An Origin Health Check That Validates the Certificate and Reads the Body
A health check on an origin with allow_insecure false, since an origin whose certificate expired last week passes a check that was told not to look. expected_body is what tests the application rather than the web server, because an error page, a maintenance page and a page saying the database is unreachable are all 200s. Two consecutive failures, not one.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-15 · how we verify
Use it from the registry
terraform · opentofumodule "health_check" {
source = "www.iac-bazaar.com/iac-bazaar/cloudflare-health-check/cloudflare"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
cloudflare-health-check
An origin health check on Cloudflare. Works with Terraform and OpenTofu
(>= 1.6), cloudflare provider >= 5.0, < 6.0.
allow_insecure turns off certificate validation and the check still goes green - an origin whose certificate expired last week passes a check that was told not to look.
A 200 is not proof the application works. An error page, a maintenance page and a page saying the database is unreachable are all 200s; expected_body is what tests the application instead of the web server.
One failure is a blip, not an outage. consecutive_fails at one turns a lost packet into a failover.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
cloudflare-notification-policy
An origin marked unreachable, a certificate that failed to renew, a DDoS mitigation on your zone: each is an event the account can notify about and none does until a policy exists, and a policy whose mechanisms block is empty is accepted and notifies nobody. Origin health, certificate and DDoS policies by default, more by alert type, and at least one email or webhook required for all of them.
aws-route53-health-check
A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.
do-uptime-check
An uptime check and its alerts, which are separate resources: a check on its own draws a graph somebody would have to go and look at and pages nobody, and it looks identical to one that does. Three regions by default, since one cannot tell the target being down apart from that region's path to it. The latency alert is the one that catches the slow death.
gcp-uptime-check
A Cloud Monitoring uptime check from static-address checkers in several regions, over TLS with the certificate validated (off by default), asserting on the body when you give it text, with failures logged, and the alert policy on check_passed that sends to your notification channels. Plain HTTP and a policy with no channels are each accepted by name.
oci-health-checks
A monitor can be created disabled and probes nothing; one vantage point reports the site down when that location is; and a monitor is a metric, not an alarm - nothing pages until Monitoring reads it. Enabled monitors over HTTPS from three regions by default, and the MQL query each one needs in an alarm exported for the oci-monitoring-alarms module.