Files
acdl/modules/l1/s3/README.md
T
Jon Chery 031887ec56 refactor(P57): contract surface redesign + rename + .yml repo-wide
Contract surface redesign:
- New top-level fields: id (3-6 char acronym → stack.name), name (full → stack.title),
  infrastructure (map keyed by module name, replaces module:)
- Drop uses: field (dead reference; version pin lives in CI workflow uses: line)
- Drop top-level module/inputs (now nested under infrastructure map)
- Per-module optional version (defaults to latest published from registry)
- Multi-module contracts: one file deploys N modules in one pipeline run,
  resource IDs namespaced with module name to avoid collisions
- stack.schema.json: add optional title field for display name

Rename:
- pipelines/deploy.yaml → pipelines/contract.yml (declarative spec, not a pipeline)
- pipelines/ci.yaml → pipelines/ci.yml
- All 44 .yaml files → .yml repo-wide (contracts, module examples, kyverno policies)
- .acdl/contract.yaml → .acdl/contract.yml

Resolver (core/contract_resolver.py):
- Rewrite resolve() to loop infrastructure map, default version to latest,
  merge module fragments into one stack with namespaced resource IDs
- _latest_version() picks highest non-deprecated from registry
- _namespace_resources() prefixes IDs + rewrites ref: expressions for multi-module
- Single-module path: unprefixed IDs (backward compatible)

Verification:
- 494 tests pass (0 contract-shape failures)
- Local E2E passes (contract → resolver → adapter → local ECS HTTP 200 → outbox)

---ci---
project: acdl
phase: 57
milestone: v1.10.2
status: execute
---/ci---
2026-07-27 21:37:40 +00:00

3.0 KiB

s3 — S3 bucket

Module kind: primitive | Version: 1.0.0

A single S3 bucket for object storage. The simplest module — one resource, two inputs, two outputs. Versioning is enabled by default.

Resources

Resource Type Purpose
bucket aws_s3_bucket The S3 bucket itself

Inputs

Name Type Required Default Description
bucket_name string yes Globally-unique S3 bucket name
region string yes AWS region the bucket is created in

Outputs

Name Type Description
bucket_arn arn The S3 bucket ARN
bucket_name string The bucket name (echoes the input)

NFRs

Name Type Default Description
versioning boolean true Enable S3 versioning

Usage

{
  "id": "s3",
  "type": "aws:s3:bucket",
  "module": "s3@1.0.0",
  "inputs": {
    "bucket_name": "acdl-spike-bucket",
    "region": "us-east-1"
  }
}

A concrete instance is at instance.json (used by the platform pipeline as the regression baseline).

Compliance extension points

  • Encryption at rest — add aws_s3_bucket_server_side_encryption_configuration with a customer-managed KMS key (SOC2 CC6.1, GDPR Art.32).
  • Object Lock — add aws_s3_bucket_object_lock_configuration in compliance mode with 7-year retention for immutable evidence (SOX §802, DORA audit trail).
  • Access logging — add aws_s3_bucket_logging to a target logging bucket (SOC2 CC7.2).
  • Public access block — add aws_s3_bucket_public_access_block to prevent data exfiltration (SOC2 CC6.1, GDPR Art.32).
  • Lifecycle policy — add aws_s3_bucket_lifecycle_configuration for retention enforcement (GDPR Art.5(2).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: s3a
infrastructure:
  s3:
    inputs:
      bucket_name: my-simple-bucket
      region: us-east-1
    version: 1.0.0
name: s3-bucket

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: s3a
infrastructure:
  s3:
    inputs:
      bucket_name: my-production-bucket
      region: us-east-1
    version: 1.0.0
name: s3-bucket

Note: the s3 primitive's compliance extensions (Object Lock, access logging, public access block, lifecycle policy) are documented in the Compliance extension points section above but not yet wired as inputs. The complex example uses the same inputs as the simple example; compliance extensions are roadmap.

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.