fda4564a7f
EXECUTE stage. Fixes the 4-VPC bug: adds a single shared VPC to
terraform/platform, drops the vpc child from the microservice composition
(references the platform VPC via data source), and makes state keys
env-aware (spike/{id}/{env}/terraform.tfstate — stable across lifecycle).
Platform VPC (terraform/platform/main.tf):
- aws_vpc.acdl_shared (10.0.0.0/16) + 2 subnets + IGW + route table + SG
- Outputs: vpc_id, subnet_ids, ecs_security_group_id
Microservice composition (modules/l2/microservice/composition.json):
- Dropped the vpc child (no per-contract VPC ever again).
- Added data_sources block: platform_vpc → terraform_remote_state (platform).
- Wires: vpc.outputs.subnet_ids → platform_vpc.outputs.subnet_ids.
- Wires: platform_vpc.outputs.vpc_id → alb.inputs.vpc_id.
- Wires: platform_vpc.outputs.ecs_security_group_id → service.inputs.security_group.
Contract resolver (core/contract_resolver.py):
- Added environment to the stack instance (stack.environment).
- Added data_sources handling: pseudo-children with outputs but no resources.
- data_sources propagated through fragment merge to the final stack instance.
Adapter (adapters/terraform/adapter.py):
- State key: spike/{stack_name}/{environment}/terraform.tfstate (env-aware).
- Emits data "terraform_remote_state" "platform" block when data_sources present.
- ref:platform_vpc.<output> → data.terraform_remote_state.platform.outputs.<output>.
Tests (tests/test_adapter.py):
- test_adapt_env_aware_state_key: spike/msvc/prod/terraform.tfstate.
- test_adapt_emits_data_source_block: data.terraform_remote_state.platform.
- test_adapt_no_vpc_for_microservice: no resource "aws_vpc" in microservice output.
- Updated existing state key assertion (spike/s3/dev/terraform.tfstate).
Regression: 467 passed, 0 skipped, 5 deselected. run_platform.sh --check-only
passes for both microservice (9 resources, no VPC) and static-assets (5 resources).
---ci---
project: acdl
phase: P58
milestone: v1.11
status: execute
---/ci---
178 lines
6.9 KiB
Python
178 lines
6.9 KiB
Python
"""ACDL Terraform adapter — stateless assembler (v1.11 RESTART, P56a).
|
|
|
|
The adapter is a STATELESS ASSEMBLER. It owns no module content — no resource
|
|
shape, no nested HCL blocks, no defaults, no type-specific logic. It reads
|
|
the registry to find each L1 module's terraform/ dir, then emits a root
|
|
main.tf that instantiates each resource as a `module "<rid>" { source = ... }`
|
|
block with resolved inputs and wired refs.
|
|
|
|
Engine-specific knowledge (resource type, arg names, nested blocks, defaults)
|
|
lives in the per-module terraform/ subdir (versions/variables/locals/main/
|
|
outputs.tf), NOT in this file. interface.json stays engine-agnostic.
|
|
|
|
CLI: adapter.py <instance.json> <out_dir>
|
|
"""
|
|
|
|
import json
|
|
import os
|
|
import sys
|
|
|
|
|
|
def _load_registry(repo_root):
|
|
"""Load registry.json → {module_name: terraform_dir}."""
|
|
with open(os.path.join(repo_root, "modules", "registry.json")) as fh:
|
|
registry = json.load(fh)
|
|
terraform_dirs = {}
|
|
for name, versions in registry.items():
|
|
latest = versions.get("1.0.0", {})
|
|
if "terraform_dir" in latest:
|
|
terraform_dirs[name] = latest["terraform_dir"]
|
|
return terraform_dirs
|
|
|
|
|
|
def _module_name(resource):
|
|
"""Extract the module name from a resource's `module` field (e.g. s3@1.0.0 → s3)."""
|
|
return resource.get("module", "").split("@")[0]
|
|
|
|
|
|
def _ref_expr(value, data_source_names=None):
|
|
"""Translate a `ref:<rid>.<output>` string to a Terraform interpolation.
|
|
|
|
For module resources: `module.<rid>.<output>`.
|
|
For data sources (platform-owned): `data.terraform_remote_state.platform.outputs.<output>`.
|
|
Returns None if the value is not a ref."""
|
|
if not isinstance(value, str) or not value.startswith("ref:"):
|
|
return None
|
|
body = value[len("ref:"):]
|
|
rid, out_name = body.split(".", 1)
|
|
if data_source_names and rid in data_source_names:
|
|
return f"data.terraform_remote_state.platform.outputs.{out_name}"
|
|
return f"module.{rid}.{out_name}"
|
|
|
|
|
|
def _tf_value(value, data_source_names=None):
|
|
"""Render a Python value as a Terraform expression fragment."""
|
|
if isinstance(value, bool):
|
|
return "true" if value else "false"
|
|
if isinstance(value, (int, float)) and not isinstance(value, bool):
|
|
return str(value)
|
|
if isinstance(value, str):
|
|
ref = _ref_expr(value, data_source_names)
|
|
if ref is not None:
|
|
return ref
|
|
stripped = value.lstrip()
|
|
if stripped and stripped[0] in "{[":
|
|
try:
|
|
parsed = json.loads(value)
|
|
if isinstance(parsed, (dict, list)):
|
|
return f"jsonencode({json.dumps(parsed, sort_keys=True)})"
|
|
except json.JSONDecodeError:
|
|
pass
|
|
return f'"{value}"'
|
|
if isinstance(value, (dict, list)):
|
|
return f"jsonencode({json.dumps(value, sort_keys=True)})"
|
|
raise ValueError(f"unsupported input value type {type(value).__name__}")
|
|
|
|
|
|
def _emit_module_block(resource, terraform_dirs, repo_root, data_source_names=None):
|
|
"""Emit a `module "<rid>" { source = ... ... }` block for one resource."""
|
|
rid = resource["id"]
|
|
name = _module_name(resource)
|
|
tf_dir = terraform_dirs.get(name)
|
|
if not tf_dir:
|
|
raise ValueError(f"no terraform_dir in registry for module '{name}' (resource {rid})")
|
|
source_path = os.path.join(repo_root, tf_dir)
|
|
lines = [f'module "{rid}" {{', f' source = "{source_path}"']
|
|
for in_name, value in resource.get("inputs", {}).items():
|
|
if in_name == "region":
|
|
continue
|
|
lines.append(f" {in_name} = {_tf_value(value, data_source_names)}")
|
|
lines.append("}")
|
|
return "\n".join(lines)
|
|
|
|
|
|
def _emit_root_output(out_name, rid, module_output_name):
|
|
"""Emit a root output wiring a module output to a stack output."""
|
|
return f'output "{out_name}" {{\n value = module.{rid}.{module_output_name}\n}}'
|
|
|
|
|
|
def adapt(stack_instance, out_dir):
|
|
"""Emit main.tf + terraform.tf + providers.tf to out_dir for the stack instance."""
|
|
os.makedirs(out_dir, exist_ok=True)
|
|
repo_root = os.path.dirname(os.path.dirname(os.path.dirname(os.path.abspath(__file__))))
|
|
terraform_dirs = _load_registry(repo_root)
|
|
|
|
stack = stack_instance.get("stack", {})
|
|
resources = stack_instance.get("resources", [])
|
|
stack_outputs = stack_instance.get("outputs", {})
|
|
|
|
# --- providers.tf: aws provider, region from the first resource's inputs.region ---
|
|
region = "us-east-1"
|
|
for r in resources:
|
|
if "region" in r.get("inputs", {}):
|
|
region = r["inputs"]["region"]
|
|
break
|
|
providers_tf = f'provider "aws" {{\n region = "{region}"\n}}\n'
|
|
|
|
# --- terraform.tf: required_version + required_providers + S3 backend ---
|
|
stack_name = stack.get("name", "spike")
|
|
environment = stack.get("environment", "dev")
|
|
terraform_tf = (
|
|
'terraform {\n'
|
|
' required_version = ">= 1.9, < 1.10"\n'
|
|
' required_providers {\n'
|
|
' aws = {\n'
|
|
' source = "hashicorp/aws"\n'
|
|
' version = "~> 5.0"\n'
|
|
' }\n'
|
|
' }\n'
|
|
' backend "s3" {\n'
|
|
' bucket = "acdl-tfstate-581513795199-us-east-1"\n'
|
|
f' key = "spike/{stack_name}/{environment}/terraform.tfstate"\n'
|
|
' region = "us-east-1"\n'
|
|
' }\n'
|
|
'}\n'
|
|
)
|
|
|
|
# --- data sources: emit terraform_remote_state for platform-owned resources ---
|
|
data_source_names = stack_instance.get("data_sources", [])
|
|
data_blocks = []
|
|
if data_source_names:
|
|
data_blocks.append(
|
|
'data "terraform_remote_state" "platform" {\n'
|
|
' backend = "s3"\n'
|
|
' config = {\n'
|
|
' bucket = "acdl-tfstate-581513795199-us-east-1"\n'
|
|
' key = "platform/terraform.tfstate"\n'
|
|
' region = "us-east-1"\n'
|
|
' }\n'
|
|
'}\n'
|
|
)
|
|
|
|
# --- main.tf: data blocks + module instantiations + root outputs ---
|
|
parts = list(data_blocks)
|
|
parts.extend(_emit_module_block(r, terraform_dirs, repo_root, set(data_source_names)) for r in resources)
|
|
for out_name, out_spec in stack_outputs.items():
|
|
if isinstance(out_spec, dict) and "from" in out_spec:
|
|
rid = out_spec["from"]
|
|
mod_out = out_spec.get("output", out_name)
|
|
parts.append(_emit_root_output(out_name, rid, mod_out))
|
|
main_tf = "\n\n".join(parts) + "\n"
|
|
|
|
with open(os.path.join(out_dir, "main.tf"), "w") as fh:
|
|
fh.write(main_tf)
|
|
with open(os.path.join(out_dir, "terraform.tf"), "w") as fh:
|
|
fh.write(terraform_tf)
|
|
with open(os.path.join(out_dir, "providers.tf"), "w") as fh:
|
|
fh.write(providers_tf)
|
|
return out_dir
|
|
|
|
|
|
if __name__ == "__main__":
|
|
if len(sys.argv) != 3:
|
|
print("usage: adapter.py <instance.json> <out_dir>", file=sys.stderr)
|
|
sys.exit(2)
|
|
with open(sys.argv[1], "r") as fh:
|
|
stack = json.load(fh)
|
|
adapt(stack, sys.argv[2])
|
|
print(f"adapter: emitted terraform to {sys.argv[2]}", file=sys.stderr) |