Tencent TKE Cluster
Managed TKE Kubernetes with node pools and VPC-CNI networking.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o tencent-tke-cluster-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/tencent-tke-cluster/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle tencent-tke-cluster-1.0.0.sigstore.json \
tencent-tke-cluster-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "529c00929dd752bd3cc4a406a6587b9d3afe0bb8d387f3b105beead7ff9c9bbf tencent-tke-cluster-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "tke_cluster" {
source = "www.iac-bazaar.com/iac-bazaar/tencent-tke-cluster/tencentcloud"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Premium, so its contract unlocks when you buy it.
Documentation
tencent-tke-cluster
A production-ready Tencent Kubernetes Engine (TKE) managed cluster with
VPC-CNI networking and autoscaling worker node pools. It pins one
opinionated path — managed control plane, VPC-CNI, and node pools attached
separately from the cluster — so the cluster does not churn when worker shapes
change. Bring your own VPC and private subnets (e.g. from
tencent-vpc-foundation).
Status: static-validated, live-test pending. Validated with
tofu validate+tflint+checkovagainst thetencentcloudstack/tencentcloudprovider. Not yet applied against a live Tencent Cloud account (no sandbox subscription), so it ships under live-test quarantine.
Design & secure defaults
- Private API server by default. The public endpoint is off; the cluster is reachable over the intranet endpoint (or via a bastion/VPN). Turning on the internet endpoint is gated by a precondition that forces you to supply a fronting security group.
- No inline
worker_config. The cluster is created with zero inline workers; all capacity comes fromtencentcloud_kubernetes_node_pool. This avoids the well-known TKE foot-gun where changingworker_configforces the entire cluster to be recreated. - VPC-CNI networking. Pods receive real VPC ENI IPs from
eni_subnet_ids, which enables KubernetesNetworkPolicyand direct in-VPC addressing. - Deletion protection on, so an accidental API/console delete is blocked (Terraform destroy still requires flipping it off first).
- Audit + event logs to CLS. API-server audit logging and Kubernetes event persistence are on by default and ship to Cloud Log Service for forensics.
- Encrypted, private nodes. Worker data disks are encrypted; nodes get no public IP and egress through the VPC's NAT.
Provider
tencentcloudstack/tencentcloud >= 1.81.0, < 2.0. Requires Terraform/OpenTofu
>= 1.6.
License
Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Key inputs
- Outputs
Related modules
Alibaba Cloud ACK Cluster
Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.
Azure Kubernetes Service Cluster
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
Civo Kubernetes Cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
DigitalOcean DOKS Cluster
Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.
EKS Cluster with Managed Node Groups
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
Exoscale SKS Cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.