Two architectural changes: 1. Created terraform/ci-vpc/ — a short-lived VPC for L1 module lifecycle testing, separate from the long-lived platform VPC. Created before VPC-dependent modules (alb, ecs-service, rds, uptime) are tested, destroyed after. Outputs (vpc_id, subnet_ids, sg_id, cluster_arn) are passed to those modules via scripts/run_lifecycle_test.sh + run_lifecycle_destroy.sh wrappers that inject the CI VPC outputs into the example contracts. 2. Updated the workflow to use ci-vpc-apply → lifecycle (with artifact passing) → ci-vpc-destroy (always runs). 8 module-specific fixes: - s3: unique bucket names (acdl-ci-s3a-simple/complex) instead of globally-taken 'my-simple-bucket' - kms-key: alias name with no spaces (locals.tf → alias/acdl-ci-kms) - iam-role: example contract uses role_name (not name, which the interface doesn't declare) - ecs-service: example contract uses family (not name); VPC inputs (cluster_arn, subnets, security_group) injected by CI VPC wrapper - uptime: added subnets, security_group, cluster_arn to interface + module; network_configuration is dynamic (only when subnets provided) - rds: added subnet_ids input + db_subnet_group resource (conditional on subnet_ids being non-empty) - alb: removed hardcoded placeholder sg/subnet values from examples; vpc_id + subnets + security_group injected by CI VPC wrapper - cloudfront: removed invalid placeholder WAF ARN from complex example Regression: 479 passed, 0 skipped, 5 deselected. All 24 example contracts pass --check-only. ---ci--- project: acdl phase: P59 milestone: v1.11 status: execute ---/ci---
cloudfront — CloudFront distribution
Module kind: primitive | Version: 1.0.0
A CloudFront distribution with an S3 origin via Origin Access Control (OAC). The distribution serves the bucket's static content from the global edge network with HTTPS redirection by default. An optional WAF web ACL can be associated to filter traffic before it reaches the origin.
Resources
| Resource | Type | Purpose |
|---|---|---|
oac |
aws_cloudfront_origin_access_control |
Origin Access Control signing the S3 origin |
distribution |
aws_cloudfront_distribution |
The CloudFront distribution with an S3 origin via OAC |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
bucket_regional_domain_name |
string | yes | — | The S3 bucket regional domain name (ref to s3 origin) |
price_class |
string | no | PriceClass_100 |
CloudFront price class |
viewer_protocol_policy |
string | no | redirect-to-https |
Viewer protocol policy |
default_ttl |
number | no | 3600 | Default TTL in seconds |
max_ttl |
number | no | 86400 | Max TTL in seconds |
waf_web_acl_arn |
string | no | — | WAF web ACL ARN to associate (ref to waf) |
region |
string | yes | — | AWS region (CloudFront is global but the provider region is used for the OAC) |
Outputs
| Name | Type | Description |
|---|---|---|
distribution_arn |
arn | The CloudFront distribution ARN |
distribution_domain_name |
string | The CloudFront distribution domain name (e.g. d111111abcdef8.cloudfront.net) |
oac_id |
string | The Origin Access Control ID |
Usage
{
"id": "cloudfront",
"type": "aws:cloudfront:distribution",
"module": "cloudfront@1.0.0",
"inputs": {
"bucket_regional_domain_name": "ref:s3.bucket_regional_domain_name",
"price_class": "PriceClass_100",
"viewer_protocol_policy": "redirect-to-https",
"default_ttl": 3600,
"max_ttl": 86400,
"waf_web_acl_arn": "ref:waf.web_acl_arn",
"region": "us-east-1"
}
}
The bucket_regional_domain_name and waf_web_acl_arn inputs are
typically wired as ref: expressions from the s3 and waf primitives
inside a module composition (see modules/l2/static-assets).
Compliance extension points
- TLS/HTTPS — viewer protocol policy defaults to
redirect-to-https; a custom ACM certificate +viewer_certificateblock can pin TLS to a customer domain (SOC2 CC6.1, GDPR Art.32). - Geo restriction — the
restrictions.geo_restrictionblock can whitelist/blacklist countries for data-residency compliance (GDPR Art.44, SOC2 CC6.1). - Logging — CloudFront access logs to an S3 bucket for auditability (SOC2 CC7.2, DORA audit trail).
- Field-level encryption — add field-level encryption for PII fields in POST bodies (GDPR Art.32).
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment:
environment: dev
id: cdn
infrastructure:
cloudfront:
inputs:
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
region: us-east-1
version: 1.0.0
name: cloudfront
Complex
A production deployment with optional inputs:
environment: dev
id: cdn
infrastructure:
cloudfront:
inputs:
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
default_ttl: 3600
max_ttl: 86400
price_class: PriceClass_100
region: us-east-1
viewer_protocol_policy: redirect-to-https
waf_web_acl_arn: arn:aws:wafv2:us-east-1:000000000000:webacl/my-waf
version: 1.0.0
name: cloudfront
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.