Files
acdl/modules/l1/ecr
Jon Chery de91a4bb76 feat(P31): encryption-by-default + per-stack CMK (REQ-83, REQ-84, REQ-85)
---ci---
project: acdl
phase: 31
milestone: v1.8
status: execute
---/ci---

- New kms-key L1 primitive (aws:kms:key) with enable_key_rotation=true
  (AWS-managed annual rotation, D-075). Registered in registry.json.
- Adapter TYPE_MAP expanded for aws:kms:key + aws:kms:alias.
- Adapter emits enable_key_rotation from NFR.
- S3 adapter emits server_side_encryption_configuration with KMS when
  kms_key_arn provided; managed KMS fallback with stderr warning when not.
- All 10 existing L1 primitives now have encryption_enabled NFR (default true).
- s3, rds, ecr, ecs-service, ecs-cluster have kms_key_arn input.
- Both L2 compositions (static-assets, microservice) now include a kms-key
  child + wires connecting kms_key_arn to children.
- L2 stack outputs include kms_key_arn.

Tests: +7 (300 -> 307). All pass. run_platform.sh --check-only green
(static-assets now resolves to 5 resources with the CMK).
2026-07-22 22:11:03 +00:00
..

ecr — ECR repository

Module kind: primitive | Version: 1.0.0

A single ECR repository that hosts the container image for the ECS task. The simplest container-registry module — one resource, two inputs, two outputs.

Resources

Resource Type Purpose
repository aws_ecr_repository The ECR repository

Inputs

Name Type Required Default Description
name string yes The ECR repository name
region string yes AWS region the repository is created in

Outputs

Name Type Description
repository_url string The ECR repository URL
repository_arn arn The ECR repository ARN

Usage

{
  "id": "ecr",
  "type": "aws:ecr:repository",
  "module": "ecr@1.0.0",
  "inputs": {
    "name": "acdl-microservice",
    "region": "us-east-1"
  }
}

The repository_url output is used to build the image input for ecs-service (e.g. <repository_url>:latest).

Compliance extension points

  • Image scanning — add image_scanning_configuration { scan_on_push = true } for vulnerability scanning (SOC2 CC7.6, DORA ICT risk testing, HIPAA security monitoring).
  • Encryption — add encryption_configuration { encryption_type = "KMS", kms_key = ... } with a customer-managed key (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv), GDPR Art.32).
  • Image tag immutability — add image_tag_mutability = "IMMUTABLE" to prevent tag overwriting (SOX §802, SOC2 CC6.1 integrity, DORA audit integrity).
  • Lifecycle policy — add aws_ecr_lifecycle_policy to enforce image retention / cleanup (GDPR Art.5(2) data minimization, SOC2 CC5.2).
  • Access policy — add a repository policy restricting pull/push to known roles (SOC2 CC6.1, HIPAA §164.308(a)(4)).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: ecr
environment: dev
inputs:
  name: my-repo
  region: us-east-1

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex ECR with lifecycle policy + image scanning
uses: acdl/pipelines/deploy.yaml@v1.6
module: ecr
environment: dev
inputs:
  name: my-production-repo
  region: us-east-1

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.