Files
acdl/modules
Jon Chery fda4564a7f feat(P58): single platform VPC + deterministic env-aware state keys
EXECUTE stage. Fixes the 4-VPC bug: adds a single shared VPC to
terraform/platform, drops the vpc child from the microservice composition
(references the platform VPC via data source), and makes state keys
env-aware (spike/{id}/{env}/terraform.tfstate — stable across lifecycle).

Platform VPC (terraform/platform/main.tf):
- aws_vpc.acdl_shared (10.0.0.0/16) + 2 subnets + IGW + route table + SG
- Outputs: vpc_id, subnet_ids, ecs_security_group_id

Microservice composition (modules/l2/microservice/composition.json):
- Dropped the vpc child (no per-contract VPC ever again).
- Added data_sources block: platform_vpc → terraform_remote_state (platform).
- Wires: vpc.outputs.subnet_ids → platform_vpc.outputs.subnet_ids.
- Wires: platform_vpc.outputs.vpc_id → alb.inputs.vpc_id.
- Wires: platform_vpc.outputs.ecs_security_group_id → service.inputs.security_group.

Contract resolver (core/contract_resolver.py):
- Added environment to the stack instance (stack.environment).
- Added data_sources handling: pseudo-children with outputs but no resources.
- data_sources propagated through fragment merge to the final stack instance.

Adapter (adapters/terraform/adapter.py):
- State key: spike/{stack_name}/{environment}/terraform.tfstate (env-aware).
- Emits data "terraform_remote_state" "platform" block when data_sources present.
- ref:platform_vpc.<output> → data.terraform_remote_state.platform.outputs.<output>.

Tests (tests/test_adapter.py):
- test_adapt_env_aware_state_key: spike/msvc/prod/terraform.tfstate.
- test_adapt_emits_data_source_block: data.terraform_remote_state.platform.
- test_adapt_no_vpc_for_microservice: no resource "aws_vpc" in microservice output.
- Updated existing state key assertion (spike/s3/dev/terraform.tfstate).

Regression: 467 passed, 0 skipped, 5 deselected. run_platform.sh --check-only
passes for both microservice (9 resources, no VPC) and static-assets (5 resources).

---ci---
project: acdl
phase: P58
milestone: v1.11
status: execute
---/ci---
2026-07-28 16:07:57 +00:00
..

ACDL Modules

Reusable building blocks for cloud infrastructure. Each module is self-documented with a README.md following the template.

How the modules work

There are two kinds of module:

  • Primitives — a single cloud resource or a small group of related resources (e.g. a VPC with subnets and routing). Each primitive has an interface.json declaring its inputs and outputs, and a README.md in plain language.
  • Modules — a pattern that references multiple primitives to deploy a complete stack (e.g. an ECS Fargate microservice). Each module has a composition.json declaring its children and wires.

The engine adapter (adapters/terraform/adapter.py) compiles a module instance to infrastructure. Each module's README documents which resources it creates.

Primitives

Module What it creates README
s3 aws_s3_bucket — a single S3 bucket README
vpc aws_vpc + aws_subnet + aws_route_table + aws_internet_gateway — VPC with subnets and routing README
ecs-cluster aws_ecs_cluster — ECS Fargate cluster README
ecs-service aws_ecs_task_definition + aws_ecs_service — Fargate service with task definition README
iam-role aws_iam_role — IAM role with assume-role policy README
alb aws_lb + aws_lb_target_group + aws_lb_listener — Application Load Balancer README
ecr aws_ecr_repository — ECR container image repository README
cloudfront aws_cloudfront_distribution + aws_cloudfront_origin_access_control — CloudFront distribution with S3 origin via OAC README
waf aws_wafv2_web_acl — WAFv2 Web ACL (CloudFront-scoped) README
rds aws_db_instance — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support README
kms-key aws_kms_key — Customer-managed KMS key with rotation enabled (per-stack CMK) README
uptime aws_ecs_service — Uptime-kuma monitoring on ECS Fargate with alert channels README

Modules

Module What it references README
microservice 6 primitives (vpc, cluster, ecr, iam-role, alb, ecs-service) README
static-assets 3 primitives (s3, cloudfront, waf) README

Registry

Module versions are tracked in registry.json. Both primitives and modules are registered.

Template

New modules should use README-TEMPLATE.md as their starting point.

Module patterns (roadmap)

The current composition.json mechanism is a thin pattern layer. A future redesign will let a consumer dynamically create a module directly from the contract file (an agentic "composition" flow). That is on the roadmap, not implemented today.