A Kafka Cluster Where a Misspelled Topic Fails Instead of Being Created
A DMS Kafka instance with enable_auto_topic off, because a producer that misspells a topic otherwise creates one: the messages go somewhere real, nothing errors, and nobody consumes them. TLS and SASL are both on, which is what makes the user mean anything; the disk is encrypted at creation; and what happens when the disk fills is a decision you take.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-15 · how we verify
Use it from the registry
terraform · opentofumodule "kafka_streaming" {
source = "www.iac-bazaar.com/iac-bazaar/huawei-kafka-streaming/huaweicloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
huawei-kafka-streaming
A managed Kafka cluster on Huawei Cloud Distributed Message Service. Works with Terraform and OpenTofu
(>= 1.6), huaweicloud provider >= 1.60, < 2.0.
enable_auto_topic turns a typo into a topic. A producer that misspells a name creates one instead of failing, so the messages go somewhere real, nothing errors, and nobody consumes them. Off here.
ssl_enable off is plaintext, and without SASL there is no authentication at all - any client reaching the VPC can read or write any topic. Both are on, which is what makes the user and password mean something.
retention_policy decides what happens when the disk fills: time_base deletes the oldest messages quietly, produce_reject stops the producers loudly. That is a business decision, so the module makes you take it.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-mq
deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.
aws-kinesis-firehose
Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.
tencent-tdmq-queue
A TDMQ for Pulsar cluster and its namespaces. msg_ttl is how long an UNACKNOWLEDGED message lives, not how long consumed ones are kept: too short silently drops work when a consumer is slow, too long turns a stuck consumer into unbounded backlog, and both extremes are refused. Retention is the separate thing that lets a new subscription read history.
oci-queue
dead_letter_queue_delivery_count defaults to zero, which is no dead-letter queue: a message a consumer cannot process is redelivered after every visibility timeout until retention expires, a poison message that holds a consumer for a day. Five deliveries then the dead-letter queue, seven days of retention instead of one, and a vault key instead of an Oracle-managed one.
oci-streaming
A public stream pool is an FQDN reachable from anywhere with a valid token; auto_create_topics lets any producer create a stream by writing to a new name; retention defaults to 24 hours, so a consumer a day behind loses data with no error on the producer side. Private endpoint behind NSGs, declared streams, seven days of retention, and the stream that loses data soonest reported as an output.
alicloud-mns-queue
A Message Service queue with a dead-letter queue that receives a message after five failed receives, long polling, logging on (it is off by default and is the only record of what was sent), and server-side encryption with your KMS key on both queues (the service key by name).