AWSStatic-verified

Global Accelerator with Health-Checked Failover

Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.

terraformAWSaws
aws-global-acceleratorvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan pending (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "global_accelerator" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-global-accelerator/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-global-accelerator

Global Accelerator with listeners, per-region endpoint groups, health checks and traffic dials. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Defaults worth knowing:

  • Client IP preservation is off. Turning it on makes the origin see the real client address, which is usually what you want - but the origin's security groups must then permit the internet rather than the accelerator, and it is not supported for every endpoint type. Switching it on without changing the security groups produces a service reachable from nowhere
  • client_affinity defaults to NONE. SOURCE_IP pins a client to one endpoint, which a stateful backend needs and a stateless one pays for in uneven distribution
  • traffic_dial_percentage is how a region is drained: set it to 0 and the group stays present and health-checked while taking no traffic
  • Flow logs are offered because otherwise nothing records who reached the accelerator

Note that an accelerator bills a fixed hourly charge whether or not it is enabled, plus data transfer. enabled = false does not make it free.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules