Files
acdl/modules/l1/waf
Jon Chery 90be5839ab feat(P26): 3 platform pipelines + release job with semver/tag updates
Phase 26 — platform-pipelines-and-release-automation:

- platform-test.yml: PR pipeline (lint + unit-test + integration-test +
  schema-validation) replacing ci.yml for PRs; integration-test runs
  run_platform.sh --check-only for every contracts/*.yaml
- primitives-plan.yml: PR pipeline with matrix over all 9 L1 primitives
  (s3, vpc, ecs-cluster, ecs-service, iam-role, alb, ecr, cloudfront, waf)
- patterns-plan.yml: PR pipeline with matrix over all 2 L2 modules
  (static-assets, microservice)
- release.yml: push-to-main pipeline computing next semver tag (PATCH for
  regular phases, MINOR for milestone completions), updating floating
  MAJOR.MINOR + MAJOR tags, and creating GitHub releases
- run_primitive_plan.sh: plan-only/check-only runner for a single L1
  primitive (adapter compile + structure validation offline)
- run_pattern_plan.sh: plan-only/check-only runner for a single L2 pattern
  (environment check + contract validate + resolve + adapter + structure
  validation offline)
- contracts/microservice.yaml: sample consumer contract for the
  microservice L2 module (schema-compliant scalar inputs)
- instance.json for 8 L1 primitives (vpc, ecs-cluster, ecs-service,
  iam-role, alb, ecr, cloudfront, waf) so the primitives-plan matrix can
  run the adapter offline; s3 already had one
- tests/test_release_logic.py: unit test for semver computation
  (PATCH bump, MINOR bump on milestone, floating tag format)
- tests/test_pipeline_contract.py: 19 new tests validating the 4 platform
  workflows exist and conform (stages, matrices, triggers, permissions)

DEVIATION: The microservice pattern (run_pattern_plan.sh --check-only
microservice + run_platform.sh --check-only contracts/microservice.yaml)
fails at the adapter stage due to a pre-existing resolver ref-id mismatch
for multi-resource L1s (resolver emits ref:vpc.subnet_ids but the expanded
resource id is vpc-subnet). This predates Phase 26 and is out of scope for
pipeline automation; the static-assets pattern passes end-to-end. The
microservice contract is schema-valid and resolves correctly (11
resources); only the adapter compilation of multi-resource L1 refs fails.

VERIFICATION:
- bash scripts/run_ci.sh: PASS (lint + test + check-only)
- python3 -m pytest tests/ -v: 266 passed
- bash scripts/run_primitive_plan.sh --check-only s3: PASS
- bash scripts/run_pattern_plan.sh --check-only static-assets: PASS
- All 9 primitives pass run_primitive_plan.sh --check-only
- All instance.json validate against stack.schema.json

---ci---
project: acdl
phase: 26
milestone: v1.7
status: execute
---/ci---
2026-07-22 20:13:36 +00:00
..

waf — WAFv2 Web ACL

Module kind: primitive | Version: 1.0.0

A WAFv2 Web ACL scoped to CloudFront. It applies managed rule groups by default and can be associated with a CloudFront distribution to filter traffic before it reaches the origin. CloudFront-scoped Web ACLs are always created in us-east-1.

Resources

Resource Type Purpose
webacl aws_wafv2_web_acl WAFv2 Web ACL with managed rules

Inputs

Name Type Required Default Description
name string yes Name of the Web ACL
scope string no cloudfront Scope of the Web ACL (default cloudfront for CloudFront associations)
default_action string no allow Default action (default allow)
rules string no Optional custom rules as JSON (default: managed rules only)
region string yes AWS region (CloudFront-scoped WAF is always us-east-1; the adapter ignores this for cloudfront scope)

Outputs

Name Type Description
web_acl_arn arn The WAF Web ACL ARN

Usage

{
  "id": "waf",
  "type": "aws:wafv2:webacl",
  "module": "waf@1.0.0",
  "inputs": {
    "name": "acdl-static-assets-waf",
    "scope": "cloudfront",
    "default_action": "allow",
    "region": "us-east-1"
  }
}

The web_acl_arn output is typically wired as a ref: expression into the cloudfront primitive's waf_web_acl_arn input inside a module composition (see modules/l2/static-assets).

Compliance extension points

  • Rate limiting — add a rate-based rule to cap requests per IP (SOC2 CC6.1, DORA operational resilience).
  • Geo blocking — add a geo-match statement to block/allow countries for data-residency compliance (GDPR Art.44, SOC2 CC6.1).
  • Custom rules — add custom rule statements for application-specific filtering (e.g. block SQLi/IP allow-lists) (SOC2 CC6.1).
  • Logging — enable WAF access logging to S3/CloudWatch/Kinesis for auditability (SOC2 CC7.2, DORA audit trail).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.