AWSStatic-verified

Managed SFTP where a Rebuild Keeps Its Host Key

SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.

terraformAWSaws
aws-transfer-familyvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan: findings disclosed (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "transfer_family" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-transfer-family/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-transfer-family

A managed SFTP, FTPS or FTP server in front of S3, with its users and their keys. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

FTP is in the protocol list and encrypts nothing - not the credentials, not the files. AWS restricts it to VPC endpoints, which is the only reason it is not worse. The module refuses it unless allow_plaintext_ftp says so, because "the partner's client only does FTP" is how it gets turned on, and the credential crosses the wire either way.

A rebuilt server gets a new host key. With host_key null AWS generates one, and it does not survive replacing the server. Every client then reports that the host key changed - the warning that means a machine-in-the-middle - and the usual fix is to tell people to accept it. After the second time nobody reads it. Supplying your own key makes a rebuild invisible, and host_key_survives_rebuild is an output so the answer is visible before the rebuild.

security_policy_name is a date in disguise. The default accepts ciphers that were reasonable when it was written, and nothing complains when they stop being.

For users, home_directory_type = "LOGICAL" is the default here and worth the extra lines: a PATH home directory lets the user see the bucket name and every sibling prefix in it, while LOGICAL shows a root that maps only to what they may reach. session_policy then narrows the role per user, so one role serves many partners without any of them reaching another's prefix.

Preconditions refuse FTP on a public endpoint, FTPS with no certificate, a LOGICAL home with no mappings, and - unless you say otherwise - a server whose transfers nothing records.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • What the security scan reports

Related modules