Files
acdl/modules/l1/cloudfront
Jon Chery 90be5839ab feat(P26): 3 platform pipelines + release job with semver/tag updates
Phase 26 — platform-pipelines-and-release-automation:

- platform-test.yml: PR pipeline (lint + unit-test + integration-test +
  schema-validation) replacing ci.yml for PRs; integration-test runs
  run_platform.sh --check-only for every contracts/*.yaml
- primitives-plan.yml: PR pipeline with matrix over all 9 L1 primitives
  (s3, vpc, ecs-cluster, ecs-service, iam-role, alb, ecr, cloudfront, waf)
- patterns-plan.yml: PR pipeline with matrix over all 2 L2 modules
  (static-assets, microservice)
- release.yml: push-to-main pipeline computing next semver tag (PATCH for
  regular phases, MINOR for milestone completions), updating floating
  MAJOR.MINOR + MAJOR tags, and creating GitHub releases
- run_primitive_plan.sh: plan-only/check-only runner for a single L1
  primitive (adapter compile + structure validation offline)
- run_pattern_plan.sh: plan-only/check-only runner for a single L2 pattern
  (environment check + contract validate + resolve + adapter + structure
  validation offline)
- contracts/microservice.yaml: sample consumer contract for the
  microservice L2 module (schema-compliant scalar inputs)
- instance.json for 8 L1 primitives (vpc, ecs-cluster, ecs-service,
  iam-role, alb, ecr, cloudfront, waf) so the primitives-plan matrix can
  run the adapter offline; s3 already had one
- tests/test_release_logic.py: unit test for semver computation
  (PATCH bump, MINOR bump on milestone, floating tag format)
- tests/test_pipeline_contract.py: 19 new tests validating the 4 platform
  workflows exist and conform (stages, matrices, triggers, permissions)

DEVIATION: The microservice pattern (run_pattern_plan.sh --check-only
microservice + run_platform.sh --check-only contracts/microservice.yaml)
fails at the adapter stage due to a pre-existing resolver ref-id mismatch
for multi-resource L1s (resolver emits ref:vpc.subnet_ids but the expanded
resource id is vpc-subnet). This predates Phase 26 and is out of scope for
pipeline automation; the static-assets pattern passes end-to-end. The
microservice contract is schema-valid and resolves correctly (11
resources); only the adapter compilation of multi-resource L1 refs fails.

VERIFICATION:
- bash scripts/run_ci.sh: PASS (lint + test + check-only)
- python3 -m pytest tests/ -v: 266 passed
- bash scripts/run_primitive_plan.sh --check-only s3: PASS
- bash scripts/run_pattern_plan.sh --check-only static-assets: PASS
- All 9 primitives pass run_primitive_plan.sh --check-only
- All instance.json validate against stack.schema.json

---ci---
project: acdl
phase: 26
milestone: v1.7
status: execute
---/ci---
2026-07-22 20:13:36 +00:00
..

cloudfront — CloudFront distribution

Module kind: primitive | Version: 1.0.0

A CloudFront distribution with an S3 origin via Origin Access Control (OAC). The distribution serves the bucket's static content from the global edge network with HTTPS redirection by default. An optional WAF web ACL can be associated to filter traffic before it reaches the origin.

Resources

Resource Type Purpose
oac aws_cloudfront_origin_access_control Origin Access Control signing the S3 origin
distribution aws_cloudfront_distribution The CloudFront distribution with an S3 origin via OAC

Inputs

Name Type Required Default Description
bucket_regional_domain_name string yes The S3 bucket regional domain name (ref to s3 origin)
price_class string no PriceClass_100 CloudFront price class
viewer_protocol_policy string no redirect-to-https Viewer protocol policy
default_ttl number no 3600 Default TTL in seconds
max_ttl number no 86400 Max TTL in seconds
waf_web_acl_arn string no WAF web ACL ARN to associate (ref to waf)
region string yes AWS region (CloudFront is global but the provider region is used for the OAC)

Outputs

Name Type Description
distribution_arn arn The CloudFront distribution ARN
distribution_domain_name string The CloudFront distribution domain name (e.g. d111111abcdef8.cloudfront.net)
oac_id string The Origin Access Control ID

Usage

{
  "id": "cloudfront",
  "type": "aws:cloudfront:distribution",
  "module": "cloudfront@1.0.0",
  "inputs": {
    "bucket_regional_domain_name": "ref:s3.bucket_regional_domain_name",
    "price_class": "PriceClass_100",
    "viewer_protocol_policy": "redirect-to-https",
    "default_ttl": 3600,
    "max_ttl": 86400,
    "waf_web_acl_arn": "ref:waf.web_acl_arn",
    "region": "us-east-1"
  }
}

The bucket_regional_domain_name and waf_web_acl_arn inputs are typically wired as ref: expressions from the s3 and waf primitives inside a module composition (see modules/l2/static-assets).

Compliance extension points

  • TLS/HTTPS — viewer protocol policy defaults to redirect-to-https; a custom ACM certificate + viewer_certificate block can pin TLS to a customer domain (SOC2 CC6.1, GDPR Art.32).
  • Geo restriction — the restrictions.geo_restriction block can whitelist/blacklist countries for data-residency compliance (GDPR Art.44, SOC2 CC6.1).
  • Logging — CloudFront access logs to an S3 bucket for auditability (SOC2 CC7.2, DORA audit trail).
  • Field-level encryption — add field-level encryption for PII fields in POST bodies (HIPAA §164.312(a)(2)(iv), GDPR Art.32).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.