Files
acdl/modules/l1/s3/README.md
T
Jon Chery 94065a4fbc feat(P27): add Examples section to every module README (D-058)
Each module README (10 primitives + 2 patterns) now has a ## Examples
section before ## Versioning, referencing and excerpting the validated
simple.yaml + complex.yaml (+ mysql.yaml for RDS) example contracts. The
RDS README includes a Multi-engine variation subsection (D-059).

---ci---
project: acdl
phase: 27
milestone: v1.7
status: execute
---/ci---
2026-07-22 20:23:48 +00:00

3.0 KiB

s3 — S3 bucket

Module kind: primitive | Version: 1.0.0

A single S3 bucket for object storage. The simplest module — one resource, two inputs, two outputs. Versioning is enabled by default.

Resources

Resource Type Purpose
bucket aws_s3_bucket The S3 bucket itself

Inputs

Name Type Required Default Description
bucket_name string yes Globally-unique S3 bucket name
region string yes AWS region the bucket is created in

Outputs

Name Type Description
bucket_arn arn The S3 bucket ARN
bucket_name string The bucket name (echoes the input)

NFRs

Name Type Default Description
versioning boolean true Enable S3 versioning

Usage

{
  "id": "s3",
  "type": "aws:s3:bucket",
  "module": "s3@1.0.0",
  "inputs": {
    "bucket_name": "acdl-spike-bucket",
    "region": "us-east-1"
  }
}

A concrete instance is at instance.json (used by the platform pipeline as the regression baseline).

Compliance extension points

  • Encryption at rest — add aws_s3_bucket_server_side_encryption_configuration with a customer-managed KMS key (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv), GDPR Art.32).
  • Object Lock — add aws_s3_bucket_object_lock_configuration in compliance mode with 7-year retention for immutable evidence (SOX §802, DORA audit trail).
  • Access logging — add aws_s3_bucket_logging to a target logging bucket (SOC2 CC7.2).
  • Public access block — add aws_s3_bucket_public_access_block to prevent data exfiltration (SOC2 CC6.1, GDPR Art.32).
  • Lifecycle policy — add aws_s3_bucket_lifecycle_configuration for retention enforcement (GDPR Art.5(2), HIPAA §164.530(j)).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: s3
environment: dev
inputs:
  bucket_name: my-simple-bucket
  region: us-east-1

Complex

A production deployment with optional inputs:

examples/complex.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: s3
environment: dev
inputs:
  bucket_name: my-production-bucket
  region: us-east-1

Note: the s3 primitive's compliance extensions (Object Lock, access logging, public access block, lifecycle policy) are documented in the Compliance extension points section above but not yet wired as inputs. The complex example uses the same inputs as the simple example; compliance extensions are roadmap.

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.