Presentation changes (both Marp decks + source markdown): 1. Title slide: deck title as H1 (slightly bigger), 'Agentic Cloud Delivery Platform' as H3 subtitle — cleaner title hierarchy 2. DX deck: removed Local Reproducibility slide (not beneficial for DX) 3. DX deck: Safe Promotion Path slide redesigned with side-by-side layout for Approaches A and B (HTML table, two columns) 4. DX deck: 'an agent' → 'an AI agent' (slide 2 + Citizen Developer slide) 5. DX deck: What a Developer Does — diagram floated to the right side 6. Header simplified to just the deck name (subtitle now on title slide) HIPAA removal (25 files): - Completely removed all HIPAA references from all markdown documentation, presentation source files, module READMEs, and rendered HTML - Removed HIPAA from compliance milestone lists (GDPR, SOX, SOC2, DORA remain) - Removed HIPAA section references (§164.xxx) from compliance annotations - Cleaned up empty parentheses and broken commas left by removal - Re-rendered both HTML decks from updated Marp source ---ci--- phase: 47 milestone: v1.9 status: complete requirements: covered: [] partial: [] ---/ci---
2.9 KiB
s3 — S3 bucket
Module kind: primitive | Version: 1.0.0
A single S3 bucket for object storage. The simplest module — one resource, two inputs, two outputs. Versioning is enabled by default.
Resources
| Resource | Type | Purpose |
|---|---|---|
| bucket | aws_s3_bucket |
The S3 bucket itself |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
bucket_name |
string | yes | — | Globally-unique S3 bucket name |
region |
string | yes | — | AWS region the bucket is created in |
Outputs
| Name | Type | Description |
|---|---|---|
bucket_arn |
arn | The S3 bucket ARN |
bucket_name |
string | The bucket name (echoes the input) |
NFRs
| Name | Type | Default | Description |
|---|---|---|---|
versioning |
boolean | true | Enable S3 versioning |
Usage
{
"id": "s3",
"type": "aws:s3:bucket",
"module": "s3@1.0.0",
"inputs": {
"bucket_name": "acdl-spike-bucket",
"region": "us-east-1"
}
}
A concrete instance is at instance.json (used by the platform
pipeline as the regression baseline).
Compliance extension points
- Encryption at rest — add
aws_s3_bucket_server_side_encryption_configurationwith a customer-managed KMS key (SOC2 CC6.1, GDPR Art.32). - Object Lock — add
aws_s3_bucket_object_lock_configurationin compliance mode with 7-year retention for immutable evidence (SOX §802, DORA audit trail). - Access logging — add
aws_s3_bucket_loggingto a target logging bucket (SOC2 CC7.2). - Public access block — add
aws_s3_bucket_public_access_blockto prevent data exfiltration (SOC2 CC6.1, GDPR Art.32). - Lifecycle policy — add
aws_s3_bucket_lifecycle_configurationfor retention enforcement (GDPR Art.5(2).
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment:
uses: acdl/pipelines/deploy.yaml@v1.6
module: s3
environment: dev
inputs:
bucket_name: my-simple-bucket
region: us-east-1
Complex
A production deployment with optional inputs:
uses: acdl/pipelines/deploy.yaml@v1.6
module: s3
environment: dev
inputs:
bucket_name: my-production-bucket
region: us-east-1
Note: the s3 primitive's compliance extensions (Object Lock, access logging, public access block, lifecycle policy) are documented in the Compliance extension points section above but not yet wired as inputs. The complex example uses the same inputs as the simple example; compliance extensions are roadmap.
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.