A Migration that Is Not in Clear Text
ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "dms" {
source = "www.iac-bazaar.com/iac-bazaar/aws-dms/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-dms
A Database Migration Service replication instance, its endpoints and its tasks.
Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
ssl_mode defaults to none in AWS. A DMS task reads your entire
production database and writes it somewhere else; with none it does that in
clear text across whatever network sits between. This module defaults to
require, and a precondition refuses none unless you state it - because this
is the one setting where the gap between the AWS default and the right answer is
your whole dataset on the wire. plaintext_endpoints is an output so the answer
is checkable.
The password is the other half of the same problem. password on an
endpoint is written to the state file in plain text. DMS also accepts a Secrets
Manager secret plus a role, and a precondition requires exactly one of the
two shapes - so an endpoint cannot end up with a secret configured and a
forgotten password beside it. endpoints_with_password_in_state lists the ones
that took the plaintext route.
publicly_accessible puts the replication instance on the internet. Off is
not the same as unreachable - it still reaches the databases through the VPC.
The usual reason it ends up on is that somebody was debugging connectivity and
never turned it back, so turning it on here is an explicit statement.
Preconditions also catch what DMS reports late:
verify-caandverify-fullneedcertificate_arn, and the other modes do not use itsecrets_manager_arnwithout the access role, which DMS assumes to read it- a one-subnet replication subnet group
replication_instance_private_ips is an output because allowing those addresses
on both databases' firewalls is the step that is usually missing, and the
failure looks like a timeout rather than a permission error.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-athena
Query results are a copy of the data, written to S3. Without enforce_workgroup_configuration - the AWS default - a client sends its own location and encryption and every setting becomes a suggestion.
aws-aurora
Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.
aws-documentdb
A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.
aws-dynamodb-table
DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.
aws-elasticache-redis
A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.
aws-memorydb
Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.