Create run_codegen.sh (pre-TF: env check, validate, resolve, adapt). Create run_postapply.sh (post-TF: Checkov, confidence, HITL, outbox, SSM, uptime). Add variable 'enabled' (bool, default true) + count=var.enabled?1:0 to all 12 L1 modules (alb, cloudfront, ecr, ecs-cluster, ecs-service, iam-role, kms-key, rds, s3, uptime, vpc, waf). Fix all cross-resource references with [0] indexing. Update interface.json for all modules to declare 'enabled' input. Fix stale artifact path /tmp/acdl_platform_run_v18 → /tmp/nova_platform_run (REQ-238). run_platform.sh remains as backward-compat shim for local-dev usage. ---ci--- project: acdl phase: 4 milestone: v1.20 status: execute requirements: [REQ-233, REQ-234, REQ-235, REQ-236, REQ-237, REQ-238] ---/ci---
s3 — S3 bucket
Module kind: primitive | Version: 1.0.0
A single S3 bucket for object storage. The simplest module — one resource, two inputs, two outputs. Versioning is enabled by default.
Resources
| Resource | Type | Purpose |
|---|---|---|
| bucket | aws_s3_bucket |
The S3 bucket itself |
Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
bucket_name |
string | yes | — | Globally-unique S3 bucket name |
region |
string | yes | — | AWS region the bucket is created in |
Outputs
| Name | Type | Description |
|---|---|---|
bucket_arn |
arn | The S3 bucket ARN |
bucket_name |
string | The bucket name (echoes the input) |
NFRs
| Name | Type | Default | Description |
|---|---|---|---|
versioning |
boolean | true | Enable S3 versioning |
Usage
{
"id": "s3",
"type": "aws:s3:bucket",
"module": "s3@1.0.0",
"inputs": {
"bucket_name": "acdl-spike-bucket",
"region": "us-east-1"
}
}
A concrete instance is at instance.json (used by the platform
pipeline as the regression baseline).
Compliance extension points
- Encryption at rest — add
aws_s3_bucket_server_side_encryption_configurationwith a customer-managed KMS key (SOC2 CC6.1, GDPR Art.32). - Object Lock — add
aws_s3_bucket_object_lock_configurationin compliance mode with 7-year retention for immutable evidence (SOX §802, DORA audit trail). - Access logging — add
aws_s3_bucket_loggingto a target logging bucket (SOC2 CC7.2). - Public access block — add
aws_s3_bucket_public_access_blockto prevent data exfiltration (SOC2 CC6.1, GDPR Art.32). - Lifecycle policy — add
aws_s3_bucket_lifecycle_configurationfor retention enforcement (GDPR Art.5(2).
Examples
Validated example contracts are in examples/. The platform-test
pipeline validates them against schemas/contract.schema.json.
Simple
A minimal deployment:
environment: dev
id: s3a
infrastructure:
s3:
inputs:
bucket_name: my-simple-bucket
region: us-east-1
version: 1.0.0
name: s3-bucket
Complex
A production deployment with optional inputs:
environment: dev
id: s3a
infrastructure:
s3:
inputs:
bucket_name: my-production-bucket
region: us-east-1
version: 1.0.0
name: s3-bucket
Note: the s3 primitive's compliance extensions (Object Lock, access logging, public access block, lifecycle policy) are documented in the Compliance extension points section above but not yet wired as inputs. The complex example uses the same inputs as the simple example; compliance extensions are roadmap.
Versioning
1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.