AWSStatic-verified

A Migration that Is Not in Clear Text

ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.

terraformAWSaws
aws-dmsvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "dms" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-dms/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-dms

A Database Migration Service replication instance, its endpoints and its tasks. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

ssl_mode defaults to none in AWS. A DMS task reads your entire production database and writes it somewhere else; with none it does that in clear text across whatever network sits between. This module defaults to require, and a precondition refuses none unless you state it - because this is the one setting where the gap between the AWS default and the right answer is your whole dataset on the wire. plaintext_endpoints is an output so the answer is checkable.

The password is the other half of the same problem. password on an endpoint is written to the state file in plain text. DMS also accepts a Secrets Manager secret plus a role, and a precondition requires exactly one of the two shapes - so an endpoint cannot end up with a secret configured and a forgotten password beside it. endpoints_with_password_in_state lists the ones that took the plaintext route.

publicly_accessible puts the replication instance on the internet. Off is not the same as unreachable - it still reaches the databases through the VPC. The usual reason it ends up on is that somebody was debugging connectivity and never turned it back, so turning it on here is an explicit statement.

Preconditions also catch what DMS reports late:

  • verify-ca and verify-full need certificate_arn, and the other modes do not use it
  • secrets_manager_arn without the access role, which DMS assumes to read it
  • a one-subnet replication subnet group

replication_instance_private_ips is an output because allowing those addresses on both databases' firewalls is the step that is usually missing, and the failure looks like a timeout rather than a permission error.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules