Jon Chery a003168b3a docs(P08): create Phase 08 plan (aws-bootstrap)
---ci---
project: acdl
phase: 8
milestone: v1.1
status: plan
plan:
  waves: 5
  tasks: 8
  requirements: [REQ-23]
---/ci---

Phase 08 plan authored by ci-planner. 5 waves:
- Wave 1 (security): T-8.1 spike_runner_policy.json (least-privilege)
- Wave 2 (platform): T-8.2/T-8.3 create_state_backend.py, T-8.4 create_iam_user.py
- Wave 3 (platform): T-8.5 rotate_spike_key.sh
- Wave 4 (lead): T-8.6 verify_phase08.sh, T-8.7 README + .gitignore
- Wave 5 (lead, EXECUTE-only): T-8.8 run bootstrap against AWS + D-034 closure

7 authored files. Key decisions: D-P08-1 (one DynamoDB table acdl-outbox
for both lock + outbox), D-P08-2 (IAM user acdl-spike-runner not OIDC
role; OIDC deferred to v1.2 per D-039), D-P08-3 (Wave 5 EXECUTE-only),
D-P08-4 (optional Gitea secret upload), D-P08-5 (initial key is
throwaway).

Security: root key via env vars only (never committed); .env.secrets
gitignored; IAM policy explicit Deny-everything-else; D-034 closure =
user manually rotates root key post-phase.
2026-07-21 18:57:31 +00:00

ACDL — Agentic Cloud Delivery Platform

Consumers declare intent; the platform delivers safe production deployment through an agentic stack — automatically, safely, and with a complete audit trail. A merged change progresses through lower environments end-to-end without a platform engineer joining a thread; a non-technical consumer ships a production deployment by declaring intent, without authoring a workflow, a configuration file, or a Terraform module.

Status

  • v1.1 (active): architecture finalization + v1 spike. Finalize the architecture to v1.0 (resolve the 11 open design decisions) and prove the locked commitments with one end-to-end implementation spike (l1-s3 + l2-static-asset + Terraform adapter → real terraform plan against AWS).
  • v1.0 demo (complete, archived): tag v1.1.0. The 30-minute stub-driven executive demo is preserved under demo/ as the intent reference; it is not the platform.

Repository layout

Path Purpose Populated
acdl_platform/ Platform code: confidence signal, contract resolver, outbox, HITL/ledger designs (renamed from platform/ in Phase 08 to avoid shadowing the stdlib platform module) Phase 07+
schemas/ JSON Schemas: IR, PolicyCheckResult, contract Phase 07
adapters/ Substrate adapters (Terraform adapter in v1; the only substrate-specific code per §12) Phase 09
terraform/ State backend + provider config (S3 state + DynamoDB lock) Phase 08+
modules-ir/ IR-typed L1/L2 modules (l1-s3, l2-static-asset) Phase 0910
scripts/ v1.1 verify scripts (verify_phaseNN.sh) Phase 06+
demo/ Archived v1.0 executive demo (tag v1.1.0); runs locally via demo/scripts/run_demo.sh --no-upload complete
.ciagent/ CIAgent metadata (plans, decisions, personas, roadmap, research) active
docs/ Upstream vision + architecture sources active

Running the archived demo

The v1.0 demo is an archived artifact. To re-run it locally:

bash demo/scripts/run_demo.sh --no-upload

The demo deck is at demo/ACDL_DEMO.md. The demo runs entirely on local stubs — no AWS, no AI — and shows intent and safety behavior rather than provisioning real cloud resources. It is the reference of intent for the real platform; it is not the platform itself.

S
Description
Nova — The New Dawn of DevSecOps. Autonomous infrastructure delivery: consumers declare intent, the platform ships safely with an immutable audit trail.
Readme 69 MiB
Languages
Python 87.2%
Shell 8.6%
HCL 4.2%