0ca383dae6
Create run_codegen.sh (pre-TF: env check, validate, resolve, adapt). Create run_postapply.sh (post-TF: Checkov, confidence, HITL, outbox, SSM, uptime). Add variable 'enabled' (bool, default true) + count=var.enabled?1:0 to all 12 L1 modules (alb, cloudfront, ecr, ecs-cluster, ecs-service, iam-role, kms-key, rds, s3, uptime, vpc, waf). Fix all cross-resource references with [0] indexing. Update interface.json for all modules to declare 'enabled' input. Fix stale artifact path /tmp/acdl_platform_run_v18 → /tmp/nova_platform_run (REQ-238). run_platform.sh remains as backward-compat shim for local-dev usage. ---ci--- project: acdl phase: 4 milestone: v1.20 status: execute requirements: [REQ-233, REQ-234, REQ-235, REQ-236, REQ-237, REQ-238] ---/ci---
22 lines
616 B
Terraform
22 lines
616 B
Terraform
locals {
|
|
encryption_config = var.kms_key_arn != null ? {
|
|
encryption_type = "KMS"
|
|
kms_key = var.kms_key_arn
|
|
} : null
|
|
}
|
|
|
|
resource "aws_ecr_repository" "this" {
|
|
count = var.enabled ? 1 : 0
|
|
name = var.name
|
|
image_tag_mutability = "MUTABLE"
|
|
image_scanning_configuration {
|
|
scan_on_push = true
|
|
}
|
|
dynamic "encryption_configuration" {
|
|
for_each = local.encryption_config != null ? [local.encryption_config] : []
|
|
content {
|
|
encryption_type = encryption_configuration.value.encryption_type
|
|
kms_key = encryption_configuration.value.kms_key
|
|
}
|
|
}
|
|
} |