Tencent Cloud VPC Foundation
VPC with subnets, route tables, NAT, and security groups across AZs.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o tencent-vpc-foundation-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/tencent-vpc-foundation/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle tencent-vpc-foundation-1.0.0.sigstore.json \
tencent-vpc-foundation-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "b339b22d63b8a363509719966d736f76293c4885ca51f23e3138cee3a9f8f06f tencent-vpc-foundation-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "vpc_foundation" {
source = "www.iac-bazaar.com/iac-bazaar/tencent-vpc-foundation/tencentcloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/tencent-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, static-verified on IaC Bazaar: [Tencent Cloud VPC Foundation](https://www.iac-bazaar.com/catalog/tencent-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "vpc_foundation" {
source = "www.iac-bazaar.com/iac-bazaar/tencent-vpc-foundation/tencentcloud"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
tencent-vpc-foundation
A production-ready Tencent Cloud network foundation: a multi-AZ VPC with subnets, a standard NAT gateway (EIP + per-subnet SNAT and a default route for outbound-only internet egress), and a least-privilege base security group. Subnets opt in to internet egress one at a time; everything else stays private with no public addressing.
Status: static-validated, live-test pending. Validated with
tofu validate+tflint+checkovagainst thetencentcloudstack/tencentcloudprovider. Not yet applied against a live Tencent Cloud account (no sandbox subscription), so it ships under live-test quarantine.
Design & secure defaults
- No inbound exposure by default. The base security group denies all
inbound traffic until you declare
ingress_rules; egress is allowed and (optionally) intra-VPC traffic is permitted viaallow_intra_security_group. - Outbound-only egress. Only subnets with
nat = trueget a default route to the NAT gateway and a matching SNAT entry. There is no internet gateway and no public IP on any instance, so workloads are never directly addressable. - Two route tables, explicit isolation. Private subnets attach to a route
table with only the implicit local route (no
0.0.0.0/0); NAT subnets attach to a separate table whose default route points at the NAT gateway. - Standard (v2) NAT gateway by default, with a traffic-billed EIP, so
nat_bandwidth_mbpsis a ceiling on the EIP's egress. Standard NAT fixes the gateway's own bandwidth and concurrency, sonat_bandwidth_mbps/nat_max_concurrentonly size the gateway when you opt into traditional NAT (nat_product_version = 1). Tencent accepts only fixed tiers, which the variables validate.
Provider
tencentcloudstack/tencentcloud >= 1.81.0, < 2.0. Requires Terraform/OpenTofu
>= 1.6.
License
Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Key inputs
- Outputs
Related modules
tencent-ccn
A Tencent Cloud CCN (pay-as-you-go; prepaid bandwidth by name) with the route tables you name and a VPC attachment per VPC on the current v2 resource, each bound to one table so the default routing domain is never used. Route propagation policies between tables are the next resource to add.
tencent-direct-connect
A Direct Connect gateway terminating a dedicated circuit into a VPC or a CCN. Attaching one to a CCN creates the attachment and no routes, so the CCN has no way back to your premises while everything reports healthy; an empty route list on a CCN gateway is refused here. NAT mode rewrites your addresses and has to be chosen rather than inherited.
tencent-nat-gateway
A standard NAT gateway for an existing Tencent Cloud VPC, with a traffic-billed elastic IP, a bandwidth and concurrency tier of its own, and a default route entry written in every route table listed, because a gateway no table routes to forwards nothing. The elastic IP's cap and the gateway's tier are the two numbers to raise when downloads crawl.
tencent-vpc-peering
A peering connection between two VPCs with a route table entry written into every route table you list, on both sides, for every CIDR of the other side, because an Active peering carries nothing until the routes exist. POSTPAID by default: PREPAID buys a bandwidth tier for a term that can be raised and never lowered, so it has to be accepted by name.
tencent-privatelink-endpoint
A Tencent Cloud Private Link endpoint to an endpoint service, with a VIP in the subnet you name behind the security groups you name; an endpoint with no security group is reachable from the whole VPC and has to be accepted by name. One subnet per endpoint; a second zone is a second endpoint.
tencent-vpn-gateway
A Tencent Cloud VPN gateway (pay-by-hour; prepaid by name) with a customer gateway and one policy-based IPsec connection on IKEv2 negotiating AES-CBC-256, SHA-256 and DH group 14 in both phases. Tencent's own defaults are 3DES, MD5 and group 1; the validations refuse them, IKEv1 is accepted only by name, and dead peer detection restarts a dead tunnel.