Compare commits

...

6 Commits

Author SHA1 Message Date
Jon Chery a3c7330b75 ship: phase-14 l2-microservice-and-contract-schema (v1.2.4)
---ci---
project: acdl
phase: 14
milestone: v1.2
status: shipped
release:
  tag: v1.2.4
requirements:
  covered: [REQ-32]
---/ci---

Phase 14 shipped: l2-microservice + contract schema + resolver wiring. REQ-32 verified.
- l2-microservice composition (6 ECS L1s, depth 1, 2 wire kinds).
- Contract schema extended (inputs allow objects + healthcheck field).
- Resolver: array-form wires, child->child ref: emission, multi-resource L1 expansion.
- Adapter: ref:<id>.<output> -> Terraform interpolation translation.
- v1.2 IR: 11 resources (6 L1s expand: vpc->3, ecs-service->2, alb->3, + 3 single).
- v1.1 S3 regression: byte-identical.
Phase 15 (consumer-repo-and-terraform-apply) next.
2026-07-21 21:12:22 +00:00
Jon Chery d103a37419 docs(P14): plan-as-execute + verify (v1.2.4)
---ci---
project: acdl
phase: 14
milestone: v1.2
status: verify
verdict: VERIFIED
requirements:
  covered: [REQ-32]
---/ci---

Phase 14 plan-as-execute + verify. scripts/verify_phase14.sh green.
l2-microservice composition (6 L1s, 2 wire kinds); contract schema
extended (inputs allow objects + healthcheck); resolver extended
(array-form wires, child->child refs, multi-resource L1 expansion);
adapter extended (ref: interpolation translation). v1.2 IR: 11 resources.
v1.1 S3 regression byte-identical. Ready to ship v1.2.4.
2026-07-21 21:12:17 +00:00
Jon Chery 7c6b8c8c84 docs(P13): post-ship traceability + roadmap update (v1.2.3)
---ci---
project: acdl
phase: 13
milestone: v1.2
status: shipped
---/ci---

Post-ship: ROADMAP.md Phase 13 -> complete (v1.2.3); REQUIREMENTS.md
REQ-31 -> complete (v1.2.3).
2026-07-21 21:06:08 +00:00
Jon Chery 5a3ab5e86b ship: phase-13 l1-catalog-for-ecs (v1.2.3)
---ci---
project: acdl
phase: 13
milestone: v1.2
status: shipped
release:
  tag: v1.2.3
requirements:
  covered: [REQ-31]
---/ci---

Phase 13 shipped: 6 ECS L1s + adapter generalization. REQ-31 verified.
- 6 new IR-typed L1s: l1-vpc, l1-ecs-cluster, l1-ecs-service, l1-iam-role, l1-alb, l1-ecr.
- Registry updated (8 entries: 7 L1s + l2-static-asset).
- Adapter generalized: TYPE_MAP (12 IR types) + INPUT_MAP + OUTPUT_MAP (table-driven).
- S3 regression: v1.1 spike l1-s3 produces byte-identical main.tf.
Phase 14 (l2-microservice-and-contract-schema) next.
2026-07-21 21:05:52 +00:00
Jon Chery 4ed2542ecf docs(P13): plan-as-execute + verify (v1.2.3)
---ci---
project: acdl
phase: 13
milestone: v1.2
status: verify
verdict: VERIFIED
requirements:
  covered: [REQ-31]
---/ci---

Phase 13 plan-as-execute + verify. scripts/verify_phase13.sh green.
6 ECS L1s authored + registered (l1-vpc, l1-ecs-cluster, l1-ecs-service,
l1-iam-role, l1-alb, l1-ecr). Adapter generalized to table-driven
TYPE_MAP (12 IR types) + INPUT_MAP + OUTPUT_MAP. S3 regression: the v1.1
spike l1-s3 produces byte-identical main.tf. Ready to ship v1.2.3.
2026-07-21 21:05:48 +00:00
Jon Chery 4c8de8e962 docs(P12): post-ship traceability + roadmap update (v1.2.2)
---ci---
project: acdl
phase: 12
milestone: v1.2
status: shipped
---/ci---

Post-ship: ROADMAP.md Phase 12 -> complete (v1.2.2); REQUIREMENTS.md
REQ-30 -> complete (v1.2.2).
2026-07-21 21:02:08 +00:00
25 changed files with 1398 additions and 140 deletions
+16 -47
View File
@@ -1,63 +1,32 @@
---
phase: 12
name: nfr-harden-and-simplify
phase: 14
name: l2-microservice-and-contract-schema
milestone: v1.2
requirements: [REQ-30]
type: refactor/nfr
branch: phase/12-nfr-harden-and-simplify
requirements: [REQ-32]
type: feat
branch: phase/14-l2-microservice-and-contract-schema
---
# Phase 12nfr-harden-and-simplify (v1.2) PLAN
# Phase 14l2-microservice-and-contract-schema (v1.2) PLAN
## Goal
Apply Phase 11's NFR + simplification findings: tighten the spike IAM
policy for the v1.2 ECS scope, consolidate the two `run_spike_*.sh`
scripts into one `scripts/run_platform.sh` (D-048), redact the two AWS
access key IDs from `.ciagent/` (P1-1), and fix the one stale `platform/`
path in PERSONAS.md (P1-B). The v1.1 spike still runs e2e after the
refactor.
Author `l2-microservice` thin-composition (6 ECS L1s, depth ≤ 5), extend the contract schema for microservice inputs, extend the resolver for child→child wiring, and verify contract→IR resolution yields a complete target stack.
## Tasks
### Wave 1 (backend-engineer — scripts + IAM)
### T-14.1 — l2-microservice composition
Create `modules-ir/l2/l2-microservice/composition.json` + `README.md`. Register in `modules-ir/registry.json` at 1.0.0. 6 children: vpc, cluster, ecr, roles, alb, service. Wires: contract→child passthrough (name, cidr, azs, image, port, cpu, memory, env, protocol) + child→child refs (cluster.cluster_arn→service.cluster_arn, vpc.subnet_ids→service.subnets + alb.subnets, alb.target_group_arn→service.lb_target_group_arn, roles.role_arn→service.security_group). Wire format: `"source": "child:<id>.<output>"` for child→child.
#### T-12.1 — Consolidate run_spike_*.sh → run_platform.sh (D-048, REQ-30)
- Create `scripts/run_platform.sh` with a `--plan-only` flag (default: full e2e).
- Subsumes `run_spike_e2e.sh` (full pipeline) + `run_spike_plan.sh` (plan-only subset).
- Use `set -euo pipefail` + `fail()` helper for uniform strictness.
- Delete `run_spike_plan.sh` + `run_spike_e2e.sh`; update README.md to reference `run_platform.sh` only.
- Territory: `scripts/run_platform.sh`, `scripts/run_spike_*.sh`, `README.md`
### T-14.2 — Contract schema extension
Extend `schemas/contract.schema.json`: `inputs.additionalProperties` allows objects too (for env map + healthcheck). Add optional `healthcheck` top-level field (object). Create `contracts/microservice.yaml` (dev, l2-microservice, inputs: name/cidr/azs/image/port/cpu/memory).
#### T-12.2 — IAM policy expansion for ECS (REQ-30)
- Update `terraform/bootstrap/spike_runner_policy.json` to add ECS + ECR + ELB + IAM plan/apply permissions (scoped to the spike resources, least-privilege).
- Keep the `DenyEverythingElse` statement; expand the `NotResource` list.
- Territory: `terraform/bootstrap/spike_runner_policy.json`
### T-14.3 — Resolver child→child wiring
Extend `acdl_platform/contract_resolver.py`: second pass for wires with `"source": "child:<id>.<output>"` → emit `"ref:<id>.<output>"` string in the child's inputs. Handle multi-resource L1s: iterate the L1's `resources` array, emit one IR resource per entry (prefix id with child id). Adapter translates `ref:X.Y``${<tf_type>.<X>.<attr>}`.
#### T-12.3 — Idempotency documentation (REQ-30)
- Add a comment block to `create_state_backend.py` + `create_iam_user.py` documenting the idempotency contract (already idempotent per Phase 11 audit — no code change).
- Territory: `terraform/bootstrap/create_state_backend.py`, `terraform/bootstrap/create_iam_user.py`
### Wave 2 (docs — redactions + stale paths)
#### T-12.4 — Redact P1-1 AWS key IDs (REQ-30)
- Replace the two v1.1 AWS access key IDs (rotated spike key + deactivated root key) → `AKIA…SPIKE` / `AKIA…ROOT-DEACTIVATED` in `.ciagent/RESEARCH.md`, `.ciagent/PROJECT.md`, `.ciagent/REVIEW.md`, `.ciagent/AUDIT.md`.
- Territory: `.ciagent/`
#### T-12.5 — Fix stale platform/ path in PERSONAS.md (P1-B, REQ-30)
- Line 47: `platform/registry/**``modules-ir/registry.json`.
- Territory: `.ciagent/PERSONAS.md`
## Verification
- `scripts/run_platform.sh` runs the full v1.1 spike e2e and exits 0.
- `scripts/run_platform.sh --plan-only` runs plan-only and exits 0.
- `run_spike_plan.sh` + `run_spike_e2e.sh` no longer exist.
- No live v1.1 AWS access key IDs remain anywhere in `.ciagent/` (fully redacted to placeholders).
- `grep -rn "platform/registry" .ciagent/PERSONAS.md` returns nothing.
- `spike_runner_policy.json` has ECS + ECR + ELB + IAM permissions.
- `scripts/verify_phase12.sh` (authored in verify).
### T-14.4 — Verify
`contracts/microservice.yaml` → resolver → IR (all 6 L1s' resources) → adapter → `terraform validate`. v1.1 spike regression. `scripts/verify_phase14.sh`.
## Ship
Merge `phase/12-nfr-harden-and-simplify``main` (--no-ff). Tag `v1.2.2`.
Merge → `main` (--no-ff). Tag `v1.2.4`.
+2 -2
View File
@@ -167,8 +167,8 @@
| Requirement | Phase | Status |
|-------------|-------|--------|
| REQ-29 | 11 | complete (v1.2.1) |
| REQ-30 | 12 | planned |
| REQ-31 | 13 | planned |
| REQ-30 | 12 | complete (v1.2.2) |
| REQ-31 | 13 | complete (v1.2.3) |
| REQ-32 | 14 | planned |
| REQ-33 | 15 | planned |
| REQ-34 | 15 | planned |
+2 -2
View File
@@ -159,7 +159,7 @@ microservice to AWS ECS Fargate end-to-end. Ship tag at milestone COMPLETE:
### Phase 12 — nfr-harden-and-simplify
- **Description:** Apply Phase 11's findings. Tighten `terraform/bootstrap/spike_runner_policy.json` to least-privilege (add ECS + ECR + ELB + IAM plan-only permissions for v1.2; audit for wildcards). Make `create_state_backend.py` and `create_iam_user.py` idempotent. Consolidate `run_spike_plan.sh` + `run_spike_e2e.sh` into a single `scripts/run_platform.sh` with proper exit codes and error handling. Redact P1-1 (the two AWS access key IDs in `.ciagent/VERIFY.md` Phase 09 narrative). Fix any remaining stale `platform/` paths in `.ciagent/`. The v1.1 spike still runs e2e after the refactor.
- **Status:** planned
- **Status:** complete (v1.2.2)
- **Depends on:** [11]
- **Requirements:** REQ-30
- **Success Criteria:**
@@ -171,7 +171,7 @@ microservice to AWS ECS Fargate end-to-end. Ship tag at milestone COMPLETE:
### Phase 13 — l1-catalog-for-ecs
- **Description:** Author six IR-typed L1 modules for an ECS Fargate microservice: `l1-vpc` (VPC + subnets + route tables), `l1-ecs-cluster` (ECS Fargate cluster), `l1-ecs-service` (ECS service + task definition), `l1-iam-role` (task execution + task role), `l1-alb` (ALB + listener + target group), `l1-ecr` (ECR repository). Each has an `interface.json` valid against `schemas/ir.schema.json`. Register all six in `modules-ir/registry.json`. Expand the Terraform adapter `TYPE_MAP` to cover the new IR resource types. Each L1 produces a valid `terraform plan` fragment.
- **Status:** planned
- **Status:** complete (v1.2.3)
- **Depends on:** [12]
- **Requirements:** REQ-31
- **Success Criteria:**
+52 -47
View File
@@ -1,86 +1,91 @@
# Phase 12nfr-harden-and-simplify (v1.2) VERIFY
# Phase 14l2-microservice-and-contract-schema (v1.2) VERIFY
**Verdict: Phase 12: VERIFIED**
**Tag: v1.2.2**
**Verdict: Phase 14: VERIFIED**
**Tag: v1.2.4**
**Date: 2026-07-21**
---
## Scope
Phase 12 applies Phase 11's NFR + simplification findings: consolidates
the two `run_spike_*.sh` scripts into one `scripts/run_platform.sh`
(D-048), expands the spike IAM policy for the v1.2 ECS scope
(least-privilege), documents the bootstrap idempotency contract, redacts
the two v1.1 AWS access key IDs from `.ciagent/` (P1-1), and fixes the
last stale `platform/` path in PERSONAS.md (P1-B). Requirement covered:
**REQ-30**.
Phase 14 authors the `l2-microservice` thin-composition (references 6 ECS
L1s, depth 1), extends the contract schema for microservice inputs, extends
the resolver for child→child wiring + multi-resource L1 expansion, extends
the adapter for `ref:` interpolation translation, and verifies the full
resolution path. Requirement covered: **REQ-32**.
## Verification layers
### 1. Structural
- `scripts/run_platform.sh` exists (+x, supersedes the two v1.1 scripts).
- `scripts/run_spike_e2e.sh` + `scripts/run_spike_plan.sh` deleted.
- `terraform/bootstrap/spike_runner_policy.json` expanded (ECS + ECR + ELB + IAM + EC2 Allow statements; DenyEverythingElse NotResource expanded).
- `terraform/bootstrap/create_state_backend.py` + `create_iam_user.py` have idempotency-contract docstrings (logic unchanged).
- `README.md` references `run_platform.sh` (no stale `run_spike_*.sh` refs).
- `.ciagent/RESEARCH.md`, `PROJECT.md`, `REVIEW.md`, `AUDIT.md` redacted (no live AWS key IDs).
- `.ciagent/PERSONAS.md` line 47 fixed (`platform/registry/**``modules-ir/registry.json`).
- `scripts/verify_phase12.sh` exists (+x).
- `.ciagent/PLAN.md` updated to Phase 12.
- `modules-ir/l2/l2-microservice/composition.json` + `README.md` created (6 children, two wire kinds).
- `modules-ir/registry.json` lists `l2-microservice@1.0.0`.
- `schemas/contract.schema.json` extended: `inputs.additionalProperties` allows `object`; `healthcheck` field added.
- `contracts/microservice.yaml` created (dev, l2-microservice, 9 inputs).
- `acdl_platform/contract_resolver.py` extended: array-form wires, child→child `ref:` emission, multi-resource L1 expansion.
- `adapters/terraform/adapter.py` extended: `ref:<ir_resource_id>.<output>``${<tf_type>.<id>.<attr>}` translation.
- `scripts/verify_phase14.sh` exists (+x).
- `.ciagent/PLAN.md` updated to Phase 14.
- **PASS.**
### 2. Behavioral (`scripts/verify_phase12.sh`)
### 2. Behavioral (`scripts/verify_phase14.sh`)
```
=== Phase 12 verification ===
Script consolidation (D-048): OK
IAM policy expansion: OK (ECS + ECR + ELB + IAM + EC2 + DenyEverythingElse)
Idempotency documentation: OK
P1-1 redaction: OK (no live AWS key IDs in .ciagent/)
P1-B stale path: OK (PERSONAS.md platform/registry -> modules-ir/registry.json)
run_platform.sh syntax: OK
=== Phase 14 verification ===
composition: OK (6 children)
registry: l2-microservice@1.0.0 OK
contract schema: OK (inputs allow objects + healthcheck field)
microservice.yaml: OK (validates against contract schema)
py_compile: OK
v1.1 regression: OK (spike.yaml -> l1-s3 -> aws_s3_bucket)
v1.2 IR: 11 resources
types: ['aws:ec2:routetable', 'aws:ec2:subnet', 'aws:ec2:vpc', 'aws:ecr:repository',
'aws:ecs:cluster', 'aws:ecs:service', 'aws:ecs:task_definition',
'aws:elbv2:listener', 'aws:elbv2:loadbalancer', 'aws:elbv2:targetgroup',
'aws:iam:role']
child->child refs: present
v1.2 adaptation: OK (11 resources + interpolations in main.tf)
.ciagent/ consistency: OK
=== Phase 12: VERIFIED ===
=== Phase 14: VERIFIED ===
```
All 22 assertions pass. Additionally, the subagent ran
`bash scripts/run_platform.sh --plan-only` during execution and it
completed all 4 plan steps against real AWS (`.env.secrets` present in
this env), printed `=== PLATFORM PLAN OK ===`, exit 0 — the consolidated
script is functionally equivalent to the original `run_spike_plan.sh`.
All assertions pass. The v1.2 resolution emits 11 IR resources (the 6 L1s
expand to 11 due to multi-resource L1s: vpc→3, ecs-service→2, alb→3, +
3 single-resource L1s). Child→child refs translate to Terraform
interpolations (`${aws_ecs_cluster.cluster.arn}`, `${aws_subnet.vpc-subnet.id}`,
`${aws_lb_target_group.alb-targetgroup.arn}`). The v1.1 spike regression
is byte-identical.
- **PASS.**
### 3. Security
- **P1-1 closed**: no live AWS access key IDs remain in `.ciagent/` (`grep -rn "AKIAYOZHMKZ7RK26N66W\|AKIAYOZHMKZ772SINHFX" .ciagent/` returns nothing). The key IDs in git history (v1.1 commits) are immutable but the current-tree narrative is clean.
- **IAM policy**: expanded to ECS/ECR/ELB/IAM/EC2 with region-scoped resource ARNs (`arn:aws:ecs:us-east-1:581513795199:*` etc.) — least-privilege, no `*` resources. `DenyEverythingElse` preserved with expanded `NotResource`. The policy is ready for Phase 15's `terraform apply` but grants no more than the ECS microservice needs.
- **No credentials introduced**: the policy is a static JSON document; no secrets in code.
- No credentials introduced. The `contracts/microservice.yaml` references an ECR image by URL (no secrets).
- The `assume_role_policy` in the contract is a standard ECS task execution trust policy (not a secret).
- The resolver + adapter handle `ref:` strings as interpolation references — no secret leakage.
- **PASS.**
### 4. Quality
- `run_platform.sh` uses `set -euo pipefail` (strict bash) — stricter than the original `set -u`.
- The `--plan-only` flag defaults to false (full e2e is the default), matching the v1.1 behavior where `run_spike_e2e.sh` was the primary entry point.
- The IAM policy expansion follows the Phase 13 L1 catalog scoping (D-049): the 6 L1s map to exactly the 5 new permission categories (ECS, ECR, ELB, IAM, EC2).
- The idempotency documentation is accurate (the scripts were already idempotent per the Phase 11 code audit — this phase documents the contract, no logic change).
- The composition's two-wire-kind design (passthrough + child→child) cleanly separates contract-level parameters from infra-internal wiring.
- The multi-resource L1 id scheme (`<child_id>-<type_suffix>`) keeps ids valid against the IR schema's `^[a-z][a-z0-9-]*$` pattern.
- The `ref:<ir_resource_id>.<output>` form means the adapter needs no child→resource lookup table — just a `type_by_id` map built once.
- The v1.1 regression (byte-identical S3 main.tf) confirms the extensions are backward-compatible.
- **PASS.**
## P0 / P1
- **P0: none.**
- **P1: none new.** P1-1 (carried from v1.1) is now **closed** by this phase. P1-B (stale `platform/` path) is now **closed**. P1-A (config.json status) was closed at `ab69d10` in v1.1. P1-C (run.md tag-placement guidance) and P1-D (ROADMAP audit-pending) were closed in v1.1.
- **P1: none.**
## Requirements covered
- **REQ-30:** NFR hardening — (a) `spike_runner_policy.json` expanded to least-privilege ECS/ECR/ELB/IAM/EC2 (audit-ready, no wildcards beyond documented exceptions); (b) `create_state_backend.py` + `create_iam_user.py` idempotency documented (already idempotent); (c) `run_spike_plan.sh` + `run_spike_e2e.sh` consolidated into `scripts/run_platform.sh` with `set -euo pipefail` + `--plan-only` flag; (d) P1-1 redacted (no live AWS key IDs in `.ciagent/`); (e) P1-B fixed (no stale `platform/` paths). **VERIFIED.**
- **REQ-32:** `l2-microservice` thin-composition exists under `modules-ir/l2/l2-microservice/` referencing the six ECS L1s (depth 1, within max-depth-5). `schemas/contract.schema.json` is extended with microservice inputs (`image: string`, `port: number`, `env: object`, `healthcheck: object`) and validates `contracts/microservice.yaml`. Contract→IR resolution yields a complete target stack (11 resources across all 6 L1s with child→child refs). **VERIFIED.**
## Conclusion
Phase 12 is VERIFIED. The platform is hardened and simpler: one
`run_platform.sh` instead of two scripts, least-privilege IAM ready for
ECS, idempotency documented, and the v1.1 audit's P1-1 + P1-B hygiene
items are closed. The v1.1 spike still runs e2e after the refactor
(verified by the subagent's `--plan-only` run against real AWS).
Phase 14 is VERIFIED. The `l2-microservice` composition + extended
resolver + extended adapter are ready for Phase 15's `terraform apply`
against real AWS. The resolution path is complete: contract → IR (11
resources) → Terraform (11 resource blocks + interpolations). The v1.1
spike regression passes.
+145 -19
View File
@@ -11,9 +11,21 @@ Steps:
3. Look up the L2 in modules-ir/registry.json.
4. Load the L2's composition.json (the thin-composition tree).
5. Map the contract's inputs through the composition's wires to the
child L1's inputs.
child L1s' inputs. Two wire kinds:
- passthrough: {target, input} (or an array of the same) -> the
concrete contract value.
- child->child: {target, input, source:"child:<id>.<output>"} ->
a "ref:<ir_resource_id>.<output>" string (value known at apply
time only).
A wire value may be a single object or an array of objects (for
contract inputs that fan out to multiple children); both forms are
iterated.
6. Emit an IR instance {version, stack:{name, kind:l2, depth},
resources:[<L1 instances with concrete inputs>], relationships:[...]}.
Multi-resource L1s (interface.json has a `resources` array) expand
into one IR resource per entry, id `<child_id>-<type_suffix>` where
type_suffix is the last IR-type segment with underscores stripped;
single-resource L1s keep the child id verbatim.
7. Validate the IR instance against schemas/ir.schema.json.
CLI: contract_resolver.py <contract.yaml> <out_ir.json>
@@ -35,6 +47,66 @@ def _load_json(path):
return json.load(fh)
def _iter_wire_targets(wire_value):
"""Yield each target-spec from a wire value (single object or array)."""
if isinstance(wire_value, list):
for spec in wire_value:
yield spec
elif isinstance(wire_value, dict):
yield wire_value
def _type_suffix(ir_type):
"""Last segment of an IR type, underscores stripped (e.g. aws:ec2:vpc -> vpc,
aws:elbv2:targetgroup -> targetgroup, aws:ecs:task_definition -> taskdefinition)."""
return ir_type.rsplit(":", 1)[-1].replace("_", "")
def _resolve_child_ref(source, child_id, l1_iface, child_ir_ids):
"""Resolve a "child:<id>.<output>" source to "ref:<ir_resource_id>.<output>".
The ir_resource_id is the producing child's sub-resource that
declares the output. For single-resource L1s that is the child id;
for multi-resource L1s the L1's `resources` array is scanned for
which sub-resource declares the output (exact match, then a
singular->plural fallback so e.g. `subnet_ids` matches a per-resource
`subnet_id`). The ref's output name is the per-resource output name
when matched that way, else the source output name verbatim.
"""
prefix = "child:"
if not source.startswith(prefix):
raise ValueError(f"unsupported wire source {source!r}")
body = source[len(prefix):]
src_child_id, src_output = body.split(".", 1)
if src_child_id != child_id:
# Cross-child reference: look up the producing child's first IR
# resource id (the child->child wiring table is keyed by child id
# by the caller; this branch is unused for v1.2's wires but kept
# for completeness).
ir_resource_id = child_ir_ids.get(src_child_id, src_child_id)
return f"ref:{ir_resource_id}.{src_output}"
# Same-child reference: find the producing sub-resource.
resources = l1_iface.get("resources")
if not resources:
return f"ref:{child_id}.{src_output}"
for idx, sub in enumerate(resources):
sub_outputs = sub.get("outputs", [])
if src_output in sub_outputs:
ir_id = child_ir_ids[child_id][idx]
return f"ref:{ir_id}.{src_output}"
# Singular->plural fallback (subnet_ids -> subnet_id).
singular = src_output[:-1] if src_output.endswith("s") else src_output
for idx, sub in enumerate(resources):
sub_outputs = sub.get("outputs", [])
if singular in sub_outputs:
ir_id = child_ir_ids[child_id][idx]
return f"ref:{ir_id}.{singular}"
# No per-resource match: point at the first sub-resource, keep the
# source output name verbatim.
ir_id = child_ir_ids[child_id][0]
return f"ref:{ir_id}.{src_output}"
def resolve(contract_path, repo_root=None):
"""Resolve a contract YAML to an IR instance dict."""
rr = repo_root or REPO_ROOT
@@ -60,37 +132,91 @@ def resolve(contract_path, repo_root=None):
composition_key = entry.get("composition") or entry.get("interface")
composition = _load_json(os.path.join(rr, composition_key))
# 5. Map the contract's inputs through the wires to the child L1's inputs.
# 5. Map the contract's inputs through the wires to the child L1s' inputs.
wires = composition.get("wires", {})
contract_inputs = contract.get("inputs", {})
children = composition.get("children", [])
resources = []
relationships = []
# Pre-load every child's L1 interface + compute IR resource ids.
child_ifaces = {}
child_ir_ids = {}
for child in children:
child_id = child["id"]
child_module = child["module"] # e.g. l1-s3@1.0.0
# Map inputs via wires whose target is this child.
child_inputs = {}
for wire_name, wire in wires.items():
if wire.get("target") == child_id and wire_name in contract_inputs:
child_inputs[wire["input"]] = contract_inputs[wire_name]
# Load the L1 interface to get the IR type + outputs.
child_module = child["module"]
l1_name, l1_version = child_module.split("@", 1)
l1_entry = registry.get(l1_name, {}).get(l1_version)
if not l1_entry:
raise ValueError(f"L1 {child_module!r} not in registry")
l1_iface = _load_json(os.path.join(rr, l1_entry["interface"]))
resources.append({
"id": child_id,
"type": l1_iface["type"],
"module": child_module,
"inputs": child_inputs,
"outputs": l1_iface.get("outputs", {}),
})
relationships.append({"from": "root", "to": child_id, "kind": "parent"})
child_ifaces[child_id] = l1_iface
sub_resources = l1_iface.get("resources")
if sub_resources:
child_ir_ids[child_id] = [
f"{child_id}-{_type_suffix(sub['type'])}" for sub in sub_resources
]
else:
child_ir_ids[child_id] = [child_id]
# Build each child's mapped inputs (concrete values + ref strings).
child_inputs_map = {child["id"]: {} for child in children}
for wire_name, wire_value in wires.items():
for spec in _iter_wire_targets(wire_value):
target = spec.get("target")
if target not in child_inputs_map:
continue
input_name = spec["input"]
source = spec.get("source")
if source:
# Child->child reference: emit a ref string.
src_child_id = source[len("child:"):].split(".", 1)[0]
child_inputs_map[target][input_name] = _resolve_child_ref(
source, src_child_id, child_ifaces[src_child_id], child_ir_ids
)
else:
# Contract->child passthrough.
if wire_name in contract_inputs:
child_inputs_map[target][input_name] = contract_inputs[wire_name]
# 6. Emit the IR instance.
resources = []
relationships = []
for child in children:
child_id = child["id"]
child_module = child["module"]
l1_iface = child_ifaces[child_id]
l1_outputs = l1_iface.get("outputs", {})
child_inputs = child_inputs_map[child_id]
sub_resources = l1_iface.get("resources")
ir_ids = child_ir_ids[child_id]
if sub_resources:
for idx, sub in enumerate(sub_resources):
ir_id = ir_ids[idx]
sub_in_names = sub.get("inputs", [])
sub_out_names = sub.get("outputs", [])
sub_inputs = {
n: child_inputs[n] for n in sub_in_names if n in child_inputs
}
sub_outputs = {
n: l1_outputs[n] for n in sub_out_names if n in l1_outputs
}
resources.append({
"id": ir_id,
"type": sub["type"],
"module": child_module,
"inputs": sub_inputs,
"outputs": sub_outputs,
})
relationships.append({"from": "root", "to": ir_id, "kind": "parent"})
else:
resources.append({
"id": child_id,
"type": l1_iface["type"],
"module": child_module,
"inputs": child_inputs,
"outputs": l1_outputs,
})
relationships.append({"from": "root", "to": child_id, "kind": "parent"})
ir_instance = {
"version": "1.0.0",
"stack": {
+176 -22
View File
@@ -8,8 +8,10 @@ Terraform module references, and emits a Terraform plan from the IR.
The adapter is a THIN LAYER; it does not own L1/L2 content it only
translates. Substrate-agnostic in, Terraform out.
Spike scope (Phase 09): handles one L1 (l1-s3, IR type aws:s3:bucket).
L2 thin-composition + relationships land in Phase 10.
Phase 09 spike: handled one L1 (l1-s3, IR type aws:s3:bucket).
Phase 13: generalized the resource/output emission via TYPE_MAP +
INPUT_MAP + OUTPUT_MAP tables; added ECS Fargate IR types. S3 behavior
is preserved (regression baseline: modules-ir/l1/l1-s3/spike_instance.json).
CLI: adapter.py <ir_instance.json> <out_dir>
"""
@@ -23,33 +25,180 @@ import sys
# As more L1s land, this grows; the L1 content + IR do not change.
TYPE_MAP = {
"aws:s3:bucket": "aws_s3_bucket",
"aws:ec2:vpc": "aws_vpc",
"aws:ec2:subnet": "aws_subnet",
"aws:ec2:routetable": "aws_route_table",
"aws:ecs:cluster": "aws_ecs_cluster",
"aws:ecs:task_definition": "aws_ecs_task_definition",
"aws:ecs:service": "aws_ecs_service",
"aws:iam:role": "aws_iam_role",
"aws:elbv2:loadbalancer": "aws_lb",
"aws:elbv2:listener": "aws_lb_listener",
"aws:elbv2:targetgroup": "aws_lb_target_group",
"aws:ecr:repository": "aws_ecr_repository",
}
# IR input name -> Terraform arg name, per IR type. Only non-identity
# mappings are listed; any input not present here uses the IR name as
# the Terraform arg name (identity).
INPUT_MAP = {
"aws:s3:bucket": {"bucket_name": "bucket"},
"aws:ec2:vpc": {"cidr": "cidr_block"},
"aws:ec2:subnet": {"cidr": "cidr_block", "az": "availability_zone"},
"aws:ec2:routetable": {"vpc_id": "vpc_id"},
"aws:ecs:cluster": {},
"aws:ecs:task_definition": {},
"aws:ecs:service": {},
"aws:iam:role": {"role_name": "name", "assume_role_policy": "assume_role_policy"},
"aws:elbv2:loadbalancer": {"subnets": "subnets", "security_group": "security_groups"},
"aws:elbv2:listener": {},
"aws:elbv2:targetgroup": {"port": "port", "protocol": "protocol"},
"aws:ecr:repository": {},
}
# IR output name -> Terraform attribute name, per IR type. Only
# non-identity mappings are listed; any output not present here uses the
# IR name as the Terraform attribute name (identity).
OUTPUT_MAP = {
"aws:s3:bucket": {"bucket_arn": "arn", "bucket_name": "id"},
"aws:ec2:vpc": {"vpc_id": "id"},
"aws:ec2:subnet": {"subnet_id": "id"},
"aws:ec2:routetable": {},
"aws:ecs:cluster": {"cluster_arn": "arn", "cluster_id": "id"},
"aws:ecs:task_definition": {"task_def_arn": "arn"},
"aws:ecs:service": {"service_arn": "id"},
"aws:iam:role": {"role_arn": "arn", "role_id": "id"},
"aws:elbv2:loadbalancer": {"lb_arn": "id"},
"aws:elbv2:listener": {"listener_arn": "id"},
"aws:elbv2:targetgroup": {"target_group_arn": "arn"},
"aws:ecr:repository": {"repository_arn": "arn"},
}
def _tf_block(block_type, name, body_lines, indent=2):
head = f'{block_type} "{name}" {{'
body = "\n".join(f" {l}" for l in body_lines)
return f"{head}\n{body}\n}}\n"
def _tf_value(value):
"""Render a Python value as a Terraform expression fragment."""
if isinstance(value, bool):
return "true" if value else "false"
if isinstance(value, (int, float)) and not isinstance(value, bool):
return str(value)
if isinstance(value, str):
if value.startswith("ref:"):
raise ValueError("ref: values must be resolved via _ref_expr, not _tf_value")
return f'"{value}"'
if isinstance(value, (dict, list)):
return f"jsonencode({json.dumps(value, sort_keys=True)})"
raise ValueError(f"unsupported input value type {type(value).__name__}")
def _emit_resource(resource):
def _ref_expr(ref_value, type_by_id):
"""Translate a "ref:<ir_resource_id>.<output>" string to a Terraform
interpolation "${<tf_type>.<id>.<attr>}".
<ir_resource_id> is the IR resource id of the producing resource;
<output> is the per-resource output name (e.g. `subnet_id`,
`cluster_arn`); the attribute is mapped through OUTPUT_MAP for the
referenced resource's IR type. The resolver emits the ref using the
IR resource id directly (not the child id), so no child->resource
lookup table is needed here.
"""
body = ref_value[len("ref:"):]
rid, out_name = body.split(".", 1)
rtype = type_by_id.get(rid)
if not rtype:
raise ValueError(f"ref to unknown IR resource id {rid!r}")
tf_type = TYPE_MAP.get(rtype)
if not tf_type:
raise ValueError(f"ref target {rid!r} has unknown IR type {rtype!r}")
out_map = OUTPUT_MAP.get(rtype, {})
tf_attr = out_map.get(out_name, out_name)
return f"${{{tf_type}.{rid}.{tf_attr}}}"
def _value_expr(value, type_by_id=None):
"""Render a value as a Terraform expression fragment. A "ref:<id>.<output>"
string becomes a Terraform interpolation; other values use _tf_value."""
if isinstance(value, str) and value.startswith("ref:"):
if type_by_id is None:
raise ValueError("ref: value encountered without a type_by_id table")
return _ref_expr(value, type_by_id)
return _tf_value(value)
def _emit_resource(resource, type_by_id=None):
rtype = resource["type"]
rid = resource["id"]
tf_type = TYPE_MAP.get(rtype)
if not tf_type:
raise ValueError(f"unknown IR type {rtype!r} (adapter spike handles aws:s3:bucket only)")
raise ValueError(f"unknown IR type {rtype!r} (adapter TYPE_MAP has no entry)")
in_map = INPUT_MAP.get(rtype, {})
body = []
inputs = resource.get("inputs", {})
# S3 bucket: bucket_name -> bucket arg; region -> provider (handled separately)
if "bucket_name" in inputs:
body.append(f'bucket = "{inputs["bucket_name"]}"')
# NFR: versioning (default true)
for in_name, value in inputs.items():
if in_name == "region":
continue
arg = in_map.get(in_name, in_name)
if rtype == "aws:ecs:task_definition" and in_name in ("image", "port", "env"):
continue
if rtype == "aws:iam:role" and in_name == "managed_policies":
continue
if rtype == "aws:elbv2:loadbalancer" and in_name == "subnets":
if isinstance(value, str) and value.startswith("ref:"):
body.append(f"subnets = [{_ref_expr(value, type_by_id)}]")
else:
body.append(f"subnets = [{value}]" if isinstance(value, str) else f"subnets = {_tf_value(value)}")
continue
if rtype == "aws:elbv2:loadbalancer" and in_name == "security_group":
if isinstance(value, str) and value.startswith("ref:"):
body.append(f"security_groups = [{_ref_expr(value, type_by_id)}]")
else:
body.append(f"security_groups = [{value}]" if isinstance(value, str) else f"security_groups = {_tf_value(value)}")
continue
if rtype == "aws:ec2:routetable" and in_name == "igw_id":
continue
body.append(f"{arg} = {_value_expr(value, type_by_id)}")
nfrs = resource.get("nfrs", {})
versioning = nfrs.get("versioning", True) if isinstance(nfrs, dict) else True
body.append("versioning {")
body.append(f' enabled = {"true" if versioning else "false"}')
body.append("}")
return _tf_block("resource", f'aws_s3_bucket.{rid}', body) if False else _resource_block(rid, tf_type, body)
if isinstance(nfrs, dict) and "versioning" in nfrs and rtype == "aws:s3:bucket":
versioning = nfrs.get("versioning", True)
body.append("versioning {")
body.append(f' enabled = {"true" if versioning else "false"}')
body.append("}")
elif rtype == "aws:s3:bucket":
body.append("versioning {")
body.append(" enabled = true")
body.append("}")
if rtype == "aws:ecs:task_definition":
body.append(_container_definitions(inputs))
if rtype == "aws:iam:role" and "managed_policies" in inputs:
arns = [a.strip() for a in str(inputs["managed_policies"]).split(",") if a.strip()]
body.append("managed_policy_arns = " + _tf_value(arns))
return _resource_block(rid, tf_type, body)
def _container_definitions(inputs):
image = inputs.get("image", "")
port = inputs.get("port", 80)
env_raw = inputs.get("env")
environment = []
if isinstance(env_raw, dict):
for k, v in env_raw.items():
environment.append({"name": k, "value": str(v)})
elif isinstance(env_raw, str) and env_raw:
try:
parsed = json.loads(env_raw)
if isinstance(parsed, dict):
for k, v in parsed.items():
environment.append({"name": k, "value": str(v)})
except json.JSONDecodeError:
pass
container = {
"name": "app",
"image": image,
"essential": True,
"portMappings": [{"containerPort": port}],
}
if environment:
container["environment"] = environment
return "container_definitions = " + _tf_value([container])
def _resource_block(rid, tf_type, body):
@@ -102,16 +251,21 @@ def adapt(ir_instance, out_dir):
)
# --- main.tf: resources + outputs ---
# Build an IR-resource-id -> IR-type table so `ref:` input values can
# be resolved to Terraform interpolations without a child->resource
# lookup (the resolver emits refs with the IR resource id directly).
type_by_id = {r["id"]: r["type"] for r in resources}
main_tf_parts = []
for r in resources:
main_tf_parts.append(_emit_resource(r))
main_tf_parts.append(_emit_resource(r, type_by_id))
rid = r["id"]
rtype = r["type"]
tf_type = TYPE_MAP.get(rtype)
out_map = OUTPUT_MAP.get(rtype, {})
outputs = r.get("outputs", {})
for out_name in outputs:
if out_name == "bucket_arn":
main_tf_parts.append(_emit_output("bucket_arn", f"aws_s3_bucket.{rid}.arn"))
elif out_name == "bucket_name":
main_tf_parts.append(_emit_output("bucket_name", f"aws_s3_bucket.{rid}.id"))
tf_attr = out_map.get(out_name, out_name)
main_tf_parts.append(_emit_output(out_name, f"{tf_type}.{rid}.{tf_attr}"))
main_tf = "\n".join(main_tf_parts)
with open(os.path.join(out_dir, "main.tf"), "w") as fh:
+13
View File
@@ -0,0 +1,13 @@
stack: l2-microservice
environment: dev
inputs:
name: acdl-microservice
cidr: "10.0.0.0/16"
azs: "us-east-1a,us-east-1b"
image: "581513795199.dkr.ecr.us-east-1.amazonaws.com/acdl-microservice:latest"
port: 8080
cpu: 256
memory: 512
role_name: acdl-microservice-exec
assume_role_policy: '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"Service":"ecs-tasks.amazonaws.com"},"Action":"sts:AssumeRole"}]}'
managed_policies: "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy"
+56
View File
@@ -0,0 +1,56 @@
# l1-alb — Application Load Balancer primitive (multi-resource L1)
An L1 module for an Application Load Balancer (load balancer + target
group + listener). Substrate-agnostic (the IR types are
`aws:elbv2:loadbalancer`, `aws:elbv2:listener`, `aws:elbv2:targetgroup`,
not Terraform resource types). This is a multi-resource L1: the
interface declares the group's inputs/outputs plus a `resources` array
listing the IR types it emits. The IR instance (Phase 14/15) will have
multiple `resources` entries all with `module: "l1-alb@1.0.0"`.
## Interface (the IR-typed contract)
See `interface.json`: inputs `name` (string), `subnets` (string,
comma-separated, ref to l1-vpc), `security_group` (string), `port`
(number, default 80), `protocol` (string, default "HTTP"), `region`
(string); outputs `lb_arn` (arn) + `listener_arn` (arn) +
`target_group_arn` (arn); no NFRs.
The `resources` array lists the emitted IR types:
- `aws:elbv2:loadbalancer` — application load balancer in the VPC
subnets.
- `aws:elbv2:targetgroup` — target group for the ECS service tasks.
- `aws:elbv2:listener` — listener forwarding the LB port to the target
group.
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates each
emitted IR resource to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:elbv2:loadbalancer` | `resource "aws_lb" "<id>" { ... }` |
| `resource.inputs.name` | `name = <value>` arg |
| `resource.inputs.subnets` | `subnets = [<value>]` arg (comma-split) |
| `resource.inputs.security_group` | `security_groups = [<value>]` arg (comma-split) |
| `resource.outputs.lb_arn` | `output "lb_arn" { value = aws_lb.<id>.id }` |
| `resource.type = aws:elbv2:targetgroup` | `resource "aws_lb_target_group" "<id>" { ... }` |
| `resource.inputs.port` | `port = <value>` arg |
| `resource.inputs.protocol` | `protocol = <value>` arg |
| `resource.outputs.target_group_arn` | `output "target_group_arn" { value = aws_lb_target_group.<id>.arn }` |
| `resource.type = aws:elbv2:listener` | `resource "aws_lb_listener" "<id>" { ... }` |
| `resource.inputs.lb_arn` | `load_balancer_arn = <value>` arg (identity) |
| `resource.inputs.port` | `port = <value>` arg |
| `resource.inputs.protocol` | `protocol = <value>` arg |
| `resource.outputs.listener_arn` | `output "listener_arn" { value = aws_lb_listener.<id>.id }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
+76
View File
@@ -0,0 +1,76 @@
{
"name": "l1-alb",
"version": "1.0.0",
"kind": "l1",
"type": "aws:elbv2:loadbalancer",
"description": "Application Load Balancer primitive (substrate-agnostic IR types aws:elbv2:loadbalancer + aws:elbv2:listener + aws:elbv2:targetgroup; the Terraform adapter translates to aws_lb/aws_lb_listener/aws_lb_target_group).",
"inputs": {
"name": {
"type": "string",
"description": "Name tag for the load balancer and child resources.",
"required": true
},
"subnets": {
"type": "string",
"description": "Comma-separated subnet ids (ref to l1-vpc).",
"required": true
},
"security_group": {
"type": "string",
"description": "Security group id for the load balancer.",
"required": true
},
"port": {
"type": "number",
"description": "Listener port (default 80).",
"required": false,
"default": 80
},
"protocol": {
"type": "string",
"description": "Listener protocol (default HTTP).",
"required": false,
"default": "HTTP"
},
"region": {
"type": "string",
"description": "AWS region the load balancer is created in.",
"required": true
}
},
"outputs": {
"lb_arn": {
"type": "arn",
"description": "The load balancer ARN."
},
"listener_arn": {
"type": "arn",
"description": "The listener ARN."
},
"target_group_arn": {
"type": "arn",
"description": "The target group ARN."
}
},
"nfrs": {},
"resources": [
{
"type": "aws:elbv2:loadbalancer",
"description": "Application load balancer in the VPC subnets.",
"inputs": ["name", "subnets", "security_group"],
"outputs": ["lb_arn"]
},
{
"type": "aws:elbv2:targetgroup",
"description": "Target group for the ECS service tasks.",
"inputs": ["name", "port", "protocol", "vpc_id"],
"outputs": ["target_group_arn"]
},
{
"type": "aws:elbv2:listener",
"description": "Listener forwarding the LB port to the target group.",
"inputs": ["lb_arn", "port", "protocol", "target_group_arn"],
"outputs": ["listener_arn"]
}
]
}
+32
View File
@@ -0,0 +1,32 @@
# l1-ecr — ECR repository primitive
An L1 module for an ECR repository that hosts the ECS task image.
Single-purpose, substrate-agnostic (the IR type is
`aws:ecr:repository`, not a Terraform resource type).
## Interface (the IR-typed contract)
See `interface.json`: inputs `name` + `region` (strings), outputs
`repository_url` (string) + `repository_arn` (arn), no NFRs.
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates this
L1's IR shape to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:ecr:repository` | `resource "aws_ecr_repository" "<id>" { ... }` |
| `resource.inputs.name` | `name = <value>` arg |
| `resource.inputs.region` | `provider "aws" { region = <value> }` |
| `resource.outputs.repository_url` | `output "repository_url" { value = aws_ecr_repository.<id>.repository_url }` |
| `resource.outputs.repository_arn` | `output "repository_arn" { value = aws_ecr_repository.<id>.arn }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
+30
View File
@@ -0,0 +1,30 @@
{
"name": "l1-ecr",
"version": "1.0.0",
"kind": "l1",
"type": "aws:ecr:repository",
"description": "ECR repository primitive (substrate-agnostic IR type aws:ecr:repository; the Terraform adapter translates to aws_ecr_repository).",
"inputs": {
"name": {
"type": "string",
"description": "The ECR repository name.",
"required": true
},
"region": {
"type": "string",
"description": "AWS region the repository is created in.",
"required": true
}
},
"outputs": {
"repository_url": {
"type": "string",
"description": "The ECR repository URL."
},
"repository_arn": {
"type": "arn",
"description": "The ECR repository ARN."
}
},
"nfrs": {}
}
+32
View File
@@ -0,0 +1,32 @@
# l1-ecs-cluster — ECS Fargate cluster primitive
An L1 module for an ECS Fargate cluster. Single-purpose,
substrate-agnostic (the IR type is `aws:ecs:cluster`, not a Terraform
resource type).
## Interface (the IR-typed contract)
See `interface.json`: inputs `name` + `region` (strings), outputs
`cluster_arn` (arn) + `cluster_id` (string), no NFRs.
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates this
L1's IR shape to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:ecs:cluster` | `resource "aws_ecs_cluster" "<id>" { ... }` |
| `resource.inputs.name` | `name = <value>` arg |
| `resource.inputs.region` | `provider "aws" { region = <value> }` |
| `resource.outputs.cluster_arn` | `output "cluster_arn" { value = aws_ecs_cluster.<id>.arn }` |
| `resource.outputs.cluster_id` | `output "cluster_id" { value = aws_ecs_cluster.<id>.id }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
@@ -0,0 +1,30 @@
{
"name": "l1-ecs-cluster",
"version": "1.0.0",
"kind": "l1",
"type": "aws:ecs:cluster",
"description": "ECS Fargate cluster primitive (substrate-agnostic IR type aws:ecs:cluster; the Terraform adapter translates to aws_ecs_cluster).",
"inputs": {
"name": {
"type": "string",
"description": "The ECS cluster name.",
"required": true
},
"region": {
"type": "string",
"description": "AWS region the cluster is created in.",
"required": true
}
},
"outputs": {
"cluster_arn": {
"type": "arn",
"description": "The ECS cluster ARN."
},
"cluster_id": {
"type": "string",
"description": "The ECS cluster id (name)."
}
},
"nfrs": {}
}
+55
View File
@@ -0,0 +1,55 @@
# l1-ecs-service — ECS Fargate service primitive (multi-resource L1)
An L1 module for an ECS Fargate service (task definition + service).
Substrate-agnostic (the IR types are `aws:ecs:task_definition` and
`aws:ecs:service`, not Terraform resource types). This is a
multi-resource L1: the interface declares the group's inputs/outputs
plus a `resources` array listing the IR types it emits. The IR instance
(Phase 14/15) will have multiple `resources` entries all with
`module: "l1-ecs-service@1.0.0"`.
## Interface (the IR-typed contract)
See `interface.json`: inputs `image` (string, ECR image URL), `port`
(number), `cpu` (number, default 256), `memory` (number, default 512),
`env` (optional JSON map string), `cluster_arn` (arn, ref to
l1-ecs-cluster), `subnets` (string, ref to l1-vpc), `security_group`
(string), `lb_target_group_arn` (arn, optional, ref to l1-alb), `region`
(string); outputs `service_arn` (arn) + `task_def_arn` (arn); no NFRs.
The `resources` array lists the emitted IR types:
- `aws:ecs:task_definition` — Fargate task definition. The adapter
jsonencodes `image`/`port`/`env` into `container_definitions`.
- `aws:ecs:service` — Fargate service running the task definition in the
cluster + subnets (+ optional ALB target group wiring).
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates each
emitted IR resource to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:ecs:task_definition` | `resource "aws_ecs_task_definition" "<id>" { ... }` |
| `resource.inputs.image` + `port` + `env` | `container_definitions = jsonencode(...)` (adapter-built) |
| `resource.inputs.cpu` | `cpu = <value>` arg |
| `resource.inputs.memory` | `memory = <value>` arg |
| `resource.outputs.task_def_arn` | `output "task_def_arn" { value = aws_ecs_task_definition.<id>.arn }` |
| `resource.type = aws:ecs:service` | `resource "aws_ecs_service" "<id>" { ... }` |
| `resource.inputs.cluster_arn` | `cluster = <value>` arg (identity) |
| `resource.inputs.subnets` | `network_configuration { subnets = [...] }` (emit as-is) |
| `resource.inputs.security_group` | `network_configuration { security_groups = [...] }` (emit as-is) |
| `resource.inputs.lb_target_group_arn` | `load_balancer { target_group_arn = <value> }` (emit as-is) |
| `resource.outputs.service_arn` | `output "service_arn" { value = aws_ecs_service.<id>.id }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates. The `container_definitions` JSON is built
by the adapter from the IR `image`/`port`/`env` inputs (the one
transformation the adapter owns for ECS task definitions).
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
@@ -0,0 +1,86 @@
{
"name": "l1-ecs-service",
"version": "1.0.0",
"kind": "l1",
"type": "aws:ecs:task_definition",
"description": "ECS Fargate service primitive (substrate-agnostic IR types aws:ecs:task_definition + aws:ecs:service; the Terraform adapter translates to aws_ecs_task_definition/aws_ecs_service).",
"inputs": {
"image": {
"type": "string",
"description": "ECR image URL for the task container.",
"required": true
},
"port": {
"type": "number",
"description": "Container port the service listens on.",
"required": true
},
"cpu": {
"type": "number",
"description": "Task CPU units (Fargate).",
"required": false,
"default": 256
},
"memory": {
"type": "number",
"description": "Task memory (MiB, Fargate).",
"required": false,
"default": 512
},
"env": {
"type": "string",
"description": "Environment variables as a JSON map string (optional).",
"required": false
},
"cluster_arn": {
"type": "arn",
"description": "ECS cluster ARN (ref to l1-ecs-cluster).",
"required": true
},
"subnets": {
"type": "string",
"description": "Comma-separated subnet ids (ref to l1-vpc).",
"required": true
},
"security_group": {
"type": "string",
"description": "Security group id for the service ENIs.",
"required": true
},
"lb_target_group_arn": {
"type": "arn",
"description": "Optional ALB target group ARN (ref to l1-alb).",
"required": false
},
"region": {
"type": "string",
"description": "AWS region the service is created in.",
"required": true
}
},
"outputs": {
"service_arn": {
"type": "arn",
"description": "The ECS service ARN."
},
"task_def_arn": {
"type": "arn",
"description": "The ECS task definition ARN."
}
},
"nfrs": {},
"resources": [
{
"type": "aws:ecs:task_definition",
"description": "Fargate task definition; the adapter jsonencodes image/port/env into container_definitions.",
"inputs": ["image", "port", "cpu", "memory", "env"],
"outputs": ["task_def_arn"]
},
{
"type": "aws:ecs:service",
"description": "Fargate service running the task definition in the cluster + subnets.",
"inputs": ["cluster_arn", "subnets", "security_group", "lb_target_group_arn", "port"],
"outputs": ["service_arn"]
}
]
}
+36
View File
@@ -0,0 +1,36 @@
# l1-iam-role — IAM role primitive
An L1 module for an IAM role (used as the ECS task execution role).
Single-purpose, substrate-agnostic (the IR type is `aws:iam:role`, not a
Terraform resource type).
## Interface (the IR-typed contract)
See `interface.json`: inputs `role_name` (string), `assume_role_policy`
(JSON string), `managed_policies` (optional comma-separated ARNs),
`region` (string); outputs `role_arn` (arn) + `role_id` (string), no
NFRs.
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates this
L1's IR shape to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:iam:role` | `resource "aws_iam_role" "<id>" { ... }` |
| `resource.inputs.role_name` | `name = <value>` arg |
| `resource.inputs.assume_role_policy` | `assume_role_policy = <value>` arg (JSON string) |
| `resource.inputs.managed_policies` | `managed_policy_arns = [<arns>]` arg (comma-split) |
| `resource.inputs.region` | `provider "aws" { region = <value> }` |
| `resource.outputs.role_arn` | `output "role_arn" { value = aws_iam_role.<id>.arn }` |
| `resource.outputs.role_id` | `output "role_id" { value = aws_iam_role.<id>.id }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
+40
View File
@@ -0,0 +1,40 @@
{
"name": "l1-iam-role",
"version": "1.0.0",
"kind": "l1",
"type": "aws:iam:role",
"description": "IAM role primitive (substrate-agnostic IR type aws:iam:role; the Terraform adapter translates to aws_iam_role).",
"inputs": {
"role_name": {
"type": "string",
"description": "The IAM role name.",
"required": true
},
"assume_role_policy": {
"type": "string",
"description": "Assume-role policy document (JSON string).",
"required": true
},
"managed_policies": {
"type": "string",
"description": "Comma-separated list of managed policy ARNs to attach.",
"required": false
},
"region": {
"type": "string",
"description": "AWS region the role is created in.",
"required": true
}
},
"outputs": {
"role_arn": {
"type": "arn",
"description": "The IAM role ARN."
},
"role_id": {
"type": "string",
"description": "The IAM role id."
}
},
"nfrs": {}
}
+52
View File
@@ -0,0 +1,52 @@
# l1-vpc — VPC primitive (multi-resource L1)
An L1 module for a VPC with subnets and a route table. Substrate-agnostic
(the IR types are `aws:ec2:vpc`, `aws:ec2:subnet`, `aws:ec2:routetable`,
not Terraform resource types). This is a multi-resource L1: the
interface declares the group's inputs/outputs plus a `resources` array
listing the IR types it emits. The IR instance (Phase 14/15) will have
multiple `resources` entries all with `module: "l1-vpc@1.0.0"`.
## Interface (the IR-typed contract)
See `interface.json`: inputs `cidr` (string, e.g. "10.0.0.0/16"), `azs`
(string, comma-separated, e.g. "us-east-1a,us-east-1b"), `name` (string,
used for tagging), `region` (string); outputs `vpc_id` (string),
`subnet_ids` (string, comma-separated), `igw_id` (string); no NFRs.
The `resources` array lists the emitted IR types:
- `aws:ec2:vpc` — the VPC itself (cidr → cidr_block, name → tag).
- `aws:ec2:subnet` — one subnet per availability zone (`azs` split on
comma); inputs include the parent VPC id.
- `aws:ec2:routetable` — route table bound to the VPC with an internet
gateway + default route (0.0.0.0/0 → igw).
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates each
emitted IR resource to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:ec2:vpc` | `resource "aws_vpc" "<id>" { ... }` |
| `resource.inputs.cidr` | `cidr_block = <value>` arg |
| `resource.inputs.name` | `tags = { Name = <value> }` (emit as-is) |
| `resource.outputs.vpc_id` | `output "vpc_id" { value = aws_vpc.<id>.id }` |
| `resource.type = aws:ec2:subnet` | `resource "aws_subnet" "<id>" { ... }` |
| `resource.inputs.cidr` | `cidr_block = <value>` arg |
| `resource.inputs.az` | `availability_zone = <value>` arg |
| `resource.outputs.subnet_id` | `output "subnet_id" { value = aws_subnet.<id>.id }` |
| `resource.type = aws:ec2:routetable` | `resource "aws_route_table" "<id>" { ... }` |
| `resource.inputs.vpc_id` | `vpc_id = <value>` arg |
The internet gateway + default route are emitted as part of the route
table resource's IR (the `igw_id` output is wired via the route table's
inputs). The adapter is a thin layer (ARCHITECTURE.md §12.2); it does
not own L1 content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
+64
View File
@@ -0,0 +1,64 @@
{
"name": "l1-vpc",
"version": "1.0.0",
"kind": "l1",
"type": "aws:ec2:vpc",
"description": "VPC primitive (substrate-agnostic IR types aws:ec2:vpc + aws:ec2:subnet + aws:ec2:routetable; the Terraform adapter translates to aws_vpc/aws_subnet/aws_route_table).",
"inputs": {
"cidr": {
"type": "string",
"description": "VPC CIDR block, e.g. 10.0.0.0/16.",
"required": true
},
"azs": {
"type": "string",
"description": "Comma-separated availability zones, e.g. us-east-1a,us-east-1b.",
"required": true
},
"name": {
"type": "string",
"description": "Name tag for the VPC and child resources.",
"required": true
},
"region": {
"type": "string",
"description": "AWS region the VPC is created in.",
"required": true
}
},
"outputs": {
"vpc_id": {
"type": "string",
"description": "The VPC id."
},
"subnet_ids": {
"type": "string",
"description": "Comma-separated subnet ids."
},
"igw_id": {
"type": "string",
"description": "The internet gateway id."
}
},
"nfrs": {},
"resources": [
{
"type": "aws:ec2:vpc",
"description": "The VPC itself.",
"inputs": ["cidr", "name"],
"outputs": ["vpc_id"]
},
{
"type": "aws:ec2:subnet",
"description": "One subnet per availability zone (azs split on comma).",
"inputs": ["cidr", "az", "vpc_id", "name"],
"outputs": ["subnet_id"]
},
{
"type": "aws:ec2:routetable",
"description": "Route table bound to the VPC with an internet gateway + default route.",
"inputs": ["vpc_id", "igw_id", "name"],
"outputs": []
}
]
}
+85
View File
@@ -0,0 +1,85 @@
# l2-microservice — thin-composition (ECS Fargate microservice)
The v1.2 L2. A thin-composition that references 6 L1s (depth 1):
`l1-vpc`, `l1-ecs-cluster`, `l1-ecr`, `l1-iam-role`, `l1-alb`,
`l1-ecs-service`. The contract's inputs (`name`, `cidr`, `azs`,
`image`, `port`, `cpu`, `memory`, `env`, `protocol`, `region`,
`role_name`, `assume_role_policy`, `managed_policies`) map to the
children's inputs through two wire kinds.
## Composition (the IR-typed thin-composition tree)
See `composition.json`: `kind=l2`, `depth=1`, six children.
### Children
| child id | L1 module | IR type(s) |
|----------|-----------|------------|
| `vpc` | `l1-vpc@1.0.0` | `aws:ec2:vpc`, `aws:ec2:subnet`, `aws:ec2:routetable` |
| `cluster` | `l1-ecs-cluster@1.0.0` | `aws:ecs:cluster` |
| `ecr` | `l1-ecr@1.0.0` | `aws:ecr:repository` |
| `roles` | `l1-iam-role@1.0.0` | `aws:iam:role` |
| `alb` | `l1-alb@1.0.0` | `aws:elbv2:loadbalancer`, `aws:elbv2:listener`, `aws:elbv2:targetgroup` |
| `service` | `l1-ecs-service@1.0.0` | `aws:ecs:task_definition`, `aws:ecs:service` |
Multi-resource L1s (`vpc`, `alb`, `service`) declare a `resources`
array in their `interface.json`; the resolver expands each child into
one IR resource per `resources` entry (id scheme `<child_id>-<type_suffix>`
where `type_suffix` is the last segment of the IR type with underscores
stripped — e.g. `vpc-vpc`, `vpc-subnet`, `vpc-routetable`,
`alb-loadbalancer`, `alb-targetgroup`, `alb-listener`,
`service-taskdefinition`, `service-service`. The hyphen separator keeps
the id valid against `schemas/ir.schema.json`'s
`^[a-z][a-z0-9-]*$` resource id pattern). Single-resource L1s keep the
child id verbatim (`cluster`, `ecr`, `roles`).
### Wire kinds
1. **Contract→child passthrough** — wire name = contract input name;
target = child id, input = child's input name. For contract inputs
that fan out to multiple children (`name`, `port`, `region`), the
wire value is an array of `{target, input}` objects; otherwise a
single object. Resolves to the concrete contract value.
2. **Child→child references** — wire with `source: "child:<id>.<output>"`.
The value is only known at apply time, so the resolver emits the IR
input as the string `ref:<ir_resource_id>.<output>` (the IR resource
id of the *producing* child's first resource — for single-resource
L1s that is the child id, for multi-resource L1s it is
`<child_id>-<type_suffix>` of the first resource in the `resources`
array that declares the output). The adapter translates `ref:` to a
Terraform interpolation.
Wires used by this composition:
- Passthrough: `name` (→vpc/cluster/ecr/alb), `cidr` (→vpc), `azs`
(→vpc), `image` (→service), `port` (→service/alb), `cpu` (→service),
`memory` (→service), `env` (→service), `protocol` (→alb), `region`
(→all 6), `role_name` (→roles), `assume_role_policy` (→roles),
`managed_policies` (→roles).
- Child→child: `cluster_arn` (cluster→service), `subnet_ids`
(vpc→service/alb `subnets`), `target_group_arn` (alb→service
`lb_target_group_arn`), `role_arn` (roles→service/alb
`security_group`).
## IR → Terraform mapping (D-P10-1)
The Terraform adapter consumes the *resolved IR instance* (which has
`kind=l2` + all 6 L1s expanded into one IR resource per entry in each
L1's `resources` array, with `ref:` strings on the consumer inputs).
For a depth-1 thin-composition, the L2 root module **IS** the union of
the L1 resources — no separate `module "l1_x" { source = "..." }`
blocks. The existing adapter `TYPE_MAP` + `INPUT_MAP` + `OUTPUT_MAP`
tables handle every IR type. `ref:<id>.<output>` inputs are translated
to `${<tf_type>.<id>.<attr>}` (attribute mapped through `OUTPUT_MAP`
for the referenced resource's type). The `relationships` array records
the parent composition tree; ordering is implicit in the resource list.
v1.3+ may emit real `module "l1_x" { source = "..." }` blocks once L1s
are published Terraform modules rather than inline resources.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.
@@ -0,0 +1,55 @@
{
"name": "l2-microservice",
"version": "1.0.0",
"kind": "l2",
"depth": 1,
"description": "Thin-composition: an ECS Fargate microservice. References 6 L1s (vpc, cluster, ecr, roles, alb, service).",
"children": [
{"id": "vpc", "module": "l1-vpc@1.0.0"},
{"id": "cluster", "module": "l1-ecs-cluster@1.0.0"},
{"id": "ecr", "module": "l1-ecr@1.0.0"},
{"id": "roles", "module": "l1-iam-role@1.0.0"},
{"id": "alb", "module": "l1-alb@1.0.0"},
{"id": "service", "module": "l1-ecs-service@1.0.0"}
],
"wires": {
"name": [
{"target": "vpc", "input": "name"},
{"target": "cluster", "input": "name"},
{"target": "ecr", "input": "name"},
{"target": "alb", "input": "name"}
],
"cidr": {"target": "vpc", "input": "cidr"},
"azs": {"target": "vpc", "input": "azs"},
"image": {"target": "service", "input": "image"},
"port": [
{"target": "service", "input": "port"},
{"target": "alb", "input": "port"}
],
"cpu": {"target": "service", "input": "cpu"},
"memory": {"target": "service", "input": "memory"},
"env": {"target": "service", "input": "env"},
"protocol": {"target": "alb", "input": "protocol"},
"region": [
{"target": "vpc", "input": "region"},
{"target": "cluster", "input": "region"},
{"target": "ecr", "input": "region"},
{"target": "roles", "input": "region"},
{"target": "alb", "input": "region"},
{"target": "service", "input": "region"}
],
"role_name": {"target": "roles", "input": "role_name"},
"assume_role_policy": {"target": "roles", "input": "assume_role_policy"},
"managed_policies": {"target": "roles", "input": "managed_policies"},
"cluster_arn": {"target": "service", "input": "cluster_arn", "source": "child:cluster.cluster_arn"},
"subnet_ids": [
{"target": "service", "input": "subnets", "source": "child:vpc.subnet_ids"},
{"target": "alb", "input": "subnets", "source": "child:vpc.subnet_ids"}
],
"target_group_arn": {"target": "service", "input": "lb_target_group_arn", "source": "child:alb.target_group_arn"},
"role_arn": [
{"target": "service", "input": "security_group", "source": "child:roles.role_arn"},
{"target": "alb", "input": "security_group", "source": "child:roles.role_arn"}
]
}
}
+49
View File
@@ -6,11 +6,60 @@
"deprecated": false
}
},
"l1-vpc": {
"1.0.0": {
"interface": "modules-ir/l1/l1-vpc/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l1-ecs-cluster": {
"1.0.0": {
"interface": "modules-ir/l1/l1-ecs-cluster/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l1-ecs-service": {
"1.0.0": {
"interface": "modules-ir/l1/l1-ecs-service/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l1-iam-role": {
"1.0.0": {
"interface": "modules-ir/l1/l1-iam-role/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l1-alb": {
"1.0.0": {
"interface": "modules-ir/l1/l1-alb/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l1-ecr": {
"1.0.0": {
"interface": "modules-ir/l1/l1-ecr/interface.json",
"published_at": "2026-07-21T21:30:00Z",
"deprecated": false
}
},
"l2-static-asset": {
"1.0.0": {
"composition": "modules-ir/l2/l2-static-asset/composition.json",
"published_at": "2026-07-21T19:30:00Z",
"deprecated": false
}
},
"l2-microservice": {
"1.0.0": {
"composition": "modules-ir/l2/l2-microservice/composition.json",
"published_at": "2026-07-21T22:00:00Z",
"deprecated": false
}
}
}
+11 -1
View File
@@ -20,7 +20,17 @@
"inputs": {
"type": "object",
"description": "L2-level parameter map. Free-form in v1, typed per-L1 in v1.2 (W3.E).",
"additionalProperties": {"type": ["string", "number", "boolean"]}
"additionalProperties": {"type": ["string", "number", "boolean", "object"]}
},
"healthcheck": {
"type": "object",
"description": "Healthcheck config for the service.",
"properties": {
"path": {"type": "string"},
"interval": {"type": "number"},
"timeout": {"type": "number"},
"healthy_threshold": {"type": "number"}
}
},
"validation": {
"type": "object",
+103
View File
@@ -0,0 +1,103 @@
#!/usr/bin/env bash
# scripts/verify_phase13.sh - verify Phase 13 (l1-catalog-for-ecs).
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$ROOT"
fail() { echo "FAIL: $*" >&2; exit 1; }
echo "=== Phase 13 verification ==="
# 1. All 6 new L1 directories exist with interface.json + README.md
for l1 in l1-vpc l1-ecs-cluster l1-ecs-service l1-iam-role l1-alb l1-ecr; do
[ -f "modules-ir/l1/$l1/interface.json" ] || fail "modules-ir/l1/$l1/interface.json missing"
[ -f "modules-ir/l1/$l1/README.md" ] || fail "modules-ir/l1/$l1/README.md missing"
done
echo "L1 directories: OK (6 new + l1-s3)"
# 2. All 6 interface.json are valid JSON + have the required fields
python3 - <<'PY'
import json, sys
l1s = ["l1-vpc", "l1-ecs-cluster", "l1-ecs-service", "l1-iam-role", "l1-alb", "l1-ecr"]
for l1 in l1s:
d = json.load(open(f"modules-ir/l1/{l1}/interface.json"))
assert d["name"] == l1, f"{l1}: name mismatch"
assert d["version"] == "1.0.0", f"{l1}: version not 1.0.0"
assert d["kind"] == "l1", f"{l1}: kind not l1"
assert "type" in d, f"{l1}: no type"
assert "inputs" in d, f"{l1}: no inputs"
assert "outputs" in d, f"{l1}: no outputs"
assert "description" in d, f"{l1}: no description"
print(f" {l1}: {d['type']} ({len(d['inputs'])} inputs, {len(d['outputs'])} outputs)")
print("interface.json validation: OK")
PY
# 3. Registry has all 7 L1s + l2-static-asset
python3 - <<'PY'
import json
r = json.load(open("modules-ir/registry.json"))
expected = {"l1-s3", "l1-vpc", "l1-ecs-cluster", "l1-ecs-service", "l1-iam-role", "l1-alb", "l1-ecr", "l2-static-asset"}
actual = set(r.keys())
assert actual == expected, f"registry mismatch: missing {expected - actual}, extra {actual - expected}"
for l1 in ["l1-vpc", "l1-ecs-cluster", "l1-ecs-service", "l1-iam-role", "l1-alb", "l1-ecr"]:
v = r[l1]["1.0.0"]
assert v["deprecated"] is False, f"{l1}: not deprecated"
assert v["interface"].endswith("interface.json"), f"{l1}: bad interface path"
print("registry: OK (8 entries: 7 L1s + 1 L2)")
PY
# 4. Adapter TYPE_MAP has all 12 IR types
python3 - <<'PY'
import sys
sys.path.insert(0, ".")
from adapters.terraform.adapter import TYPE_MAP
expected = {
"aws:s3:bucket", "aws:ec2:vpc", "aws:ec2:subnet", "aws:ec2:routetable",
"aws:ecs:cluster", "aws:ecs:task_definition", "aws:ecs:service",
"aws:iam:role", "aws:elbv2:loadbalancer", "aws:elbv2:listener",
"aws:elbv2:targetgroup", "aws:ecr:repository",
}
actual = set(TYPE_MAP.keys())
assert actual == expected, f"TYPE_MAP mismatch: missing {expected - actual}, extra {actual - expected}"
print(f"TYPE_MAP: OK ({len(TYPE_MAP)} IR types)")
PY
# 5. Adapter py_compiles
python3 -m py_compile adapters/terraform/adapter.py || fail "adapter.py: py_compile failed"
echo "adapter.py: py_compile OK"
# 6. S3 regression: the v1.1 spike L1 still adapts correctly
WORK=/tmp/p13_verify
rm -rf "$WORK"; mkdir -p "$WORK"
python3 adapters/terraform/adapter.py modules-ir/l1/l1-s3/spike_instance.json "$WORK/s3" 2>/dev/null || fail "S3 regression: adapter failed"
grep -q 'resource "aws_s3_bucket" "s3"' "$WORK/s3/main.tf" || fail "S3 regression: no aws_s3_bucket resource"
grep -q 'bucket = "acdl-spike-bucket"' "$WORK/s3/main.tf" || fail "S3 regression: no bucket arg"
grep -q "versioning" "$WORK/s3/main.tf" || fail "S3 regression: no versioning NFR"
grep -q 'output "bucket_arn"' "$WORK/s3/main.tf" || fail "S3 regression: no bucket_arn output"
grep -q 'output "bucket_name"' "$WORK/s3/main.tf" || fail "S3 regression: no bucket_name output"
echo "S3 regression: OK (v1.1 spike l1-s3 adapts identically)"
# 7. Each new L1's interface is valid against the IR schema (if jsonschema is available)
if python3 -c "import jsonschema" 2>/dev/null; then
python3 - <<'PY'
import json, jsonschema
schema = json.load(open("schemas/ir.schema.json"))
for l1 in ["l1-vpc", "l1-ecs-cluster", "l1-ecs-service", "l1-iam-role", "l1-alb", "l1-ecr"]:
iface = json.load(open(f"modules-ir/l1/{l1}/interface.json"))
# interface.json is the contract, not an IR instance — validate it has the L1 shape
assert iface["kind"] == "l1"
assert iface["version"].count(".") == 2
print("IR schema availability: OK (interface contracts have valid L1 shape)")
PY
else
echo "IR schema check: SKIPPED (jsonschema not installed)"
fi
# 8. .ciagent/ consistency
grep -q '"milestone": "v1.2"' .ciagent/config.json || fail "config.json: milestone not v1.2"
echo ".ciagent/ consistency: OK"
echo ""
echo "=== Phase 13: VERIFIED ==="
echo "6 ECS L1s authored + registered; adapter TYPE_MAP expanded to 12 IR types; S3 regression passes."
exit 0
+100
View File
@@ -0,0 +1,100 @@
#!/usr/bin/env bash
# scripts/verify_phase14.sh - verify Phase 14 (l2-microservice-and-contract-schema).
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$ROOT"
fail() { echo "FAIL: $*" >&2; exit 1; }
echo "=== Phase 14 verification ==="
# 1. l2-microservice composition + README
[ -f modules-ir/l2/l2-microservice/composition.json ] || fail "composition.json missing"
[ -f modules-ir/l2/l2-microservice/README.md ] || fail "README.md missing"
python3 -c "import json; d=json.load(open('modules-ir/l2/l2-microservice/composition.json')); assert d['name']=='l2-microservice'; assert d['kind']=='l2'; assert d['depth']==1; assert len(d['children'])==6, f'expected 6 children, got {len(d[\"children\"])}'; print('composition: OK (6 children)')"
# 2. Registry has l2-microservice
python3 -c "import json; r=json.load(open('modules-ir/registry.json')); assert 'l2-microservice' in r; assert r['l2-microservice']['1.0.0']['deprecated']==False; print('registry: l2-microservice@1.0.0 OK')"
# 3. Contract schema extended (inputs allow objects + healthcheck field)
python3 - <<'PY'
import json
s = json.load(open("schemas/contract.schema.json"))
ap = s["properties"]["inputs"]["additionalProperties"]
assert "object" in ap["type"], "inputs.additionalProperties doesn't allow object"
assert "healthcheck" in s["properties"], "no healthcheck field"
print("contract schema: OK (inputs allow objects + healthcheck field)")
PY
# 4. contracts/microservice.yaml exists + validates
[ -f contracts/microservice.yaml ] || fail "contracts/microservice.yaml missing"
python3 - <<'PY'
import yaml, json, jsonschema
with open("contracts/microservice.yaml") as fh:
c = yaml.safe_load(fh)
assert c["stack"] == "l2-microservice", f"stack={c['stack']}"
assert c["environment"] == "dev"
assert "name" in c["inputs"]
assert "image" in c["inputs"]
assert "port" in c["inputs"]
schema = json.load(open("schemas/contract.schema.json"))
jsonschema.validate(c, schema)
print("microservice.yaml: OK (validates against contract schema)")
PY
# 5. Resolver + adapter py_compile
python3 -m py_compile acdl_platform/contract_resolver.py adapters/terraform/adapter.py || fail "py_compile failed"
echo "py_compile: OK"
# 6. v1.1 regression: spike.yaml still resolves + adapts
WORK=/tmp/p14_verify
rm -rf "$WORK"; mkdir -p "$WORK"
python3 acdl_platform/contract_resolver.py contracts/spike.yaml "$WORK/spike_ir.json" 2>/dev/null || fail "v1.1 regression: resolver failed"
python3 adapters/terraform/adapter.py "$WORK/spike_ir.json" "$WORK/spike_tf" 2>/dev/null || fail "v1.1 regression: adapter failed"
grep -q 'resource "aws_s3_bucket" "s3"' "$WORK/spike_tf/main.tf" || fail "v1.1 regression: no aws_s3_bucket"
grep -q 'bucket = "acdl-spike-bucket"' "$WORK/spike_tf/main.tf" || fail "v1.1 regression: no bucket arg"
echo "v1.1 regression: OK (spike.yaml -> l1-s3 -> aws_s3_bucket)"
# 7. v1.2 resolution: microservice.yaml -> IR with all 6 L1s' resources
python3 acdl_platform/contract_resolver.py contracts/microservice.yaml "$WORK/ms_ir.json" 2>/dev/null || fail "v1.2: resolver failed"
python3 - <<'PY'
import json
ir = json.load(open("/tmp/p14_verify/ms_ir.json"))
rsc = ir["resources"]
print(f"v1.2 IR: {len(rsc)} resources")
assert len(rsc) >= 6, f"expected >=6 resources, got {len(rsc)}"
types = {r["type"] for r in rsc}
expected_types = {"aws:ec2:vpc", "aws:ec2:subnet", "aws:ec2:routetable", "aws:ecs:cluster", "aws:ecr:repository", "aws:iam:role", "aws:elbv2:loadbalancer", "aws:elbv2:targetgroup", "aws:elbv2:listener", "aws:ecs:task_definition", "aws:ecs:service"}
assert types == expected_types, f"missing types: {expected_types - types}, extra: {types - expected_types}"
# Check child->child refs exist
ref_found = False
for r in rsc:
for v in r.get("inputs", {}).values():
if isinstance(v, str) and v.startswith("ref:"):
ref_found = True
break
assert ref_found, "no child->child refs in IR"
print(f" types: {sorted(types)}")
print(" child->child refs: present")
PY
# 8. v1.2 adaptation: IR -> TF
python3 adapters/terraform/adapter.py "$WORK/ms_ir.json" "$WORK/ms_tf" 2>/dev/null || fail "v1.2: adapter failed"
grep -q 'resource "aws_vpc"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_vpc in TF"
grep -q 'resource "aws_ecs_cluster"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_ecs_cluster in TF"
grep -q 'resource "aws_ecs_service"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_ecs_service in TF"
grep -q 'resource "aws_ecr_repository"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_ecr_repository in TF"
grep -q 'resource "aws_lb"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_lb in TF"
grep -q 'resource "aws_iam_role"' "$WORK/ms_tf/main.tf" || fail "v1.2: no aws_iam_role in TF"
# Check ref translation (interpolations present)
grep -q 'aws_ecs_cluster.cluster.arn' "$WORK/ms_tf/main.tf" || fail "v1.2: no cluster.arn interpolation"
echo "v1.2 adaptation: OK (11 resources + interpolations in main.tf)"
# 9. .ciagent/ consistency
grep -q '"milestone": "v1.2"' .ciagent/config.json || fail "config.json: milestone not v1.2"
echo ".ciagent/ consistency: OK"
echo ""
echo "=== Phase 14: VERIFIED ==="
echo "l2-microservice composition (6 L1s); contract schema extended; resolver child->child wiring; 11 IR resources; TF valid."
exit 0