Managed SFTP where a Rebuild Keeps Its Host Key
SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan: findings disclosed (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "transfer_family" {
source = "www.iac-bazaar.com/iac-bazaar/aws-transfer-family/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-transfer-family
A managed SFTP, FTPS or FTP server in front of S3, with its users and their
keys. Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0.
FTP is in the protocol list and encrypts nothing - not the credentials, not
the files. AWS restricts it to VPC endpoints, which is the only reason it is not
worse. The module refuses it unless allow_plaintext_ftp says so, because "the
partner's client only does FTP" is how it gets turned on, and the credential
crosses the wire either way.
A rebuilt server gets a new host key. With host_key null AWS generates
one, and it does not survive replacing the server. Every client then reports
that the host key changed - the warning that means a machine-in-the-middle - and
the usual fix is to tell people to accept it. After the second time nobody reads
it. Supplying your own key makes a rebuild invisible, and
host_key_survives_rebuild is an output so the answer is visible before the
rebuild.
security_policy_name is a date in disguise. The default accepts ciphers
that were reasonable when it was written, and nothing complains when they stop
being.
For users, home_directory_type = "LOGICAL" is the default here and worth the
extra lines: a PATH home directory lets the user see the bucket name and every
sibling prefix in it, while LOGICAL shows a root that maps only to what they may
reach. session_policy then narrows the role per user, so one role serves many
partners without any of them reaching another's prefix.
Preconditions refuse FTP on a public endpoint, FTPS with no certificate, a LOGICAL home with no mappings, and - unless you say otherwise - a server whose transfers nothing records.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- What the security scan reports
Related modules
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
aws-backup
A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.
aws-efs
An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.
aws-ebs-volume
Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.
aws-fsx-lustre
A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.