FSx for Lustre, Persistent by Default
A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "fsx_lustre" {
source = "www.iac-bazaar.com/iac-bazaar/aws-fsx-lustre/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-fsx-lustre
An FSx for Lustre file system, with the S3 link, root squash and backup settings
that decide whether it is a scratch pad or storage. Works with Terraform and
OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
Deployment type is a durability decision, and the names do not say so.
SCRATCH_1/SCRATCH_2are not replicated. A single file server failing loses the data that was on it, and AWS documents that as expected behaviour rather than an incident. Scratch exists for data you can regenerate - a working copy of something that lives in S3PERSISTENT_1/PERSISTENT_2replicate within the availability zone and support backups
This module defaults to PERSISTENT_2, and its preconditions refuse the
combinations FSx rejects at apply time - or accepts quietly:
backup_retention_dayson a scratch file system. There is nothing to back up from and nothing to fall back onkms_key_arnon a scratch file system, which uses an AWS-owned keyHDDstorage outsidePERSISTENT_1s3_export_pathwith nos3_import_path: no linked bucket to export to- User-provisioned metadata IOPS outside
PERSISTENT_2
Two other defaults:
data_compression_typeisLZ4. AWS defaults it toNONE, so an uncompressed file system bills for every byte it did not need to store, and turning it on costs nothingroot_squashis offered and documented. Without it, root on any machine that can mount the file system is root on every file in it
The mount_command output is the full client mount line, because the mount name
is a computed field people look up by hand.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
aws-backup
A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.
aws-efs
An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.
aws-ebs-volume
Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.