources
with name uniqueness constraints.

---ci---
project: acdl
phase: P60
milestone: v1.11
status: execute
---/ci---
2026-07-28 20:22:41 +00:00
..

alb — Application Load Balancer (load balancer + target group + listener)

Module kind: primitive | Version: 1.0.0

An Application Load Balancer with a target group and a listener. This is a multi-resource module: it creates a load balancer, a target group, and a listener that forwards traffic to the target group. The target group is what ecs-service registers its tasks with.

Resources

Resource Type Purpose
load_balancer aws_lb Application load balancer in the VPC subnets
target_group aws_lb_target_group Target group for the ECS service tasks
listener aws_lb_listener Listener forwarding the LB port to the target group

Inputs

Name Type Required Default Description
name string yes Name tag for the load balancer and child resources
subnets string yes Comma-separated subnet ids (from vpc)
security_group string yes Security group id for the load balancer
port number no 80 Listener port
protocol string no HTTP Listener protocol
region string yes AWS region the load balancer is created in

Outputs

Name Type Description
lb_arn arn The load balancer ARN
listener_arn arn The listener ARN
target_group_arn arn The target group ARN

Usage

{
  "id": "alb",
  "type": "aws:elbv2:loadbalancer",
  "module": "alb@1.0.0",
  "inputs": {
    "name": "acdl-microservice",
    "subnets": "ref:vpc.subnet_ids",
    "security_group": "ref:roles.role_arn",
    "port": 8080,
    "protocol": "HTTP",
    "region": "us-east-1"
  }
}

The target_group_arn output is referenced by ecs-service as its lb_target_group_arn input to wire the service to the ALB.

Compliance extension points

  • TLS / HTTPS listener — add aws_acm_certificate + ssl_policy + certificate_arn for encryption in transit (SOC2 CC6.1, PCI-DSS 4.1, GDPR Art.32).
  • Access logs — add access_logs { bucket = ..., prefix = ... } to the load balancer (SOX, SOC2 CC7.2, DORA ICT audit trail).
  • Security group rules — add ingress/egress rules restricting traffic to known sources (SOC2 CC6.6, PCI-DSS 1.2).
  • Health check — add a health_check block to the target group (SOC2 CC7.3 monitoring, DORA operational resilience).
  • WAF — add aws_wafv2_web_acl_association for application-layer protection (SOC2 CC7.6, PCI-DSS 6.5, DORA ICT risk).
  • Deregistration delay — add deregistration_delay for graceful draining (SOC2 CC9.1 resilience).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: alb
infrastructure:
  alb:
    inputs:
      name: my-alb
      port: 80
      protocol: HTTP
      region: us-east-1
      security_group: sg-xxx
      subnets: subnet-aaa,subnet-bbb
    version: 1.0.0
name: alb-loadbalancer

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: alb
infrastructure:
  alb:
    inputs:
      name: my-production-alb
      port: 443
      protocol: HTTPS
      region: us-east-1
      security_group: sg-xxx
      subnets: subnet-aaa,subnet-bbb
    version: 1.0.0
name: alb-loadbalancer

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.