Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "site_to_site_vpn" {
source = "www.iac-bazaar.com/iac-bazaar/aws-site-to-site-vpn/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-site-to-site-vpn
Site-to-Site VPN: customer gateway, connection, static routes and propagation,
attached to either a VPN gateway or a Transit Gateway. Works with Terraform
and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
Secure defaults:
- Modern crypto, not the API defaults. IKEv2 only, DH groups 14 and above, AES-256, SHA-2. The API still permits DH group 2, AES-128 and SHA-1
- Preshared keys are deliberately not inputs. A PSK passed as a Terraform variable lands in state in plain text and usually in a tfvars file beside it. AWS generates one per tunnel; if you must pin them, inject them at apply time from a secret store
- Static routing by default: a dynamic peer can advertise a prefix you did not expect and win the route
startup_action = "start", so AWS brings the tunnel up rather than waiting for a device that may be behind NAT- Tunnel logging is offered prominently, because without it nobody can say why a tunnel dropped
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-client-vpn
Remote-access VPN endpoint with certificate or SAML authentication, split tunnelling, per-group authorization rules and connection logging. There is no allow-all shortcut: an endpoint with no rule reaches nothing.
aws-cloud-map
Private DNS, public DNS or API-only namespaces and the services registered in them. Documents the health-check trap: a private namespace gets a custom check that something else must update, and one nobody updates reports healthy forever.
aws-cloud-wan
A global network whose segments, routing and attachment placement live in one policy document rather than per-region route tables. The policy VERSION is executed as a second step, so a change cannot report success while the network still runs the previous one.
aws-vpc
Battle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.
aws-transit-gateway
Hub-and-spoke Transit Gateway with its own route tables, VPC attachments, static and blackhole routes, and RAM sharing. Default route table association and propagation are off, so an attachment joins a routing domain because you said so rather than by default.
aws-vpc-endpoints
Free gateway endpoints for S3 and DynamoDB, interface endpoints for everything else, and a security group that opens 443 to the VPC rather than the world. Interface endpoints are listed explicitly because each bills per hour per availability zone.