Alibaba CloudPlan-validated

Alibaba Cloud VPC Foundation

Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.

terraformAlt & Specialty Cloudsalicloud

Compare Virtual Private Cloud (VPC) across clouds →

alicloud-vpc-foundationvizier v1.2.0

Verification

Plan-validated

Passed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o alicloud-vpc-foundation-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/alicloud-vpc-foundation/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle alicloud-vpc-foundation-1.0.0.sigstore.json \
  alicloud-vpc-foundation-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "0adc1dd0326c04f0a8bfb363b182e3c374416463abe5c272f9a1146f2a13108d  alicloud-vpc-foundation-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "vpc_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/alicloud-vpc-foundation/alicloud"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: plan-validated](https://www.iac-bazaar.com/api/artifacts/alicloud-vpc-foundation/badge)](https://www.iac-bazaar.com/catalog/alicloud-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, plan-validated on IaC Bazaar: [Alibaba Cloud VPC Foundation](https://www.iac-bazaar.com/catalog/alicloud-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "vpc_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/alicloud-vpc-foundation/alicloud"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: plan-validated

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

alicloud-vpc-foundation

A production-ready Alibaba Cloud (Aliyun) network foundation: a multi-AZ VPC with vSwitches, an enhanced NAT gateway (EIP + per-vSwitch SNAT for outbound-only internet egress), a least-privilege base security group, and optional VPC flow logs into Log Service (SLS).

Status: static-validated, live-test pending. Validated with tofu validate + tflint + checkov against the aliyun/alicloud provider. Not yet applied against a live Alibaba Cloud account (no sandbox subscription), so it ships under live-test quarantine.

Design & secure defaults

  • No inbound exposure by default. The base security group allows egress and (optionally) intra-group traffic; nothing is reachable from the internet until you declare ingress_rules.
  • Outbound-only egress. Only vSwitches with nat = true get SNAT internet access through the NAT gateway — there is no Internet Gateway, so instances are never directly addressable.
  • Enhanced NAT (nat_type = "Enhanced"), the current generation; the bound EIP is billed PayByTraffic, so nat_eip_bandwidth_mbps is a ceiling.
  • Flow logs are opt-in and validated: enabling them without an existing SLS project/logstore fails at plan time via a precondition.

Provider

aliyun/alicloud >= 1.0, < 2.0. Requires Terraform/OpenTofu >= 1.6.

License

Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Key inputs
  • Outputs

Related modules

Static validatedLive test pending

alicloud-cen-transit-router

An Alibaba Cloud CEN instance with an Enterprise Edition transit router, the route tables you name, and a VPC attachment per VPC with an interface per zone (one zone by name), each associated with one route table and propagating into the tables you list. The default route table is never used, so no VPC reaches another until you say so.

View module
Static validatedLive test pending

alicloud-privatelink-endpoint

An Alibaba Cloud PrivateLink endpoint to a PrivateLink service or an Alibaba Cloud service, with an elastic network interface in each vSwitch you name (one zone has to be accepted by name), behind the security groups you name, and protected from deletion until the protection is turned off.

View module
Static validatedLive test pending

alicloud-vpc-peering

A peer connection between two VPCs with a route entry written into every route table you list, on both sides, for every CIDR of the other side, because an Activated peering carries nothing until the routes exist. A default route through a peering is refused, and a cross-account peering that the other account has yet to accept has to be taken by name.

View module
Static validatedLive test pending

alicloud-vpn-gateway

An Alibaba Cloud VPN gateway (pay-as-you-go; subscription by name) with a customer gateway and one IPsec connection on IKEv2 negotiating AES-256, SHA-256 and DH group 14 in both phases, the weak options refused by validation and IKEv1 accepted only by name, dead peer detection and NAT traversal on, and the remote subnets' routes written for you.

View module
Static validatedLive test pending

alicloud-express-connect

A virtual border router on a physical connection you already have, with BFD on so a dead circuit is noticed in milliseconds rather than at the BGP hold timer, and an optional Express Connect Router attachment. Without that attachment the circuit terminates at the border router, which looks like a working connection and routes nothing. Sitelink is billed and off.

View module
Static validatedLive test pending

alicloud-nat-gateway

An enhanced, pay-as-you-go NAT gateway for an existing Alibaba Cloud VPC, with a PayByTraffic elastic IP whose bandwidth cap every subnet shares, and an SNAT entry for each vSwitch listed, because a gateway with no SNAT entry forwards nothing. Deletion protection is on for the gateway and the address; off has to be accepted by name.

View module