OpenSearch Domain that Refuses to Be Public
A VPC domain with fine-grained access control and the three encryption settings that cannot be added afterwards. Building a public endpoint takes an explicit opt-in, because a public domain with a permissive policy is how this service leaks databases.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "opensearch" {
source = "www.iac-bazaar.com/iac-bazaar/aws-opensearch/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-opensearch
An Amazon OpenSearch Service domain, placed in a VPC, with fine-grained access
control and the three encryption settings that cannot be added later. Works with
Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
The failure mode this service is known for is a domain with a public endpoint and a permissive access policy. It has leaked medical records, voter rolls and customer databases, repeatedly, and every time the cause was those two settings together. So:
- Passing
subnet_idsplaces the domain in a VPC - Leaving them null builds a public endpoint, and a precondition refuses that
unless
allow_public_endpoint = truesays you meant it access_policiesdefaults to unset, so authorization is done by the fine-grained roles inside the domain rather than a policy with a wildcard principal
Three settings are not variables: encryption at rest, node-to-node encryption, and HTTPS enforcement. All three are settable only at creation or through a blue/green deployment, so a domain created without them stays without them.
Fine-grained access control uses an IAM principal (master_user_arn), not
the internal user database. An internal master means a password in the state
file and a second identity system to rotate.
Preconditions that catch what the API reports late or not at all:
instance_countmust divide evenly acrossavailability_zonesdedicated_master_countmust be 3 or 5 - an even number cannot break a tie, and 1 is not a quorumlog_typesset with nolog_group_arnmeans logs with nowhere to go
dedicated_master_enabled defaults to off, which runs cluster state on the
nodes that also serve queries - survivable on a small domain, and the reason the
default is cheap rather than safe. The example turns it on, because anything
carrying production traffic should.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-aurora
Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.
aws-documentdb
A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.
aws-dynamodb-table
DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.
aws-elasticache-redis
A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.
aws-memorydb
Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.
aws-rds
Single-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.