Tencent CloudStatic-verified

Tencent Cloud VPC Foundation

VPC with subnets, route tables, NAT, and security groups across AZs.

terraformAlt & Specialty Cloudstencentcloud

Compare Virtual Private Cloud (VPC) across clouds →

tencent-vpc-foundationvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o tencent-vpc-foundation-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/tencent-vpc-foundation/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle tencent-vpc-foundation-1.0.0.sigstore.json \
  tencent-vpc-foundation-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "b339b22d63b8a363509719966d736f76293c4885ca51f23e3138cee3a9f8f06f  tencent-vpc-foundation-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "vpc_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/tencent-vpc-foundation/tencentcloud"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: static-verified](https://www.iac-bazaar.com/api/artifacts/tencent-vpc-foundation/badge)](https://www.iac-bazaar.com/catalog/tencent-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, static-verified on IaC Bazaar: [Tencent Cloud VPC Foundation](https://www.iac-bazaar.com/catalog/tencent-vpc-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "vpc_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/tencent-vpc-foundation/tencentcloud"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: static-verified

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

tencent-vpc-foundation

A production-ready Tencent Cloud network foundation: a multi-AZ VPC with subnets, a standard NAT gateway (EIP + per-subnet SNAT and a default route for outbound-only internet egress), and a least-privilege base security group. Subnets opt in to internet egress one at a time; everything else stays private with no public addressing.

Status: static-validated, live-test pending. Validated with tofu validate + tflint + checkov against the tencentcloudstack/tencentcloud provider. Not yet applied against a live Tencent Cloud account (no sandbox subscription), so it ships under live-test quarantine.

Design & secure defaults

  • No inbound exposure by default. The base security group denies all inbound traffic until you declare ingress_rules; egress is allowed and (optionally) intra-VPC traffic is permitted via allow_intra_security_group.
  • Outbound-only egress. Only subnets with nat = true get a default route to the NAT gateway and a matching SNAT entry. There is no internet gateway and no public IP on any instance, so workloads are never directly addressable.
  • Two route tables, explicit isolation. Private subnets attach to a route table with only the implicit local route (no 0.0.0.0/0); NAT subnets attach to a separate table whose default route points at the NAT gateway.
  • Standard (v2) NAT gateway by default, with a traffic-billed EIP, so nat_bandwidth_mbps is a ceiling on the EIP's egress. Standard NAT fixes the gateway's own bandwidth and concurrency, so nat_bandwidth_mbps/ nat_max_concurrent only size the gateway when you opt into traditional NAT (nat_product_version = 1). Tencent accepts only fixed tiers, which the variables validate.

Provider

tencentcloudstack/tencentcloud >= 1.81.0, < 2.0. Requires Terraform/OpenTofu >= 1.6.

License

Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Key inputs
  • Outputs

Related modules

Static validatedLive test pending

tencent-ccn

A Tencent Cloud CCN (pay-as-you-go; prepaid bandwidth by name) with the route tables you name and a VPC attachment per VPC on the current v2 resource, each bound to one table so the default routing domain is never used. Route propagation policies between tables are the next resource to add.

View module
Static validatedLive test pending

tencent-direct-connect

A Direct Connect gateway terminating a dedicated circuit into a VPC or a CCN. Attaching one to a CCN creates the attachment and no routes, so the CCN has no way back to your premises while everything reports healthy; an empty route list on a CCN gateway is refused here. NAT mode rewrites your addresses and has to be chosen rather than inherited.

View module
Static validatedLive test pending

tencent-nat-gateway

A standard NAT gateway for an existing Tencent Cloud VPC, with a traffic-billed elastic IP, a bandwidth and concurrency tier of its own, and a default route entry written in every route table listed, because a gateway no table routes to forwards nothing. The elastic IP's cap and the gateway's tier are the two numbers to raise when downloads crawl.

View module
Static validatedLive test pending

tencent-vpc-peering

A peering connection between two VPCs with a route table entry written into every route table you list, on both sides, for every CIDR of the other side, because an Active peering carries nothing until the routes exist. POSTPAID by default: PREPAID buys a bandwidth tier for a term that can be raised and never lowered, so it has to be accepted by name.

View module
Static validatedLive test pending

tencent-privatelink-endpoint

A Tencent Cloud Private Link endpoint to an endpoint service, with a VIP in the subnet you name behind the security groups you name; an endpoint with no security group is reachable from the whole VPC and has to be accepted by name. One subnet per endpoint; a second zone is a second endpoint.

View module
Static validatedLive test pending

tencent-vpn-gateway

A Tencent Cloud VPN gateway (pay-by-hour; prepaid by name) with a customer gateway and one policy-based IPsec connection on IKEv2 negotiating AES-CBC-256, SHA-256 and DH group 14 in both phases. Tencent's own defaults are 3DES, MD5 and group 1; the validations refuse them, IKEv1 is accepted only by name, and dead peer detection restarts a dead tunnel.

View module