Files
acdl/modules
Jon Chery cec34abc22 fix(P04 W1): ecs-service execution_role_arn + task_role_arn wiring (live apply gap)
The live terraform apply (P4) uncovered a P2 module-completeness gap: the
ecs-service L1 aws_ecs_task_definition was missing execution_role_arn +
task_role_arn, and the microservice L2 composition did not wire
roles.outputs.role_arn to the service. Fargate requires an execution role
for ECR image pull. Fixed: interface.json + variables.tf + main.tf +
composition.json wires. The iam-role assume-policy trusts ecs-tasks +
the inline policy grants ECR pull + CW logs.

A second live gap surfaced once the task definition applied: the ALB
aws_lb had no security group (AWS rejects an ALB with an empty SG list).
The platform VPC only outputs an ECS SG; the composition now wires
platform_vpc.outputs.ecs_security_group_id to alb.inputs.security_group
(the ECS SG opens port 80 to 0.0.0.0/0 — acceptable for an internet-facing
ALB + dev pilot per D-020). No iam-role module changes were needed — its
locals.tf already trusts ecs-tasks.amazonaws.com and grants ECR pull +
CloudWatch logs by default.

Live apply now succeeds: Apply complete! Resources: 0 added, 1 changed, 0
destroyed (task def + ECS service created on the first re-apply; ALB SG
updated in-place on the second). Full suite: 844 passed.

---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W1
---
2026-08-19 03:01:47 +00:00
..

Nova Modules

Reusable building blocks for cloud infrastructure. Each module is self-documented with a README.md following the template.

How the modules work

There are two kinds of module:

  • Primitives — a single cloud resource or a small group of related resources (e.g. a VPC with subnets and routing). Each primitive has an interface.json declaring its inputs and outputs, and a README.md in plain language.
  • Modules — a pattern that references multiple primitives to deploy a complete stack (e.g. an ECS Fargate microservice). Each module has a composition.json declaring its children and wires.

The engine adapter (adapters/terraform/adapter.py) compiles a module instance to infrastructure. Each module's README documents which resources it creates.

Primitives

Module What it creates README
s3 aws_s3_bucket — a single S3 bucket README
vpc aws_vpc + aws_subnet + aws_route_table + aws_internet_gateway — VPC with subnets and routing README
ecs-cluster aws_ecs_cluster — ECS Fargate cluster README
ecs-service aws_ecs_task_definition + aws_ecs_service — Fargate service with task definition README
iam-role aws_iam_role — IAM role with assume-role policy README
alb aws_lb + aws_lb_target_group + aws_lb_listener — Application Load Balancer README
ecr aws_ecr_repository — ECR container image repository README
cloudfront aws_cloudfront_distribution + aws_cloudfront_origin_access_control — CloudFront distribution with S3 origin via OAC README
waf aws_wafv2_web_acl — WAFv2 Web ACL (CloudFront-scoped) README
rds aws_db_instance — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support README
kms-key aws_kms_key — Customer-managed KMS key with rotation enabled (per-stack CMK) README
uptime aws_ecs_service — Uptime-kuma monitoring on ECS Fargate with alert channels README
dynamodb aws_dynamodb_table — DynamoDB table with encryption + PITR (v1.8 NFR defaults) README

Modules

Module What it references README
microservice 6 primitives (vpc, cluster, ecr, iam-role, alb, ecs-service) README
static-assets 3 primitives (s3, cloudfront, waf) README

Registry

Module versions are tracked in registry.json. Both primitives and modules are registered.

Template

New modules should use README-TEMPLATE.md as their starting point.

Module patterns (roadmap)

The current composition.json mechanism is a thin pattern layer. A future redesign will let a consumer dynamically create a module directly from the contract file (an agentic "composition" flow). That is on the roadmap, not implemented today.