031887ec56
Contract surface redesign: - New top-level fields: id (3-6 char acronym → stack.name), name (full → stack.title), infrastructure (map keyed by module name, replaces module:) - Drop uses: field (dead reference; version pin lives in CI workflow uses: line) - Drop top-level module/inputs (now nested under infrastructure map) - Per-module optional version (defaults to latest published from registry) - Multi-module contracts: one file deploys N modules in one pipeline run, resource IDs namespaced with module name to avoid collisions - stack.schema.json: add optional title field for display name Rename: - pipelines/deploy.yaml → pipelines/contract.yml (declarative spec, not a pipeline) - pipelines/ci.yaml → pipelines/ci.yml - All 44 .yaml files → .yml repo-wide (contracts, module examples, kyverno policies) - .acdl/contract.yaml → .acdl/contract.yml Resolver (core/contract_resolver.py): - Rewrite resolve() to loop infrastructure map, default version to latest, merge module fragments into one stack with namespaced resource IDs - _latest_version() picks highest non-deprecated from registry - _namespace_resources() prefixes IDs + rewrites ref: expressions for multi-module - Single-module path: unprefixed IDs (backward compatible) Verification: - 494 tests pass (0 contract-shape failures) - Local E2E passes (contract → resolver → adapter → local ECS HTTP 200 → outbox) ---ci--- project: acdl phase: 57 milestone: v1.10.2 status: execute ---/ci---
248 lines
7.5 KiB
Python
248 lines
7.5 KiB
Python
"""P1-1: adapter ECS/ALB/VPC defaults are parameterized via L1 interface.json
|
|
inputs (REQ-102, D-085). The adapter is a thin translator — defaults live in
|
|
the interface, not the adapter.
|
|
"""
|
|
import json
|
|
import os
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
import yaml
|
|
|
|
ROOT = Path(__file__).resolve().parent.parent
|
|
sys.path.insert(0, str(ROOT))
|
|
|
|
from adapters.terraform.adapter import adapt
|
|
from core.contract_resolver import resolve
|
|
|
|
|
|
def _load_ir(path):
|
|
with open(path) as f:
|
|
return json.load(f)
|
|
|
|
|
|
def _tf_for_contract(contract_dict, tmp_path):
|
|
"""Resolve a contract dict to a stack, emit TF, return the main.tf text."""
|
|
contract_path = tmp_path / "contract.yaml"
|
|
contract_path.write_text(yaml.safe_dump(contract_dict))
|
|
stack = resolve(str(contract_path))
|
|
out_dir = tmp_path / "tf"
|
|
adapt(stack, str(out_dir))
|
|
return (out_dir / "main.tf").read_text()
|
|
|
|
|
|
def test_desired_count_override_emits_overridden_value(tmp_path):
|
|
"""An L1 with desired_count: 3 in contract inputs emits desired_count = 3."""
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
"desired_count": 3,
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert "desired_count = 3" in tf
|
|
assert "desired_count = 1" not in tf
|
|
|
|
|
|
def test_desired_count_default_emits_one_via_interface(tmp_path):
|
|
"""Absent desired_count emits desired_count = 1 via interface default."""
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert "desired_count = 1" in tf
|
|
|
|
|
|
def test_launch_type_override_emits_overridden_value(tmp_path):
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
"launch_type": "EC2",
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert 'launch_type = "EC2"' in tf
|
|
assert 'launch_type = "FARGATE"' not in tf
|
|
|
|
|
|
def test_target_type_override_emits_overridden_value(tmp_path):
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
"target_type": "instance",
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert 'target_type = "instance"' in tf
|
|
assert 'target_type = "ip"' not in tf
|
|
|
|
|
|
def test_load_balancer_type_override_emits_overridden_value(tmp_path):
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
"load_balancer_type": "network",
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert 'load_balancer_type = "network"' in tf
|
|
assert 'load_balancer_type = "application"' not in tf
|
|
|
|
|
|
def test_family_override_emits_overridden_value(tmp_path):
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
"family": "myservice",
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert 'family = "myservice"' in tf
|
|
|
|
|
|
def test_family_default_emits_app(tmp_path):
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert 'family = "app"' in tf
|
|
|
|
|
|
def test_v1_1_s3_regression_still_passes(tmp_path):
|
|
"""The v1.1 S3 regression: the static-assets L1 (s3-only) must still
|
|
produce valid Terraform with no ECS/ALB/VPC defaults leaking in."""
|
|
contract_path = ROOT / "contracts" / "static-assets.yml"
|
|
stack = resolve(str(contract_path))
|
|
out_dir = tmp_path / "tf"
|
|
adapt(stack, str(out_dir))
|
|
tf = (out_dir / "main.tf").read_text()
|
|
assert "aws_s3_bucket" in tf
|
|
assert "desired_count" not in tf
|
|
assert "launch_type" not in tf
|
|
assert "target_type" not in tf
|
|
|
|
|
|
def test_no_hardcoded_microservice_name_in_route_table(tmp_path):
|
|
"""The hardcoded 'acdl-microservice-rt' / 'acdl-microservice-igw' Name
|
|
tags are removed (D-085); the name derives from the VPC name input."""
|
|
contract = {
|
|
"id": "msvc",
|
|
"name": "microservice-test",
|
|
"environment": "dev",
|
|
"infrastructure": {
|
|
"microservice": {
|
|
"version": "1.0.0",
|
|
"inputs": {
|
|
"bucket_name": "acdl-test",
|
|
"region": "us-east-1",
|
|
"image": "public.ecr.aws/docker/library/nginx:latest",
|
|
"port": 80,
|
|
},
|
|
}
|
|
}
|
|
}
|
|
tf = _tf_for_contract(contract, tmp_path)
|
|
assert "acdl-microservice-rt" not in tf
|
|
assert "acdl-microservice-igw" not in tf
|
|
|
|
|
|
def test_ecs_service_interface_has_parameterized_inputs():
|
|
"""The L1 interface declares the inputs (the adapter reads them)."""
|
|
iface = _load_ir(ROOT / "modules" / "l1" / "ecs-service" / "interface.json")
|
|
inputs = iface["inputs"]
|
|
assert "desired_count" in inputs
|
|
assert inputs["desired_count"]["default"] == 1
|
|
assert "launch_type" in inputs
|
|
assert inputs["launch_type"]["default"] == "FARGATE"
|
|
assert "family" in inputs
|
|
assert inputs["family"]["default"] == "app"
|
|
|
|
|
|
def test_alb_interface_has_parameterized_inputs():
|
|
iface = _load_ir(ROOT / "modules" / "l1" / "alb" / "interface.json")
|
|
inputs = iface["inputs"]
|
|
assert "load_balancer_type" in inputs
|
|
assert inputs["load_balancer_type"]["default"] == "application"
|
|
assert "target_type" in inputs
|
|
assert inputs["target_type"]["default"] == "ip" |