Files
acdl/modules/l1/ecr
Jon Chery 90be5839ab feat(P26): 3 platform pipelines + release job with semver/tag updates
Phase 26 — platform-pipelines-and-release-automation:

- platform-test.yml: PR pipeline (lint + unit-test + integration-test +
  schema-validation) replacing ci.yml for PRs; integration-test runs
  run_platform.sh --check-only for every contracts/*.yaml
- primitives-plan.yml: PR pipeline with matrix over all 9 L1 primitives
  (s3, vpc, ecs-cluster, ecs-service, iam-role, alb, ecr, cloudfront, waf)
- patterns-plan.yml: PR pipeline with matrix over all 2 L2 modules
  (static-assets, microservice)
- release.yml: push-to-main pipeline computing next semver tag (PATCH for
  regular phases, MINOR for milestone completions), updating floating
  MAJOR.MINOR + MAJOR tags, and creating GitHub releases
- run_primitive_plan.sh: plan-only/check-only runner for a single L1
  primitive (adapter compile + structure validation offline)
- run_pattern_plan.sh: plan-only/check-only runner for a single L2 pattern
  (environment check + contract validate + resolve + adapter + structure
  validation offline)
- contracts/microservice.yaml: sample consumer contract for the
  microservice L2 module (schema-compliant scalar inputs)
- instance.json for 8 L1 primitives (vpc, ecs-cluster, ecs-service,
  iam-role, alb, ecr, cloudfront, waf) so the primitives-plan matrix can
  run the adapter offline; s3 already had one
- tests/test_release_logic.py: unit test for semver computation
  (PATCH bump, MINOR bump on milestone, floating tag format)
- tests/test_pipeline_contract.py: 19 new tests validating the 4 platform
  workflows exist and conform (stages, matrices, triggers, permissions)

DEVIATION: The microservice pattern (run_pattern_plan.sh --check-only
microservice + run_platform.sh --check-only contracts/microservice.yaml)
fails at the adapter stage due to a pre-existing resolver ref-id mismatch
for multi-resource L1s (resolver emits ref:vpc.subnet_ids but the expanded
resource id is vpc-subnet). This predates Phase 26 and is out of scope for
pipeline automation; the static-assets pattern passes end-to-end. The
microservice contract is schema-valid and resolves correctly (11
resources); only the adapter compilation of multi-resource L1 refs fails.

VERIFICATION:
- bash scripts/run_ci.sh: PASS (lint + test + check-only)
- python3 -m pytest tests/ -v: 266 passed
- bash scripts/run_primitive_plan.sh --check-only s3: PASS
- bash scripts/run_pattern_plan.sh --check-only static-assets: PASS
- All 9 primitives pass run_primitive_plan.sh --check-only
- All instance.json validate against stack.schema.json

---ci---
project: acdl
phase: 26
milestone: v1.7
status: execute
---/ci---
2026-07-22 20:13:36 +00:00
..

ecr — ECR repository

Module kind: primitive | Version: 1.0.0

A single ECR repository that hosts the container image for the ECS task. The simplest container-registry module — one resource, two inputs, two outputs.

Resources

Resource Type Purpose
repository aws_ecr_repository The ECR repository

Inputs

Name Type Required Default Description
name string yes The ECR repository name
region string yes AWS region the repository is created in

Outputs

Name Type Description
repository_url string The ECR repository URL
repository_arn arn The ECR repository ARN

Usage

{
  "id": "ecr",
  "type": "aws:ecr:repository",
  "module": "ecr@1.0.0",
  "inputs": {
    "name": "acdl-microservice",
    "region": "us-east-1"
  }
}

The repository_url output is used to build the image input for ecs-service (e.g. <repository_url>:latest).

Compliance extension points

  • Image scanning — add image_scanning_configuration { scan_on_push = true } for vulnerability scanning (SOC2 CC7.6, DORA ICT risk testing, HIPAA security monitoring).
  • Encryption — add encryption_configuration { encryption_type = "KMS", kms_key = ... } with a customer-managed key (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv), GDPR Art.32).
  • Image tag immutability — add image_tag_mutability = "IMMUTABLE" to prevent tag overwriting (SOX §802, SOC2 CC6.1 integrity, DORA audit integrity).
  • Lifecycle policy — add aws_ecr_lifecycle_policy to enforce image retention / cleanup (GDPR Art.5(2) data minimization, SOC2 CC5.2).
  • Access policy — add a repository policy restricting pull/push to known roles (SOC2 CC6.1, HIPAA §164.308(a)(4)).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.