Files
acdl/modules/l1/alb
Jon Chery f68f85c9fd
acdl-ci / Lint (push) Successful in 7s
acdl-ci / Test (push) Successful in 15s
acdl-ci / Platform check-only (offline) (push) Successful in 9s
review(v1.5): READY TO SHIP — multi-persona code review
---ci---
project: acdl
phase: 20
milestone: v1.5
status: review
verdict: READY TO SHIP
p0: 1 (fixed — contract path resolution in deploy workflow)
p1: 6 (flagged post-hoc)
---/ci---

Multi-persona review of v1.5 phase 20 (docs + reusable deploy workflow).

P0 (blocking) — AUTO-FIXED:
- C1: scripts/run_platform.sh contract path resolution broken in deploy
  workflow. The reusable workflow invokes run_platform.sh from the consumer
  workspace root with a relative contract path (.acdl/contract.yaml), but
  run_platform.sh does `cd "$ROOT"` (platform repo) early, so the relative
  path resolved against the platform repo and the pipeline could never run.
  Fix (commit 75c2274): capture CALLER_CWD before cd "$ROOT"; resolve
  caller-supplied relative paths against CALLER_CWD; default no-arg contract
  stays relative to ROOT (preserves platform-local CI). Reproduced pre-fix;
  verified post-fix.

P1 (important) — FLAGGED FOR POST-HOC REVIEW (do not block ship):
- C2: ref: v1.4 in the deploy workflow platform checkout — no v1.4 tag exists
  (only v1.4.0 / v1.4.1). Operator must create a floating v1.4 tag or change
  the ref to v1.4.1.
- C3: modules/l2/{static-asset,microservice}/README.md still use @v1 in their
  Usage examples; missed by the v1.4 bump.
- S1: static-key override is not wired. ACDL_AWS_* env vars on the OIDC step
  are not read by aws-actions/configure-aws-credentials@v4 (it reads AWS_*
  or its own access-key/secret-key inputs). The README/CONSUMER_GUIDE claim
  a working override that doesn't function as written. Needs a conditional
  step or renamed env vars + input wiring.
- S2: README overstates ABAC repo:org/repo:ref:... scoping. The workflow
  constructs a numeric role name (github.repository_id); the actual claim
  enforcement lives in the IAM trust policy, not in this workflow.
- T1: no deploy-workflow triggers conformance test (CI workflow has one;
  deploy doesn't). Minor — reusable workflows use workflow_call, not push
  triggers, but the contract's triggers field is then unenforced.
- A1: terraform/spike/terraform.tf uploaded as artifact leaks the AWS account
  ID via the state-backend bucket name. Recommend excluding terraform.tf or
  gating artifact upload to non-public repos.

P2 (nits) — listed for awareness: floating-tag terminology imprecision (M1),
  header comment "Gitea Actions" in the GitHub copy (M2, intentional byte-
  identical), pip install split (P1-perf), comment drift in pipelines/deploy.yaml
  header (C4), module README internal inconsistency (C5).

Verdict: READY TO SHIP. The one P0 is fixed. The 6 P1s are post-hoc items —
the deploy workflow is a scaffold whose first real consumer run requires
operator setup (tag, IAM role, secrets) that gates go-live. The P1s should
be addressed before any consumer invokes uses: acdl/.gitea/workflows/
deploy.yml@v1.4 in earnest.

Tests: 154 pass (19 new). run_ci.sh green.
2026-07-22 17:24:28 +00:00
..

alb — Application Load Balancer (load balancer + target group + listener)

Module kind: L1 primitive | Version: 1.0.0

An Application Load Balancer with a target group and a listener. This is a multi-resource module: it creates a load balancer, a target group, and a listener that forwards traffic to the target group. The target group is what ecs-service registers its tasks with.

Resources

Resource Type Purpose
load_balancer aws_lb Application load balancer in the VPC subnets
target_group aws_lb_target_group Target group for the ECS service tasks
listener aws_lb_listener Listener forwarding the LB port to the target group

Inputs

Name Type Required Default Description
name string yes Name tag for the load balancer and child resources
subnets string yes Comma-separated subnet ids (from vpc)
security_group string yes Security group id for the load balancer
port number no 80 Listener port
protocol string no HTTP Listener protocol
region string yes AWS region the load balancer is created in

Outputs

Name Type Description
lb_arn arn The load balancer ARN
listener_arn arn The listener ARN
target_group_arn arn The target group ARN

Usage

{
  "id": "alb",
  "type": "aws:elbv2:loadbalancer",
  "module": "alb@1.0.0",
  "inputs": {
    "name": "acdl-microservice",
    "subnets": "ref:vpc.subnet_ids",
    "security_group": "ref:roles.role_arn",
    "port": 8080,
    "protocol": "HTTP",
    "region": "us-east-1"
  }
}

The target_group_arn output is referenced by ecs-service as its lb_target_group_arn input to wire the service to the ALB.

Compliance extension points

  • TLS / HTTPS listener — add aws_acm_certificate + ssl_policy + certificate_arn for encryption in transit (SOC2 CC6.1, PCI-DSS 4.1, HIPAA §164.312(e)(1), GDPR Art.32).
  • Access logs — add access_logs { bucket = ..., prefix = ... } to the load balancer (SOX, SOC2 CC7.2, DORA ICT audit trail).
  • Security group rules — add ingress/egress rules restricting traffic to known sources (SOC2 CC6.6, PCI-DSS 1.2).
  • Health check — add a health_check block to the target group (SOC2 CC7.3 monitoring, DORA operational resilience).
  • WAF — add aws_wafv2_web_acl_association for application-layer protection (SOC2 CC7.6, PCI-DSS 6.5, DORA ICT risk).
  • Deregistration delay — add deregistration_delay for graceful draining (SOC2 CC9.1 resilience).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.