Files
acdl/modules
Jon Chery 38b51f3e6d feat(P4): regression-gate policies + docs (REQ-304..307)
regression/ policies (3): cap-013-adapter-dedup, cap-023-metrics-collector,
cap-024-deck-structure — declarative mirrors of core/regression_verify.py
over capability-inventory JSON. The imperative regression_verify.py is kept
(drives CI gate); the policies are the declarative mirror (IDEATE I1 quality
improvement).

tests: test_regression_policies.py + clean/drifted fixtures. Skip-without-kj.

docs: adapters/README.md (new kyverno-json row + PolicyEngine Protocol
section with how-to-add-OpaEngine), adapters/kyverno-json/README.md (engine,
install, policy directory layout, 4 categories, severity convention),
schemas/README.md (D-116 engine enum reuse note), modules/STANDARDS.md §10
Policy Authoring Standard, docs/METRICS.md (swappable engine narrative).

---ci---
project: acdl
phase: 4
milestone: v1.25
status: execute
phase_role: execution
requirements:
  covered: [REQ-304, REQ-305, REQ-306, REQ-307]
  partial: []
---/ci---
2026-08-12 18:42:55 +00:00
..

Nova Modules

Reusable building blocks for cloud infrastructure. Each module is self-documented with a README.md following the template.

How the modules work

There are two kinds of module:

  • Primitives — a single cloud resource or a small group of related resources (e.g. a VPC with subnets and routing). Each primitive has an interface.json declaring its inputs and outputs, and a README.md in plain language.
  • Modules — a pattern that references multiple primitives to deploy a complete stack (e.g. an ECS Fargate microservice). Each module has a composition.json declaring its children and wires.

The engine adapter (adapters/terraform/adapter.py) compiles a module instance to infrastructure. Each module's README documents which resources it creates.

Primitives

Module What it creates README
s3 aws_s3_bucket — a single S3 bucket README
vpc aws_vpc + aws_subnet + aws_route_table + aws_internet_gateway — VPC with subnets and routing README
ecs-cluster aws_ecs_cluster — ECS Fargate cluster README
ecs-service aws_ecs_task_definition + aws_ecs_service — Fargate service with task definition README
iam-role aws_iam_role — IAM role with assume-role policy README
alb aws_lb + aws_lb_target_group + aws_lb_listener — Application Load Balancer README
ecr aws_ecr_repository — ECR container image repository README
cloudfront aws_cloudfront_distribution + aws_cloudfront_origin_access_control — CloudFront distribution with S3 origin via OAC README
waf aws_wafv2_web_acl — WAFv2 Web ACL (CloudFront-scoped) README
rds aws_db_instance — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support README
kms-key aws_kms_key — Customer-managed KMS key with rotation enabled (per-stack CMK) README
uptime aws_ecs_service — Uptime-kuma monitoring on ECS Fargate with alert channels README

Modules

Module What it references README
microservice 6 primitives (vpc, cluster, ecr, iam-role, alb, ecs-service) README
static-assets 3 primitives (s3, cloudfront, waf) README

Registry

Module versions are tracked in registry.json. Both primitives and modules are registered.

Template

New modules should use README-TEMPLATE.md as their starting point.

Module patterns (roadmap)

The current composition.json mechanism is a thin pattern layer. A future redesign will let a consumer dynamically create a module directly from the contract file (an agentic "composition" flow). That is on the roadmap, not implemented today.