AWSStatic-verified

Firewall Manager Org-Wide Policy

WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.

terraformAWSaws
aws-firewall-managervizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan pending (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "firewall_manager" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-firewall-manager/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-firewall-manager

Firewall Manager policies applied across an organization: WAF, security group audit, Network Firewall and DNS Firewall. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

remediation_enabled is the whole decision. With it off, a policy reports which accounts do not comply and changes nothing - useful as a survey, useless as a control. With it on, Firewall Manager edits resources in member accounts to match, which is the point and also the risk: a carelessly written policy can detach a web ACL something depended on.

It defaults to off here, so the first apply produces a report you can read before it produces changes you did not expect. remediating_policies in the outputs names every policy that will edit rather than report, so the difference is visible in a plan review.

Other things worth knowing:

  • Exclusions beat inclusions in the API, so naming both is how a carve-out is stated rather than implied
  • managed_service_data is the service-specific JSON blob, passed through verbatim so this module does not lag its schema. It is validated as JSON
  • delete_all_policy_resources decides whether deleting the policy also removes what it created in every member account

Firewall Manager requires an organization, an administrator account, and AWS Config enabled in the accounts in scope.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules