Files
acdl/core/environments

Platform-managed environments

This directory holds environment definitions used by the onboarding scaffold. Each file is a named environment the platform owns (an AWS account or scoped partition, a network, a state backend, and an IAM role surfaced to the consumer via ABAC).

A consumer never provides an AWS account, VPC, subnet, S3 state bucket, or runner key — the platform manages all of that here.

Files

  • dev.json — the default dev environment (autonomous, confidence >= 0.50).
  • qa.json — QA environment (attested, QA HITL gate, confidence >= 0.75). Placeholder binding (replace account_id with the real QA account).
  • prod.json — Production environment (attested, SRE HITL gate, confidence >= 0.90). Placeholder binding.
  • dr.json — DR environment (attested, SRE HITL gate, confidence >= 0.95). Placeholder binding.

All files validate against schemas/environment.schema.json. The qa/prod/dr placeholders use account_id: 000000000000 with a stderr warning at load time (prompts real binding before deploying).

How it is used

core/environment_check.py reads a contract's environment field and looks up the matching <name>.json in this directory. If no matching file exists, the check prints a friendly onboarding prompt and exits non-zero, halting the pipeline before any work is done.

Adding an environment

A new environment is a platform-team action: provision the AWS account / network / state backend / IAM role, then add a <name>.json here and bind it to the consumer repo.

P19 (REQ-183): the request step is now self-service. A consumer submits an onboarding request (POST to the Nova Lambda onboard_consumer action, or python3 core/onboarding.py --request '{...}') and the platform generates a <name>.json binding file from the request + opens a PR. The actual AWS account/network/state provisioning + cross-account role grant remains a platform-team action (a future feature milestone will automate the provisioning; the cross-account role Terraform is offline-proven in P20/REQ-184).