Files
acdl/docs/index.md
T
Jon Chery d830357230 docs(P21): restructure docs/ into Jekyll Pages site (REQ-54, REQ-55, REQ-56)
---ci---
project: acdl
phase: 21
milestone: v1.6
status: execute
---/ci---

Restructure docs/ into a Jekyll-style GitHub Pages site:
- docs/_config.yml (Pages config + nav, excludes internal/)
- docs/index.md (landing: platform + consumer model, Features, Roadmap)
- docs/modules/index.md (catalog: primitives + modules, normalized terms)
- docs/contracts/index.md (schema, fields, sample, multi-contract)
- docs/pipeline/index.md (CI + deploy pipeline, stages mermaid, streaming)
- docs/pipeline/versioning.md (module + deploy-pipeline versioning)
- docs/environments/index.md (platform-managed envs + onboarding, REQ-61)
- docs/consumer-guide.md (renamed from CONSUMER_GUIDE.md; GitHub-only,
  no .gitea, forge->platform runners, L2->modules, composition->pattern,
  updated mermaid with security-checks + infrastructure-apply)
- docs/architecture.md (consolidated from architecture.md +
  architecture-v1.0.md, current-architecture only, normalized terms:
  primitives/modules, platform runners, no L1/L2/forge/gitea in prose)
- Removed docs/architecture-v1.0.md (consolidated) + docs/CONSUMER_GUIDE.md
  (renamed).

No .ciagent/ or .gitea/ references in docs/. Consumer-facing terminology
normalized (L2->modules, L1->primitives, composition->pattern, forge->
platform runners).
2026-07-22 18:22:58 +00:00

4.3 KiB

ACDL — Agentic Cloud Delivery Platform

Consumers declare intent; the platform delivers safe production deployment through an agentic stack — automatically, safely, and with a complete audit trail. A merged change progresses through lower environments end-to-end without a platform engineer joining a thread; a non-technical consumer ships a production deployment by declaring intent, without authoring a workflow, a configuration file, or an infrastructure module.

Two repositories

There are two kinds of repository in the ACDL model:

  • Platform repo (this one). The source code of the platform. It owns modules/, adapters/, core/, schemas/, pipelines/, scripts/, and the reusable workflow files. Platform engineers work here. A consumer never clones it.
  • Consumer repo (yours). A consumer repo contains only its application code, one or more contracts (.acdl/contract.yaml), and one or more CI definitions (a thin .github/workflows/deploy.yml that uses: the central reusable workflow, pointing at the appropriate environment + contract). The consumer does not write infrastructure modules, workflow YAML, or adapter code.

Documentation

Section Audience What it covers
Consumer Guide Consumers Step-by-step: create a repo, write a contract, reference the central pipeline, ship a deployment.
Modules Consumers + platform engineers The module catalog — primitives and modules, their inputs/outputs, and usage.
Contracts Consumers The contract schema, fields, and a worked sample.
Pipeline Consumers + platform engineers The central CI + deployment pipeline and its stages.
Versioning Consumers + platform engineers Module versioning + deploy-pipeline versioning (the uses: tag).
Environments Consumers Platform-managed environments and the first-run onboarding flow.
Architecture Platform engineers The current architecture — layers, cross-cutting concerns, the substrate abstraction.
Vision All The why — the friction the platform absorbs and the north star.

Features

  • Contract-driven deploys — a consumer writes a YAML contract; the platform resolves it to a stack, compiles it, and deploys it.
  • Reusable versioned deploy workflow — consumer repos uses: a versioned central workflow; no platform code is cloned by the consumer.
  • Module catalog — primitives (single resources) and modules (patterns of primitives) with self-documented inputs/outputs.
  • Zero-trust credentials — OIDC federation + attribute-based authorization (ABAC) by default; no long-lived keys in consumer repos.
  • Security + policy checks — a security-check stage and a policy-check stage run before any infrastructure is created.
  • Confidence signal — a computed, explainable score gates promotion.
  • Evidence outbox — every deployment writes a hash-chained evidence event to an audit outbox.
  • Shell reproducibilityscripts/run_ci.sh mirrors the CI pipeline locally; scripts/run_platform.sh --check-only runs offline.
  • Platform-managed environments — consumers provide no AWS account, VPC, subnet, or state bucket; the platform manages environments.

Roadmap

Planned future features (no dates; tracked in the internal roadmap):

  • Dynamic module creation from a contract — an agentic flow where a consumer creates a module directly from the contract file (the "composition" mechanism, redesigned).
  • Compliance milestone — per-module compliance extension points (GDPR, SOX, SOC2, HIPAA, DORA) wired into the pipeline.
  • Additional substrate adapters — beyond the Terraform adapter.
  • Environment self-service — a consumer-facing flow to request and provision a new platform-managed environment.
  • HITL gates for qa / prod / dr — human attestation + higher confidence thresholds for higher environments.
  • OIDC for all platform runners — zero-trust credentials everywhere.