Files
acdl/modules/l1/vpc
Jon Chery bb3ac7c74d
acdl-ci / Lint (pull_request) Successful in 8s
acdl-ci / Platform check-only (offline) (pull_request) Successful in 24s
acdl-modules-lifecycle / CI VPC apply (pull_request) Successful in 40s
acdl-ci / Test (pull_request) Successful in 4m1s
acdl-modules-lifecycle / L1 lifecycle (alb) (pull_request) Failing after 1m54s
acdl-modules-lifecycle / L1 lifecycle (cloudfront) (pull_request) Successful in 9m20s
acdl-modules-lifecycle / L1 lifecycle (ecr) (pull_request) Successful in 2m38s
acdl-modules-lifecycle / L1 lifecycle (ecs-cluster) (pull_request) Successful in 2m58s
acdl-modules-lifecycle / L1 lifecycle (iam-role) (pull_request) Successful in 2m37s
acdl-modules-lifecycle / L1 lifecycle (ecs-service) (pull_request) Failing after 5m13s
acdl-modules-lifecycle / L1 lifecycle (rds) (pull_request) Failing after 1m18s
acdl-modules-lifecycle / L1 lifecycle (kms-key) (pull_request) Successful in 2m54s
acdl-modules-lifecycle / L1 lifecycle (s3) (pull_request) Successful in 2m55s
acdl-modules-lifecycle / L1 lifecycle (vpc) (pull_request) Successful in 2m49s
acdl-modules-lifecycle / L1 lifecycle (uptime) (pull_request) Failing after 6m3s
acdl-modules-lifecycle / L1 lifecycle (waf) (pull_request) Successful in 3m11s
acdl-modules-lifecycle / CI VPC destroy (pull_request) Failing after 20m40s
fix(P60): WAF scope case + VPC modify DependencyViolation
Two module defects found in the prior live matrix run (3000, SHA
a55752e2) that hadn't been fixed:

1. WAF: `scope: cloudfront` in complex example failed with "expected
   scope to be one of [CLOUDFRONT REGIONAL], got cloudfront". AWS
   requires uppercase. Added `scope = upper(var.scope)` in locals.tf
   so the module is resilient to either casing, and fixed the complex
   example to use CLOUDFRONT.

2. VPC: simple→complex modify tried to replace the VPC (CIDR changed
   10.0.0.0/16 → 10.50.0.0/16, which is ForceNew) while subnets/IGW/
   route tables still referenced it → DependencyViolation. Fixed the
   complex example to use the same CIDR (10.0.0.0/16) so terraform
   modifies in-place (adds a 3rd AZ subnet, updates tags). Also added
   create_before_destroy lifecycle on the VPC as a defensive measure.

Regression: 479 passed, 5 deselected. 24 example contracts resolve.

---ci---
project: acdl
phase: P60
milestone: v1.11
status: execute
---/ci---
2026-07-28 20:13:07 +00:00
..

vpc — VPC with subnets and routing

Module kind: primitive | Version: 1.0.0

A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids.

Resources

Resource Type Purpose
vpc aws_vpc The VPC itself
subnet aws_subnet One subnet per availability zone
route_table aws_route_table Route table with default route 0.0.0.0/0
internet_gateway aws_internet_gateway IGW for public internet access
route_table_association aws_route_table_association Binds subnet to route table

Inputs

Name Type Required Default Description
cidr string yes VPC CIDR block, e.g. 10.0.0.0/16
azs string yes Comma-separated availability zones, e.g. us-east-1a,us-east-1b
name string yes Name tag for the VPC and child resources
region string yes AWS region the VPC is created in

Outputs

Name Type Description
vpc_id string The VPC id
subnet_ids string Comma-separated subnet ids

Usage

{
  "id": "vpc",
  "type": "aws:ec2:vpc",
  "module": "vpc@1.0.0",
  "inputs": {
    "cidr": "10.0.0.0/16",
    "azs": "us-east-1a,us-east-1b",
    "name": "acdl-microservice",
    "region": "us-east-1"
  }
}

The azs input is split on comma; one subnet is created per zone. The route table gets a default route 0.0.0.0/0 → internet gateway. Other modules reference subnet_ids for their network placement.

Compliance extension points

  • VPC Flow Logs — add aws_flow_log + CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, DORA ICT risk logging).
  • Private subnets + NAT gateway — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, network isolation).
  • VPC endpoints — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk).
  • Security groups — add aws_security_group as a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2).
  • Network ACLs — add aws_network_acl for subnet-level segmentation (PCI-DSS 1.3).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: vpc
infrastructure:
  vpc:
    inputs:
      azs: us-east-1a,us-east-1b
      cidr: 10.0.0.0/16
      name: my-vpc
      region: us-east-1
    version: 1.0.0
name: vpc-network

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: vpc
infrastructure:
  vpc:
    inputs:
      azs: us-east-1a,us-east-1b,us-east-1c
      cidr: 10.50.0.0/16
      name: my-production-vpc
      region: us-east-1
    version: 1.0.0
name: vpc-network

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.