Module catalog

Find infrastructure. Inspect the evidence.

Showing 901 of 901 modules

Modules matching these filters

Open A B2C Tenant Where Its Customer Directory Should Live, on the Tier the Features Need

azure-b2c

An Azure AD B2C tenant created where its customer directory should live, on PremiumP1 or P2, linked to the subscription that pays per monthly active user. Data residency and the onmicrosoft.com name are chosen once and cannot change; user flows, policies and app registrations are configured inside the tenant with an azuread provider pointed at the exported tenant ID.

Static validated · Live test pendingAzureTerraform
Open A Backup Policy that Selects by Tag, Backs Up Daily and Copies to a Second Region

ibm-backup-policy

Backup for VPC: a policy that selects volumes (or instances) carrying the tags you name, a daily plan that keeps snapshots thirty days and copies the user tags across, and a copy of each snapshot to a second region with an encryption key of yours there; a single region is accepted by name. A policy with no plan backs up nothing; the plan is created here.

Static validated · Live test pendingIBM CloudTerraform
Open A Backup Vault with Enforced Retention and Resources that Follow It

gcp-backup-dr

The vault and the plan are what the console shows; the association is what makes a backup exist, and a plan associated with nothing backs up nothing. Enforced retention is the setting ransomware cannot undo - no backup younger than it can be deleted by anyone - and WITHIN_PROJECT access lets a compromised owner restore everything. Resources come with the plan; 14 days enforced; org-scoped.

Static validated · Live test pendingGoogle CloudTerraform
Open A Bastion That Carves a Range Out of Your VPC and Caps What You Can Register

tencent-bastion

A Tencent Bastion Host deployment. cidr_block is a range the service claims inside your VPC and an overlap is found by whatever stops working, not by the plan. resource_node is both the bill and the ceiling: registering more assets than you bought fails at registration, months later. time_unit is months and nothing else.

Static validated · Live test pendingTencent CloudTerraform
Open A Bastion That Says Out Loud What Owning It Does Not Do

alicloud-bastion

A Bastionhost instance, its exposure and the directory its operators come from. Public access with an empty allow list is refused: that is a login page for production. Without AD or LDAP every account is local and outlives the person who left. Destroying it needs Alibaba to white-list the account first, which is documented provider behaviour and reported as an output.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Bastion Whose Admin Password Is in Your State File, and Which Says So

huawei-bastion

A CBH instance. The console administrator password is a required argument, so it is written to Terraform state in plain text and whoever reads that state administers every recorded session in the estate; the module will not build until that is acknowledged. period is ForceNew, so changing the term destroys and rebuilds the appliance rather than renewing it.

Static validated · Live test pendingHuawei CloudTerraform
Open A Billing Budget Somebody Actually Hears About

gcp-billing-budget

The API accepts a budget with default recipients disabled and no channel, topic or threshold rule - a number that is tracked and never sent anywhere. Refuses that, insists on a FORECASTED_SPEND rule, and defaults credit_types_treatment to EXCLUDE_ALL_CREDITS, because a budget that counts credits measures your runway, not your spend, and looks healthy until the month they run out.

Static validated · Live test pendingGoogle CloudTerraform
Open A Block Storage Volume with Snapshots Taken on Purpose

exoscale-block-storage

Snapshots exist as a resource you take and nothing on the platform schedules one; a volume attaches from the instance side, one instance at a time, in its zone; and a volume made from a snapshot is the restore path. A baseline snapshot when asked, restore from a snapshot when given, and an output that says no schedule exists.

Static validated · Live test pendingExoscaleTerraform
Open A Block Volume Backed Up by a Policy that Matches It

ibm-block-volume

VPC backup policies match volumes by user tag, so a volume created without the tag sits silently outside the policy; encryption is provider-managed unless a root key CRN is given; and an attachment can delete the volume with the instance. The policy created with its plan and the volume tagged with the tag it matches (none by name), your key when given, the volume kept on instance deletion.

Static validated · Live test pendingIBM CloudTerraform
Open A Block Volume that Is Backed Up, to Another Region

oci-block-volume

Every tenancy ships Bronze, Silver and Gold policies and a volume follows one only through a separate assignment - the page reads Backup policy: none for the many never assigned. Assigns a policy to the volume it creates and refuses one without. Custom schedules add destination_region and retention lock, which Oracle policies lack: same-region backups are a copy of the failure.

Static validated · Live test pendingOracle CloudTerraform
Open A Block Volume that Is Formatted, Attached and Honest About Backups

do-volume

Droplet backups copy the boot disk and nothing attached to it, so a database whose data lives on a volume is an empty server to the backup; there is no snapshot schedule for volumes either. A formatted, attached, regional volume with two outputs that say exactly that, so whatever consumes the module cannot assume a copy exists.

Static validated · Live test pendingDigitalOceanTerraform
Open A Block Volume with the IOPS Tier Chosen and Snapshots Taken on Purpose

scaleway-block-volume

iops is required, is the price per GB, and cannot change after creation; snapshots exist as a resource you take and nothing on the platform schedules one; the volume is zonal and attaches from the server side. The tier validated to the two that exist, a baseline snapshot when asked, and an output that says no schedule exists.

Static validated · Live test pendingScalewayTerraform
Open A Broker whose Maintenance Is Not an Outage

aws-mq

deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.

Static validated · Live test pendingAWSTerraform
Open A Bucket that Is Private, Versioned, and Can Lock Objects

scaleway-object-bucket

Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.

Static validated · Live test pendingScalewayTerraform
Open A Budget Somebody Actually Hears About

oci-budget

The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.

Static validated · Live test pendingOracle CloudTerraform
Open A Budget Somebody Actually Hears About

azure-budget

Azure requires a notification block, which makes the problem look solved: a notification can be created disabled, and contact_roles = Owner emails whoever holds the role, which is often a service principal with no mailbox. Insists on an enabled notification with a real address or action group, and on a Forecasted threshold so the first message arrives while there is still a month to act.

Static validated · Live test pendingAzureTerraform
Open A Budget Somebody Actually Hears About

aws-budgets

A budget with no notification tracks correctly and tells nobody, so the invoice is the first notice; ACTUAL-only alerts arrive after the money is gone. And include_credit defaults true, so a budget on a credited account reports runway rather than spend - until the credits end and nothing crosses a threshold.

Static validated · Live test pendingAWSTerraform
Open A Budget That Names Which of Eight Money Figures It Is Watching

tencent-budget

A billing budget with thresholds and a scope. fee_type picks which figure is counted: COST is list price you were never going to pay, CASH ignores everything settled with vouchers and credits and reports you under budget until they run out, REAL_COST is what you pay. A budget stops nothing and stops_spending says so.

Static validated · Live test pendingTencent CloudTerraform
Open A Build Project that Is Not Root on Its Host

aws-codebuild

privileged_mode hands the build the Docker socket, so anything it runs can read every environment variable and assume the service role. Off by default, and a PLAINTEXT variable whose name looks like a secret is refused.

Static validated · Live test pendingAWSTerraform
Open A CAM Role a Service May Assume, No Console Login, with a Custom Policy

tencent-cam-role

A CAM role assumable by the services or root accounts you name and nothing else (a wildcard principal is refused), console login off because a role is for workloads, a custom policy written from your statements, the preset policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

Static validated · Live test pendingTencent CloudTerraform
Open A CBR Policy and a Multi-Zone Server Vault that Grows Before It Fills

huawei-cbr-backup

A Cloud Backup and Recovery policy that backs up nightly and keeps thirty days, bound to a server vault spread across zones (single-zone by name) that auto-expands rather than stopping when full (a fixed size by name), crash-consistent unless the CBR agent is on every server, with the servers in the map protected. Pay-per-use.

Static validated · Live test pendingHuawei CloudTerraform
Open A CDC Stream to BigQuery that Starts, Privately, with a Secret

gcp-datastream

A stream is created NOT_STARTED and replicates nothing until somebody starts it; the source password is a literal in state unless it is a Secret Manager reference; public connectivity means the database admits Google's published ranges; and backfill_none is change capture with no history. Running from apply, private connection peered into your VPC, secret required, backfill on.

Static validated · Live test pendingGoogle CloudTerraform
Open A CDN Domain with HTTPS Forced, HSTS, OCSP Stapling and TLS 1.2+

tencent-cdn

A Tencent Cloud CDN domain in front of your COS bucket or origin hosts, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from SSL Certificate Service, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

Static validated · Live test pendingTencent CloudTerraform
Open A CDN Domain with HTTPS Forced, HSTS, OCSP Stapling and TLS 1.2+

huawei-cdn

A Huawei Cloud CDN domain in front of your OBS bucket or origin host, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from Cloud Certificate Manager, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, cache headers followed from the origin, and the origin fetched over HTTPS. The CNAME is exported.

Static validated · Live test pendingHuawei CloudTerraform
Open A CDN Domain with HTTPS Forced, HSTS, TLS 1.2+ and the Origin Fetched over HTTPS

alicloud-cdn

An Alibaba Cloud CDN domain in front of your OSS bucket or origin host, serving outside mainland China unless an ICP-filed scope is accepted by name, with the certificate from Certificate Management, every HTTP request redirected, HSTS, HTTP/2, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

Static validated · Live test pendingAlibaba CloudTerraform
Open A CDN in Front of a Spaces Bucket on Your Domain with a Managed Certificate

do-cdn

A DigitalOcean CDN endpoint in front of a Spaces bucket, served on your domain with a DigitalOcean-managed certificate you name (the cdn.digitaloceanspaces.com name is accepted by name), with a cache TTL you chose. The CDN serves the bucket's public objects; a private object stays private through it.

Static validated · Live test pendingDigitalOceanTerraform
Open A CEN Transit Router with Explicit Route Tables and a VPC Attachment per VPC, Each a Decision

alicloud-cen-transit-router

An Alibaba Cloud CEN instance with an Enterprise Edition transit router, the route tables you name, and a VPC attachment per VPC with an interface per zone (one zone by name), each associated with one route table and propagating into the tables you list. The default route table is never used, so no VPC reaches another until you say so.

Static validated · Live test pendingAlibaba CloudTerraform
Open A CFS File System in Your Subnet, Mounted Only from the CIDR You Name

tencent-cfs-file-system

A Tencent Cloud CFS file system (NFS) in your subnet behind its own access group, whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 has to be accepted by name), on the standard or high-performance tier. CFS encrypts at rest with keys it holds, which the module says rather than hides.

Static validated · Live test pendingTencent CloudTerraform
Open A CLB that Checks the Application, Redirects HTTP and Refuses Deletion

tencent-clb

A listener's health check is a switch that, off, sends traffic to every target forever; a port-80 listener forwards unless a redirection resource points it at 443; and delete_protect defaults to false. HTTP health checks on a path through listener rules, a 301 from 80 to 443 whenever a certificate is given, deletion protection on, access logs when a CLS topic is given.

Static validated · Live test pendingTencent CloudTerraform
Open A COS Bucket that Is Private, Versioned and Encrypted

tencent-cos-bucket

A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.

Static validated · Live test pendingTencent CloudTerraform
Open A COS Bucket that Is Versioned, Key-Encrypted and Reachable from Where You Say

ibm-cos-bucket

Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.

Static validated · Live test pendingIBM CloudTerraform
Open A CSMS Secret Encrypted with Your KMS Key, with an Expiry

huawei-csms-secret

A secret in Huawei Cloud Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the account's default CSMS key (the default by name), with an expiry after which CSMS flags it (none by name) and event subscriptions that notice version changes and expiry.

Static validated · Live test pendingHuawei CloudTerraform
Open A CVM Custom Image Captured from an Instance into an Image Family

tencent-image

A Tencent Cloud custom image captured from a CVM instance into an image family, so instances that name the family get the newest image (no family by name). The capture refuses a running instance rather than powering it off, and takes the system disk only unless data disks are named.

Static validated · Live test pendingTencent CloudTerraform
Open A CVM Instance with a Key Pair, No Public Address, an Encrypted Disk and the Agents On

tencent-cvm-instance

A CVM instance in your subnet with login by key pair and no password, ordered security groups, no public address (one by name), the system disk encrypted with your KMS key (the service key by name), the Cloud Workload Protection and Cloud Monitor agents left on, a CAM role when you name one, and API termination refused. Pay-as-you-go by the hour.

Static validated · Live test pendingTencent CloudTerraform
Open A Cache Cluster with Replicas, Behind an NSG

oci-cache

One node is a primary with no replica, so a node failure or a maintenance window is an outage that empties the cache; and the cluster is reachable by anything that can route to its subnet unless an NSG says otherwise, because it has no other access control. Three nodes across availability domains, an NSG required, Valkey or Redis, sharded or not - decided at creation.

Static validated · Live test pendingOracle CloudTerraform
Open A Cassandra Table that Can Be Restored

aws-keyspaces

point_in_time_recovery defaults to DISABLED and Keyspaces has no snapshots or automated backups, so off means a dropped table is simply gone. PITR on, a customer-managed key, and the two one-way doors - client-side timestamps and TTL - named rather than set quietly.

Static validated · Live test pendingAWSTerraform
Open A Certificate Purchase That Checks the Order Before Placing It

huawei-tls-certificate

A public TLS certificate bought through Huawei CCM, and its application. Applying is a purchase, so brand, type and validity have no defaults and every combination rule is checked at plan. It does not renew itself. The provider accepts Huawei's privacy terms on every application, so the module waits for a person to. Validation records appear one refresh after the first apply.

Static validated · Live test pendingHuawei CloudTerraform
Open A Certificate Uploaded to Certificate Management Service, with the SM2 Pair Checked

alicloud-ssl-certificate

A certificate uploaded into Certificate Management Service for SLB, ALB, CDN and API Gateway to reference. The private key is an argument, so it lands in the Terraform state and the README says so plainly. SM2 is a signing pair plus an encryption pair and the module refuses a half-filled set, which would upload something no client can handshake with.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Chaos Experiment Bounded by Duration, Scope and Identity

azure-chaos-studio

Chaos Studio has no stop condition: an experiment runs for its actions' duration or until somebody presses Stop, so the duration is the only guardrail and every action here is capped. The experiment acts as its own identity and fails safely without a role on each target; every fault it can inject is a capability somebody enabled on an onboarded target, so the scope cannot quietly widen.

Static validated · Live test pendingAzureTerraform
Open A Chaos Experiment that Can Be Stopped

aws-fis

FIS refuses a template with no stop condition, which reads like a guarantee - and source = 'none' is a legal stop condition meaning the experiment never halts by itself. Refused here, along with targets that grow at run time and an empty-target mode that reports success for having tested nothing.

Static validated · Live test pendingAWSTerraform
Open A Civo DNS Zone with Its Records and the Nameservers for the Registrar

civo-dns-zone

A Civo DNS zone with every record in one map, each with the TTL Civo requires per record, and the nameservers exported for the registrar. Civo does not sign zones and has no CAA or NS record types; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.

Static validated · Live test pendingCivoTerraform
Open A ClickHouse Cluster with a Second Replica and a Cold Tier Rather Than Neither

tencent-clickhouse

A ClickHouse cluster with high availability on, since without it each shard has one replica and losing a data node is losing its data. A COS cold tier is set, because without one every partition stays on the most expensive storage the cluster has while the cluster reports healthy and the invoice is the only signal. Single-zone and PREPAID both have to be taken by name.

Static validated · Live test pendingTencent CloudTerraform
Open A Cloud Connect Network with Explicit Route Tables and a VPC Attachment per VPC Bound to One

tencent-ccn

A Tencent Cloud CCN (pay-as-you-go; prepaid bandwidth by name) with the route tables you name and a VPC attachment per VPC on the current v2 resource, each bound to one table so the default routing domain is never used. Route propagation policies between tables are the next resource to add.

Static validated · Live test pendingTencent CloudTerraform
Open A Cloud Firewall Attached to Droplets with SSH from Somewhere Specific

do-firewall

A firewall with no droplets and no tags applies to nothing while the console shows it active; SSH from 0.0.0.0/0 is the first rule the console offers; and with no outbound rule nothing leaves, DNS included. Droplets or tags expected, port 22 from everywhere refused unless accepted, and an outbound default that allows what a server needs.

Static validated · Live test pendingDigitalOceanTerraform
Open A Cloud Guard Target whose Responders Respond

oci-cloud-guard

Oracle ships every responder rule in USERACTION mode: a Remediate button appears on each problem and nothing happens until a person clicks it, so a tenancy with hundreds of findings has by default fixed none of them. Sets AUTOACTION per rule and exports the IAM statements each auto-action needs, since one without its policy fails on every execution.

Static validated · Live test pendingOracle CloudTerraform
Open A Cloud Search Service Cluster with Security Mode On, Which Is What Makes a Password Mean Anything

huawei-css-cluster

A CSS cluster with security_mode true, since false means the cluster answers anyone who can reach it with no credentials while the console reports it healthy. HTTPS requires security mode and the API says so late, so the module says so first; disks are encrypted at creation, and public access without a whitelist is refused.

Static validated · Live test pendingHuawei CloudTerraform
Open A CloudAudit Tracking Set for Every Resource, Action and Event, to Your Bucket

tencent-cloud-audit

A CloudAudit tracking set scoped to every resource type, action and event name (narrower by name), compressed and delivered to a COS bucket you own under a prefix. The console keeps ninety days and forgets; the tracking set is what keeps more. Organization tracking collects every member account from the management account.

Static validated · Live test pendingTencent CloudTerraform
Open A CloudHSM Cluster, Honest About What It Cannot Do

aws-cloudhsm

Cluster and HSMs, with the parts nobody mentions: AWS holds no copy of your keys, Terraform cannot initialise the cluster, and an uninitialised cluster bills per HSM per hour while being unable to store anything.

Static validated · Live test pendingAWSTerraform
Open A Cloudant Instance, IAM-Only, with CORS Off and Document Reads in the Audit Trail

ibm-cloudant

A Cloudant instance on the standard plan with CORS off, and a wildcard origin together with allow_credentials refused outright because it would let any site make authenticated requests as the signed-in user. Legacy username-and-password auth is off, and data events are on, since without them the trail never records that anyone read a document.

Static validated · Live test pendingIBM CloudTerraform
Open A Cloudflare Tunnel Connector That Keeps Its Token Off The Command Line

ansible-cloudflared-tunnel

cloudflared from Cloudflare's signed repository (a 2025 key rpm on EL 10 accepts), pinned, run as a hardened unit that reads the tunnel token from a root-only file, not from the unit or ps. Never self-updating. The live test greps the unit and the connector's command lines for the token and expects nothing. Original role, live-tested on Rocky Linux 10.

Live-testedCloudflareAnsible
Open A Code Engine Application That Is Private, Which the Default Is Not

ibm-code-engine-app

A Code Engine project and application with managed_domain_mappings local_private, because the field defaults to local_public and an application deployed with no opinion about it answers the world. scale_min_instances is one rather than zero, run_as_user is not root, and a private image without its pull secret is refused - that failure otherwise arrives long after the apply.

Static validated · Live test pendingIBM CloudTerraform
Open A Code Engine Function in Its Own Project, Private, with a Compute Resource Token

ibm-code-engine-function

A Code Engine function in a project created here, callable only from inside the project unless a public URL is accepted by name, with the compute resource token mounted so it obtains IAM tokens through a trusted profile and needs no API key, and CPU, memory, concurrency and execution time capped so a runaway caller cannot drive the bill.

Static validated · Live test pendingIBM CloudTerraform
Open A Compartment where the Wrong Resource Cannot Be Created

oci-security-zone

The opposite of every other guardrail here: a security zone does not detect or report, it REFUSES - the API call fails. There is no dry-run mode. So the risk inverts too: applied to a compartment that already holds non-compliant resources, the team that owns them discovers they can no longer change them.

Static validated · Live test pendingOracle CloudTerraform
Open A Config Recorder that Is Actually Running

aws-config

Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.

Static validated · Live test pendingAWSTerraform
Open A Connector that Is Active and Archives What Logging Forgets

oci-service-connector

OCI Logging keeps a log for at most six months; a service connector from a log group to Object Storage is the archive, and it can be created INACTIVE, which is how one that was set up has moved nothing since. Created active, reads a whole log group so new logs are included, writes to a bucket, stream, function, topic, metric or Log Analytics, and exports the IAM statement the hub needs.

Static validated · Live test pendingOracle CloudTerraform
Open A Constraint that Is Enforced rather than Rehearsed

gcp-org-policy

dry_run_spec is a separate configuration from spec and only spec enforces, so a dry-run policy appears in the console, evaluates everything and denies nothing. inherit_from_parent defaults to false, which makes a local addition silently REPLACE the organization policy rather than add to it.

Static validated · Live test pendingGoogle CloudTerraform
Open A Container Instance that Is Private, Non-Root and Health-Checked

oci-container-instances

A container with no health check is restarted only when its process exits, so a deadlocked one stays; containers run as root unless the security context says otherwise; and a public IP on the instance is an internet-facing container with only an NSG in front. Every container gets a check that restarts it and runs non-root on a read-only filesystem; the instance stays private.

Static validated · Live test pendingOracle CloudTerraform
Open A Container Registry Namespace with the Retention Policy that Keeps It from Filling

ibm-container-registry

An IBM Cloud Container Registry namespace in the provider's region, with a retention policy that keeps the last ten images per repository and drops untagged ones, because without one every CI run adds an image until the account's storage quota refuses the next push. Quotas and the plan are account-wide and not managed here.

Static validated · Live test pendingIBM CloudTerraform
Open A Container Registry Whose Credentials Expire

do-container-registry

Docker credentials for the registry never expire unless told to, so the login a CI job wrote to disk two years ago still pushes today; there is one registry per account; and the tier is a storage ceiling that turns into a failed push far from the cause. The registry, read-only credentials that live a day and read-write ones that live an hour, both re-issued on the next apply after expiry.

Static validated · Live test pendingDigitalOceanTerraform
Open A Control Policy That Will Not Switch Off Every Other One

tencent-org-policy

A Tencent Cloud Organization service control policy and its attachments. It refuses a policy attached to nothing, an allow statement read as a grant, and an unasked-for root attachment. Destroying the policy-type switch disables every control policy in the organisation, so the module leaves it alone by default and protects it from destroy when asked to manage it.

Static validated · Live test pendingTencent CloudTerraform
Open A Control Policy and the Attachments Without Which It Constrains Nobody

alicloud-org-policy

A Resource Management control policy and the folders or accounts it attaches to, which are separate resources: an unattached policy appears in the console list with a name and a document and constrains nobody. A control policy is a ceiling, so the module counts Deny statements and asks about Allow ones, which grant nothing. Attaching to the root reaches the management account.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Control Tower Landing Zone with Governed Regions, Logging Kept a Year, and Controls per Unit

aws-control-tower

A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.

Static validated · Live test pendingAWSTerraform
Open A Cross-Region DRG Peering that Says What It Still Needs

oci-remote-peering

A remote peering connection is half a link until the requestor connects to the acceptor, and a PEERED connection with no DRG route import and no VCN route rule passes nothing while reading as connected. Acceptor and requestor halves from one module, the peering status exported, and an output that lists the routes and security rules that live outside it and are the usual reason no packets cross.

Static validated · Live test pendingOracle CloudTerraform
Open A Custom Image Captured from an Instance or Imported from Object Storage

oci-custom-image

A custom Compute image from exactly one source: an instance you built (its boot volume, secrets and all, so build it clean) or a QCOW2 or VMDK object in Object Storage with its operating system named, in the launch mode the workload needs (NATIVE for images built on OCI, PARAVIRTUALIZED for imports). OCI has no image family; the name carries the build.

Static validated · Live test pendingOracle CloudTerraform
Open A Custom Image in a Family, Encrypted with Your Key and Shared by IAM

gcp-compute-image

A custom Compute Engine image from a disk, snapshot, image or raw tarball (exactly one), in a family instances resolve, encrypted with your Cloud KMS key, stored in the location you choose and shared by a compute.imageUser binding. The guest features default to a current distribution image; no family and the Google-managed key are each accepted by name.

Static validated · Live test pendingGoogle CloudTerraform
Open A Customer Directory Whose Licence Change Would Delete Every Account

oci-customer-identity

An OCI identity domain on the external-user licence. license_type is not updatable, so changing it replaces the domain with an empty one and every customer account is gone - and the admin email is create-time only too. A domain must be deactivated before it can be deleted, which the module exposes, and it stays off your staff sign-in page.

Static validated · Live test pendingOracle CloudTerraform
Open A Customer User Store That Admits It Does Not Configure Sign-In

tencent-customer-identity

A Tencent CIAM user store and its groups. The provider exposes the store and nothing about how a customer signs in: login methods, password rules, MFA and social providers are console-only and invisible to Terraform, which configures_authentication reports. The logo appears on the customer sign-in page, so it must be HTTPS.

Static validated · Live test pendingTencent CloudTerraform
Open A D1 Database Placed on Purpose with Its Recovery Window Stated

cloudflare-d1-database

Where a D1 primary lives is decided at creation, near whoever ran the create unless a hint or jurisdiction says otherwise; read replication is off by default; and backups are Time Travel with a window the plan decides (30 days paid, 7 free) and no export schedule. Hint or jurisdiction set, replication by name, the recovery window as an output, and an output that says no export is scheduled.

Static validated · Live test pendingCloudflareTerraform
Open A DCS Redis Instance Across Two Zones with TLS, a Whitelist and FLUSHALL Renamed

huawei-dcs-redis

A Distributed Cache Service Redis instance in your VPC with primary and standby across two zones (one by name), TLS required (plaintext by name), the whitelist on with your ranges, a password from a secret store never output, weekly backups kept seven days, a maintenance window, and flushall, flushdb, keys and hgetall renamed so an accident cannot type them.

Static validated · Live test pendingHuawei CloudTerraform
Open A DDoS Network Protection Plan with Its Price Written Down

azure-ddos-protection-plan

The plan is a fixed monthly charge of roughly three thousand dollars from the moment it exists, attached VNets or not; it protects only the VNets that reference it; and DDoS IP Protection on the addresses themselves is an order of magnitude cheaper for a handful. The charge accepted by name before the plan is created, the plan ID exported for azure-vnet, an output that says it bills unattached.

Static validated · Live test pendingAzureTerraform
Open A DNS Server Policy that Logs, Applies, and Blocks

gcp-resolver-policy

A Cloud DNS server policy bound to no network resolves for nobody, and query logging is off by default, so nothing records which host resolved which name - the first question in most incidents. Refuses a policy with no networks, logs every query, and can add a response policy that answers listed domains with a sinkhole address before recursion, for every workload on every governed network at once.

Static validated · Live test pendingGoogle CloudTerraform
Open A DNS Zone, and a Plain Account of Why It Is Not Yet Serving Anybody

do-dns-zone

A DigitalOcean domain and its records. Creating the zone does not delegate it: until the registrar's nameservers point here the zone is correct, complete and serving nobody, which looks exactly like a working zone. The domain's ip_address shortcut, which hides an apex A record from your records map, is deliberately not used, and a CNAME at the apex is refused.

Static validated · Live test pendingDigitalOceanTerraform
Open A DNSPod Zone with Its Records on the Default Line and the Nameservers Exported

tencent-dns-zone

A Tencent Cloud DNSPod zone with every record in one map, all on the default resolution line so every resolver gets the same answer, MX priority carried on the record, and the free-grade nameservers exported for the registrar. DNSSEC is not a resource in the provider; dnssec_available says so.

Static validated · Live test pendingTencent CloudTerraform
Open A DRS Job with RPO and RTO Alarms and a Target Held Read-Only

huawei-database-migration

A DRS job with the lag alarm armed to an SMN topic, since without one the console shows the same green whether the job is current or hours behind. The target is held read-only, because anything writing to it produces conflicts the job cannot see or repair; multi_write and a FULL_TRANS-only snapshot both have to be chosen by name.

Static validated · Live test pendingHuawei CloudTerraform
Open A DTS Job with the Delay Alarm Armed, Because a Lagging Job Reads RUNNING Too

alicloud-database-migration

A DTS instance and synchronization job with delay_notice on, since a job that has fallen behind reports the same RUNNING as one that has not. Structure, data and synchronization are three separate required flags and the module names what each leaves out. The provider does not mark the endpoint passwords sensitive, so these variables do.

Static validated · Live test pendingAlibaba CloudTerraform
Open A DWS Cluster Whose Snapshots Outlive It, Which the Default Does Not Arrange

huawei-dws

A DWS cluster keeping its manual snapshots when it is deleted, since the default of zero deletes the backups along with the thing they were backing up and turns a mistaken delete into a permanent one. Disks are encrypted at creation because they cannot be later, audit logging to LTS is on, and there is no public endpoint unless you ask for one.

Static validated · Live test pendingHuawei CloudTerraform
Open A Dashboard that Reads One Account

aws-grafana

account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.

Static validated · Live test pendingAWSTerraform
Open A Data Factory that Moves Data Privately and Keeps Pipelines in Git

azure-data-factory

The managed virtual network cannot be turned on after creation, and without it the integration runtime that copies your data reaches every source over public endpoints; the studio endpoint is public by default; and a factory with no git repository keeps its pipelines only in the service, with no review. Managed VNet on, studio private, git required, Key Vault linked for secrets.

Static validated · Live test pendingAzureTerraform
Open A Data Integration Workspace on Your VCN so Pipelines Reach Private Databases

oci-data-integration

An OCI Data Integration workspace attached to your VCN and subnet so pipelines reach databases that have no public path (internet-only sources by name), with a private DNS server when your names live there. The workspace is the boundary for pipelines and the hourly bill from creation; the pipelines themselves are built inside it.

Static validated · Live test pendingOracle CloudTerraform
Open A Database Migration Service in Your Subnet with a Project per Source and Target

azure-database-migration

An Azure Database Migration Service instance placed in a subnet that must reach both source and target, on the Premium SKU that runs online migrations with continuous sync so a cutover is minutes (the Standard tiers are offline), with a migration project per source and target pair from a map. Tasks and credentials are supplied when a migration runs, not here.

Static validated · Live test pendingAzureTerraform
Open A Database Proxy Where No Client Holds the Password

aws-database-proxy

Amazon RDS Proxy in front of an RDS instance or Aurora cluster: TLS required, clients authenticate with IAM tokens while the proxy reads the password from Secrets Manager, through a role limited to those secrets. Debug logging writes SQL statement text to the logs, so it is off unless that is accepted. End-to-end IAM removes the stored password entirely.

Static validated · Live test pendingAWSTerraform
Open A Database whose Irreversible Choices Are Made Deliberately

gcp-firestore

Type, location and CMEK cannot be changed after creation - getting one wrong means exporting every document into a new database and repointing every client. delete_protection defaults OFF, and Firestore has no snapshots: point-in-time recovery is the only way back and only covers incidents after it was enabled.

Static validated · Live test pendingGoogle CloudTerraform
Open A Databases for Redis Deployment that Is Private, Encrypted with Your Keys and Protected

ibm-databases-redis

An IBM Cloud Databases for Redis deployment on the private endpoint only (public by name), with deletion protection on, an allowlist of your ranges (empty by name), disk and backup encryption with Key Protect keys you hold (IBM's keys by name), and the two-member group that is the HA and cannot be reduced. Access is by service credential, a separate resource.

Static validated · Live test pendingIBM CloudTerraform
Open A Databricks Workspace in Your VNet with No Public IPs

azure-databricks

The default deployment puts the clusters in a managed network you cannot see with a public IP per node, and the workspace URL - notebooks, jobs, tokens - is reachable from the internet. VNet injection into your subnets with no public IPs, the workspace endpoint off the internet, and one Key Vault key wired to all four encryption settings including the DBFS root, a separate resource.

Static validated · Live test pendingAzureTerraform
Open A Dataflow Job on Private Workers that Drains on Destroy

gcp-dataflow

on_delete defaults to cancel, which discards every element in flight on a streaming pipeline the moment the job is destroyed or replaced; workers get public IPs by default; and the default worker identity is the Compute Engine default account. Drain on delete, private workers with Private Google Access, a dedicated service account with the default refused, and a customer-managed key.

Static validated · Live test pendingGoogle CloudTerraform
Open A Dedicated ELB on TLS 1.2 that Checks the Application and Redirects HTTP

huawei-elb

The default TLS policy accepts TLS 1.0; a pool without a monitor resource is never unhealthy and sends traffic to every member forever; an HTTPS listener does nothing about port 80 until an L7 policy redirects it; and deletion protection is off. tls-1-2-strict, an HTTP monitor on a path, a redirect on 80 whenever a certificate is given, two zones unless one is accepted, deletion protection on.

Static validated · Live test pendingHuawei CloudTerraform
Open A Dedicated WAF in Your VPC, a Policy that Blocks, and the Domain with TLS 1.2

huawei-waf

A dedicated WAF of two anti-affinity instances in your subnet (one by name), pay-per-use, with a policy in block mode (log mode by name) that turns on basic web protection, CC attack protection, precise protection, web shell detection, anti-crawler and data masking, and the protected domain with your certificate, TLS 1.2, cipher suite 2 and PCI DSS checks, forwarding to origins over HTTPS.

Static validated · Live test pendingHuawei CloudTerraform
Open A Delivery Pipeline whose Production Target Waits for a Person

gcp-cloud-deploy

require_approval defaults to false on every target, so a release rolls into production the moment somebody promotes it with nobody signing off; the verify flag defaults off, so skaffold verify has never run. Treats the last stage as production and refuses a pipeline whose last target skips approval, verifies after every rollout, and refuses the Compute default service account as the runner.

Static validated · Live test pendingGoogle CloudTerraform
Open A Delivery Stream whose Errors Are Separable

aws-kinesis-firehose

Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.

Static validated · Live test pendingAWSTerraform
Open A DevOps Project whose Pushes Build, on Your Network

oci-devops

The project, repository and pipeline are separate resources and none reacts to a commit until a trigger ties a push to the pipeline; builds run as the DevOps service and fail on the first step without a dynamic group and policy; and the runner is on Oracle's network unless given a subnet. Trigger created, runner attached to your subnet, and the IAM rule and statements exported.

Static validated · Live test pendingOracle CloudTerraform
Open A DigitalOcean Custom Image Imported from a URL into the Regions You Name

do-custom-image

A DigitalOcean custom image imported from a URL (raw, qcow2, vhdx, vdi or vmdk) into the regions you name, one region by name. Host the file in a Space you own: a URL nobody controls is an image nobody controls. The name carries the build.

Static validated · Live test pendingDigitalOceanTerraform
Open A Direct Connect Gateway, with the CCN Routes Published Rather Than Left Unsaid

tencent-direct-connect

A Direct Connect gateway terminating a dedicated circuit into a VPC or a CCN. Attaching one to a CCN creates the attachment and no routes, so the CCN has no way back to your premises while everything reports healthy; an empty route list on a CCN gateway is refused here. NAT mode rewrites your addresses and has to be chosen rather than inherited.

Static validated · Live test pendingTencent CloudTerraform
Open A Direct Link Gateway Whose Route Filters Deny by Default, Which the API Does Not

ibm-direct-link

A Direct Link gateway with both default route filters set to deny, because permit accepts every prefix the other side advertises including a default route that would pull the VPC's whole egress across the circuit. The BGP session is authenticated, BFD is on, global routing and metered billing are required inputs, and a virtual connection per VPC is what makes the circuit reach anything.

Static validated · Live test pendingIBM CloudTerraform
Open A DynamoDB Cache Encrypted From the Start

aws-dax-cache

DynamoDB Accelerator with TLS and encryption at rest. DAX leaves both off by default, and neither can be turned on for an existing cluster, so a fix means a new cluster. This module also creates its own security group (DAX otherwise uses the VPC default), a service role limited to the named tables and their indexes, and states that writes bypassing DAX leave stale reads until the TTL.

Static validated · Live test pendingAWSTerraform
Open A FastConnect Circuit with BFD, a Partner, and a Gateway

oci-fastconnect

One virtual circuit is one cable that goes down for maintenance, and the SLA assumes two; BFD is off by default, leaving a failed link to BGP hold timers for up to ninety seconds; and a circuit without a gateway is PROVISIONED and reaches no VCN. BFD on, the DRG required, a redundant partner circuit declared or the single circuit accepted by name, and the redundancy metadata exported.

Static validated · Live test pendingOracle CloudTerraform
Open A File Share on a Private Account, with a Quota You Chose and a Backup that Is Assigned

azure-file-share

A share inherits its security boundary from the storage account, which defaults to public access and TLS 1.0; the quota is the price on premium; and a share is backed up only when a Recovery Services vault protects it through a policy and an assignment. A private account with TLS 1.2, the quota deliberate, share soft delete on, vault, policy and protection created together (none by name).

Static validated · Live test pendingAzureTerraform
Open A Firewall Group that Names Its Sources and Says What It Does Not Do

vultr-firewall

A firewall group filters inbound on the public interface only: outbound is always open and the VPC interface is never filtered. It is attached by the instance, so the group cannot see whether any uses it, and SSH from a /0 is the first rule offered. Named sources or Cloudflare's edge, SSH from anywhere refused unless accepted, and outputs that say attachment is not proven and outbound is open.

Static validated · Live test pendingVultrTerraform
Open A Firewall Policy that Governs a Network and Leaves a Record

gcp-firewall-policy

A global network firewall policy exists independently of any network; an association puts it in the path, and a policy with a hundred rules and none governs nobody while rendering as fully configured. enable_logging defaults to false on every rule, so a deny that fires leaves no evidence. Refuses a policy with no network, logs every rule unless told not to, and counts the disabled ones.

Static validated · Live test pendingGoogle CloudTerraform
Open A Firewall Without the Default Rules that Admit Everything

civo-firewall

create_default_rules defaults to true and the rules it writes allow all inbound traffic on every port from every address, which turns a firewall into a name on a list; SSH from 0.0.0.0/0 is the first rule offered; and with the defaults off a firewall with no egress rule blocks all outbound. Defaults off, SSH from anywhere refused unless accepted, egress opened unless outbound rules narrow it.

Static validated · Live test pendingCivoTerraform
Open A Firewall that Blocks rather than Narrates

azure-firewall

Every security feature on this service defaults to telling you, not to stopping it: threat_intelligence_mode defaults to Alert, which logs traffic to known-malicious destinations and forwards it, and intrusion detection does the same. Deny for both here, with the DNS proxy on so FQDN rules and the client agree on an answer.

Static validated · Live test pendingAzureTerraform
Open A Fleet Backup Policy with Daily and Weekly Schedules, a Second Region, and Deletion Prevented

oci-backup-policy

A block volume backup policy that many volumes share: incremental daily backups kept thirty days and full weekly backups kept a year, each copied to a second region (one region by name) and encrypted there with a key of yours when given, deletion prevented until retention ends (deletable by name), and every volume in the map assigned, because a policy with no assignment backs up nothing.

Static validated · Live test pendingOracle CloudTerraform
Open A Flow Log Collector with the Authorization Without Which Its Writes Never Land

ibm-vpc-flow-logs

A VPC flow log collector writing into a Cloud Object Storage bucket the module creates with an expiry rule and your Key Protect key if you hold one, plus the is to cloud-object-storage Writer authorization without which a collector reports active and logs nothing - the usual reason an IBM flow log leaves an empty bucket. An inactive collector has to be accepted by name.

Static validated · Live test pendingIBM CloudTerraform
Open A Flow That Says Whether It Can Call Anything Before You Run It

alicloud-workflows

A Serverless Workflow flow and its schedules. role_arn is optional in the API, so a flow without one is created, reads correctly in the console and fails at the first task that touches another service - at execution time. The module refuses that, and turns schedules on, because the API default is off and a disabled schedule shows its cron expression anyway.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Free Certificate That Still Renews Next Year

azure-managed-certificate

A free App Service managed certificate for a custom subdomain, with its hostname binding, the SNI binding that puts it to use, and optionally the DNS records. Microsoft blocks issuance and renewal when the CNAME passes through anything before the app, so the module writes the direct record and refuses the wildcards, apex names and long hostnames the product does not support.

Static validated · Live test pendingAzureTerraform
Open A Free DV Certificate Where the Validation Method Is a Decision, Not a Default

tencent-ssl-certificate

A free domain-validated certificate from Tencent Cloud SSL. DNS_AUTO writes the record for you and silently only works when the domain is on DNSPod, so the module refuses it unless you confirm that. The issued private key is a computed attribute and therefore in state, and the resource finishes before the certificate is issued, so read the status output.

Static validated · Live test pendingTencent CloudTerraform
Open A Function Compute 3.0 Function with Its Own Role, No Internet, and Logs to Log Service

alicloud-fc-function

A Function Compute 3.0 function running as the RAM role you name, with internet access off (on by name), in your VPC when a vpc_config is given, logging every invocation to a Log Service project and logstore (none by name), with code fetched from an OSS object you uploaded. Memory, CPU, disk, timeout and instance concurrency are inputs.

Static validated · Live test pendingAlibaba CloudTerraform
Open A FunctionGraph Function with Its Own Agency, LTS Logs, and Secrets Encrypted with Your Key

huawei-fgs-function

A FunctionGraph v2 function running as the IAM agency you name, in your VPC when a subnet is given, logging every invocation to the LTS group and stream you name, with plain environment variables in user_data and secrets in encrypted_user_data under your KMS key (which also encrypts the code), fetched from an OBS URL. A ceiling on instances is an input.

Static validated · Live test pendingHuawei CloudTerraform
Open A Gateway Service That Is Not on the Internet and Has a Rate Limit

tencent-api-gateway

An API Gateway service with net_type INNER rather than OUTER, https rather than the http that stays plaintext to the gateway, and QPS ceilings required - without a limit one caller can spend the whole backend's capacity. auth_type NONE and CORS are both named per API, since either turns an endpoint into an open one.

Static validated · Live test pendingTencent CloudTerraform
Open A Golden AMI Pipeline that Rebuilds on a Schedule, Tests and Scans

aws-image-builder

A pipeline with no schedule builds when somebody clicks, so the golden image ages until a person remembers it; image tests are the switch turned off to save an hour and scanning is off unless enabled; and the build instance's metadata service can hand its credentials to whatever a step downloads. Weekly rebuilds when a dependency changed, tests and scanning on, IMDSv2-only builds.

Static validated · Live test pendingAWSTerraform
Open A GoldenGate Deployment that Is Private, Backed Up and Patched

oci-goldengate

is_public puts the GoldenGate console and REST API on the internet; the admin password is a vault secret or a literal in state; a deployment with no backup schedule keeps extracts, replicats and checkpoints in one place; and without a maintenance window upgrades land whenever Oracle schedules them. Private behind an NSG, secret required, daily backups to a bucket, and a window you chose.

Static validated · Live test pendingOracle CloudTerraform
Open A Grafana that Reads as Its Identity, Privately, without API Keys

azure-grafana

API keys are long-lived, unscoped bearer tokens that read every dashboard and end up in CI variables; the login page is public by default; and the Essential SKU is a single instance with no SLA. Keys off, login over a private endpoint, Standard SKU zone-redundant, fixed outbound addresses for data-source allow lists, and the identity it reads with exported for its Monitoring Reader grant.

Static validated · Live test pendingAzureTerraform
Open A Graph Database that Has No Password

aws-neptune

Neptune has no user, no password and no GRANT. Authorization is IAM and it defaults to OFF, so anything that can reach port 8182 can read every edge and drop the lot. IAM auth on, storage encrypted, and the audit log driven from one variable because its two halves live in different resources and either alone logs nothing.

Static validated · Live test pendingAWSTerraform
Open A GraphQL API that Does Not Publish Its Own Schema

aws-appsync

introspection_config defaults to ENABLED, handing any caller a complete map of every type, field and argument, and query_depth_limit defaults to 0, which means no limit - so one nested query multiplies into thousands of resolver calls. Both closed here, with request bodies kept out of CloudWatch and a WAF association for the rate nothing else bounds.

Static validated · Live test pendingAWSTerraform
Open A Guardrail that Is Attached, Versioned and Not Empty

aws-bedrock-guardrail

Creating a guardrail does not apply it: the application must send guardrailIdentifier and guardrailVersion on every call, and DRAFT is mutable. This publishes a numbered version, outputs the two values your code needs, and refuses a guardrail with no policies at all - which attaches successfully, filters nothing, and reports as active.

Static validated · Live test pendingAWSTerraform
Open A Hetzner Firewall Applied to Servers that Says What It Does About Outbound

hetzner-firewall

A firewall applied to no server protects nothing; SSH from everywhere is the default suggestion; and once one outbound rule exists Hetzner drops every other outbound packet, DNS included. Servers or a label selector expected, port 22 from everywhere refused unless accepted, a DNS and HTTPS baseline added once outbound is restricted, and an output that says the private network is not filtered.

Static validated · Live test pendingHetznerTerraform
Open A Hetzner Snapshot of a Server, Labelled So a Fleet Can Select It

hetzner-snapshot

A Hetzner snapshot of a server, which is Hetzner's custom image, labelled by role and build so hcloud_image data sources can select the newest (unlabelled has to be accepted by name). The snapshot is the server at that moment, secrets and all: build the source clean and power it off first.

Static validated · Live test pendingHetznerTerraform
Open A Huawei Cloud Public Zone with Record Sets, Signed, and the Nameservers Exported

huawei-dns-zone

A Huawei Cloud public DNS zone with the flat record map grouped into the record sets Huawei expects (one per name and type, several values), DNSSEC on with the DS record for the registrar, and the nameservers exported. Private zones bound to a VPC are a different zone type and not this module.

Static validated · Live test pendingHuawei CloudTerraform
Open A Huawei Cloud VPC with Zonal Subnets, DNS You Chose, and a Range Checked Private

huawei-vpc

A Huawei Cloud VPC whose range is checked against RFC 1918 (a public range by name), with subnets placed in the zones you name, each with its gateway at the first address and DHCP handing out Huawei's resolvers so the platform's service names resolve. Nothing egresses: a NAT gateway (huawei-nat-gateway) or an EIP is a separate decision.

Static validated · Live test pendingHuawei CloudTerraform
Open A Hub with Spokes that Do Not Export Everything

gcp-network-connectivity-center

A hub with no spokes connects nothing; a VPC spoke advertises every subnet to every other spoke unless told otherwise, which is how a sandbox learns the production database range; and site-to-site data transfer routes branches through Google at its rates. Spokes come with the hub, each VPC spoke narrows its exports or says why not, and branch transit is off unless accepted.

Static validated · Live test pendingGoogle CloudTerraform
Open A KMS Key Placed on Purpose with What the Service Lacks Written Down

exoscale-kms-key

A key is zonal unless multi-zone, which is the surprise at the first cross-zone restore; and the service has no automatic rotation setting and no flag that refuses deletion, so a key is deleted in one call. Multi-zone unless told otherwise, and outputs that say rotation and deletion protection are not available, so nothing downstream assumes a control that is not there.

Static validated · Live test pendingExoscaleTerraform
Open A KMS Key that Rotates and Cannot Be Scheduled for Deletion

alicloud-kms-key

automatic_rotation defaults to Disabled, so today's key material encrypts everything for the life of the account; a key scheduled for deletion is gone after its window with everything encrypted under it; and deletion_protection, the switch that refuses the schedule, defaults to off. Rotation on at your interval, deletion protection on and off by name, the maximum pending window, and an alias.

Static validated · Live test pendingAlibaba CloudTerraform
Open A KMS Key that Rotates with the Longest Deletion Window

huawei-kms-key

rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its pending window with everything encrypted under it, on a service with no flag to refuse the schedule. Rotation on at your interval, a 30-day window, and an output that says no deletion-protection flag exists.

Static validated · Live test pendingHuawei CloudTerraform
Open A KMS Key that Rotates with the Longest Deletion Window

tencent-kms-key

key_rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its window with everything encrypted under it, on a service that has no flag to refuse the schedule. Rotation on for symmetric keys, a 30-day window (the maximum), and an output that says no deletion-protection flag exists.

Static validated · Live test pendingTencent CloudTerraform
Open A KMS Secret Encrypted with Your Key, with a Recovery Window Before It Is Gone

alicloud-kms-secret

A secret in Alibaba Cloud KMS Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the service key (the service key by name), with a version label that rotates the value when changed and a recovery window of up to thirty days before a deleted secret is gone; force deletion is accepted by name.

Static validated · Live test pendingAlibaba CloudTerraform
Open A KV v2 Engine that Keeps Versions and Refuses Blind Overwrites

vault-kv-engine

KV v1 overwrites in place, so a bad write is the end of the previous secret; cas_required defaults to false, so two writers that read the same version both succeed and the second silently replaces the first; and version history is unbounded by default. v2 always, check-and-set on (off by name), versions bounded by count and age, the mount's lease ceilings set rather than inherited.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open A Kafka Cluster Where a Misspelled Topic Fails Instead of Being Created

huawei-kafka-streaming

A DMS Kafka instance with enable_auto_topic off, because a producer that misspells a topic otherwise creates one: the messages go somewhere real, nothing errors, and nobody consumes them. TLS and SASL are both on, which is what makes the user mean anything; the disk is encrypted at creation; and what happens when the disk fills is a decision you take.

Static validated · Live test pendingHuawei CloudTerraform
Open A Kusto Cluster with an SLA, Off the Internet, Encrypted Twice

azure-data-explorer

The Dev(No SLA) SKUs say it in the name and are what a proof of concept becomes production on; public network access is on by default; disk and double encryption are off by default and set only at creation. Standard SKU with two instances across zones, private endpoints, both encryption layers on, a customer-managed key, and purge enabled because it is the only way to honour an erasure request.

Static validated · Live test pendingAzureTerraform
Open A Let's Encrypt Certificate in Secrets Manager That Renews Itself and Rotates Its Key

ibm-public-certificate

A publicly-trusted certificate issued into Secrets Manager, validated over DNS through Cloud Internet Services, with both configurations created here rather than left to a console. Staging issues a certificate no browser trusts while looking like success, so it is refused by name; auto-rotation and key rotation are on, because a ninety-day certificate nothing renews is a dated outage.

Static validated · Live test pendingIBM CloudTerraform
Open A Lightsail Instance with a Firewall that Names Its Sources, a Static IP and Snapshots

aws-lightsail-instance

A Lightsail instance is created with 22 and 80 open to every address; its public address changes when it stops unless a static IP is attached, and every DNS record pointing at it is then wrong; and automatic snapshots are off. The port list replaced by your rules with SSH from anywhere accepted by name, a static IP attached, and the daily AutoSnapshot add-on on at the hour you choose.

Static validated · Live test pendingAWSTerraform
Open A Linode Image Captured from a Disk and Replicated to the Fleet's Regions

linode-image

A Linode image captured from an instance disk, replicated to the regions you name (one region has to be accepted by name), cloud-init ready, with the label carrying the build. The image is the disk at that moment, secrets and all: build the source clean.

Static validated · Live test pendingLinodeTerraform
Open A Load Balancer that Checks the Application and Redirects HTTP

vultr-load-balancer

The default health check is TCP on the backend port, which a process that stopped serving still passes; ssl_redirect defaults to false, so the site stays in clear on 80; and a balancer with no instances is a public address that fails. HTTP checks on a path, redirect on whenever HTTPS exists, backends required, and a Let's Encrypt certificate from auto_ssl_domain rather than a pasted key in state.

Static validated · Live test pendingVultrTerraform
Open A Load Balancer that Checks the Application and Redirects HTTP

do-load-balancer

The default health check is a TCP handshake, which a process that stopped serving still passes; redirect_http_to_https defaults to false, so the site stays in clear on 80; and a balancer with no tag and no droplets is a public address that 503s. HTTP checks on a path, redirect on whenever HTTPS exists, STRONG ciphers, backends required, and a Let's Encrypt certificate made from your domains.

Static validated · Live test pendingDigitalOceanTerraform
Open A Load Balancer with a Certificate It Renews that Checks the Application

upcloud-load-balancer

The backend health check defaults to TCP, which a process that stopped serving still passes; TLS is a certificate bundle nobody creates; a port-80 frontend forwards unless a rule redirects it; and a public network puts the frontend on the internet. HTTP checks on a path (TCP by name), a Let's Encrypt bundle for the hostnames you list, a 301 from 80 whenever it exists, and public by name.

Static validated · Live test pendingUpCloudTerraform
Open A Load Balancer with a Let's Encrypt Certificate, Modern TLS, HTTP Redirected and Private Backends

scaleway-load-balancer

A Scaleway Load Balancer on a flexible IP with a Let's Encrypt certificate it issues itself (so the DNS must point at it first), TLS at the modern compatibility level (older clients by name), HTTP/3, the port 80 frontend answering only a 301 to HTTPS, and backends named by their Private Network address and probed over HTTP on a path you chose.

Static validated · Live test pendingScalewayTerraform
Open A Load Balancer with a Monitor that Checks and a Fallback that Is Separate

cloudflare-load-balancer

A pool with no monitor is healthy forever and keeps sending traffic to a dead origin; the fallback pool is required and the easiest value is the same pool that just failed; the notification email that says a pool went down is optional. Every pool uses the module's HTTPS monitor, a fallback that is also a default is refused, an address is told, and the balancer is proxied so origins stay hidden.

Static validated · Live test pendingCloudflareTerraform
Open A Local Peering Gateway Pair that Is Connected and Routed

oci-local-peering

A local peering gateway with no peer stays NEW forever, and a PEERED pair with no route rule sending the other CIDR to the gateway passes nothing while reading as connected. Both gateways created and connected from one call, a route table with the rule to the peer created on each side for the subnets that should reach across, overlap refused, and an output that says it is not transitive.

Static validated · Live test pendingOracle CloudTerraform
Open A Local Resolver That Validates What It Answers

ansible-unbound-resolver

Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open A Local Transit Gateway with a Connection per VPC and Prefix Filters as the Route Table

ibm-transit-gateway

An IBM Cloud Transit Gateway local to one region (global by name) with a connection per VPC you name, each denying every prefix by default and permitting the prefix rules you write, since a transit gateway has no route tables and every connection advertises everything otherwise; a connection that permits all has to say so.

Static validated · Live test pendingIBM CloudTerraform
Open A Log Sink that Actually Delivers

gcp-log-sink

Creating a sink creates a service account for it and grants that account nothing, so until it holds a role on the destination every export fails - the sink shows active, the destination stays empty, and the errors are logged into the project that was supposed to be exported. Grants the role with the sink, refuses an empty filter, and can manage _Default retention past 30 days.

Static validated · Live test pendingGoogle CloudTerraform
Open A Looker Instance over Private Service Connect, Sign-In Limited to Your Domains

gcp-looker

A Looker (Google Cloud core) instance reachable over Private Service Connect from the VPCs you allow, no public address, sign-in limited to your email domains, encrypted with your Cloud KMS key, in a maintenance window you chose. The OAuth client secret is sensitive and never output; the edition has no default because the annual editions commit for a year.

Static validated · Live test pendingGoogle CloudTerraform
Open A Lustre File System Behind NSGs, Encrypted with Your Key, Root Squashed

oci-lustre

OCI File Storage with Lustre in your subnet, reachable only through the network security groups you name, encrypted with a Vault key of yours (the Oracle-managed key by name), with root on clients squashed to a UID and GID you chose except for the clients you exempt (NONE by name), on the throughput tier you chose, with capacity checked against the 31,200 GB step before the plan.

Static validated · Live test pendingOracle CloudTerraform
Open A Managed AD Domain with Legacy Protocols Off and Its Prerequisites Created

azure-entra-domain-services

Microsoft Entra Domain Services with NTLM v1, TLS 1.0 and RC4 off and Kerberos armoring on, the WinRM network security group the service insists on, the AAD DC Administrators group with the members you name, and the Domain Controller Services principal registered, all of which fail late when missing. Notifications go to the admins; filtered sync and LDAPS are inputs.

Static validated · Live test pendingAzureTerraform
Open A Managed Database Behind a Firewall with More than One Node

civo-database

firewall_id is optional and a database without one answers to every address that can reach its endpoint; nodes = 1 is one node whose failure is downtime; and backups are the platform's, not configurable here. Firewall and network required, two nodes (one by name), the password as a sensitive output, and an output that says no backup schedule can be set.

Static validated · Live test pendingCivoTerraform
Open A Managed Database Reachable from Somewhere Specific with a Standby

vultr-database

A managed database gets a public hostname and trusted_ips is optional: left empty, any address on the internet may try the password; the backup hour is picked for you; and a plan with no replicas is one node whose failure is downtime. Trusted ranges required (a /0 refused unless accepted), a VPC attachment, one standby by default, both windows set, and the password as a sensitive output.

Static validated · Live test pendingVultrTerraform
Open A Managed Disk that Is Private, Attached, and Backed Up by a Policy that Is Assigned

azure-managed-disk

A managed disk's export SAS works from anywhere until public access is off; your key is a disk encryption set nobody creates; and Azure Backup for disks is a vault, a policy and an instance, where the instance is the assignment most vaults lack. Public export closed, the encryption set taken when given, and vault, policy, role assignments and backup instance created together (none by name).

Static validated · Live test pendingAzureTerraform
Open A Managed Instance that Is Entra-Only, Private and Zone-Redundant

azure-sql-managed-instance

The public data endpoint turns a private database into one listening on the internet on port 3342; SQL logins put an administrator password in state when Entra-only authentication would remove them entirely; and zone redundancy is off by default. Private, Entra-only with SQL authentication accepted by name, Business Critical across zones, TLS 1.2, and geo-zone-redundant backups.

Static validated · Live test pendingAzureTerraform
Open A Managed Kubernetes Cluster with an API Allow-List, Private Nodes and Encrypted Storage

upcloud-kubernetes

An UpCloud Managed Kubernetes cluster whose API answers only the ranges you list (0.0.0.0/0 by name), with private node groups off the public internet, node storage encrypted at rest (unencrypted by name), anti-affinity across hosts, manual upgrades, and node groups from a map with labels and taints. The plan is the control plane's redundancy and bill.

Static validated · Live test pendingUpCloudTerraform
Open A Managed Valkey Service on Your Private Network, TLS On, Backed Up, Protected

upcloud-valkey

An UpCloud Managed Valkey service attached to your SDN private network with public access off (on by name) and an IP filter of the ranges that may connect, TLS on, RDB persistence with a nightly backup, an eviction policy set, service logs on, a maintenance window you chose, and termination protection (off by name). The password is generated and the URI is a sensitive output.

Static validated · Live test pendingUpCloudTerraform
Open A MaxCompute Project That Refuses the Full Table Scan Which Writes the First Bill

alicloud-maxcompute

A MaxCompute project with allow_full_scan off, so a query with no partition predicate fails rather than quietly reading the whole table and billing per byte - the single most effective cost control MaxCompute has, and the one people turn on after the invoice. Storage encryption is a creation-time choice, and an unset IP white list admits every address rather than none.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Metrics Store that Can Actually Raise an Alarm

aws-prometheus

Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.

Static validated · Live test pendingAWSTerraform
Open A Migration that Is Not in Clear Text

aws-dms

ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.

Static validated · Live test pendingAWSTerraform
Open A Model Endpoint Reached by Identity, not a Key

azure-cognitive-services

custom_subdomain_name looks cosmetic and decides everything: without it Entra ID auth does not work and no private endpoint can attach, so the account is silently key-only and public - and it is ForceNew. Restricting outbound access is the data-loss-prevention control for an OpenAI account.

Static validated · Live test pendingAzureTerraform
Open A ModelArts Notebook Reachable Only from the Addresses You Name

huawei-machine-learning

A ModelArts workspace and notebook with allowed_access_ips required, since empty means any address and the notebook has your training data mounted and your credentials in its environment. auth_type PUBLIC means every user in the account rather than the internet. There is no auto-stop argument, and the module says so rather than implying a protection it cannot give.

Static validated · Live test pendingHuawei CloudTerraform
Open A MongoDB Replica Set in a VPC, Encrypted at Rest, Three Nodes Unless You Say Otherwise

tencent-mongodb

A MongoDB instance with TDE storage encryption on, which the API cannot add after creation, three nodes so the set can elect a new primary, and a VPC, subnet and security group all required, because an instance created without them lands in the classic network where nothing can fence it. PREPAID rebuilds the instance, so POSTPAID is the default.

Static validated · Live test pendingTencent CloudTerraform
Open A MongoDB-Compatible DDS Instance with TLS On and the Flavor List the Mode Requires

huawei-dds-mongodb

A Document Database Service instance with ssl true, since false accepts plaintext client connections and nothing in the console says so, a named backup window and retention, and disk encryption that cannot be added afterwards. Sharding needs mongos, shard and config flavors and the module checks the combination before the apply rather than after.

Static validated · Live test pendingHuawei CloudTerraform
Open A NAS File System Encrypted with Your Key, Mounted from the CIDR You Name, with a Recycle Bin

alicloud-nas-file-system

An Alibaba Cloud NAS file system (NFS) encrypted with your KMS key (NAS-managed without one; unencrypted is not offered), a mount target in your vSwitch behind an access group whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 by name), and a recycle bin that keeps deleted files two weeks (none by name).

Static validated · Live test pendingAlibaba CloudTerraform
Open A NAT Gateway for an Existing VCN with Its Route Table and a Reserved Address

oci-nat-gateway

A NAT gateway for an existing VCN with the private route table that sends subnets through it, because a gateway no table points at forwards nothing. The NAT address is ephemeral unless a reserved public IP is attached, and every allow-list that named it breaks on recreation; the ephemeral address is accepted by name. block_traffic, the kill switch, stays off and is exported.

Static validated · Live test pendingOracle CloudTerraform
Open A NAT Gateway for an Existing VPC with Its EIP and the Route Entries Written

tencent-nat-gateway

A standard NAT gateway for an existing Tencent Cloud VPC, with a traffic-billed elastic IP, a bandwidth and concurrency tier of its own, and a default route entry written in every route table listed, because a gateway no table routes to forwards nothing. The elastic IP's cap and the gateway's tier are the two numbers to raise when downloads crawl.

Static validated · Live test pendingTencent CloudTerraform
Open A Named VPC with a Range You Chose and Peerings that Do Not Collide

do-vpc

Every resource created without a vpc_uuid lands in the region's default VPC beside everything the team ever made there; an auto-assigned ip_range is the one most likely to collide with the next peer; and a peering between overlapping ranges is accepted and carries nothing. A named VPC, a required range, overlaps refused at plan time, and an output that says nothing inside the VPC is filtered.

Static validated · Live test pendingDigitalOceanTerraform
Open A Network Firewall that Prevents rather than Detects

oci-network-firewall

An INSPECT rule hands the flow to the threat engine, and inspection decides what happens next: INTRUSION_PREVENTION drops the session, INTRUSION_DETECTION logs it and forwards it, and the rule reads INSPECT either way. Every inspect rule is prevention unless detection is accepted by name; policy and appliance are both created, and the address the route tables must point at is an output.

Static validated · Live test pendingOracle CloudTerraform
Open A Network Load Balancer Whose Services Check the Application

exoscale-nlb

A service's health check can be a TCP handshake that a process which stopped serving still passes; an NLB fronts instance pools rather than instances; and it is layer 4, so no listener certificate exists and the one you look for lives on the instances. HTTP or HTTPS checks on a path with TCP accepted by name, a pool per service, and an output that says TLS is not terminated here.

Static validated · Live test pendingExoscaleTerraform
Open A Network with a Range You Chose

civo-network

Every resource created without a network_id lands in the region's default network beside everything the team ever made there; cidr_v4 is optional, so a network created without it gets whatever range was free, the one most likely to collide with the office or the VPN. A named network, a required range, the resolvers you chose, and an output that says the network itself filters nothing.

Static validated · Live test pendingCivoTerraform
Open A NoSQL Table that Is Not Reclaimed Behind Your Back

oci-nosql

is_auto_reclaimable is the Always Free shape and means the table is dropped, with its data, after 90 days without a read or write - right for a prototype and wrong for a table a quarterly job reads. Never reclaimable unless accepted by name, provisioned capacity with a ceiling set deliberately, and the DDL checked for a primary key before the API complains about syntax.

Static validated · Live test pendingOracle CloudTerraform
Open A Notebook that Is Not Root with Open Egress

aws-sagemaker-notebook

AWS defaults a notebook to direct internet access AND root access: a root shell with a path off the network that misses your NAT, routing and DNS firewall, holding a role chosen to read your training data. Both off here, IMDSv2 only.

Static validated · Live test pendingAWSTerraform
Open A PAI Workspace with Members, Because Without Them the Team Cannot See It

alicloud-machine-learning

A PAI workspace and the people in it. Created with no members the workspace belongs to whoever ran the apply and the team seeing nothing reads as a permissions problem elsewhere. env_types is fixed at creation and decides whether a dev-to-prod pipeline is even possible, and the role names are the permission model, so each member names their own.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Package Domain that Resists Dependency Confusion

aws-codeartifact

A repository with a public external connection serves whatever the public registry holds for any name it does not. This puts the connection on its own repository, reached through an upstream, and emits the origin-control commands Terraform cannot apply.

Static validated · Live test pendingAWSTerraform
Open A Pages Project Whose Previews Are Not Public by Accident

cloudflare-pages-project

Every branch pushed gets a public preview URL by default, the half-finished pricing page included; an environment variable is readable in the dashboard unless stored as a secret; and the production branch is whatever the repository's default was. Previews limited to the branches you list (every branch by name), each variable marked secret or plain, bindings per environment, and custom domains.

Static validated · Live test pendingCloudflareTerraform
Open A Patch Baseline That Says It Patches Nothing By Itself

alicloud-patch-manager

An OOS patch baseline: which updates are acceptable on one operating system. A baseline is a policy and an OOS task has to run it, which the module reports rather than letting the word imply a schedule. ALLOW_AS_DEPENDENCY makes a rejection advisory - the patch installs anyway when something approved needs it - so BLOCK is the default.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Patch Baseline, Its Patch Group and a Maintenance Window that Installs

aws-ssm-patch-manager

A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.

Static validated · Live test pendingAWSTerraform
Open A Patch Deployment that Targets Hosts and Reboots When Needed

gcp-os-config-patch

An instance filter that matches nothing patches nothing - the deployment runs on schedule, reports success and touches no host - and reboot_config NEVER installs the kernel and keeps running the old one. Refuses an empty filter, makes all-instances a stated choice because it includes the databases, reboots when the packages need it, and caps the share of a zone patched at once.

Static validated · Live test pendingGoogle CloudTerraform
Open A Patch Schedule Assigned to Machines that Reboots When Needed

azure-update-manager

A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.

Static validated · Live test pendingAzureTerraform
Open A Peering Connection with the Route Table Entries on Both Sides, Postpaid by Default

tencent-vpc-peering

A peering connection between two VPCs with a route table entry written into every route table you list, on both sides, for every CIDR of the other side, because an Active peering carries nothing until the routes exist. POSTPAID by default: PREPAID buys a bandwidth tier for a term that can be raised and never lowered, so it has to be accepted by name.

Static validated · Live test pendingTencent CloudTerraform
Open A Perimeter that Enforces rather than Rehearses

gcp-service-perimeter

spec is the dry-run configuration and status is the enforced one - two blocks of the same shape, and a perimeter with only a spec is evaluated on every request, logs violations, and blocks nothing. Empty restricted_services is the other way to have none: the perimeter exists, covers the projects, and governs no API.

Static validated · Live test pendingGoogle CloudTerraform
Open A Persistent Disk with a Snapshot Schedule that Is Attached

gcp-persistent-disk

A snapshot schedule is a resource policy, and its attachment to a disk is a separate resource, so a schedule in the console with no disks is the usual state; encryption is Google-managed unless a KMS key is given. The daily schedule created and attached or yours attached (none by name), your key when given, and the disk attached from its own side so the instance's disk list is left alone.

Static validated · Live test pendingGoogle CloudTerraform
Open A Persistent Parallelstore Instance on the Private Services Range You Already Have

gcp-parallelstore

A persistent Parallelstore instance on the private services range you already allocated, because a VPC has one service networking peering and a module that made another would break the databases on it. Twelve TiB minimum in steps of four, balanced striping, one zone. SCRATCH, which loses the data on maintenance, is accepted by name; the bucket you import from is the durable copy.

Static validated · Live test pendingGoogle CloudTerraform
Open A Policy Assignment that Actually Denies

azure-policy

enforce = false is Azure DoNotEnforce: the assignment appears, resources are evaluated, a compliance percentage is charted - and every violating resource is created anyway. From the portal compliance view that is indistinguishable from an enforced policy. Also refuses a silent not_scopes exclusion and an unexplained denial.

Static validated · Live test pendingAzureTerraform
Open A Policy Store where a Broken Rule Cannot Hide

aws-verified-permissions

validation_settings.mode defaults to OFF, so a Cedar policy naming an action the schema does not define is accepted and then never matches. A broken permit fails closed and somebody complains; a broken forbid fails OPEN and nobody does. STRICT here, with the schema that makes it possible.

Static validated · Live test pendingAWSTerraform
Open A Policy That Cannot Quietly Grant and Forbid Nothing

ovh-iam-policy

An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.

Static validated · Live test pendingOVHcloudTerraform
Open A Policy-Mode VPN Gateway with Its Own IKE and IPsec Policies Pinned to Strong Cryptography

ibm-vpn-gateway

An IBM Cloud VPC VPN gateway in policy mode with one connection to your on-premises gateway on IKEv2, with its own IKE and IPsec policies (AES-256, SHA-256, DH group 14) so IBM's auto-negotiation list never admits SHA-1 or a small group, the weak options refused by validation, IKEv1 by name, and dead peer detection that restarts the connection.

Static validated · Live test pendingIBM CloudTerraform
Open A PostgreSQL that Keeps Its Password in the Vault and Its Backups

oci-postgresql

password_type PLAIN_TEXT writes the admin password into the Terraform state and every plan that shows it; storage that is not regionally durable dies with its availability domain; and a DB system created without a management policy takes no backups. Vault secret reference, regionally durable storage, daily backups optionally copied to another region, a read replica, and an NSG on port 5432.

Static validated · Live test pendingOracle CloudTerraform
Open A Power BI Embedded Capacity with Named Administrators

azure-powerbi-embedded

A Power BI Embedded Gen2 capacity with the administrators who may assign workspaces named (required), in the size you chose with no default because the capacity bills by the hour from creation whether a report is rendered or not. Workspaces are assigned to the capacity in Power BI, which is an admin action outside the module.

Static validated · Live test pendingAzureTerraform
Open A Private CA Where Revoke Means Something to a Client

huawei-private-ca

A CCM private CA, root or subordinate. CRL publication is off by default, and without it you can press revoke while every client keeps trusting the certificate until it expires - so the module refuses that unless it is accepted. Deleting a CA starts a 7 to 30 day clock rather than deleting, and the product exists in two regions only.

Static validated · Live test pendingHuawei CloudTerraform
Open A Private CA Whose Templates Cannot Issue for Any Name

ibm-private-ca

A root CA, an intermediate it signs and certificate templates in IBM Cloud Secrets Manager. IBM's examples let a template issue for any name; here templates name their domains, both CAs carry name constraints, and CRLs are built and published. Lifetimes are checked to nest, and the module says plainly that Terraform cannot revoke a CA.

Static validated · Live test pendingIBM CloudTerraform
Open A Private CA that Can Revoke What It Issues

gcp-certificate-authority

The DevOps tier does not persist the certificates it issues: no record, no CRL, no revocation - a year-long certificate from it can only answer a key compromise by the CA being distrusted whole. ENTERPRISE tier with the CRL published, a 90-day ceiling on every certificate, RSA below 2048 refused, and deletion protection on because deleting a CA invalidates everything it signed.

Static validated · Live test pendingGoogle CloudTerraform
Open A Private CA that Issues from the Intermediate with Roles Bound to Domains

vault-pki-certificate-authority

Issuing from the root puts every leaf one signature from the root's compromise; a PKI role's defaults issue nothing until somebody reaches for allow_any_name, which issues for every hostname; and without AIA and CRL URLs a leaf is valid and unverifiable. A root that signs one intermediate, roles bound to allowed_domains, 30-day leaves under a 90-day ceiling, URLs on both mounts.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open A Private CA whose Revocations Are Published

oci-certificate-authority

The CRL bucket is optional: a CA created without one can mark a certificate revoked and never tell anyone, and every client keeps trusting it until it expires. Required here unless no CRL is accepted by name. Issued certificates renew by rule; one without a renewal rule is a countdown and is listed. Leaf validity is capped at 90 days; the signing key is an HSM key in your vault.

Static validated · Live test pendingOracle CloudTerraform
Open A Private Db2 Deployment with a Standby and an Allow List That Is Not Empty

ibm-db2

A Db2 deployment on a private endpoint with high availability on, disk encryption with a key you hold, and named ranges, because Db2 reads an absent allow list as any address rather than none. Autoscaling is off unless configured and its plan limit is the point: it is the difference between a slow hour and an unbounded invoice. Oracle compatibility is fixed at creation.

Static validated · Live test pendingIBM CloudTerraform
Open A Private Elasticsearch Deployment with Three Members, Because Two Cannot Elect

ibm-databases-elasticsearch

A Databases for Elasticsearch deployment on a private endpoint with deletion protection on, your Key Protect keys for both the data and the backups, and an allowlist that must name ranges because an empty one is read as any address. Three members, fixed rather than offered as a knob with one safe value. The plan, not the module, decides whether field-level security exists.

Static validated · Live test pendingIBM CloudTerraform
Open A Private Link Endpoint with a VIP in Your Subnet Behind Your Security Groups

tencent-privatelink-endpoint

A Tencent Cloud Private Link endpoint to an endpoint service, with a VIP in the subnet you name behind the security groups you name; an endpoint with no security group is reachable from the whole VPC and has to be accepted by name. One subnet per endpoint; a second zone is a second endpoint.

Static validated · Live test pendingTencent CloudTerraform
Open A Private Network with a Managed Range You Chose

exoscale-private-network

A private network without start, end and netmask hands out no addresses: every instance configures its own and two that pick the same one collide silently; and nothing filters traffic on the segment. A managed range required and derived from your RFC 1918 CIDR, addresses reserved at the ends for gateways, and an output that says every attached instance reaches every other.

Static validated · Live test pendingExoscaleTerraform
Open A Private Network with a Range You Chose and a Way Out When You Want One

upcloud-network

A private network on a public range is the surprise at the first NAT, and dhcp_default_route defaults to false, so servers get an address and no route, right for an isolated segment and wrong for one behind a router. An RFC 1918 range required, DHCP handing out the resolvers you chose, a router created and the default route set when you ask, and an output that says the network filters nothing.

Static validated · Live test pendingUpCloudTerraform
Open A Private Network with a Subnet You Chose and a Gateway Out

ovh-private-network

A private network is a vRack VLAN that carries no addresses until a subnet hands them out; a subnet without a gateway address has no way to the internet; and nothing filters traffic on the segment. The subnet's RFC 1918 range required, DHCP with the resolvers you chose, an OVH gateway created by default so instances reach out without a public address, the network named as unfiltered.

Static validated · Live test pendingOVHcloudTerraform
Open A Private Purview Account Without the Managed Event Hub, Granted Read on Its Sources

azure-purview

A Microsoft Purview account for the data map with public network access off, the managed Event Hub that bills monthly whether used or not turned off, a system identity, and Storage Blob Data Reader granted to that identity on every storage account it will scan, since a scan fails otherwise. The account bills for data map capacity from creation; public access is accepted by name.

Static validated · Live test pendingAzureTerraform
Open A Private Registry Namespace with a Push Key that Is Scoped and Expires

scaleway-container-registry

is_public makes every image in the namespace pullable by anyone, and the key CI pushes with is usually a person's API key with every permission that person has and no expiry. Private unless public is accepted by name, and on request an IAM application whose only permission is registry access in one project, with an API key that expires on the date you set.

Static validated · Live test pendingScalewayTerraform
Open A Private Registry that Answers Only to the Ranges You Say

ovh-container-registry

A registry's endpoint is public and every address may try a login until an IP restriction exists; the registry user is the credential and its password lands in state; and the plan is the storage ceiling. Allowed ranges expected with none accepted by name, one user created for the pipeline with its password as a sensitive output, and the plan looked up by name.

Static validated · Live test pendingOVHcloudTerraform
Open A Private Resolver Whose Rules Forward and Whose VNets Are Linked

azure-dns-private-resolver

A resolver is five resources - endpoints, ruleset, rules and VNet links - and the half-built state most sit in resolves Azure names and forwards nothing to on-premises; a ruleset not linked to a VNet applies to nothing; and each endpoint needs its own delegated subnet. All five created, forwarding rules required, VNet links expected (none by name), the inbound address exported.

Static validated · Live test pendingAzureTerraform
Open A Private Scaleway Instance Image Built from a Snapshot of a Root Volume

scaleway-image

A Scaleway instance image built from a snapshot the module takes of the root volume you name, private (public lists it for every Scaleway account and has to be accepted by name), for x86_64 or arm64, in one zone. Stop the server first so the file system is consistent.

Static validated · Live test pendingScalewayTerraform
Open A Private Vultr Container Registry on the Plan You Chose

vultr-container-registry

A Vultr container registry that is private (public, which lets anyone pull every image, is accepted by name), on the plan you chose (start_up is free and small; the paid plans bill monthly from creation), in the region your clusters are in. The root user Vultr creates is not output; a robot user per cluster is the credential to hand out.

Static validated · Live test pendingVultrTerraform
Open A Private Zone with the Permitted Networks Without Which It Resolves for Nobody

ibm-dns-zone

An IBM Cloud DNS Services private zone, its permitted networks and its records. The zone and the permission are separate resources: with none, the zone is created, the records are created, everything reports Active, and no VPC can resolve any of it. An empty list is refused. This is private DNS and it is not the public zone, which is CIS.

Static validated · Live test pendingIBM CloudTerraform
Open A PrivateLink Endpoint with an Interface per Zone Behind Your Security Groups, Protected from Deletion

alicloud-privatelink-endpoint

An Alibaba Cloud PrivateLink endpoint to a PrivateLink service or an Alibaba Cloud service, with an elastic network interface in each vSwitch you name (one zone has to be accepted by name), behind the security groups you name, and protected from deletion until the protection is turned off.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Public Gateway on a Reserved Address with Masquerade, Bastion and SMTP Off

scaleway-public-gateway

A Scaleway Public Gateway on a reserved address, attached to a Private Network with masquerade and the default route pushed to the hosts, since a gateway with no gateway network forwards nothing. The bastion (SSH into the network through the gateway) is off and accepted by name; outbound SMTP is off so a compromised host cannot send mail under your name.

Static validated · Live test pendingScalewayTerraform
Open A Public NAT Gateway for an Existing VPC with Its EIP and SNAT Rules

huawei-nat-gateway

A pay-per-use public NAT gateway for an existing Huawei Cloud VPC, with a traffic-billed elastic IP whose bandwidth cap every subnet shares, and an SNAT rule for each subnet listed, because a gateway with no SNAT rule forwards nothing. The spec is a concurrency tier (10,000 to a million connections) and what an idle gateway costs per hour.

Static validated · Live test pendingHuawei CloudTerraform
Open A Public Website Bucket That Does Not Publish Its File List

gcp-static-site

A Cloud Storage bucket serving a static website. Google's own guide notes that objectViewer lets anyone list the bucket, so this module grants legacyObjectReader: read a named file, list nothing. It says plainly that Cloud Storage does not serve your domain over HTTPS, requires you to accept that everything in it is public, and keeps trimmed previous versions as the rollback.

Static validated · Live test pendingGoogle CloudTerraform
Open A Published Service that Decides Who May Connect

gcp-private-service-connect

ACCEPT_AUTOMATIC admits any project on Google Cloud that knows the attachment URI, which is not a secret and appears in logs. Manual by default with a per-consumer connection limit; an empty accept list is refused too. PROXY protocol is on so backends see the consumer rather than the NAT range, removed consumers are disconnected, and the NAT subnet is created with the attachment.

Static validated · Live test pendingGoogle CloudTerraform
Open A Pulsar Cluster Where TTL and Retention Are Told Apart

tencent-tdmq-queue

A TDMQ for Pulsar cluster and its namespaces. msg_ttl is how long an UNACKNOWLEDGED message lives, not how long consumed ones are kept: too short silently drops work when a consumer is slow, too long turns a stuck consumer into unbounded backlog, and both extremes are refused. Retention is the separate thing that lets a new subscription read history.

Static validated · Live test pendingTencent CloudTerraform
Open A Queue with a Dead-Letter Queue and a Week of Retention

oci-queue

dead_letter_queue_delivery_count defaults to zero, which is no dead-letter queue: a message a consumer cannot process is redelivered after every visibility timeout until retention expires, a poison message that holds a consumer for a day. Five deliveries then the dead-letter queue, seven days of retention instead of one, and a vault key instead of an Oracle-managed one.

Static validated · Live test pendingOracle CloudTerraform
Open A QuickSight Subscription on Enterprise Through Identity Center, with a VPC Connection

aws-quicksight

A QuickSight subscription on Enterprise edition through IAM Identity Center, with admin, author and reader groups, termination protection on because unsubscribing deletes every dashboard, and a VPC connection with its own role so a private database stays private. The authentication method is permanent; Standard edition and QuickSight-managed users are accepted by name.

Static validated · Live test pendingAWSTerraform
Open A RAM Role a Service May Assume, with a Custom Policy and an Hour-Long Session

alicloud-ram-role

A RAM role assumable by the services or accounts you name and nothing else (a wildcard principal is refused), with a custom policy written from your statements, the system policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Redis Cluster on a Private Network Only, TLS On, Allow-Listed, Three Nodes

scaleway-redis

A Scaleway Managed Database for Redis cluster attached to your Private Network with no public endpoint (one by name), TLS required (plaintext by name), a password from a secret store never output, an ACL of the ranges that may connect (required), an eviction policy set, and three nodes so the data has three copies (fewer by name).

Static validated · Live test pendingScalewayTerraform
Open A Registry Where Pushing v1.4.2 Twice Is an Error

alicloud-container-registry

Namespaces, repositories, VPC access and an internet allowlist on an Alibaba Cloud Container Registry Enterprise Edition instance. Repositories are private and their tags immutable unless set otherwise, auto-create is off, and the internet endpoint is only switched on - by the resource existing - when you give it CIDRs. Image cleanup is deliberately not managed.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Resource Directory Where Policy Can Attach and Accounts Can Be Deleted

alicloud-landing-zone

A Resource Directory with its folders and member accounts. Two switches decide whether it works: control policies are off until the directory enables them, so a policy written elsewhere attaches to nothing; and member deletion is off by default, which makes every account this creates permanent and terraform destroy fail on it. Both are on here.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Risk Scan Whose Settings Are Words Instead of Digits

tencent-security-posture

A CSIP risk scan. Every setting in this API is an integer and 0 means a full scan in one field, a periodic task in another and off in a third, so the module takes words and writes the numbers. A full scan is an active probe of production and weakpass attempts passwords, so both are asked for by name; without configrisk there are no posture findings at all.

Static validated · Live test pendingTencent CloudTerraform
Open A Rollout that Can Still Be Taken Back

aws-appconfig

AppConfig exists to deploy a configuration slowly and roll it back automatically, and both halves are opt-in - the predefined AllAtOnce strategy is 100% of the fleet with zero bake time. Gradual here, and a precondition refuses an environment with no alarms, where automatic rollback has nothing to fire on.

Static validated · Live test pendingAWSTerraform
Open A Root Key that Rotates and Takes Two People to Delete

ibm-key-protect-key

The rotation policy is a separate resource nobody creates, so a key made today encrypts everything for the life of the account; dual_auth_delete, the control that makes deletion a two-person act, is off by default; and force_delete would remove a key buckets still use. Rotation on at your interval, dual authorization on (off by name), force delete never, the instance created when none is given.

Static validated · Live test pendingIBM CloudTerraform
Open A Route 53 Health Check with the Alarm that Makes a Failure a Notification

aws-route53-health-check

A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.

Static validated · Live test pendingAWSTerraform
Open A SIEM that Can Still Answer for Last Quarter

azure-sentinel

retention_in_days defaults to 30, against intrusions usually discovered months later - so the first question, when did this start, gets silence rather than an answer. daily_quota_gb is a trap both ways and has no safe default, so the module makes you choose. And onboarding Sentinel connects no data source at all.

Static validated · Live test pendingAzureTerraform
Open A Scaleway DNS Zone with Its Records and the Nameservers for the Registrar

scaleway-dns-zone

A Scaleway DNS zone (the root zone of the domain unless a subdomain is named) with every record in one map and the nameservers Scaleway assigns exported for the registrar. Geo-routed, weighted and health-checked records are kept out so a plain zone stays plain; a domain registered with Scaleway is delegated already.

Static validated · Live test pendingScalewayTerraform
Open A Scaleway Instance on a Private Network, No Public Address, Protected from Deletion

scaleway-instance

A Scaleway instance on a Private Network with a required security group (the project default allows everything inbound), no public address unless a flexible IP is accepted by name, the project's SSH keys and no password, a Block Storage root volume deleted with the instance, cloud-init, and protection from deletion (off by name).

Static validated · Live test pendingScalewayTerraform
Open A Search Service with an SLA, Reached by Identity

azure-search-service

One replica - the default - is excluded from the availability SLA; the admin key, on by default, reads and writes every index and is revoked only by regenerating it for everyone; and the query endpoint is public by default. Three replicas, Entra ID only, private endpoint, 0.0.0.0/0 refused in the allow list, and optional enforcement that refuses an index without a customer-managed key.

Static validated · Live test pendingAzureTerraform
Open A Secret Group and an Arbitrary Secret in an Instance You Already Pay For

ibm-secrets-manager

A secret group and an arbitrary secret in an IBM Cloud Secrets Manager instance you already have, over the private endpoint. The instance is a paid resource created once per account and is an input, so an apply never creates a second bill; the group is the unit IAM grants are made on; the value is a sensitive variable never output; an expiry is expected, none by name.

Static validated · Live test pendingIBM CloudTerraform
Open A Secret and Its Version, Encrypted with Your KMS Key, with a Recovery Window

tencent-secrets-manager

A secret in Tencent Cloud Secrets Manager as the two resources it is: the container with your KMS key (the service key by name) and a recovery window of up to thirty days, and the version that carries the value, a sensitive variable supplied at apply time and never output. A new version label is how the value rotates; immediate deletion is accepted by name.

Static validated · Live test pendingTencent CloudTerraform
Open A Security Group Whose Members Cannot Reach Each Other Unless Told

alicloud-security-group

inner_access_policy defaults to Accept, so every instance in a group talks to every other on every port and one compromised web node is a route to the database beside it; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Members isolated unless told otherwise, SSH from anywhere refused unless accepted, egress open until rules narrow it.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Security Group Without the Rules You Did Not Write

huawei-security-group

Every new security group comes with default rules - all egress allowed and ingress from its own members - that nobody wrote and few remove; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Default rules deleted so the group holds only what the module wrote, egress stated, SSH from anywhere refused unless accepted.

Static validated · Live test pendingHuawei CloudTerraform
Open A Security Group Written as One Ordered Rule Set with a Deny at the End

tencent-security-group

Rules are ordered and the first match wins, so an ACCEPT from 0.0.0.0/0 anywhere in the list admits everything from that line down; one rule-set resource replaces the whole list on every apply; and SSH from everywhere is the first rule offered. Your rules in order with an explicit DROP appended, SSH from a /0 refused unless accepted, egress open until rules narrow it.

Static validated · Live test pendingTencent CloudTerraform
Open A Security Group that Drops Inbound by Default

scaleway-security-group

The default inbound policy is accept, so a group with no rules admits every packet on every port and your rules are exceptions to accept-all; SSH from everywhere is the first rule offered; and the group filters the public interface only. Drop by default, SSH from a /0 refused unless accepted, the SMTP block kept unless a relay says otherwise, and outputs that say the Private Network is unfiltered.

Static validated · Live test pendingScalewayTerraform
Open A Security Group that Is Attached and Says What Empty Means

ibm-security-group

An IBM VPC security group with no rules denies everything in both directions, so a group written with inbound rules only leaves instances that cannot resolve DNS; a group with no targets protects nothing; and SSH from 0.0.0.0/0 is the first rule offered. Outbound explicit with egress open by default, targets attached by the module (none by name), SSH from anywhere refused unless accepted.

Static validated · Live test pendingIBM CloudTerraform
Open A Security Group that Names Its Sources and Says What It Does Not Filter

exoscale-security-group

A group with no rules admits nothing inbound and everything outbound; SSH from 0.0.0.0/0 is the first rule offered; a rule's source can be another group, which is how tiers reach each other without a CIDR that goes stale; and the private network is never filtered. Named sources or source groups, SSH from anywhere refused unless accepted, egress narrowed only when asked.

Static validated · Live test pendingExoscaleTerraform
Open A Sending Domain That Tells You the DNS Records It Is Waiting For

tencent-ses

A Tencent Cloud SES domain, its addresses and its templates. The module exposes the exact DNS records Tencent is waiting for, because that is the thing you need next and it lives outside this Terraform. DKIM is on, since unsigned mail is accepted by the API, filed as spam and reported as sent; and a template is reviewed manually before it works.

Static validated · Live test pendingTencent CloudTerraform
Open A Sending Domain and Its Addresses, and Why an Applied Resource Is Not a Sender

alicloud-transactional-email

A DirectMail sending domain and the addresses that send from it. Creating the domain does not verify it: nothing sends until the SPF, DKIM, MX and ownership records exist in DNS, which is usually not this Terraform, and the status output is how you find out. trigger and batch are different products with the same name and are throttled and reviewed differently.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Server Firewall Whose Rules Name Their Sources and End in a Drop

upcloud-firewall

The firewall is a per-server rule list evaluated top to bottom, attached by definition but only applied while the server's firewall flag is on; the last rule decides; and SSH from 0.0.0.0/0 is the first rule offered. Your accepts in order with a drop of everything else appended, SSH from anywhere refused unless accepted, egress open until rules narrow it.

Static validated · Live test pendingUpCloudTerraform
Open A Serverless Application in a Network You Wrote Down Rather Than One SAE Invented

alicloud-sae-application

A Serverless App Engine namespace and application with auto_config false, which makes the VPC, vSwitch and security group required rather than letting SAE create three resources that live in your account and nobody's Terraform. Two replicas so a deploy is not an outage, min_ready_instances set so a rollout is actually rolling, and typed liveness and readiness probes.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Serverless Cloud Function with Its Own Role, No Public Network, and Logs to CLS

tencent-scf-function

A Serverless Cloud Function running as the CAM role you name, with public network access off (on by name), in your VPC when a subnet is given, logging every invocation to a CLS logset and topic (none by name), synchronous only, with code fetched from a COS object you uploaded. Memory and timeout are inputs.

Static validated · Live test pendingTencent CloudTerraform
Open A Serverless Collection Reachable from Your VPC with Access Granted by Name

aws-opensearch-serverless

A collection cannot exist without an encryption policy and the quickest one uses the AWS-owned key; the network policy decides whether the endpoint answers on the internet; without a data access policy nobody can read or write, with a wide one everyone can; indexes grow until a policy expires them. Private through VPC endpoints (public by name), your key when given, principals named.

Static validated · Live test pendingAWSTerraform
Open A Serverless Function in Its Own Namespace, Private, HTTP Redirected, Idling at Zero

scaleway-function

A Scaleway Serverless Function in its own namespace, private so an IAM token is needed to invoke it (public by name), plain HTTP redirected to HTTPS, secrets in the encrypted secret variables rather than the plain ones, idling at zero instances with a ceiling you chose, and the zip archive uploaded at apply with its hash so a changed archive redeploys.

Static validated · Live test pendingScalewayTerraform
Open A Serverless Spark Application with a Ceiling on Every Run and Logs in Your Bucket

oci-data-flow

An OCI Data Flow application that runs Spark from a file in Object Storage with the driver and executor shapes you size, logs to a bucket you own (required, or the output is lost with the run), reaches your VCN through a Data Flow private endpoint when you give one, stops a run after the ceiling you set and an idle session after thirty minutes, and terminates runs when deleted.

Static validated · Live test pendingOracle CloudTerraform
Open A Serverless Valkey Cache That Is Not Open to Its Whole Network

aws-elasticache-serverless

ElastiCache Serverless for Valkey. With no user group, any client that reaches the endpoint connects as the default user with no password, so this module always attaches a Valkey user group whose users sign in with IAM. It sets a storage and ECPU ceiling, since AWS sets none, and keeps 7 days of snapshots. It also says destroy takes no final snapshot.

Static validated · Live test pendingAWSTerraform
Open A Serverless Warehouse Whose Spend Limit Does More Than Log

aws-redshift-serverless

An Amazon Redshift Serverless namespace and workgroup: customer-managed encryption, SSL required, all three logs exported, and the admin password generated and held by Secrets Manager. AWS accepts plaintext connections by default and a usage limit's default action only logs the breach, so SSL is set at creation and the spend limit's action has to be chosen: alert or stop.

Static validated · Live test pendingAWSTerraform
Open A Service Control Policy Whose Type Decides What Its Document Even Means

huawei-org-policy

An Organizations policy and its attachments. The type - service control, tag or AI service - decides what the JSON means, and the same document in the wrong type either fails to attach or attaches and does nothing recognisable. An SCP is a ceiling that cannot grant, an unattached policy enforces nothing, and a root attachment reaches the management account.

Static validated · Live test pendingHuawei CloudTerraform
Open A Service Network where the Network Is Not the Permission

aws-vpc-lattice

auth_type defaults to NONE, so any client in any associated VPC can call any service with no identity and no policy - and associating one more VPC silently grants everything in it. Defaults to AWS_IAM and requires per-VPC security groups.

Static validated · Live test pendingAWSTerraform
Open A Service where a Push Is Not a Deploy

aws-app-runner

auto_deployments takes every push to the image tag straight to production with no review, which quietly makes the deployment gate "who can push". Off by default, egress routed through your VPC, and the pull role kept separate from the run role.

Static validated · Live test pendingAWSTerraform
Open A Site-to-Site VPN on IKEv2 with Both Tunnels Configured

oci-site-to-site-vpn

Every OCI IPSec tunnel is created with IKE version 1 unless told otherwise, and negotiates from a compatibility list that still accepts SHA-1, AES-128 and DH group 2 - so the weakest option a peer proposes is what it gets, and the tunnel shows UP. IKEv2 on both tunnels, explicit proposals for both phases with the weak ones refused by validation, BGP routing, and one configured tunnel only by name.

Static validated · Live test pendingOracle CloudTerraform
Open A Site-to-Site VPN with Modern Crypto, BGP, and a Connection

azure-vpn-gateway

A connection with no ipsec_policy negotiates from a built-in list that still offers 1024-bit Diffie-Hellman and SHA-1, so a peer that proposes them gets them and the tunnel comes up looking healthy. Always writes an explicit policy and refuses the weak groups. A gateway with no connection bills by the hour for nothing, so the sites come with the gateway; BGP is on, Basic is refused.

Static validated · Live test pendingAzureTerraform
Open A Snapshot Schedule Attached to Disks, that Outlives Them

gcp-snapshot-schedule

The resource policy is the schedule; a disk follows it only through a separate attachment, so a policy that reads daily-keep-30 in the console and is attached to nothing has never taken a snapshot. Takes the disks with the schedule and refuses one with none. Keeps the snapshots when the disk is deleted, because APPLY_RETENTION_POLICY lets them age out in exactly the window they are needed.

Static validated · Live test pendingGoogle CloudTerraform
Open A Snapshot Schedule That Tells You What It Will Cost and What It Will Not Survive

tencent-backup-policy

A CBS snapshot policy and the disks it runs against, because an unattached policy has a schedule and a retention and protects nothing. The hours are UTC, not your clock. Retention is always set, since a policy without one keeps every snapshot forever, and retained_snapshots_per_disk is the number the storage bill is made of.

Static validated · Live test pendingTencent CloudTerraform
Open A Spaces Bucket that Is Private, Versioned, and Cleans Up

do-spaces-bucket

A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.

Static validated · Live test pendingDigitalOceanTerraform
Open A Spark Application that Runs Inside Your VPC

aws-emr-serverless

Without network_configuration the application runs on AWS-managed networking: it cannot reach a private database, and its egress skips your routing, NAT and DNS firewall. Monitoring is absent by default too, so a failed job leaves no executor logs, and no maximum_capacity makes the account quota the only ceiling.

Static validated · Live test pendingAWSTerraform
Open A Static Site That Tells You the File List Is Public Too

tencent-static-site

A COS bucket serving a static website. The public-read ACL that makes the objects readable also lets anyone list the bucket, and file_list_is_public says so; pass a bucket policy to publish the objects alone. redirect_all_requests_to on COS is a protocol rather than a hostname, which is why it is not exposed here.

Static validated · Live test pendingTencent CloudTerraform
Open A Static Site Where Encrypting the Bucket Would Break It

huawei-static-site

An OBS bucket serving a static website, published by an OBS-format bucket policy rather than a public-read ACL, so the file list stays private. Encryption is off on purpose: every byte is published deliberately, and an anonymous reader holds no permission on your key, so a key of your own hides nothing and stops the site working.

Static validated · Live test pendingHuawei CloudTerraform
Open A Static Site Whose Bucket Is Readable and Whose File List Is Not

alicloud-static-site

An OSS bucket serving a static website. The ACL stays private and a bucket policy publishes the objects, because a public-read ACL also lets anyone list every file you ever put there. The website endpoint is plain HTTP on an Alibaba domain and no certificate can go on it, so serves_https is an output and it says false.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Static Site Whose Policy Version Is Not the One Every S3 Example Uses

scaleway-static-site

A Scaleway Object Storage bucket serving a static website. A bucket policy here is version 2023-04-17, not the AWS 2012-10-17 that every S3 example carries and Scaleway has deprecated, and the module checks which one you passed. Without a policy the public-read ACL also publishes the file list, which file_list_is_public reports.

Static validated · Live test pendingScalewayTerraform
Open A Store where a Leaked Read Key Is Not the Whole Estate

azure-app-configuration

local_auth_enabled defaults true and the keys carry no identity: a read key reads every value, cannot be scoped, and is revoked only by regenerating it for everybody. Purge protection defaults off, and purging frees the name - which frees the endpoint your applications trust.

Static validated · Live test pendingAzureTerraform
Open A Stream Pool Reached Privately, with Streams that Keep Enough

oci-streaming

A public stream pool is an FQDN reachable from anywhere with a valid token; auto_create_topics lets any producer create a stream by writing to a new name; retention defaults to 24 hours, so a consumer a day behind loses data with no error on the producer side. Private endpoint behind NSGs, declared streams, seven days of retention, and the stream that loses data soonest reported as an output.

Static validated · Live test pendingOracle CloudTerraform
Open A Synapse Workspace with No SQL Login, a Managed Network and a Dedicated Pool Audited

azure-synapse

A Synapse workspace with a dedicated SQL pool and no SQL login: Entra-only authentication with a group as admin, a managed virtual network with data exfiltration protection (neither can be turned on later), public endpoints off, extended auditing and threat detection on the workspace and the pool, and vulnerability scans when you name a container. The pool bills by the hour while online.

Static validated · Live test pendingAzureTerraform
Open A Sync Job and the Configuration Without Which It Is a Billed Instance Doing Nothing

tencent-database-migration

A DTS sync job and its configuration, created together, because creating the job alone starts billing a replication instance that replicates nothing - the easiest thing in this product to leave behind. encrypt_conn is on at both ends, retry is set so a transient fault does not end the job, and object mode All has to be taken by name.

Static validated · Live test pendingTencent CloudTerraform
Open A TCR Basic Instance, Private, with Namespaces that Scan on Push and Refuse Vulnerable Images

tencent-tcr

A Tencent Container Registry basic instance (pay-as-you-go; the premium editions are a purchase) with public network access off unless accepted by name and a security policy of allowed ranges when it is on, deletion protection on, versioned storage, and namespaces from a map that are private, scan every pushed image and refuse to pull one at or above the severity you set, with their repositories.

Static validated · Live test pendingTencent CloudTerraform
Open A Tablestore Instance Reachable Only from a VPC, with Encrypted Tables That Expire

alicloud-tablestore

A Tablestore instance whose accessed_by is Vpc rather than the Any the API defaults to, so an AccessKey and the public endpoint are not enough to read it, plus the tables you declare - each with server-side encryption on, which cannot be added later, and each naming a time to live, because a table set to never expire grows forever.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Tekton Pipeline With Tasks to Run and Something to Start It

ibm-devops

An IBM Cloud CD toolchain, Tekton pipeline, definition and triggers. Without a definition the pipeline is enabled and has no tasks while everything looks finished. enable_events_from_forks runs the pipeline with its own credentials for anyone who can open a pull request, so it is off and refused by name, and omitting a concurrency limit disables it entirely.

Static validated · Live test pendingIBM CloudTerraform
Open A TencentDB for Redis Instance with a Replica, a Password, and No Public Address

tencent-redis

A TencentDB for Redis instance in your VPC with a replica per shard (none by name), a password required rather than no_auth, security groups attached (none by name), no public address, and a recycle window that holds a deleted instance for seven days; force deletion is accepted by name. Pay-as-you-go.

Static validated · Live test pendingTencent CloudTerraform
Open A Transactional Email Domain with Its DNS Records Exported and Validated First

scaleway-transactional-email

A Scaleway Transactional Email domain with the SPF, DKIM, DMARC and MX records it needs exported (and written automatically when the domain is in Scaleway DNS), the terms of service accepted by name, and a validation step that polls until the records resolve so an apply fails rather than pretends when they are not published yet.

Static validated · Live test pendingScalewayTerraform
Open A Transfer that Copies without Deleting and Says When It Fails

gcp-storage-transfer

delete_objects_unique_in_sink turns a backup into a mirror: an object deleted at the source is deleted at the destination on the next run, replicating the event the copy was meant to survive; and a job with no notification fails while its status stays ENABLED. Copies only, refuses mirroring and moving unless accepted, publishes every outcome to a topic, and spells out what the service agent needs.

Static validated · Live test pendingGoogle CloudTerraform
Open A Transfer that Does Not Delete What It Finds

aws-datasync

preserve_deleted_files = REMOVE deletes files at the DESTINATION that are absent from the source, so an unmounted share or a renamed path empties the destination on schedule and the task reports success. PRESERVE here, with verification on, a bandwidth ceiling so it cannot take the whole Direct Connect, and a per-file report of what failed.

Static validated · Live test pendingAWSTerraform
Open A Trust Anchor that Is Not Your Whole Corporate CA

aws-rolesanywhere

Any certificate chaining to the trust anchor can exchange itself for AWS credentials, so the CA is the perimeter - and it is usually run by people who were never told. The profile carries the scope, sessions are narrowed below the role, the caller cannot name itself in CloudTrail, and CA expiry warns before every workload loses credentials at once.

Static validated · Live test pendingAWSTerraform
Open A Trusted Profile with Scoped Policies and the Compute Resources that May Assume It

ibm-trusted-profile

An IAM trusted profile, which is identity without an API key: policies that grant roles on one service and resource group each (Administrator by name), and links to the virtual servers or Kubernetes service accounts that may assume it through the metadata service, since a profile with no link is assumed by nobody (accepted by name).

Static validated · Live test pendingIBM CloudTerraform
Open A Turnstile Widget with Every Hostname Listed and the Secret Kept

cloudflare-turnstile

The widget secret is the whole check: whoever holds it mints passing verifications for your forms; domains is an allow list of hostnames, so a widget made for production does not render on staging until staging is listed; and the mode decides whether visitors see a checkbox, a spinner or nothing. Hostnames required, the mode validated, and the secret exposed only as a sensitive output.

Static validated · Live test pendingCloudflareTerraform
Open A VPC Custom Image from a Boot Volume, Wrapped with Your Key, with Deprecation Dates

ibm-image

An IBM Cloud VPC custom image made from a boot volume, wrapped with the Key Protect or HPCS key you name (provider-managed encryption has to be accepted by name), with deprecation and obsolescence dates so the fleet is told when to move on and cannot launch an obsolete image. Stop the instance first.

Static validated · Live test pendingIBM CloudTerraform
Open A VPC Endpoint Whitelisted to the CIDRs You Name, with Private DNS

huawei-vpcep-endpoint

A Huawei Cloud VPC endpoint (interface type) to an endpoint service, with a private IP in your subnet, the whitelist on and set to the CIDRs you name (an empty whitelist admits the whole VPC and has to be accepted by name), and the service's domain registered in the VPC's private DNS.

Static validated · Live test pendingHuawei CloudTerraform
Open A VPC File Share Wrapped with Your Key, Mounted over Encrypted Transit in Your Subnet

ibm-file-share

An IBM Cloud VPC file share (NFS) wrapped with your Key Protect or HPCS key (provider-managed by name), with one mount target on a virtual network interface in your subnet behind the security groups you name, using user-managed transit encryption (plain NFS has to be accepted by name). One zone; a fleet in two mounts across or replicates.

Static validated · Live test pendingIBM CloudTerraform
Open A VPC Load Balancer that Is Private, Checks the Application and Redirects HTTP

ibm-vpc-load-balancer

type defaults to public, so a load balancer created without one gets an internet address; the pool's health check can be a TCP handshake; a port-80 listener forwards unless a listener policy redirects it; and logging is off. Private with public by name, an HTTP check on a path, a 301 policy on 80 whenever a Secrets Manager certificate is given, two subnets unless one is accepted, logging on.

Static validated · Live test pendingIBM CloudTerraform
Open A VPC Peer Connection with the Route Entries on Both Sides That Make It Carry Traffic

alicloud-vpc-peering

A peer connection between two VPCs with a route entry written into every route table you list, on both sides, for every CIDR of the other side, because an Activated peering carries nothing until the routes exist. A default route through a peering is refused, and a cross-account peering that the other account has yet to accept has to be taken by name.

Static validated · Live test pendingAlibaba CloudTerraform
Open A VPC Peering Accepted in One Apply, with DNS Across It and Routes on Both Sides

aws-vpc-peering

A VPC peering between two VPCs in one account and region, accepted in the same apply, with DNS resolution across it and routes written in every listed route table on both sides for every CIDR of the other. A default route through a peering is refused (CKV2_AWS_44). Peering is not transitive; past a handful of VPCs the transit gateway is the product.

Static validated · Live test pendingAWSTerraform
Open A VPC Peering with the Routes on Both Sides and the Cross-Tenant Case Refused Early

huawei-vpc-peering

A peering connection between two VPCs with a route written into every route table you list, on both sides, for every CIDR of the other side. A cross-tenant peering sits in PENDING_ACCEPTANCE and its other side is out of reach of this provider, so the module refuses an accepter route table list in that case rather than failing at apply.

Static validated · Live test pendingHuawei CloudTerraform
Open A VPC Virtual Server with SSH Keys, No Floating IP, Secure Boot and Your Key on the Boot Volume

ibm-vsi-instance

A VPC virtual server in your subnet with the SSH keys you name and no password, security groups on the primary interface, no floating IP, the boot volume encrypted with a Key Protect key (IBM's key by name), secure boot on, and the metadata service on so a trusted profile can be the instance identity instead of a stored API key.

Static validated · Live test pendingIBM CloudTerraform
Open A VPC Whose Private Networks Have Chosen Subnets and an ACL that Drops

scaleway-vpc

A Private Network created without a subnet gets a /22 the platform picked, the one most likely to collide with the office or the next network; VPC routing forwards between every Private Network, and the ACL that filters that traffic does not exist until you create it. Subnets required per network, a named VPC rather than the project default, and a drop-by-default ACL from the rules you give.

Static validated · Live test pendingScalewayTerraform
Open A VPC with a Range You Chose

vultr-vpc

v4_subnet is optional, so a VPC created without it gets whatever range was free, the one most likely to collide with the office network or next year's VPN; and a VPC is a range, not a network - instances on it reach each other on every port and firewall groups do not filter the VPC interface. The range required, and outputs that say nothing inside is filtered and nothing peers across regions.

Static validated · Live test pendingVultrTerraform
Open A VPN Gateway and IPsec Connection on IKEv2 with Pinned Cryptography and Routes Written

alicloud-vpn-gateway

An Alibaba Cloud VPN gateway (pay-as-you-go; subscription by name) with a customer gateway and one IPsec connection on IKEv2 negotiating AES-256, SHA-256 and DH group 14 in both phases, the weak options refused by validation and IKEv1 accepted only by name, dead peer detection and NAT traversal on, and the remote subnets' routes written for you.

Static validated · Live test pendingAlibaba CloudTerraform
Open A VPN Gateway and Policy-Based IPsec Connection on IKEv2 with Tencent's Weak Defaults Refused

tencent-vpn-gateway

A Tencent Cloud VPN gateway (pay-by-hour; prepaid by name) with a customer gateway and one policy-based IPsec connection on IKEv2 negotiating AES-CBC-256, SHA-256 and DH group 14 in both phases. Tencent's own defaults are 3DES, MD5 and group 1; the validations refuse them, IKEv1 is accepted only by name, and dead peer detection restarts a dead tunnel.

Static validated · Live test pendingTencent CloudTerraform
Open A Vertex AI Search Data Store in Your Region, Encrypted with Your Key, with Its Engine

gcp-vertex-ai-search

A Vertex AI Search data store in eu, us or global (residency, no default, cannot change), encrypted with a Cloud KMS key of yours (the Google-managed key by name), indexing documents, structured records or a website as you choose, and the search engine over it on the standard tier; the enterprise tier is an input and the LLM add-on, which bills per query, is accepted by name.

Static validated · Live test pendingGoogle CloudTerraform
Open A Virtual Border Router with BFD On and the Attachment That Makes It Reach a VPC

alicloud-express-connect

A virtual border router on a physical connection you already have, with BFD on so a dead circuit is noticed in milliseconds rather than at the BGP hold timer, and an optional Express Connect Router attachment. Without that attachment the circuit terminates at the border router, which looks like a working connection and routes nothing. Sitelink is billed and off.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Virtual Gateway and Interface with the BGP Session Authenticated and BFD On

huawei-direct-connect

A Direct Connect virtual gateway on a VPC and a virtual interface on a connection you already have. bgp_md5 is the only authentication the session has and it is optional in the API, so it is required here. The two endpoint groups are where this goes wrong quietly: a wrong prefix gives a circuit that is up, a session established, and traffic that disappears.

Static validated · Live test pendingHuawei CloudTerraform
Open A Virtual Private Endpoint Gateway with a Reserved IP per Zone Behind Your Security Groups

ibm-vpe-gateway

An IBM Cloud VPC virtual private endpoint gateway to a cloud service, with a reserved IP in each subnet you name (one zone has to be accepted by name), behind the security groups you name (the VPC default group by name), and DNS resolution binding enabled so the VPC resolves the service to the gateway.

Static validated · Live test pendingIBM CloudTerraform
Open A Virtual WAN Hub with Connections and Encrypted Branches

azure-virtual-wan

A hub is billed from the moment it exists and routes nothing until something connects; disable_vpn_encryption sends branch traffic in clear; and a VNet connection without internet security sends 0.0.0.0/0 out its own default route, bypassing the hub firewall. Connections come with it, branch encryption stays on, every connection routes the internet through the hub, and the prefix must be a /23.

Static validated · Live test pendingAzureTerraform
Open A Volume in Your Network, Attached, and Honest About Snapshots

civo-volume

A volume belongs to a network and attaches only to instances in it; this provider exposes no volume snapshot and no schedule, so data on it is backed up by something on the instance or not at all; and a volume attached without attach_at_boot does not come back after a reboot. Network required, attached at boot, and an output that says snapshots are not available.

Static validated · Live test pendingCivoTerraform
Open A Volume that Cannot Be Deleted by Accident

hetzner-volume

delete_protection defaults to off, a deleted volume is gone at once with no soft delete and nothing to restore from, and server snapshots do not include volumes. Protection on and off only by name, a filesystem so automount works, exactly one of server or location, and an output that says volume snapshots do not exist.

Static validated · Live test pendingHetznerTerraform
Open A Vultr DNS Zone with Its Records, Signed, and the Nameservers for the Registrar

vultr-dns-zone

A Vultr DNS zone with every record in one map, DNSSEC on (the DS record still has to go to the registrar), and the nameservers exported because the zone answers nothing until the registrar delegates to them. The apex A record Vultr offers to write at creation is not used, so nothing exists outside the map.

Static validated · Live test pendingVultrTerraform
Open A Vultr Snapshot of an Instance, the Image New Instances Deploy From

vultr-snapshot

A Vultr snapshot of an instance, which is Vultr's custom image: global, deployable in any region, billed per gigabyte stored. The snapshot is the instance at that moment, secrets and all, so build the source clean and stop it first; the description carries the build.

Static validated · Live test pendingVultrTerraform
Open A WAF Policy that Blocks rather than Narrates

azure-waf-policy

Detection mode evaluates every rule, logs every match and forwards every request - the dashboard fills with blocked-looking entries while the backend receives them all. Prevention by default, Detection only by name. A policy attached to no listener protects nothing, so the attached listeners are an output; every exclusion is a hole and has to carry a reason.

Static validated · Live test pendingAzureTerraform
Open A WAF That Tells You Removing It Leaves It Running

ibm-waf

The CIS managed and OWASP core rulesets deployed on an IBM Cloud Internet Services domain, with the OWASP threshold, action and paranoia level set. The resource owns the whole managed phase, so console rules are overwritten, and destroying it leaves the WAF running - the module says so and makes turning it off an explicit step. The deprecated legacy WAF resources are not used.

Static validated · Live test pendingIBM CloudTerraform
Open A WAF That Tells You the Origin Can Still Be Reached Around It

tencent-waf

A domain on a Tencent Cloud SaaS WAF, rules set to block, with block and allow lists. It reads back the CNAME, the mode the WAF reports and the addresses the WAF forwards from, so the origin can refuse everything else. An allowlist here lets addresses through; it does not make a site private. The client IP is taken from the connection unless you say a proxy sits in front.

Static validated · Live test pendingTencent CloudTerraform
Open A WAF that Blocks rather than Narrates

oci-waf

CHECK is the action that evaluates the rule, logs the match and lets the request through - the console shows the protection rules and every matched attack reached the backend. BLOCK by default, DETECT only by name. The policy and the firewall binding it to a load balancer are separate resources; both are created, and a policy alone has to be asked for.

Static validated · Live test pendingOracle CloudTerraform
Open A WORM Backup Vault with Your Key, a Daily Policy, and the Instances Bound to It

alicloud-hbr-backup

A Cloud Backup vault encrypted with your KMS key (the HBR-managed key by name), zone-redundant, with WORM on so a compromised account cannot delete the copies (off by name, and it cannot be turned on again later), a policy that backs up daily and keeps thirty days, and a binding for every ECS instance in the map, because a vault with no policy and no binding backs up nothing.

Static validated · Live test pendingAlibaba CloudTerraform
Open A Website Bucket Readable by Name and Not by Listing

ibm-static-site

An IBM Cloud Object Storage bucket serving a static website. The public policy grants Object Reader, which IBM documents as download without listing, rather than Content Reader, which lists. It names the two account settings that silently switch public access off, says the endpoint is plain HTTP, requires you to accept that everything in it is public, and expires old versions.

Static validated · Live test pendingIBM CloudTerraform
Open A Weekly DLP Scan of a Bucket or Table, Sampled, with Findings that Do Not Quote

gcp-dlp

Sensitive Data Protection on a schedule: an inspection template naming the detectors and a weekly trigger over a bucket or a BigQuery table, sampling ten percent of each file, scanning only what changed since the last run, with findings written to your dataset without the matched values and a summary sent to Security Command Center. A full scan, billed per byte, is accepted by name.

Static validated · Live test pendingGoogle CloudTerraform
Open A Weekly OS Management Hub Job that Installs Every Update on the Groups You Name

oci-os-management-patching

An OS Management Hub scheduled job that installs every available update (security-only and the other partial operations by name) on the managed instance groups or compartments you name, weekly by an RRULE from a first run you set in the future, with a reboot window per instance and retries. Instances have to run the agent and be registered with a software source to be seen.

Static validated · Live test pendingOracle CloudTerraform
Open A Workgroup whose Settings Are Binding

aws-athena

Query results are a copy of the data, written to S3. Without enforce_workgroup_configuration - the AWS default - a client sends its own location and encryption and every setting becomes a suggestion.

Static validated · Live test pendingAWSTerraform
Open A Zone WAF Whose Managed Rulesets Actually Execute

cloudflare-waf

A paid plan makes the Cloudflare Managed Ruleset and the OWASP Core Ruleset available; a zone runs them only when a rule in the managed phase executes them, so a subscribed zone with no such rule is protected by the free ruleset alone. Both executed here with the OWASP threshold set, custom rules that block rather than log, and a per-client rate limit in its own phase.

Static validated · Live test pendingCloudflareTerraform
Open A reCAPTCHA Key that Is Scored, Scoped, and Not in Testing Mode

gcp-recaptcha

A key with a testing score returns that score for every assessment, bots included - right for staging and, on a production key, a filter that filters nothing; allow_all_domains lets any site consume your assessments against your quota. Testing mode refused without acceptance, domains required on web keys, invisible scoring by default; only a backend assessment call turns a token into a decision.

Static validated · Live test pendingGoogle CloudTerraform
Open ACL Rules, Antivirus, and an Honest Account of What Huawei Will Not Let You Order

huawei-network-firewall

Address groups and ACL rules on a Cloud Firewall protected object, with antivirus turned on since it is a separate resource and a complete rule set says nothing about it. Huawei takes a placement rather than a position, so order is not determined by the file: place_at_top pins the one rule that matters and the module says plainly that the rest must not overlap.

Static validated · Live test pendingHuawei CloudTerraform
Open ACM Certificate (DNS-validated)

aws-acm

Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.

Live-testedAWSTerraform
Open ACM Private Certificate Authority

aws-private-ca

A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.

Static validated · Live test pendingAWSTerraform
Open AIDE, A Baseline And A Timer That Notices A Change

ansible-aide

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open API Gateway & Deployment

oci-api-gateway

Managed API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.

Static validated · Live test pendingOracle CloudTerraform
Open API Gateway (OpenAPI 2.0)

gcp-api-gateway

A serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.

Live-testedGoogle CloudTerraform
Open API Gateway HTTP API

aws-apigateway-http

HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.

Live-testedAWSTerraform
Open API Gateway REST API (deny-by-default)

aws-apigateway-rest

A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.

Live-testedAWSTerraform
Open API Management (Consumption tier)

azure-api-management

An API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.

Live-testedAzureTerraform
Open AWS CLI v2, Signature Checked Before Unpacking

ansible-aws-cli-v2

The AWS CLI v2 from the upstream zip, verified with gpg against the AWS CLI Team key (pinned by fingerprint, in a GnuPG home of its own) before it is unpacked. EL 10 has no package; most installs run curl | unzip and never read the signature. Pinned version, tab completion, and a live test that runs an API call to 'Unable to locate credentials'. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open AWS S3 Bucket (hardened)

aws-s3-bucket

Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.

Live-testedAWSTerraform
Open Account Guardrails Applied in Every Region You List, Not Just One

aws-account-baseline

The IAM password policy, S3 account-wide Block Public Access and, per region, default EBS encryption, snapshot and AMI sharing blocks, IMDSv2 as the default and the serial console off. Five of these are per region, so the module covers a list. The password policy follows NIST SP 800-63-4, and the module says which settings destroying it turns back off.

Static validated · Live test pendingAWSTerraform
Open Activity Tracker Event Routing to Your Bucket, Every Location, Private API

ibm-activity-tracker

Activity Tracker Event Routing with a COS target written service-to-service (no API key stored), a route that sends every location's events to it (a narrower list by name), and the account settings that keep routing metadata in your region, make the target the default, and answer the routing API on private endpoints only. Without a route, events go nowhere you keep.

Static validated · Live test pendingIBM CloudTerraform
Open Akamai App & API Protector (WAF)

akamai-appsec-waf

Security configuration with policy, WAF mode, match targets, rate controls, and IP/geo blocking, activated to staging or production.

Static validated · Live test pendingAkamaiTerraform
Open Akamai CLI, Checked Against The Hash Akamai Calls A Signature

ansible-akamai-cli

akamai on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one pinned beside the version: the value Akamai publishes as a .sig file, which is not a signature but the bare hash of the binary. The live test checksums the asset again and runs the CLI to its command list. Sub-CLIs and credentials are per user. Original role, live-tested on Rocky Linux 10.

Live-testedAkamaiAnsible
Open Akamai CPS DV Certificate

akamai-cps-dv-certificate

Automated Domain Validated TLS enrollment with DNS/HTTP challenge outputs wired for Edge DNS.

Static validated · Live test pendingAkamaiTerraform
Open Akamai Edge DNS Zone

akamai-edge-dns-zone

Authoritative Edge DNS zone with full recordset management on Akamai's DDoS-resilient anycast network.

Live-testedAkamaiTerraform
Open Akamai Edge Redirector Cloudlet

akamai-cloudlets-edge-redirector

Rule-driven edge redirects (vanity URLs, migrations) managed as code with versioned policy activation.

Static validated · Live test pendingAkamaiTerraform
Open Akamai EdgeWorker with EdgeKV

akamai-edgeworker

Deploy JavaScript at the edge with bundle versioning, EdgeKV namespace, and network activation in one module.

Static validated · Live test pendingAkamaiTerraform
Open Akamai GTM Failover/Weighted Domain

akamai-gtm-failover

Global Traffic Management domain with datacenters and failover or weighted-round-robin properties plus liveness tests.

Static validated · Live test pendingAkamaiTerraform
Open Akamai Ion Delivery Property

akamai-property-ion

End-to-end Ion CDN property: origin, edge hostname, caching/performance rule tree, CP code, and staging/production activation.

Static validated · Live test pendingAkamaiTerraform
Open Akamai Network Lists

akamai-network-lists

Versioned IP and geo block/allow lists with activation, ready to feed WAF policies and property rules.

Live-testedAkamaiTerraform
Open Alarms that Reach a Person who Confirmed They Want Them

oci-monitoring-alarms

An email subscription delivers nothing until somebody clicks its confirmation link, and until then every alarm publishes to a subscriber who is not there; repeat_notification_duration is null by default, so an alarm fires once at 3am and is never mentioned again. Creates the topic, subscriptions and alarms together, repeats while firing, and lists the subscriptions still waiting on a click.

Static validated · Live test pendingOracle CloudTerraform
Open Alertmanager On Loopback, Gossip Off

ansible-alertmanager

Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Alerts that Reach Somebody and Uptime Checks that Are Not a Red Dot

do-monitoring

An alert policy with no email and no Slack webhook is valid, evaluated and triggers to nobody; CPU, memory and disk metrics exist only where the agent runs; and an uptime check without its alert resource is a status page. A recipient required, CPU/memory/disk defaults by tag, the agent-dependent alerts listed, and a down alert plus optional latency and certificate-expiry alerts on every check.

Static validated · Live test pendingDigitalOceanTerraform
Open Alibaba Cloud ACK Cluster

alicloud-ack-cluster

Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.

Static validated · Live test pendingAlibaba CloudTerraform
Open Alibaba Cloud CLI, Checked Against Alibaba's Checksums

ansible-aliyun-cli

aliyun on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Alibaba's SHASUMS256.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a profile stops at 'aliyun configure'. Original role, live-tested on Rocky Linux 10.

Live-testedAlibaba CloudAnsible
Open Alibaba Cloud VPC Foundation

alicloud-vpc-foundation

Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.

Static validated · Live test pendingAlibaba CloudTerraform
Open Alloy On Loopback, Reporting Off, Validated

ansible-alloy

Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open AlloyDB for PostgreSQL Cluster

gcp-alloydb

AlloyDB cluster with primary + read-pool instances, PSC connectivity, automated backups and columnar/vector engine flags.

Live-testedGoogle CloudTerraform
Open An ALB on TLS 1.2+ that Checks the Application and Redirects HTTP

alicloud-alb

The default TLS policy accepts TLS 1.0; a server group's health check can be turned off and then sends traffic to every member forever; an HTTPS listener does nothing about port 80; and deletion protection is off. A TLS 1.2/1.3 policy created and attached, an HTTP health check on a path, a redirect on 80 whenever a certificate exists, two zones unless one is accepted, deletion protection on.

Static validated · Live test pendingAlibaba CloudTerraform
Open An API Gateway Where No API Is Open or Unthrottled by Default

huawei-api-gateway

A Huawei Cloud APIG dedicated instance, group, environment and published APIs. The provider defaults an API to no authentication; this module defaults to signed app requests and takes open or plaintext APIs one at a time. Every published API gets the required rate limit, the gateway stays off the internet unless asked, and the debug hostname stays off.

Static validated · Live test pendingHuawei CloudTerraform
Open An API Group Whose ACL Is Attached and Whose APIs Name Their Auth Type

alicloud-api-gateway

An API Gateway group, the APIs in it, and an access control list created WITH its attachment, since an unattached list looks exactly like protection in the console. auth_type ANONYMOUS means anybody with the URL calls the backend and has to be taken per API; force_nonce_check is on for every app-authenticated API, because without it a captured signed request can be replayed.

Static validated · Live test pendingAlibaba CloudTerraform
Open An ActionTrail Trail for Every Region and Every Event, Delivered to Your Bucket

alicloud-actiontrail

An ActionTrail trail that records every region and both reads and writes (narrower by name), delivered to an OSS bucket you own through the service role and, when a project is given, to Log Service for queries. The console keeps ninety days and forgets; the trail is what keeps more. An organization trail collects every member account from the management account.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Active-Active VPN Gateway with a Connection from Each Public IP on IKEv2 with Pinned Cryptography

huawei-vpn-gateway

A Huawei Cloud Enterprise VPN gateway in active-active mode across two zones with two EIPs, a customer gateway, and a static-route connection from each EIP to the peer on IKEv2 negotiating AES-256-GCM, SHA2-256 and DH group 14 in both phases (the weak options refused, IKEv1 by name), with dead peer detection and network quality checks on.

Static validated · Live test pendingHuawei CloudTerraform
Open An Airflow UI that Is Not on the Public Internet

aws-mwaa

webserver_access_mode defaults to PUBLIC_ONLY, and the Airflow UI is not a dashboard: anyone who reaches it can trigger a DAG, which is arbitrary Python running as the execution role. PRIVATE_ONLY here, all five log streams on, and a precondition refuses an unpinned requirements.txt or plugins.zip - where bucket write access is otherwise the same permission as code execution.

Static validated · Live test pendingAWSTerraform
Open An Alidns Zone with Its Records on the Default Line and the Nameservers Exported

alicloud-dns-zone

An Alibaba Cloud DNS zone with every record in one map, all on the default resolution line so every resolver gets the same answer, and the nameservers Alidns assigns exported for the registrar. DNSSEC is a console setting on paid editions rather than a resource; dnssec_available says so.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Amplify App Whose Previews Are Behind Basic Auth and Whose Branches Do Not Multiply

aws-amplify-app

Every branch build is served at a public amplifyapp.com URL, and basic auth, the switch that puts a password on it, is off; auto branch creation builds every branch anyone pushes; the repository token lands in state; and environment variables are plaintext. Basic auth on every non-production branch (public by name), auto creation off, exactly one production branch, the custom domain attached.

Static validated · Live test pendingAWSTerraform
Open An Analytics Instance on a Private Endpoint that Announces Maintenance

oci-analytics

The network endpoint is public by default with no allow list; the encryption key is Oracle's unless a vault key is given; and an instance with no notification email is upgraded and restarted with nobody told. Private endpoint in your VCN behind NSGs, a vault key expected, a notification address required, and capacity set as OCPUs or users on purpose.

Static validated · Live test pendingOracle CloudTerraform
Open An App Platform Whose Components Are Actually Deployed

huawei-app-platform

A CAE environment, application and components. deploy_after_create is off in the API, so a component exists with a source, a runtime and a replica count and serves nothing; it is on here. The runtime list still offers Java8, Nodejs8 and Php7, which the module names and asks about, and 500m of CPU cannot take 4Gi of memory.

Static validated · Live test pendingHuawei CloudTerraform
Open An Application Platform That Patches Itself

aws-elastic-beanstalk

AWS Elastic Beanstalk with the defaults turned the right way: managed platform updates are ON (AWS leaves them off, so the platform is never patched), health reporting is enhanced rather than basic, logs stream to CloudWatch and survive termination, IMDSv1 is disabled, deployments go out in batches instead of all at once, and application versions are pruned before they hit the quota.

Static validated · Live test pendingAWSTerraform
Open An ApsaraDB for Redis Instance with a Replica in a Second Zone, TLS and an Allow-List

alicloud-redis

An ApsaraDB for Redis instance in your VPC with the replica in a second zone, TLS required, the security_ips allow-list written from your ranges (0.0.0.0/0 by name), a password from a secret store never output, transparent encryption with your KMS key (the service's by name), daily backups, a maintenance window, and release protection on. Pay-as-you-go.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Audit Store Whose Retention You Chose

aws-cloudtrail-lake

A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.

Static validated · Live test pendingAWSTerraform
Open An ECS Custom Image Captured from an Instance into an Image Family

alicloud-image

An Alibaba Cloud custom image captured from an ECS instance into an image family, so instances and scaling groups that name the family get the newest image (no family has to be accepted by name). The snapshots the capture created are deleted with the image. Build the source clean and stop it first.

Static validated · Live test pendingAlibaba CloudTerraform
Open An ECS Instance with a Key Pair, No Public Address, IMDSv2 and an Encrypted Disk

alicloud-ecs-instance

An ECS instance in your vSwitch with login by key pair and no password, no public address unless bandwidth above zero is accepted by name, the system disk encrypted with your KMS key (the service key by name), the metadata service on IMDSv2 only with a hop limit of one, the Security Center agent on, and deletion protection. Pay-as-you-go.

Static validated · Live test pendingAlibaba CloudTerraform
Open An ECS Instance with a Key Pair, No Public Address, an Agency and an Encrypted Disk

huawei-ecs-instance

An ECS instance in your subnet with login by key pair and no password, no elastic IP unless one is accepted by name, the system disk encrypted with your KMS key (the platform key by name), an IAM agency as its identity so code on it needs no stored access key (none by name), the Cloud Eye agent on, and the instance stopped before destroy with its disks. Pay-per-use.

Static validated · Live test pendingHuawei CloudTerraform
Open An EMR Cluster Whose Master Is Not on the Internet, Which the API Default Is

tencent-emr-cluster

An EMR cluster with need_master_wan set to NOT_NEED, because the API defaults to NEED and that puts the node running YARN's resource manager and the cluster web interfaces on the internet. support_ha is on, since one master is not a failover, and the security group the API leaves optional is required here.

Static validated · Live test pendingTencent CloudTerraform
Open An EMR Cluster with Kerberos On, Which security_mode NORMAL Quietly Is Not

alicloud-emr-cluster

An E-MapReduce cluster with security_mode KERBEROS, because NORMAL is the default and a NORMAL cluster comes up, answers on YARN and HDFS, runs Spark, and never checks that a submitter is who they say they are. Both disk encryption flags are on, deletion protection is on, and spot instances on a MASTER or CORE group are refused.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Edge Pipeline Whose Stages Are All Actually Joined Up

scaleway-cdn

Edge Services is a chain of stages, each naming the one it forwards to, and every stage is content to exist naming nothing: a half-wired pipeline shows a name and a status in the console and answers no requests. This builds the whole chain, subscribes the plan without which nothing serves, and puts a certificate and your own domain in front of a bucket.

Static validated · Live test pendingScalewayTerraform
Open An Egress Proxy that Lets Workloads Out to the Hosts You List

gcp-secure-web-proxy

A gateway with no rules allows nothing, and a session matcher of true is an open proxy to the internet; the gateway needs a proxy-only subnet in the region that is yours to make; and without TLS inspection the proxy sees the SNI hostname and nothing inside. Rules built from a URL list of your hosts, allow-all accepted by name only, outputs that say what is allowed and that TLS is not inspected.

Static validated · Live test pendingGoogle CloudTerraform
Open An Elasticsearch Cluster with Authentication On, Three Public Switches Closed and COS Backups

tencent-elasticsearch

An Elasticsearch cluster with basic_security_type 2, because 1 is no username and no password at all and anything that can reach the cluster could read and delete every index. The search API, Kibana and Cerebro each have their own public switch and all three are closed; automatic backup to COS is on, and destroy protection with it.

Static validated · Live test pendingTencent CloudTerraform
Open An Elasticsearch Cluster with Kibana Off the Internet, Which the Provider Does Not Default To

alicloud-elasticsearch

An Elasticsearch cluster on the current node-configuration blocks rather than the deprecated flat fields. enable_kibana_public_network defaults to true in this provider and is false here, the search endpoint is private, the data disks are encrypted, and an empty private whitelist is refused because Alibaba reads it as every address that can reach the VPC.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Encrypted CBS Disk with a Snapshot Policy that Is Attached

tencent-cbs-disk

A snapshot policy and its attachment are separate resources, so a policy in the console with no disks is the usual state; encrypt defaults to false and cannot be changed after creation; and force_delete takes a disk with data on it. Encrypted always with your KMS key or Tencent's, a policy created or yours attached (none by name), attached to the instance you give, never force-deleted.

Static validated · Live test pendingTencent CloudTerraform
Open An Encrypted Data Disk with a Snapshot Policy that Is Assigned

alicloud-ecs-disk

An automatic snapshot policy is one resource and its attachment to a disk is another, so a policy in the console with no disks is the usual state; encrypted defaults to false and cannot change after creation; and delete_auto_snapshot can take the snapshots with the disk. Encrypted always, a policy created or yours attached (none by name), the disk and its snapshots outliving the instance.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Encrypted EVS Disk Backed Up by a Vault Whose Policy Is Applied

huawei-evs-disk

A backup on Huawei Cloud is a vault, a policy and a resource list that exist separately, so the common state is a policy with no vault or a vault with no disks; and a disk is encrypted only when a KMS key is given. The vault created with the policy applied and the disk as its resource (none by name), a key expected (none by name), attached to the instance you give.

Static validated · Live test pendingHuawei CloudTerraform
Open An Encrypted Storage Device Whose Backup Rule Is Part of the Device

upcloud-storage

encrypt defaults to false and cannot change after creation; and the backup rule is the rare schedule that lives on the device itself, so it cannot be forgotten separately but can still be left out. Encryption on, a daily backup at 02:00 UTC kept 30 days unless told otherwise (none by name), filesystem resize opt-in, and the device attached from the server side in its zone.

Static validated · Live test pendingUpCloudTerraform
Open An Enhanced NAT Gateway for an Existing VPC with Its EIP and SNAT Entries

alicloud-nat-gateway

An enhanced, pay-as-you-go NAT gateway for an existing Alibaba Cloud VPC, with a PayByTraffic elastic IP whose bandwidth cap every subnet shares, and an SNAT entry for each vSwitch listed, because a gateway with no SNAT entry forwards nothing. Deletion protection is on for the gateway and the address; off has to be accepted by name.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Enterprise Router across Two Zones with Explicit Route Tables and a VPC Attachment per VPC

huawei-enterprise-router

A Huawei Cloud Enterprise Router across two zones with default association and propagation off, the route tables you name, and a VPC attachment per VPC each associated with one table and propagating into the tables you list, with routes to the router written into each VPC. Shared attachments from other accounts wait for you unless auto-accept is turned on by name.

Static validated · Live test pendingHuawei CloudTerraform
Open An Exoscale DNS Zone with Its Records and the Nameservers for the Registrar

exoscale-dns-zone

An Exoscale DNS zone with every record in one map (the apex written as the empty name Exoscale expects) and the four nameservers exported for the registrar. Exoscale does not sign zones; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.

Static validated · Live test pendingExoscaleTerraform
Open An Exoscale Instance on a Private Network with Secure Boot and No Public Address

exoscale-instance

An Exoscale compute instance on a Private Network with security groups and the SSH keys you name, created private so it has no public interface (public by name), secure boot and the TPM on where the template supports them, IPv6 off, and destroy protection (off by name).

Static validated · Live test pendingExoscaleTerraform
Open An ExpressRoute Circuit with Peering and No Illusion of Encryption

azure-expressroute

A provider circuit is a clear-text path across the provider's network - MACsec is for Direct ports only, and IPsec over the private peering is yours to build - so the module requires that to be stated and exports encrypted = false. The SKU tier decides where the circuit reaches; a circuit with no peering carries nothing once provisioned. Private peering with its /30 pairs and VLAN is created here.

Static validated · Live test pendingAzureTerraform
Open An HDInsight Spark Cluster Behind a Private Link with No Storage Key in State

azure-hdinsight-spark

An HDInsight Spark cluster in your virtual network, reached over a private link, on ADLS Gen2 through a user-assigned identity so no storage key sits in state, with encryption in transit and TLS 1.2 on the gateway. There is no scale-to-zero: nodes_at_rest says what bills when the cluster idles. An external Hive metastore makes the cluster disposable; the public gateway is accepted by name.

Static validated · Live test pendingAzureTerraform
Open An IAM Agency a Service Assumes, with Roles Scoped to Projects

huawei-iam-agency

An IAM agency that the Huawei Cloud service you name (ECS, FunctionGraph, CCE) assumes on your behalf, so instances and functions that name it need no stored access key, with roles scoped to the projects you list; account-wide roles and Tenant Administrator are each accepted by name. The delegation to a service does not expire.

Static validated · Live test pendingHuawei CloudTerraform
Open An IAM Application with a Project-Scoped Policy and an API Key that Expires

scaleway-iam-application

A Scaleway IAM application, the non-human identity a workload authenticates as, with a policy of rules granting permission sets in the projects you name (organisation scope and the full-access sets by name) and an API key that expires at a time you set (no expiry by name), whose secret is a sensitive output.

Static validated · Live test pendingScalewayTerraform
Open An IAM Role that Denies by Default, Allows by Rule, with a Bound API Key

exoscale-iam-role

An Exoscale IAM role that refuses every service it does not name (allow-by-default by name) and allows the ones it does either whole or by CEL rules on the operation, not editable in the console so the module stays the source of truth, with an API key bound to it whose secret is a sensitive output.

Static validated · Live test pendingExoscaleTerraform
Open An IDS Endpoint that Is Actually Looking at Traffic

gcp-cloud-ids

Creating the endpoint creates no packet mirroring policy, so an endpoint with nothing mirrored is provisioned, billed by the hour, shown with a green check and has never seen a packet. The mirroring policy is created with it and refused when it mirrors nothing. Cloud IDS detects and never blocks; blocks_traffic is an output that is always false.

Static validated · Live test pendingGoogle CloudTerraform
Open An IMS Private Image Captured from an ECS System Disk

huawei-image

A Huawei Cloud private image captured from an ECS instance's system disk on the current IMS resource, with memory bounds for instances launched from it. Encryption follows the source disk (an unencrypted source has to be accepted by name), and the name carries the build. Build the source clean and stop it first.

Static validated · Live test pendingHuawei CloudTerraform
Open An Inspection Load Balancer That Does Not Drop a Zone With Its Appliances

aws-gateway-load-balancer

A Gateway Load Balancer for firewall or IDS appliances, its endpoint service and endpoints. AWS turns cross-zone off, keeps flows on failed appliances and leaves deletion protection off by default; this module turns cross-zone and protection on and makes flow failover an explicit choice. It also says plainly that nothing is inspected until route tables point at the endpoints.

Static validated · Live test pendingAWSTerraform
Open An IoT Hub Reached Privately, by Identity, that Drops Nothing

azure-iot-hub

Shared access keys are symmetric credentials that grant everything their policy names and are revoked only by regeneration; the endpoint is public by default; telemetry that matches no route is dropped when the fallback route is off; and the built-in endpoint keeps one day. Keys off, private endpoints, TLS 1.2, the fallback route on so unrouted telemetry lands, and seven days of retention.

Static validated · Live test pendingAzureTerraform
Open An ML Workspace that Is Private, Isolated and Encrypted with Your Key

azure-machine-learning

The workspace endpoint is public by default, and the managed network compute runs in defaults to Disabled isolation - unrestricted outbound internet from a network that holds training data. Private workspace, outbound isolation on, high-business-impact flag set so less leaves for Microsoft, identity-based storage access, and a customer-managed key; the four dependencies stay yours.

Static validated · Live test pendingAzureTerraform
Open An MNS Queue with a Dead-Letter Queue, Logging On and Your Key

alicloud-mns-queue

A Message Service queue with a dead-letter queue that receives a message after five failed receives, long polling, logging on (it is off by default and is the only record of what was sent), and server-side encryption with your KMS key on both queues (the service key by name).

Static validated · Live test pendingAlibaba CloudTerraform
Open An MRS Cluster in Safe Mode, with a Key Pair and Logs That Survive a Failed Build

huawei-mapreduce

A MapReduce Service cluster with safe_mode true, since false turns Kerberos off and leaves a cluster where Manager answers and nothing authenticates anybody. A node credential is required rather than left to the API, MRS Manager stays off the internet unless asked, and log collection is on so a cluster that fails to build does not take the reason with it.

Static validated · Live test pendingHuawei CloudTerraform
Open An NFS Share Copied into Blob Storage by an Agent You Run, Deletes Accepted by Name

azure-storage-mover

Azure Storage Mover from an NFS share to a blob container: the mover, project, endpoints and job definition, with the agent registered from its Arc machine and granted Storage Blob Data Contributor when its IDs are given. Additive copy mode; Mirror, which deletes at the target what the source no longer has, is accepted by name. The run itself is started outside Terraform.

Static validated · Live test pendingAzureTerraform
Open An NSG that Is Associated, Names Its Sources, and Ends in a Deny

azure-network-security-group

Every NSG carries default rules nobody wrote; a group with no subnet or NIC association is a rule set in the portal that filters nothing; and SSH and RDP from Internet are the first rules the portal offers. Your allows in priority order with an explicit DenyAllInbound at 4000, subnets associated by the module (none by name), 22 and 3389 from Internet refused unless accepted.

Static validated · Live test pendingAzureTerraform
Open An NSG that Is Stateful, Names Its Sources, and Says What It Cannot Do

oci-network-security-group

An NSG with no rules admits nothing and sends nothing, so a group written with ingress only has VNICs that cannot resolve DNS; a stateless rule drops every reply that has no matching egress; and the subnet's security list still applies, unioned with the NSG. Stateful always, egress explicit and open by default, SSH from 0.0.0.0/0 refused unless accepted, the security list named as still applying.

Static validated · Live test pendingOracle CloudTerraform
Open An OBS Bucket that Is Private on Both Switches, Versioned and Encrypted

huawei-obs-bucket

Public access is two switches: a private ACL still leaves a bucket policy free to grant anonymous reads, and only Block Public Access refuses both; versioning and encryption are both off by default; abandoned uploads bill until a rule aborts them. Private ACL plus BPA with public by name, versioning on, encrypted with the region's key or yours, incomplete uploads freed after a week.

Static validated · Live test pendingHuawei CloudTerraform
Open An OSS Bucket that Is Private on Both Switches, Versioned and Encrypted

alicloud-oss-bucket

Public access is two switches: a private ACL still leaves a bucket policy or an object ACL free to grant anonymous reads, and only Block Public Access refuses both; versioning is off by default and once on can only be suspended. Private ACL through its own resource plus Block Public Access, public by name, versioning always on, encrypted, abandoned uploads aborted.

Static validated · Live test pendingAlibaba CloudTerraform
Open An Object Store with Its Own Credential and What It Lacks Written Down

civo-object-store

A store is a bucket with a size ceiling that turns into refused writes far from the cause; a store created without a credential gets the account's default one; and the service has no versioning, no lifecycle and no object lock, so an overwrite is the end of the object. The ceiling set, a credential of its own, and outputs that say versioning and lifecycle are not available.

Static validated · Live test pendingCivoTerraform
Open An OpenSearch Cluster that Authenticates and Has a Quorum

oci-opensearch

security_mode PERMISSIVE runs the security plugin, evaluates every request and lets unauthenticated ones through - the migration mode clusters stay in - and DISABLED does not evaluate at all; both look like a cluster with the plugin. ENFORCING with a master user, three masters because one is no quorum, two or more data nodes, an NSG because it is the only network control, and maintenance emails.

Static validated · Live test pendingOracle CloudTerraform
Open An Organization That Says It Is a Billing Hierarchy, Not a Policy One

tencent-landing-zone

Tencent organization nodes and members. policy_type takes one value and it is Financial: what a membership grants is numbered billing permissions, not a governance boundary, and is_a_policy_boundary says false. The permissions are taken as words and written as the integers Tencent wants, and the one that moves money is asked about.

Static validated · Live test pendingTencent CloudTerraform
Open An Organization Whose Policy Types Are Enabled Before a Policy Needs Them

huawei-landing-zone

An organization, its units and its accounts. enabled_policy_types is what makes a service control policy attachable at all: without it a policy is created and fails to attach, at apply, behind a clean plan, and neither console connects the two. The account email and phone are the recovery path, so an account with none is listed as an output.

Static validated · Live test pendingHuawei CloudTerraform
Open An Origin CA Certificate Whose Private Key Never Enters the Terraform State

cloudflare-origin-ca-certificate

A certificate for the hop between Cloudflare and your origin. It is trusted by Cloudflare and by nothing else, so it is right only when the origin accepts Cloudflare alone. A CSR is required precisely so the key stays where it was generated, and the validity is one year rather than the fifteen the API offers, since that is how long a leaked key stays usable.

Static validated · Live test pendingCloudflareTerraform
Open An Origin Health Check That Validates the Certificate and Reads the Body

cloudflare-health-check

A health check on an origin with allow_insecure false, since an origin whose certificate expired last week passes a check that was told not to look. expected_body is what tests the application rather than the web server, because an error page, a maintenance page and a page saying the database is unreachable are all 200s. Two consecutive failures, not one.

Static validated · Live test pendingCloudflareTerraform
Open An R2 Bucket that Stays Private, Cleans Up, and Can Lock Objects

cloudflare-r2-bucket

R2 has no versioning: an overwrite or delete is the end of the object, and the only control that refuses deletion is a bucket lock rule, which a bucket without one needs to accept by name. Abandoned multipart uploads bill until a lifecycle rule aborts them. Private with no domain attached, lock rules taken, incomplete uploads freed after a week, and the EU or FedRAMP jurisdiction set at creation.

Static validated · Live test pendingCloudflareTerraform
Open An S3 Container that Is Versioned, Encrypted, and Reached by a Credential Scoped to It

ovh-object-storage

Versioning is off by default; encryption is off until an algorithm is named; and a user's S3 credential reaches every container in the project unless a policy narrows it. Versioning on with off by name, object lock decided at creation, AES256, abandoned uploads freed after a week, and a user of its own whose S3 policy allows this container and nothing else.

Static validated · Live test pendingOVHcloudTerraform
Open An SFS Turbo File System Encrypted with Your Key Behind Your Security Group

huawei-sfs-turbo

A Huawei Cloud SFS Turbo file system (NFS) in your subnet, encrypted with your KMS key (unencrypted has to be accepted by name), behind the security group you name and which the module does not open, on the standard or performance tier with the capacity you provision.

Static validated · Live test pendingHuawei CloudTerraform
Open An SQS Queue with a Dead-Letter Queue, Long Polling, and a Publish-Only Credential

scaleway-queue

A Messaging and Queuing SQS queue with a dead-letter queue that receives a message after five failed receives, long polling so an idle consumer costs nothing, and two credentials: one that can manage, held by Terraform to create the queues, and one that can only publish and receive, exported for the application so it never holds a key that can delete queues.

Static validated · Live test pendingScalewayTerraform
Open An SWR Organization with Private Repositories

huawei-swr

A SoftWare Repository for Container organization, which is the namespace images are addressed under, with the repositories you list created in it, each private unless a public one is accepted by name. Who may push and pull is an IAM decision per organization or repository, made outside the module.

Static validated · Live test pendingHuawei CloudTerraform
Open An UpCloud Gateway with NAT, Attached to the Router of the Networks It Serves

upcloud-nat-gateway

An UpCloud network gateway with the NAT feature attached to a router, so every private network on that router gets a way out; the router (upcloud-network creates one) is the input. The gateway is zonal and starts with the apply; the plan (advanced or production) is the throughput ceiling and the hourly bill from creation.

Static validated · Live test pendingUpCloudTerraform
Open An UpCloud Storage Template from a Server's Disk, Labelled So a Fleet Can Select It

upcloud-storage-template

An UpCloud storage template made from a server's storage, which is UpCloud's custom image, labelled by role and build (unlabelled has to be accepted by name). The template lives in the zone of its source and is the storage at that moment, secrets and all: build the source clean and stop the server first.

Static validated · Live test pendingUpCloudTerraform
Open An Uptime Check with the Alerts That Make It Mean Something

do-uptime-check

An uptime check and its alerts, which are separate resources: a check on its own draws a graph somebody would have to go and look at and pages nobody, and it looks identical to one that does. Three regions by default, since one cannot tell the target being down apart from that region's path to it. The latency alert is the one that catches the slow death.

Static validated · Live test pendingDigitalOceanTerraform
Open An Uptime Check with the Certificate Validated and the Alert Policy that Pages

gcp-uptime-check

A Cloud Monitoring uptime check from static-address checkers in several regions, over TLS with the certificate validated (off by default), asserting on the body when you give it text, with failures logged, and the alert policy on check_passed that sends to your notification channels. Plain HTTP and a policy with no channels are each accepted by name.

Static validated · Live test pendingGoogle CloudTerraform
Open Apache Kafka, One KRaft Node Proven By A Round Trip

ansible-kafka

Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Apache httpd, One TLS Site And A Cipher List That Holds

ansible-httpd-tls

httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open AppRole Roles that Bind to Somewhere Specific and Issue Secret IDs that Expire

vault-approle

A secret ID with no TTL and no use limit is a password, and both default to unlimited; a role with no bound CIDRs logs in from anywhere; and a role with no max TTL mints tokens that renew forever. Secret IDs that live an hour and are used once, roles bound to the ranges they run from with unbound accepted by name, and token ceilings set.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open Application Gateway v2 + WAF

azure-application-gateway

Regional L7 load balancer with WAF v2 policy, TLS termination from Key Vault, autoscaling and health probes.

Live-testedAzureTerraform
Open Application Load Balancer

aws-alb

ALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.

Live-testedAWSTerraform
Open Argo CD CLI, Checked Against The Published Checksums

ansible-argocd-cli

The argocd client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's cli_checksums.txt, and re-checked with sha256sum -c by the live test, which then runs argocd app list with no server and expects 'server address unspecified'. The server is a cluster install, not this role. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Argo Workflows CLI, A Workflow Linted Offline, One Refused

ansible-argo

argo on EL 10 from the GitHub release; the asset is a bare gzip; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has lint --offline pass a valid Workflow and fail one whose entrypoint is missing (exit 1); list stops at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Artifact Registry Repositories

gcp-artifact-registry

Docker/Maven/npm repos with cleanup policies, remote and virtual repositories, CMEK and reader/writer IAM.

Live-testedGoogle CloudTerraform
Open Atmos, A Stack Validated And A Component Described

ansible-atmos

atmos on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the one in the vendor's SHA256SUMS, and the live test re-checks it, then writes an atmos.yaml, a stack and a component, validates the stacks and describes the component with no Terraform installed. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Audit Logs that Record What Was Read

gcp-audit-logging

Data Access logs are off by default for every service but BigQuery, so a project that never turned them on has no record of who read the bucket, queried the table or fetched the secret. Enables all three log types for allServices, narrows per service where read volume is a real cost, and requires a reason for every exempted member - the setting an intruder with IAM rights would add.

Static validated · Live test pendingGoogle CloudTerraform
Open Audit Retention at the Ceiling and an Archive that Keeps Events for Years

oci-audit

Audit retention set to the 365-day ceiling OCI allows, plus the archive for everything past it: a private bucket with a retention rule (seven years by default, lockable by a date you pass), the service connector that streams every compartment's audit events into it, and the IAM policy without which the connector sits in FAILED. Your Vault key, or the Oracle-managed one by name.

Static validated · Live test pendingOracle CloudTerraform
Open Aurora Cluster (Serverless v2 ready)

aws-aurora

Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.

Live-testedAWSTerraform
Open Authelia SSO Portal, Secrets Kept Out Of The Config, Proven By A Login

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Autonomous Database (Serverless)

oci-autonomous-database

ATP/ADW/JSON/APEX autonomous database with private endpoint, mTLS wallet output, ACLs, auto-scaling and backup config.

Static validated · Live test pendingOracle CloudTerraform
Open Azure App Service (Linux Web App)

azure-app-service

App Service plan + Linux web app with deployment slots, custom domain + managed TLS, VNet integration and autoscale.

Live-testedAzureTerraform
Open Azure Bastion + Hardened Jumpbox

azure-bastion-jumpbox

Bastion (Developer/Basic/Standard SKU) with optional hardened Linux VM, JIT-style NSG rules and boot diagnostics for secure VM access without public IPs.

Live-testedAzureTerraform
Open Azure CLI From The Right Repository, With The Right Key

ansible-azure-cli

The Azure CLI on EL 10 from Microsoft's rhel/10/prod repository, signed by the 2025 key: the key in most guides carries SHA-1 signatures and fails the GPG check, and the repository in most guides tops out at a 2022 build. Pinned, telemetry and the survey prompt off for every login shell; the live test asserts the SHA-1 key was never imported. Original role, live-tested on Rocky Linux 10.

Live-testedAzureAnsible
Open Azure Cache for Redis

azure-redis-cache

Azure Cache for Redis done cheap by default - the Basic C0 tier with TLS 1.2 minimum and the non-SSL port disabled - scaling cleanly up to Standard and Premium via precondition-guarded inputs.

Static validated · Live test pendingAzureTerraform
Open Azure Container Apps Environment

azure-container-apps

Container Apps environment with workload profiles, Dapr, KEDA scale rules, ACR pull identity and custom domain.

Live-testedAzureTerraform
Open Azure Container Instances (ACI)

azure-container-instances

Runs one or more containers on Azure Container Instances without VMs or an orchestrator - secure by default with no privileged containers, redacted secret fields, and an optional managed identity.

Live-testedAzureTerraform
Open Azure Container Registry

azure-acr

ACR with geo-replication, retention/trust policies, private endpoint and AcrPull role wiring for AKS/Container Apps.

Live-testedAzureTerraform
Open Azure Cosmos DB Account

azure-cosmos-db

Cosmos DB (NoSQL or MongoDB API) with multi-region failover, autoscale throughput, private endpoint and backup policy.

Live-testedAzureTerraform
Open Azure DevOps Project + Repo + Pipeline

azure-devops

Bootstraps an Azure DevOps project with an initialized Git repository and a YAML build pipeline - repeatable team setup as code.

Live-testedAzureTerraform
Open Azure Front Door (Std/Premium) + WAF

azure-front-door

Global entry point: Front Door profile, endpoints, origin groups, custom domains with managed TLS and WAF policy.

Live-testedAzureTerraform
Open Azure Functions App

azure-functions

Function app (Flex Consumption or Premium) with storage, Application Insights, managed identity and VNet integration.

Live-testedAzureTerraform
Open Azure Key Vault

azure-key-vault

RBAC-mode Key Vault with private endpoint, diagnostics, and managed keys/secrets/certificates scaffolding.

Live-testedAzureTerraform
Open Azure Kubernetes Service Cluster

azure-aks

Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.

Live-testedAzureTerraform
Open Azure Landing Zone Core

azure-landing-zone-core

Management-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.

Live-testedAzureTerraform
Open Azure Linux VM Scale Set (Uniform)

azure-vmss

A self-contained Linux VM Scale Set (Uniform orchestration) on Azure - one apply creates the resource group, VNet, subnet, NSG and an SSH-key-only scale set with deny-all-inbound and no public IPs.

Live-testedAzureTerraform
Open Azure Linux Virtual Machine (self-contained)

azure-virtual-machine

A fully self-contained general-purpose Linux VM on Azure - one apply creates the resource group, VNet, subnet, NSG, NIC, optional public IP and an SSH-key-only VM with a system-assigned identity.

Live-testedAzureTerraform
Open Azure Monitor & Log Analytics Baseline

azure-monitor-baseline

Central Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).

Live-testedAzureTerraform
Open Azure Private DNS Zone

azure-private-dns

A self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.

Live-testedAzureTerraform
Open Azure Private Endpoint (Private Link)

azure-private-endpoint

An Azure Private Endpoint giving a target PaaS resource a private IP inside your VNet so traffic stays on the Microsoft backbone - wire to existing subnet/target or run fully self-contained.

Live-testedAzureTerraform
Open Azure Public DNS Zone & Records

azure-dns-zone

An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.

Live-testedAzureTerraform
Open Azure SQL Database

azure-sql-database

Logical SQL server + database with Entra-only auth, firewall/private endpoint, auditing, TDE and failover-group option.

Live-testedAzureTerraform
Open Azure Standard Load Balancer (L4)

azure-load-balancer

An Azure Standard L4 load balancer with a self-created static public IP frontend, a backend address pool, health probes and load-balancing rules - Standard SKU throughout.

Live-testedAzureTerraform
Open Azure Static Web App

azure-static-web-app

Globally distributed hosting for static sites and SPAs on Azure Static Web Apps with optional serverless APIs, free auto-renewing TLS, and a built-in global CDN - defaulting to the cost-free Free SKU.

Live-testedAzureTerraform
Open Azure Storage Account (secure-by-default)

azure-storage-account

Storage account with containers/file shares, lifecycle rules, network rules, CMK encryption and private endpoint options - Azure's most-deployed resource done right.

Live-testedAzureTerraform
Open Azure Traffic Manager Profile

azure-traffic-manager

Global, DNS-based load balancing with a Traffic Manager profile and map-driven external endpoints - Performance, Priority, Weighted, Geographic, Subnet or MultiValue routing with an HTTPS health probe.

Live-testedAzureTerraform
Open Azure Virtual Network (hub-ready)

azure-vnet

Production VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.

Live-testedAzureTerraform
Open Azure kubelogin, A Kubeconfig Converted Offline

ansible-kubelogin

kubelogin on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the vendor's per-file .sha256, and the live test re-checks it, then converts an azure auth-provider kubeconfig into an exec block and runs get-token until it needs the Azure CLI. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedAzureAnsible
Open BIND That Answers For Its Zones And Nothing Else

ansible-bind-authoritative

BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Backup Vault, Plans and Vault Lock

aws-backup

A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.

Static validated · Live test pendingAWSTerraform
Open Backups that Survive Whoever Gets Into the Vault

azure-backup

Soft delete covers deletion; it does not cover somebody shortening a retention policy so every backup ages out on its own - which deletes nothing, so no soft-delete window opens. immutability is the control that refuses that edit, and it defaults to Disabled. Locked is irreversible and gets its own acknowledgement.

Static validated · Live test pendingAzureTerraform
Open Bandit, A shell=True Call Found At High Severity

ansible-bandit

bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Base Database Service (DBCS VM)

oci-base-database

Oracle Database VM system with DB home, TDE via Vault, automated backups and optional Data Guard standby.

Static validated · Live test pendingOracle CloudTerraform
Open Bastion Service

oci-bastion

Zero-footprint managed bastion with session-managed SSH/port-forward access to private subnets - replaces jump hosts.

Static validated · Live test pendingOracle CloudTerraform
Open Batch Jobs that Survive a Reclaimed Host

aws-batch

Batch does not retry by default, so a reclaimed spot instance or a timed-out image pull ends as FAILED - reported as if the job failed on its merits, which is how somebody ends up debugging working code. Retries infrastructure failures and exits on real ones.

Static validated · Live test pendingAWSTerraform
Open BigQuery Dataset & Tables

gcp-bigquery-dataset

Datasets with partitioned/clustered tables, authorized views, CMEK and dataset-level access controls.

Live-testedGoogle CloudTerraform
Open Blackbox Exporter, Probed With A Control

ansible-blackbox-exporter

Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Block Storage Attached Live and Honest About Snapshots

vultr-block-storage

Instance snapshots and automatic backups image the primary disk only, block storage has no snapshot of its own, and an attach without live = true reboots the instance. NVMe or HDD by name, attached live, and two outputs that say the volume is in no snapshot, so whatever consumes the module cannot assume a copy exists.

Static validated · Live test pendingVultrTerraform
Open Bot Management that Says What It Will Do to Your Own Clients

cloudflare-bot-management

Bot Fight Mode is zone-wide with no path exclusion and no allow list: it challenges CI runners, monitoring, mobile apps and every API client that worked yesterday. Off unless accepted by name, Super Bot Fight Mode with an action per class on paid plans (challenge the definitely automated, admit the rest), AI crawlers blocked, and an output that says whether API clients will be challenged.

Static validated · Live test pendingCloudflareTerraform
Open Both Halves of a Hub-and-Spoke VNet Peering with Gateway Transit Set as a Pair

azure-vnet-peering

Both halves of a hub-and-spoke VNet peering in one apply, since one half alone sits in Initiated and carries nothing. hub_has_gateway writes allow_gateway_transit on the hub and use_remote_gateways on the spoke, in the order Azure requires; forwarded traffic is on for both halves because a hub firewall forwards by definition. One subscription; both directions bill per gigabyte.

Static validated · Live test pendingAzureTerraform
Open Boundary, Run To The Controller's Door Twice

ansible-boundary

boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Brute-Force Rules That Are Reachable, and Baseline Checks That Only Report

alicloud-security-posture

Security Center defence rules and baseline checks. A rule naming no servers defends nothing while Alibaba's default keeps running, so it is refused. The block-forever value is 52560000 minutes sitting at the end of a list of ordinary numbers, so the module takes words. SQL Server interception is off by default, which is where the interesting passwords are.

Static validated · Live test pendingAlibaba CloudTerraform
Open Builds that Run as a Named Account, Privately, with Approval to Deploy

gcp-cloud-build

A trigger with no service account runs every step - including code from the pull request under test - as the broadest identity in the project; a trigger that deploys on push deploys whatever lands; the shared default pool has external IPs. A dedicated runner with the defaults refused, a private worker pool with no external addresses, and approval required on any trigger marked as deploying.

Static validated · Live test pendingGoogle CloudTerraform
Open CFSSL, A CA Minted And Read Back

ansible-cfssl

cfssl and cfssljson on EL 10 from the GitHub release, each refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which mints a root CA from a CSR, writes it as PEM through cfssljson and reads the subject back with certinfo. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Cache Rules for the Pages a Proxied Zone Does Not Cache

cloudflare-cdn

Cloudflare caches by file extension out of the box, so the hashed assets are cached and the HTML is not, and every page view still reaches the origin while the dashboard reports a healthy hit ratio. A rule that caches is what changes that; a ruleset holding none is refused, and a caching rule matching every request is refused separately.

Static validated · Live test pendingCloudflareTerraform
Open Caddy As A TLS Front Door

ansible-caddy-https

Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Certificate Manager (certificate map)

gcp-certificate-manager

A Certificate Manager certificate map for external HTTPS load balancers, with an optional Google-managed certificate and DNS authorization provisioned when you supply a domain you control.

Live-testedGoogle CloudTerraform
Open Checkov In A venv Of Its Own

ansible-checkov

Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Cilium CLI, Checked Against The Published Checksums

ansible-cilium-cli

cilium on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum Cilium publishes, and re-checked with sha256sum -c by the live test, which then runs cilium config view with no cluster and expects the refused connection. Installing Cilium into a cluster stays yours. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Civo CLI, Checked Against Civo's Checksums

ansible-civo-cli

civo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Civo's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at 'no API key is supplied'. Original role, live-tested on Rocky Linux 10.

Live-testedCivoAnsible
Open Civo Compute Stack

civo-compute-stack

Instances with network, firewall, volume, and reserved IP.

Static validated · Live test pendingCivoTerraform
Open Civo Kubernetes Cluster

civo-k3s-cluster

Fast-launch k3s cluster with node pools, firewall rules, and network.

Static validated · Live test pendingCivoTerraform
Open ClickHouse, An Analytics Database Proven By A MergeTree Round Trip

ansible-clickhouse

ClickHouse on EL 10 from the upstream LTS release (sha512-verified), as a hardened systemd service on loopback with the default user behind a password; the live test creates a MergeTree table, inserts a row and selects it back over HTTP; a query without credentials is refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Client VPN with Per-Group Authorization

aws-client-vpn

Remote-access VPN endpoint with certificate or SAML authentication, split tunnelling, per-group authorization rules and connection logging. There is no allow-all shortcut: an endpoint with no rule reaches nothing.

Static validated · Live test pendingAWSTerraform
Open Cloud Armor Security Policy (WAF)

gcp-cloud-armor

A global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.

Live-testedGoogle CloudTerraform
Open Cloud Bigtable Instance & Table

gcp-bigtable

A single-cluster Cloud Bigtable instance (one 1-node SSD cluster, the smallest footprint) plus a table with column families, IAM-only access, optional CMEK, and deletion protection on.

Live-testedGoogle CloudTerraform
Open Cloud CDN in Front of a Bucket, with the Certificate, the Cache and the Redirect

gcp-cloud-cdn

enable_cdn defaults to false, so a backend bucket behind a global load balancer is served from the bucket on every request; a backend bucket is read as allUsers, which is to say public; the managed certificate stays PROVISIONING until DNS points at the address; and port 80 forwards unless a URL map redirects it. CDN on with negative caching, the bucket named as public, TLS 1.2, a 301 on 80.

Static validated · Live test pendingGoogle CloudTerraform
Open Cloud Composer 2 (managed Airflow)

gcp-composer

Managed Apache Airflow on Cloud Composer 2 with small-by-default sizing, worker autoscaling pinned for predictable cost, and an opt-in private environment posture.

Live-testedGoogle CloudTerraform
Open Cloud DNS Zones & Records

gcp-cloud-dns

Public/private managed zones with record sets, DNSSEC, forwarding and peering configs.

Live-testedGoogle CloudTerraform
Open Cloud Eye Alarm Rules with the SMN Topic that Makes Them Reach People

huawei-monitoring-alarms

Cloud Eye alarm rules from a map of namespaces, metrics, dimensions and thresholds, each firing after three consecutive periods and quiet for an hour after, sending on alarm and on recovery to an SMN topic created here and subscribed by the addresses you name (each confirms by email). A topic with no subscribers has to be accepted by name.

Static validated · Live test pendingHuawei CloudTerraform
Open Cloud Filestore NFS Share

gcp-filestore

A managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.

Live-testedGoogle CloudTerraform
Open Cloud Firewall Policy in a Declared Order, with an IPS That Blocks Rather Than Watches

alicloud-network-firewall

Address books and control policies with their evaluation order declared, since the list is read top down and a broad accept above a narrow drop silently disables it. The intrusion prevention engine ships in observation mode, where it inspects, logs and blocks nothing while every dashboard looks right; block is the default here. Rules whose action is log are counted and reported.

Static validated · Live test pendingAlibaba CloudTerraform
Open Cloud KMS Keyring & Keys

gcp-kms

Keyrings and rotation-enabled crypto keys with per-key IAM for CMEK across GCS, BigQuery, Cloud SQL and disks.

Live-testedGoogle CloudTerraform
Open Cloud Map Service Registry

aws-cloud-map

Private DNS, public DNS or API-only namespaces and the services registered in them. Documents the health-check trap: a private namespace gets a custom check that something else must update, and one nobody updates reports healthy forever.

Static validated · Live test pendingAWSTerraform
Open Cloud Monitor Policies Bound to Every Instance, with the Notice that Sends Them

tencent-monitoring-alarms

Cloud Monitor alarm policies from a map of namespaces and rules, each bound to every instance in its namespace so a new instance is covered the day it exists, firing after three consecutive breaches, and all sending to an alarm notice created here with the sub-users and channels you name. A notice with no recipients has to be accepted by name.

Static validated · Live test pendingTencent CloudTerraform
Open Cloud Monitoring, Alerting & Log Export

gcp-monitoring

A self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.

Live-testedGoogle CloudTerraform
Open Cloud NAT Gateway

gcp-cloud-nat

A regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.

Live-testedGoogle CloudTerraform
Open Cloud Run Function (gen2)

gcp-cloud-function

Event-driven or HTTP gen2 function with source upload, dedicated runtime SA and Eventarc trigger wiring.

Live-testedGoogle CloudTerraform
Open Cloud Run Job (v2)

gcp-cloud-run-job

A Cloud Run v2 Job for batch and run-to-completion workloads with a dedicated runtime service account, auto-wired Secret Manager accessor grants, VPC egress, bounded retries and per-task timeout.

Live-testedGoogle CloudTerraform
Open Cloud Run Service

gcp-cloud-run-service

Cloud Run v2 service with autoscaling, secret and VPC egress wiring, custom domain and invoker IAM done right.

Live-testedGoogle CloudTerraform
Open Cloud SQL (PostgreSQL/MySQL) HA Instance

gcp-cloud-sql

Regional-HA Cloud SQL with private IP (PSA/PSC), automated backups, PITR, read replicas and IAM database auth.

Live-testedGoogle CloudTerraform
Open Cloud Scheduler HTTP Cron Job

gcp-cloud-scheduler

A Cloud Scheduler cron job that calls an HTTP(S) endpoint on a schedule, with a bounded attempt deadline, capped exponential-backoff retries, and per-invocation OIDC/OAuth service-account auth.

Live-testedGoogle CloudTerraform
Open Cloud Spanner Instance & Database

gcp-spanner

A regional Cloud Spanner instance at the smallest billable size (100 processing units) plus a database with optional starter schema, drop protection, and Terraform deletion protection on.

Live-testedGoogle CloudTerraform
Open Cloud Storage Bucket

gcp-gcs-bucket

Hardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.

Live-testedGoogle CloudTerraform
Open Cloud Tasks Queue

gcp-cloud-tasks

A Cloud Tasks queue with capped dispatch rate and concurrency, a bounded exponential-backoff retry policy, and full Stackdriver logging so failed dispatches are observable rather than silent.

Live-testedGoogle CloudTerraform
Open Cloud WAN Global Network and Segments

aws-cloud-wan

A global network whose segments, routing and attachment placement live in one policy document rather than per-region route tables. The policy VERSION is executed as a second step, so a change cannot report success while the network still runs the previous one.

Static validated · Live test pendingAWSTerraform
Open Cloud Workflows (least-privilege identity)

gcp-workflows

A Cloud Workflows workflow that runs as a dedicated least-privilege service account instead of the broad Compute Engine default, with inline YAML, deletion protection, and call logging.

Live-testedGoogle CloudTerraform
Open CloudFront Site (S3 + ACM + Route53)

aws-cloudfront-site

Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.

Static validated · Live test pendingAWSTerraform
Open CloudMonitor Alarms with the Contact Group that Makes Them Reach People

alicloud-monitoring-alarms

CloudMonitor alarm rules from a map of metrics and thresholds, each firing at the critical level after three consecutive breaches and quiet for an hour after, effective all day, and all sending to a contact group created here with the contacts you name. A group with no contacts notifies nobody and has to be accepted by name.

Static validated · Live test pendingAlibaba CloudTerraform
Open CloudTrail with a Hardened Evidence Bucket

aws-cloudtrail

Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.

Static validated · Live test pendingAWSTerraform
Open CloudWatch Logs, Alarm & Dashboard

aws-cloudwatch

A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.

Live-testedAWSTerraform
Open Cloudflare DNS & WAF

cloudflare-dns

Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.

Static validated · Live test pendingCloudflareTerraform
Open Cloudflare Notifications that Reach Somebody

cloudflare-notification-policy

An origin marked unreachable, a certificate that failed to renew, a DDoS mitigation on your zone: each is an event the account can notify about and none does until a policy exists, and a policy whose mechanisms block is empty is accepted and notifies nobody. Origin health, certificate and DDoS policies by default, more by alert type, and at least one email or webhook required for all of them.

Static validated · Live test pendingCloudflareTerraform
Open Cloudflare Workers Platform

cloudflare-workers-platform

Worker with KV/R2/D1 bindings, routes, custom domain, and secrets - full edge app scaffold.

Static validated · Live test pendingCloudflareTerraform
Open Cloudflare Zero Trust Access

cloudflare-zero-trust-access

Access application with policies, identity provider wiring, and a cloudflared tunnel to private origins.

Static validated · Live test pendingCloudflareTerraform
Open Cockpit Metrics and Logs Sources with Retention, and an Alert Manager with Contacts

scaleway-cockpit

Scaleway Cockpit custom metrics and logs sources with retention set to a month rather than defaulted, and the alert manager enabled with the contact addresses you name (none by name) and the preconfigured alerts you choose, because an alert with no contact point reaches nobody. Retention is the storage half of the bill.

Static validated · Live test pendingScalewayTerraform
Open Code Signing Profiles that Actually Reject

aws-signer

Signing profiles for Lambda packages and container images, plus the code signing configuration that enforces them. Defaults to Enforce rather than the API default Warn, which logs an untrusted artifact and deploys it anyway.

Static validated · Live test pendingAWSTerraform
Open CodeDeploy CI/CD (EC2 / ECS / Lambda)

aws-codedeploy

CodeDeploy application, deployment groups, and the platform-correct service role for automated EC2/ECS/Lambda rollouts with auto-rollback on failure.

Live-testedAWSTerraform
Open CodePipeline + CodeBuild CI/CD

aws-codepipeline

AWS-native CI/CD: CodePipeline orchestrating a CodeBuild project, with an encrypted private artifact bucket and least-privilege roles. Sources from S3 (or GitHub).

Live-testedAWSTerraform
Open Cognito User Pool & App Client

aws-cognito

A secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.

Live-testedAWSTerraform
Open Compliance Rule Packs, Now That Audit Manager Is Closed to New Customers

aws-conformance-packs

AWS Config conformance packs for one account or a whole organisation, with a ten-rule baseline of AWS managed rules taken from AWS's CIS sample pack. AWS Audit Manager no longer takes new customers and points them here. The module says a pack evaluates nothing without a configuration recorder and that Terraform cannot detect a pack edited in the console.

Static validated · Live test pendingAWSTerraform
Open Compute Engine VM (Shielded, private)

gcp-compute-instance

A hardened Compute Engine VM on Debian 12 with Shielded VM (Secure Boot, vTPM, integrity monitoring), OS Login for IAM-managed SSH, no external IP by default, and deletion protection on.

Live-testedGoogle CloudTerraform
Open Conftest, A Real Policy Evaluated

ansible-conftest

conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Consul CLI, SHA256SUMS Signed By HashiCorp

ansible-consul-cli

consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Consul Single Server, Five Listeners On Loopback

ansible-consul-server

HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open CoreDNS Authoritative On Loopback:53, Proven By dig

ansible-coredns

CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Cost Anomaly Alerts That Reach Somebody

aws-cost-anomaly-detection

AWS Cost Anomaly Detection with monitors and the alerts that make them useful. A monitor alone leaves anomalies in the console; AWS sends immediate alerts only over SNS and summaries only by email, so this module builds both, with a topic encrypted by a key the service may use. It needs a cost threshold, and says an account holds one AWS services monitor.

Static validated · Live test pendingAWSTerraform
Open Customer Sign-In Where the Bill and the Open Door Are Both Decisions

ibm-customer-identity

IBM Cloud App ID's customer directory, redirect URLs, token lifetimes, and MFA, password policy and activity tracking. The provider lets anyone sign up by default, so that input has no default here. Redirect URLs refuse plaintext and wildcards unless accepted, as IBM advises. MFA, password policy and tracking are billed, graduated-tier-only features, so they need an explicit yes.

Static validated · Live test pendingIBM CloudTerraform
Open Customer Sign-In with Anonymous Accounts Off, MFA Offered and Sign-Ups Throttled

gcp-identity-platform

Identity Platform for customer sign-in: email and password with the federated providers you add from a sensitive map, MFA offered (or mandatory), anonymous accounts off and auto-deleted, a daily sign-up quota so a script cannot fill the user table, request logging on, and tenants when one project serves several customer bases. localhost in the redirect list and no quota are accepted by name.

Static validated · Live test pendingGoogle CloudTerraform
Open DNS Firewall with Fail-Open Stated, Not Inherited

aws-dns-firewall

Domain lists, rule group, rules and VPC associations. Fail-open is an availability decision wearing a security name: closed makes a firewall fault a DNS outage, open resolves unfiltered without saying so. The module makes you choose.

Static validated · Live test pendingAWSTerraform
Open DNS Zone & Traffic Steering

oci-dns-zone

Public/private DNS zones with record sets, failover/geo steering policies and health-check probes.

Static validated · Live test pendingOracle CloudTerraform
Open DRG Hub & Spoke Connectivity

oci-drg-hub

Dynamic Routing Gateway with VCN attachments, custom DRG route tables, remote peering and IPSec/FastConnect attach points.

Static validated · Live test pendingOracle CloudTerraform
Open Data Lake Permissions That Are Actually in Effect

aws-lake-formation

AWS Lake Formation with its own permissions switched on for new databases and tables: admins, registered S3 locations and explicit grants. AWS ships it in IAM-only mode, and its settings resource clears any admin it is not given, so admins are required and the settings are protected from destroy. Existing databases keep IAM-only access until revoked outside Terraform, and it says so.

Static validated · Live test pendingAWSTerraform
Open Databases for PostgreSQL that Is Private, Allow-Listed and Protected

ibm-databases-postgresql

service_endpoints decides whether the deployment answers on the internet and public is the default; deletion_protection defaults to false; an empty allowlist means any address that can reach the endpoint; and disk and backup encryption use IBM's keys unless yours are given. Private with public by name, deletion protection on, ranges expected (empty by name), both key CRNs taken, two members.

Static validated · Live test pendingIBM CloudTerraform
Open Dataproc Single-Node Cluster

gcp-dataproc

A single-node Dataproc cluster (1 master, 0 workers), the cheapest managed Spark/Hadoop cluster that still applies and destroys cleanly, with internal-only IPs and deletion protection on.

Live-testedGoogle CloudTerraform
Open Defender Plans that Are Actually On

azure-defender-for-cloud

A subscription with no Defender plan still has a full Defender for Cloud page: a Secure Score, hundreds of recommendations, a compliance dashboard - and not one threat detection, because those come from the paid plans, each Off until somebody turns it on. Sets Standard per resource type, always creates the security contact, and defaults alert notifications on.

Static validated · Live test pendingAzureTerraform
Open Detective Behaviour Graph

aws-detective

Builds an investigable graph from CloudTrail, VPC flow logs and GuardDuty findings, with member accounts and organization delegation. It detects nothing itself - it makes an existing finding into a timeline.

Static validated · Live test pendingAWSTerraform
Open DigitalOcean App Platform Service

do-app-platform

Declarative App Platform deployment with services, workers, domains, and alerts.

Static validated · Live test pendingDigitalOceanTerraform
Open DigitalOcean DOKS Cluster

do-doks-cluster

Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.

Static validated · Live test pendingDigitalOceanTerraform
Open DigitalOcean Droplet Stack

do-droplet-stack

Hardened droplet(s) with VPC, firewall, volume, reserved IP, and cloud-init bootstrap.

Static validated · Live test pendingDigitalOceanTerraform
Open DigitalOcean Managed Database

do-managed-database

Managed PG/MySQL/Valkey cluster with firewall trust list, users, DBs, and replicas.

Static validated · Live test pendingDigitalOceanTerraform
Open Direct Connect, and the Fact that It Is Not Encrypted

aws-direct-connect

Gateway, connections, virtual interfaces and associations. A private circuit is a private path, not a private conversation: traffic crosses it in clear text unless MACsec is on, and should_encrypt quietly falls back to clear text.

Static validated · Live test pendingAWSTerraform
Open Dockle, A Root-User Finding With An Exit Code

ansible-dockle

dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open DocumentDB Cluster, Encrypted and Auditable

aws-documentdb

A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.

Static validated · Live test pendingAWSTerraform
Open Dragonfly, A Redis-Compatible Store Proven Over RESP

ansible-dragonfly

Dragonfly on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind a password kept in a flagfile; the live test speaks RESP itself: an unauthenticated PING and a wrong password are refused, AUTH + SET + GET round-trip. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Dynamic PostgreSQL Credentials with the Root Password Rotated Away

vault-database-secrets

The credential Vault connects with is still a password somebody knows until Vault rotates it; a role with no max TTL issues credentials that renew forever; and creation statements are the privilege, so a careless one is a superuser factory. Root rotation daily, TTLs per role, statements that grant exactly the PostgreSQL role you name, and the connection verified at apply.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open DynamoDB Table

aws-dynamodb-table

DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.

Live-testedAWSTerraform
Open EC2 Instance

aws-ec2-instance

EC2 instance with IMDSv2, encrypted EBS, instance profile, and EIP - secure defaults out of the box.

Live-testedAWSTerraform
Open EC2 Launch Template + Auto Scaling Group

aws-autoscaling

EC2 launch template and Auto Scaling group with IMDSv2 enforced, encrypted gp3 root volume, an egress-only security group, and scale-to-zero defaults so it applies cleanly with no compute cost.

Live-testedAWSTerraform
Open ECR Repository

aws-ecr

ECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.

Live-testedAWSTerraform
Open ECS Fargate Service

aws-ecs-fargate-service

Full Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.

Live-testedAWSTerraform
Open EFS File System (encrypted, in-transit TLS)

aws-efs

An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.

Live-testedAWSTerraform
Open EKS Cluster with Managed Node Groups

aws-eks

Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.

Live-testedAWSTerraform
Open Edge Policies plus the Switch Without Which They Inspect Nothing at All

tencent-network-firewall

Address templates and edge policies in a declared order, the intrusion prevention mode set to block rather than the observation mode it ships in, and the edge firewall switch turned on for the addresses you name. Writing policies and leaving that switch off produces a complete, correct and entirely inactive rule set, so naming no addresses is refused here.

Static validated · Live test pendingTencent CloudTerraform
Open Egress with Enough SNAT Ports to Survive the Afternoon

azure-nat-gateway

Default outbound access is retired, so a subnet with no NAT gateway has no internet at all and fails as a timeout rather than an error. Each public IP gives 64,512 SNAT ports held for the whole idle timeout; exceed that and connections fail intermittently in a way that looks like the remote service being flaky.

Static validated · Live test pendingAzureTerraform
Open ElastiCache for Redis / Valkey

aws-elasticache-redis

A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.

Live-testedAWSTerraform
Open Email from Your Own Domain with the DNS Records Exported and Tracking Off

azure-communication-email

Azure Communication Services email from your own domain: the email service, the domain with the DNS records to publish exported, sender addresses as a map, and the Communication Services resource that sends. CustomerManaged rather than the random azurecomm.net subdomain (accepted by name), engagement tracking off, and the key-based connection string sensitive; managed identity is the better path.

Static validated · Live test pendingAzureTerraform
Open Encrypted EBS Volumes with Snapshot Lifecycle

aws-ebs-volume

Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.

Static validated · Live test pendingAWSTerraform
Open Entra ID Workload Identity Baseline

azure-entra-id-baseline

App registrations, service principals, groups and federated credentials (OIDC for GitHub/Terraform) - the identity plumbing every Azure org rebuilds by hand.

Live-testedAzureTerraform
Open Event Grid Topic & Subscriptions

azure-event-grid

An Event Grid custom topic plus event subscriptions with an optional in-module Storage Queue target - SAS auth off (Entra ID), a system-assigned identity, and HTTPS-only TLS 1.2+ storage.

Live-testedAzureTerraform
Open Event Hubs Namespace & Hubs

azure-event-hubs

An Event Hubs namespace plus hubs, each with consumer groups and least-privilege SAS rules for high-throughput (Kafka-compatible) ingestion - TLS 1.2 floor and optional default-deny networking.

Live-testedAzureTerraform
Open Event Rules that Match Something Specific and Act

oci-events-rule

An empty condition is legal and matches the completion of every API call on every resource type in the compartment, flooding the target; a rule can be created disabled, and so can each action inside an enabled rule, which then matches events and does nothing while showing Active. Every rule names its event types, both levels are enabled unless accepted, and the IAM the service needs is exported.

Static validated · Live test pendingOracle CloudTerraform
Open Event Streams on the Standard Plan with Private Endpoints and Topics with Retention

ibm-event-streams

An IBM Cloud Event Streams (Kafka) instance on the standard multi-tenant plan (enterprise is a dedicated cluster and a purchase), with the brokers on private endpoints only (public by name), and topics from a map with partitions, retention in hours and a cleanup policy, a week and three partitions by default. Producer and consumer credentials are a separate resource.

Static validated · Live test pendingIBM CloudTerraform
Open EventBridge Bus, Rule & Target

aws-eventbridge

A custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.

Live-testedAWSTerraform
Open Eventarc Pub/Sub Trigger

gcp-eventarc

An Eventarc Pub/Sub trigger wired into a self-contained pipeline - a Cloud Run target, a dedicated delivery service account, and the run.invoker and eventReceiver grants Eventarc silently requires.

Live-testedGoogle CloudTerraform
Open Exoscale CLI, Checked, With Its Own Completion

ansible-exoscale-cli

exo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Exoscale's checksum file, re-checked by the live test, with the bash completion the release itself ships installed for every shell. No package exists. Pinned; an API call without configuration stops at 'must be configured before usage'. Original role, live-tested on Rocky Linux 10.

Live-testedExoscaleAnsible
Open Exoscale DBaaS

exoscale-dbaas

Managed PG/MySQL/Kafka with IP filters and TF-managed users.

Static validated · Live test pendingExoscaleTerraform
Open Exoscale SKS Cluster

exoscale-sks-cluster

SKS Kubernetes with node pools, security groups, and anti-affinity.

Static validated · Live test pendingExoscaleTerraform
Open FSx for Lustre, Persistent by Default

aws-fsx-lustre

A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.

Static validated · Live test pendingAWSTerraform
Open File Storage (NFS)

oci-file-storage

Elastic NFSv3 file system with mount target, export options, snapshots and NSG-scoped access.

Static validated · Live test pendingOracle CloudTerraform
Open Findings that Reach a Topic, Mutes that Say Why

gcp-security-command-center

The findings page is not a pager: a project accumulates thousands of findings with nobody having received a message, and a mute rule silences a whole category, now and in future, with no record why. Streams CRITICAL and HIGH findings to a Pub/Sub topic as a requirement, refuses a mute without a written reason, and refuses a custom detector created DISABLED, which is listed and evaluates nothing.

Static validated · Live test pendingGoogle CloudTerraform
Open Firewall Endpoints in Your Zones with a Threat Profile that Denies and the Rule that Routes

gcp-cloud-ngfw

Cloud NGFW Enterprise: a firewall endpoint per zone you list (each billed by the hour plus per gigabyte inspected), associated with your VPC, a threat prevention profile that denies critical and high severity threats and alerts on medium, and the rule added to your network firewall policy with apply_security_profile_group, without which no packet reaches the endpoint.

Static validated · Live test pendingGoogle CloudTerraform
Open Firewall Manager Org-Wide Policy

aws-firewall-manager

WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.

Static validated · Live test pendingAWSTerraform
Open Flexible Load Balancer (L7)

oci-load-balancer

HTTPS load balancer with backend sets, health checks, TLS certificates, rule sets and WAF-ready listeners.

Static validated · Live test pendingOracle CloudTerraform
Open Flow Logs That Warn When They Are Logging Nothing

gcp-vpc-flow-logs

VPC Flow Logs configs through the Network Management API, one per network, subnet, VPN tunnel or Interconnect attachment. A config for a target that does not exist is accepted and logs nothing, so a check block warns on it. Filters and sampling are reported by name, and the defaults stay Google's most complete: every flow, 5-second aggregation, all metadata.

Static validated · Live test pendingGoogle CloudTerraform
Open Flow Logs for an Existing VPC in the Extended Format, at One Minute, All Traffic

aws-vpc-flow-logs

Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.

Static validated · Live test pendingAWSTerraform
Open Flow Logs that Are On, Kept, and Analysed

azure-flow-logs

enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.

Static validated · Live test pendingAzureTerraform
Open Flux CLI, Checked Against The Published Checksums

ansible-flux-cli

flux on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked with sha256sum -c by the live test, which then runs flux check --pre with no cluster and expects the refused connection. Flux also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Functions Application

oci-functions-app

Serverless Fn application with functions, provisioned concurrency, invoke logging and Events-rule trigger wiring.

Static validated · Live test pendingOracle CloudTerraform
Open GCP Project Factory

gcp-project-factory

Opinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.

Live-testedGoogle CloudTerraform
Open GCP VPC Network Foundation

gcp-vpc

Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.

Live-testedGoogle CloudTerraform
Open GKE Cluster (Autopilot & Standard)

gcp-gke-cluster

Private, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.

Live-testedGoogle CloudTerraform
Open Garage, An S3 Object Store Proven By A Bucket

ansible-garage

Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open GitHub CLI, Checked Against The Published Checksums

ansible-gh-cli

gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open GitLab CLI, Run To GitLab's Door

ansible-glab

glab on EL 10 from the GitLab-hosted release, get_url refuses it unless its SHA-256 is the one in the vendor's checksums file, and the live test re-checks it, then runs auth status to the 401 gitlab.com returns and round-trips a config value offline. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Gitea On Loopback, A Config It Never Writes, A Repository Round-Tripped

ansible-gitea

Gitea from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; its secrets are generated once and read from files, so app.ini stays root's. The live test creates an administrator with gitea's own command, then a private repository through the API, reads it back, sees it hidden from anonymous eyes, deletes it. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Gitleaks, A Planted Key Found

ansible-gitleaks

gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Global Accelerator with Health-Checked Failover

aws-global-accelerator

Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.

Static validated · Live test pendingAWSTerraform
Open Global External HTTPS Load Balancer

gcp-http-load-balancer

Global ALB with managed TLS certs, URL map, serverless/instance NEG backends, optional Cloud CDN and Cloud Armor policy.

Live-testedGoogle CloudTerraform
Open Glue with Encrypted Job Bookmarks

aws-glue

A bookmark records exactly where a job reached in your data - which partitions, which keys - and it is written in plain text unless a security configuration says otherwise. That configuration is attached at job CREATION, so adding one later means rebuilding every job.

Static validated · Live test pendingAWSTerraform
Open GoReleaser, A Configuration Validated, A Broken One Refused

ansible-goreleaser

goreleaser on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has goreleaser check validate a minimal configuration and refuse one with an unknown field at parse, exit 1. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Golden Images that Boot Trusted, Stay Private and Expire

azure-image-gallery

Community sharing publishes every image version to every Azure customer, unauthenticated, with your publisher email attached; trusted launch supported means a VM may boot without Secure Boot, and an image with no end-of-life date is a 2021 build still being deployed. Private by default, trusted launch required on every definition, an end-of-life date on each, and Hyper-V generation 2 throughout.

Static validated · Live test pendingAzureTerraform
Open Google Cloud CLI Without gpgcheck=0

ansible-google-cloud-cli

gcloud, gsutil and bq on EL 10 from the versioned tarball, checked against a SHA-256 pinned beside the version: Google's yum key has a SHA-1 self-signature that rpm on EL 10 refuses, so the repository only installs with the GPG check off. Usage reporting and update nagging off installation-wide, read back through gcloud config get. Original role, live-tested on Rocky Linux 10.

Live-testedGoogle CloudAnsible
Open Gotify, A Push Server Proven By A Message

ansible-gotify

Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Grafana With Its Own Secret Key

ansible-grafana-server

Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Grafana k6, A Run That Passes And One That Fails

ansible-k6

k6 on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs a script to 100% checks and one whose threshold cannot hold to exit code 99; usage reporting off from profile.d. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Grafana, Datasources Provisioned And A Dashboard Proven

ansible-grafana

Grafana (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads back the datasource this role provisioned, creates a dashboard and finds it by search, sees anonymous and wrong-password requests refused, and reads the build metric naming the version installed. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Grype, Checked Against The Published Checksums

ansible-grype

grype on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs grype db status with no database fetched and expects 'database does not exist'. Anchore also signs the checksums with cosign; the role checks the hash. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open GuardDuty with Per-Plan Cost Control

aws-guardduty

Threat detection with each protection plan - S3, EKS, RDS, Lambda, malware, runtime - a separate decision with its billing dimension stated, plus organization delegation and findings filtered by severity into EventBridge.

Static validated · Live test pendingAWSTerraform
Open HA VPN (Site-to-Site)

gcp-ha-vpn

99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.

Live-testedGoogle CloudTerraform
Open HAProxy That Refuses TLS 1.0

ansible-haproxy-tls

HAProxy terminating TLS 1.2 and 1.3 only with a modern cipher policy, HTTP redirected to HTTPS, HSTS on every response including HAProxy's own error pages (http-after-response, which the live test proved http-response does not cover), a self-signed certificate until yours arrives, stats kept local. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Hard Limits For Logins And For Services, Which Are Not The Same

ansible-resource-limits

Nothing limits an account on a stock EL 10 host: limits.d is empty and what ulimit reports is systemd's ceiling. This role sets hard limits on processes, open files and core dumps in both places that decide, because a systemd service never goes through PAM at all. The live test reads a real login session and a real service, and tries to raise both. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Headscale Control Server On Loopback, Proven By A Pre-Auth Key

ansible-headscale

Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Helm, Checked Against The Published Hash

ansible-helm

helm on EL 10 from get.helm.sh, refused by Ansible's get_url unless its SHA-256 is the one in the .sha256sum file published beside the tarball, and re-checked with sha256sum -c by the live test, which then runs helm list with no cluster and expects 'kubernetes cluster unreachable'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Helmfile, Checked Against The Published Checksums

ansible-helmfile

helmfile on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then runs helmfile list on a one-release file with no helm on the host and expects it to read the file and stop at the missing helm; pair it with the helm role. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Hetzner CLI, Checked Against Hetzner's Checksums

ansible-hcloud-cli

hcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Hetzner's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a context stops at 'no active context or token'. Original role, live-tested on Rocky Linux 10.

Live-testedHetznerAnsible
Open Hetzner Load-Balanced Web Tier

hetzner-lb-web-tier

Managed LB with health checks, cert, and label-selected server targets.

Static validated · Live test pendingHetznerTerraform
Open Hetzner Private Network + NAT

hetzner-private-network

Private network with subnets, routes, and a NAT gateway server for egress-only fleets.

Static validated · Live test pendingHetznerTerraform
Open Hetzner Server Fleet

hetzner-server-fleet

N-server fleet with placement group, firewall, primary IPs, and cloud-init - Hetzner's price/perf with guardrails.

Static validated · Live test pendingHetznerTerraform
Open Host Protection That Waits for the Agent, and a Scan That Is Actually Open

huawei-security-posture

HSS host protection and a vulnerability scan policy. status close writes a policy with a period and a range that never runs. specific_host with an empty list scans nothing. The protection tiers are different products rather than different quotas and all of them report as protected. Protection needs the agent online, and the waiting behaviour is off in the API.

Static validated · Live test pendingHuawei CloudTerraform
Open Huawei Cloud CCE Cluster

huawei-cce-cluster

CCE Kubernetes with VPC/subnet, node pool, and EIP-attached ingress.

Static validated · Live test pendingHuawei CloudTerraform
Open Huawei Cloud KooCLI, Pinned To A Versioned URL

ansible-huawei-koocli

Huawei's hcloud on EL 10 from a versioned path on Huawei's download host (the docs give only latest), refused by get_url unless the tarball's SHA-256 is the pinned one; Huawei's .sha256 names a build-server path, so the live test reads it and asserts its first field is the pin. The privacy statement stays per user; the role accepts it for nobody. Original role, live-tested on Rocky Linux 10.

Live-testedHuawei CloudAnsible
Open IAM Access Analyzer (External + Unused Access)

aws-iam-access-analyzer

Finds what a principal outside your zone of trust could actually reach, which is the question policy reviews get wrong by reading JSON. External analysis is free; unused-access analysis is a separate, billed analyzer.

Static validated · Live test pendingAWSTerraform
Open IAM Roles, Policies & OIDC Trust

aws-iam-roles

Least-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.

Live-testedAWSTerraform
Open IAP in Front of a Web Backend: Who Gets Through, How Often They Prove It

gcp-iap-web

Identity-Aware Proxy access to a web backend service: the httpsResourceAccessor binding that decides who gets through (nobody by default), re-authentication every eight hours by the method you choose, the Host header check against your domains, and a troubleshooting link on the denied page. IAP guards the path through the load balancer and no other; the backend must still verify the signed header.

Static validated · Live test pendingGoogle CloudTerraform
Open IBM Cloud CLI, Pinned Where IBM Publishes No Checksum

ansible-ibmcloud-cli

ibmcloud on EL 10 from IBM's download host, refused by get_url unless the tarball's SHA-256 is the one pinned beside the version: IBM publishes no checksum, and the ibmcloud.sig inside the tarball has no public key to check it against. The live test hashes the tarball again and runs ibmcloud target before any endpoint is set. Original role, live-tested on Rocky Linux 10.

Live-testedIBM CloudAnsible
Open IBM Cloud Kubernetes (IKS) on VPC

ibm-iks-cluster

IKS cluster on VPC Gen2 with worker pools and COS-backed registry namespace.

Static validated · Live test pendingIBM CloudTerraform
Open IBM Cloud VPC Landing Zone (Lite)

ibm-vpc-landing

VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.

Static validated · Live test pendingIBM CloudTerraform
Open IP Address Management That Ships the Policy That Enforces It

aws-ipam

Amazon VPC IPAM with a top-level pool, a pool per region with netmask bounds and required tags, and optional sharing through AWS RAM. IPAM forces nothing on its own - a VPC can still take a hand-typed CIDR - so the module outputs the SCP AWS documents for requiring a pool. The provider defaults to the Advanced tier, billed per active IP, so the tier has no default here.

Static validated · Live test pendingAWSTerraform
Open Iceberg Tables That Say How Far Back They Go

aws-s3-tables

Amazon S3 Tables: a table bucket, its namespaces and Iceberg tables. Three maintenance jobs run by default and together they set how long history survives - snapshots expire at 120 hours, unreferenced objects are deleted permanently 13 days later, compaction targets 512 MB. This module makes each an input and returns the resulting window, and validates the numbers the provider does not.

Static validated · Live test pendingAWSTerraform
Open Identity Center Permission Sets and Assignments

aws-iam-identity-center

Permission sets with managed policy, inline policy and permissions boundaries, and the account assignments that actually grant them - written out as auditable (set, account, principal) triples rather than buried in a console.

Static validated · Live test pendingAWSTerraform
Open InfluxDB 3 Core, Proven By A Write And An SQL Query

ansible-influxdb3

InfluxDB 3 Core on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback with file object storage; the binary runs from its release directory (it links the Python it ships); the live test writes a point in line protocol and reads it back with SQL. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Infracost, Checked, And Not Checking For Updates

ansible-infracost

infracost on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 Infracost publishes, re-checked by the live test, which then runs a breakdown with no API key and expects it to stop there. The role exports INFRACOST_SKIP_UPDATE_CHECK=true for login shells and the live test reads it back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Inspector Vulnerability Scanning

aws-inspector

Continuous scanning for EC2, ECR images, Lambda dependencies and Lambda code, each its own decision with its own billing dimension, plus organization delegation and findings routed at CRITICAL and HIGH.

Static validated · Live test pendingAWSTerraform
Open Instance Pool with Autoscaling

oci-instance-pool-autoscaling

Self-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.

Static validated · Live test pendingOracle CloudTerraform
Open Interconnect Attachments in a Pair, Encrypted by Decision

gcp-interconnect

An interconnect is a private path, not a private conversation: traffic crosses the colocation facility and the partner in clear unless the attachment carries HA VPN. One attachment is no SLA, and a partner attachment is created disabled until somebody flips it. A redundant pair across two edge availability domains, IPsec by default with clear text accepted by name, and enabled unless told.

Static validated · Live test pendingGoogle CloudTerraform
Open Internal Passthrough Load Balancer (L4)

gcp-internal-lb

An internal passthrough L4 load balancer - health check, regional backend service and forwarding rule - that stands up before any backends exist, preserving client source IPs, with optional global access.

Live-testedGoogle CloudTerraform
Open Jaeger v2 With Badger On Loopback, A Span Written And Read Back

ansible-jaeger

Jaeger v2, the tracing backend built on the OpenTelemetry Collector, from the upstream release (sha256-verified against the right checksum file) as a hardened system service on loopback with badger storage and the query API on loopback. The live test pushes a span over OTLP and reads the trace back by id with its name and service. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Jenkins Controller on AWS (EC2)

aws-jenkins

Self-hosted Jenkins controller on a hardened EC2 instance - restricted security group, IMDSv2 enforced, SSM access, encrypted root volume, Jenkins auto-installed via user-data.

Live-testedAWSTerraform
Open Jenkins Controller on Azure (VM)

azure-jenkins

Self-hosted Jenkins on a hardened Azure Linux VM - self-contained vnet/subnet/NSG, SSH-key auth only, managed-disk encryption, Jenkins installed via cloud-init.

Live-testedAzureTerraform
Open Jenkins LTS, Secured On First Start, Proven By A Job Built

ansible-jenkins

Jenkins LTS (sha256-verified war) on Java 21, secured on its first start without the wizard, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees anonymous and wrong-password requests refused, creates a freestyle job through the API with a CSRF crumb, builds it to SUCCESS, reads the console and deletes it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open KMS Key with Policy Patterns

aws-kms

Customer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.

Live-testedAWSTerraform
Open Keycloak, An Optimized Image Proven Through The Admin API

ansible-keycloak

Keycloak 26 (SHA-256 pinned) on Java 21, an image the service cannot write to, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test takes an admin token, sees a wrong password and an anonymous admin request refused, creates a realm (201), duplicates it (409), reads its OpenID discovery document and deletes it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Keyless Access Scoped to Callers You Meant

gcp-workload-identity-federation

attribute_condition is optional, and the issuer is not yours - so omitting it on a GitHub Actions provider trusts every workflow in every repository belonging to anyone on GitHub. It works perfectly in testing, because your workflow is one of the ones it admits. Refused here, along with a wildcard principalSet.

Static validated · Live test pendingGoogle CloudTerraform
Open Kinesis Data Stream (on-demand)

aws-kinesis

A Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.

Live-testedAWSTerraform
Open Kopia, A Backup Taken, Listed And Verified

ansible-kopia

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open KubeLinter, Four Findings On A Bare Deployment

ansible-kube-linter

kube-linter on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then lints a Deployment with one container and nothing else, expecting run-as-non-root, no-read-only-root-fs and the two unset-resource checks with exit 1. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Kyverno CLI, A Policy Applied Both Ways

ansible-kyverno-cli

The kyverno CLI on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which applies a require-label policy offline: the unlabelled Pod fails, the labelled one passes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Lambda Function (Packaged & Wired)

aws-lambda

Lambda with execution role, log group, triggers, aliases, and zip/container packaging handled.

Live-testedAWSTerraform
Open Linkerd CLI, The Control Plane Rendered With No Cluster

ansible-linkerd

linkerd (edge channel) on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then has install --ignore-cluster render the control plane (at least three Deployments expected) and check --pre stop at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Linode Block Storage Volume

linode-volume

Attachable, resizable NVMe block volume with safe attach/detach lifecycle handling.

Static validated · Live test pendingLinodeTerraform
Open Linode CLI In A venv Of Its Own

ansible-linode-cli

The Linode CLI pinned in /opt/linode-cli, a virtual environment apart from the system Python, linked into the PATH. No package exists; pip into the system Python is the documented install. The live test runs pip check, calls the API with a token that is not one and expects Linode's 401, and asserts the system Python cannot import the package. Original role, live-tested on Rocky Linux 10.

Live-testedLinodeAnsible
Open Linode Cloud Firewall Baseline

linode-firewall

Opinionated stateful firewall with deny-by-default inbound, curated allow rules, and multi-device attachment.

Static validated · Live test pendingLinodeTerraform
Open Linode Compute Instance (production-ready)

linode-instance

Hardened Linode VM with cloud-init, disk encryption, reverse DNS, backups, and firewall attachment in one apply.

Static validated · Live test pendingLinodeTerraform
Open Linode DNS Zone & Records

linode-domain

Complete DNS zone with typed record management and sane TTL defaults on Linode's free DNS Manager.

Static validated · Live test pendingLinodeTerraform
Open Linode Kubernetes Engine Cluster

linode-lke-cluster

Production LKE cluster with autoscaling node pools, HA control plane, disk encryption, ACL, and optional Enterprise tier.

Static validated · Live test pendingLinodeTerraform
Open Linode Managed Database (MySQL/PostgreSQL)

linode-database

HA managed database cluster with allowlists, maintenance windows, and fork/restore support on the new Aiven platform.

Static validated · Live test pendingLinodeTerraform
Open Linode NodeBalancer Load Balancer

linode-nodebalancer

Managed L4/L7 load balancer with TLS termination, health checks, session stickiness, and UDP support.

Static validated · Live test pendingLinodeTerraform
Open Linode Object Storage Bucket

linode-object-storage

S3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.

Static validated · Live test pendingLinodeTerraform
Open Linode VPC with Subnets

linode-vpc

Isolated VPC network with labeled subnets ready for instances, LKE, and NodeBalancer backends.

Static validated · Live test pendingLinodeTerraform
Open Logic App (Consumption) Workflow

azure-logic-app

An Azure Logic App (Consumption) workflow with a built-in Recurrence trigger - serverless pay-per-execution automation with a system-assigned managed identity and inbound IP allowlists.

Live-testedAzureTerraform
Open Logs That Leave Over TLS, With The Collector Checked

ansible-rsyslog-forward

rsyslog ships logs in clear over port 514, which is what most examples do. This role configures the sending side with the gtls driver, the collector's CA and x509/name, so a host with a certificate from elsewhere in the estate cannot collect your logs. The live test watches a line arrive and reads the handshake. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Loki Single Binary, Retention On, Reporting Off

ansible-loki

Grafana Loki from the upstream release (sha256-verified) as a single-binary system service on loopback with filesystem storage, a TSDB index, retention the compactor enforces and usage reporting off, its configuration checked by loki -verify-config before it lands. The live test pushes one log line and queries it back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open MSK Serverless (Apache Kafka)

aws-msk

An MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.

Live-testedAWSTerraform
Open Macie Sensitive Data Discovery

aws-macie

Sensitive-data discovery for S3 with targeted classification jobs, sampling for surveying a large bucket first, and findings filters that archive an expected result with its reason. No scan-everything default: Macie bills per GB inspected.

Static validated · Live test pendingAWSTerraform
Open Mail Submission Ports That Refuse Plaintext

ansible-postfix-tls

An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Managed Instance Group (autoscaling, autohealing)

gcp-managed-instance-group

A zonal Managed Instance Group built from a hardened Shielded-VM instance template, private by default, with optional CPU autoscaling, autohealing, and zero-downtime rolling template updates.

Live-testedGoogle CloudTerraform
Open Managed Lustre with Blob Integration, Root Squash and Capacity on the SKU's Step

azure-managed-lustre

Azure Managed Lustre with the blob containers that make the data outlive the file system, root squash naming the clients that keep root, a customer-managed key through a user-assigned identity, and the capacity checked against the SKU's step before the plan. No blob integration, root on every client and the platform key are each accepted by name; the file system is zonal.

Static validated · Live test pendingAzureTerraform
Open Managed Microsoft AD Reachable Only from Named VPCs, in More than One Region

gcp-managed-ad

Managed Microsoft AD reachable only from the VPCs in authorized_networks, on a reserved /24 that cannot change later, with domain controllers in every region listed and deletion protection on. An empty network list, a single region and a deletable domain each have to be accepted by name; the setupadmin password is set with gcloud and never enters state.

Static validated · Live test pendingGoogle CloudTerraform
Open Managed Microsoft AD, Simple AD or AD Connector

aws-directory-service

A managed directory with security log forwarding and cross-account sharing. The admin password has no default and no example value anywhere in the module, and the README is explicit that Terraform state holds it regardless.

Static validated · Live test pendingAWSTerraform
Open Managed SFTP where a Rebuild Keeps Its Host Key

aws-transfer-family

SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.

Static validated · Live test pendingAWSTerraform
Open MariaDB That Ran Its Own Secure Installation

ansible-mariadb-server

MariaDB bound to loopback (the package listens everywhere), with the mariadb-secure-installation steps applied by the role: anonymous users, the test database and remote root gone, LOAD DATA LOCAL off, reverse DNS off. Provisions an application database and a user that can see nothing else. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Meilisearch, A Search Engine Proven By An Indexed Search

ansible-meilisearch

Meilisearch on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback in production mode behind a master key; the live test creates an index and documents, waits for the indexing task, searches and finds the one match, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open MemoryDB with a Real ACL, Not open-access

aws-memorydb

Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.

Static validated · Live test pendingAWSTerraform
Open Memorystore Redis/Valkey

gcp-memorystore

Private Memorystore instance or cluster (Redis or Valkey) with auth, TLS and maintenance policy on your VPC.

Live-testedGoogle CloudTerraform
Open Mimir Monolithic On Loopback, A Metric Written And Read Back

ansible-mimir

Grafana Mimir from the upstream release binary (sha256-verified) in monolithic mode as a hardened system service on loopback with filesystem storage, every ring member on loopback, usage reporting off. The live test pushes a gauge over OTLP, queries it back through the Prometheus API with its labels and sees an unknown metric answered empty. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Mosquitto That Asks Who You Are

ansible-mosquitto-broker

Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open MySQL Flexible Server

azure-mysql-flexible

Azure Database for MySQL Flexible Server with TLS required by default, correct delegated-subnet + private DNS zone ordering, an Entra administrator, databases, and cheapest-by-default Burstable sizing.

Live-testedAzureTerraform
Open MySQL HeatWave DB System

oci-mysql-heatwave

Managed MySQL with optional HeatWave analytics cluster, HA, backups, configuration and inbound replication channel.

Static validated · Live test pendingOracle CloudTerraform
Open NAT Gateways for an Existing VPC, One per Zone, with the Private Routes Written

aws-nat-gateway

NAT gateways for an existing VPC, one per availability zone with its own Elastic IP, and the private route tables routed through the gateway in the same zone. A single gateway for every zone pays cross-zone charges on every byte and loses egress with that zone; it has to be accepted by name. Private (no address) mode for transit paths; gateway_count says what bills by the hour.

Static validated · Live test pendingAWSTerraform
Open NATS CLI, A Context Saved And A Check That Says CRITICAL

ansible-nats

nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open NATS Server On Loopback, JetStream On, Round-Tripped

ansible-nats-server

NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open NFS And SMB Volumes That Keep Their Backups

aws-fsx-ontap

Amazon FSx for NetApp ONTAP: a file system, one storage virtual machine and its volumes. The provider defaults daily volume backups to OFF where the AWS API keeps 30 days, and AWS attaches the VPC's default security group when none is given. This module sets 30 days, builds the security group from AWS's port table per protocol, and writes throughput to the field that updates in place.

Static validated · Live test pendingAWSTerraform
Open NSQ, A Broker And Its Directory, Messages Counted

ansible-nsq

NSQ (SHA-256 pinned): nsqd and nsqlookupd as two hardened services from one release on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test publishes four messages, sees the topic count them with the channel holding the last, and asks the directory which broker holds the topic. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Network ACLs with the Return Rules They Need

aws-network-acl

Network ACLs are stateless, which is why most of them do not work: the reply to an allowed outbound connection is a new inbound packet nothing lets in. This generates the matching ephemeral-range rule for every TCP and UDP allow.

Static validated · Live test pendingAWSTerraform
Open Network Firewall with a Policy that Fails Closed

aws-network-firewall

Managed stateful firewall with Suricata rule groups, stateless pre-filters and logging. An empty policy drops rather than passes, and rules evaluate in strict order so "allow these, deny the rest" behaves the way it reads.

Static validated · Live test pendingAWSTerraform
Open Network Load Balancer (L4)

aws-nlb

A Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.

Live-testedAWSTerraform
Open Nginx (verified role)

ansible-nginx

Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Nomad CLI, SHA256SUMS Signed By HashiCorp

ansible-nomad-cli

nomad on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs nomad status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Nomad Pack, A Pack Scaffolded, Rendered And Described

ansible-nomad-pack

nomad-pack on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then scaffolds a pack, renders it with a variable override (the job name is read in the output) and lists its variables, all with no Nomad. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Nomad Single Server, A Variable Round-Tripped

ansible-nomad-server

HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback, an explicit advertise block (Nomad refuses to start without one) and its configuration checked by nomad config validate. The live test waits for a leader and round-trips a variable with nomad var. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Notation, A Signing Key And A Trust Store Made Offline

ansible-notation

notation on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has cert generate-test mint a key and certificate under a throwaway config home, then lists the trust store and the default key. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Notebook Sessions on Your Subnet that Bill Only When Meant To

oci-data-science

A notebook session with no subnet runs on Oracle's network with internet egress and no path to your VCN, and a session left ACTIVE bills its shape - a GPU, over a weekend - whether or not anyone is in it. Sessions attach to your subnet, the shape and storage are set on purpose, and the sessions that are billing from the moment of apply are listed in an output.

Static validated · Live test pendingOracle CloudTerraform
Open OCI CLI In A venv Of Its Own

ansible-oci-cli

The Oracle Cloud Infrastructure CLI pinned in /opt/oci-cli, a virtual environment apart from the system Python, linked into the PATH. No package exists; the documented installs are a script piped into bash or pip into the system Python. The live test runs pip check and an API call, and asserts the system Python cannot import the SDK. Original role, live-tested on Rocky Linux 10.

Live-testedOracle CloudAnsible
Open OCI Compute Instance (flex shapes)

oci-compute-instance

Opinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.

Static validated · Live test pendingOracle CloudTerraform
Open OCI IAM Foundation (compartments + policies)

oci-iam-foundation

Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.

Static validated · Live test pendingOracle CloudTerraform
Open OCI Network Load Balancer (L4)

oci-network-load-balancer

Low-latency pass-through NLB with TCP/UDP listeners, backend health checks and preserved client IPs.

Static validated · Live test pendingOracle CloudTerraform
Open OCI Registry, A Blob Pushed And Pulled

ansible-registry

The CNCF Distribution registry from the upstream release (sha256-verified) as a hardened system service on loopback with filesystem storage and deletion enabled, for a TLS proxy that authenticates. The live test walks the OCI protocol: starts an upload, puts a blob by digest, reads its headers back and deletes it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OCI VCN (hub-ready network foundation)

oci-vcn

Production VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.

Static validated · Live test pendingOracle CloudTerraform
Open OIDC Auth Whose Roles Admit the Claims You Name

vault-oidc-auth

An OIDC role with no bound claims admits every user of the identity provider; a role with no bound audience accepts tokens minted for other services; and the client secret lands in state. Bound claims expected with none accepted by name, an audience required, callbacks listed rather than assumed, token ceilings set, and the write-only secret path named for Terraform 1.11+.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open OKE Managed Kubernetes Cluster

oci-oke

Enhanced OKE cluster with managed + virtual node pools, private API endpoint, NSGs, addons and OIDC - flagship OCI workload platform.

Static validated · Live test pendingOracle CloudTerraform
Open OPA, A Real Policy Evaluated

ansible-opa

opa on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 OPA publishes, and re-checked with sha256sum -c by the live test, which then evaluates a one-rule Rego v1 policy against a one-line input with opa eval and expects the denial. The binary only; no opa server. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open ORAS CLI, Checked Against The Project's Checksums

ansible-oras

oras on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked by the live test, which then pushes a file as an OCI artifact into a layout on disk and pulls it back byte for byte, no registry needed. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OVHcloud CLI, Checked Against OVHcloud's Checksums

ansible-ovhcloud-cli

ovhcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in OVHcloud's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a login stops at 'ovhcloud login'. Original role, live-tested on Rocky Linux 10.

Live-testedOVHcloudAnsible
Open OVHcloud Managed Database

ovh-managed-database

Managed PG/MySQL/Kafka with users, IP restrictions, and private network egress.

Static validated · Live test pendingOVHcloudTerraform
Open OVHcloud Managed Kubernetes

ovh-managed-k8s

MKS cluster with node pools and private-network (vRack) attachment.

Static validated · Live test pendingOVHcloudTerraform
Open Object Storage Bucket

oci-object-storage-bucket

Bucket with versioning, lifecycle/auto-tiering, retention rules, replication and pre-authenticated request support.

Static validated · Live test pendingOracle CloudTerraform
Open Object Storage Reachable from Where You Say with a User, Policy and Key of Its Own

upcloud-object-storage

A service answers on the networks attached to it, and a public network makes the S3 endpoint an internet endpoint; a user has no access until a policy is attached and no key until one is created; and the service has no versioning and no lifecycle. Private by default with public by name, buckets, a user with the policy you name and one key, and outputs that say what is not available.

Static validated · Live test pendingUpCloudTerraform
Open Object Storage Whose Buckets Keep Versions and Can Lock

vultr-object-storage

A subscription is one S3 key pair with full rights over every bucket, written to state; versioning is off by default, so an overwrite is the end of the object; and object lock, once on, is on forever. The cluster looked up by hostname, versioning on for every bucket and off by name, lock per bucket and refused without versioning, and an output that says the keys are not scoped per bucket.

Static validated · Live test pendingVultrTerraform
Open One Certificate Authority Instead Of authorized_keys

ansible-ssh-ca

sshd can trust a CA and accept any certificate it signed, so access is granted by signing rather than by editing authorized_keys everywhere. The live test proves it four ways over a real connection: the matching certificate gets in, one for another principal does not, one that expired does not, and a key the CA never signed does not. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Only Images Somebody Vouched For Get to Run

gcp-binary-authorization

DRYRUN_AUDIT_LOG_ONLY admits the image and writes a line about it while the console shows the policy as configured. ALWAYS_ALLOW is the other way to have nothing: a valid, enforced policy that admits everything. Both have to be right, so one output reports over both.

Static validated · Live test pendingGoogle CloudTerraform
Open OpenBao Server With Integrated Storage, Initialised In The Lane

ansible-openbao

OpenBao (the MPL-licensed Vault fork) as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OpenSSH Hardened Where sshd Reads It First

ansible-ssh-hardening

An sshd drop-in numbered 01, so it is read before the 50-redhat.conf that asks for X11 forwarding: root login off, passwords off, MaxAuthTries 4, idle timeouts. The live test proves the policy with the daemon rather than the file: a password login refused, a key login accepted, root refused, and the banner delivered before authentication. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OpenSearch Domain that Refuses to Be Public

aws-opensearch

A VPC domain with fine-grained access control and the three encryption settings that cannot be added afterwards. Building a public endpoint takes an explicit opt-in, because a public domain with a permissive policy is how this service leaks databases.

Static validated · Live test pendingAWSTerraform
Open OpenSearch, One Node Proven By An Index And A Search

ansible-opensearch

OpenSearch 3 (sha512-verified min distribution, bundled JDK), one node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads the root document, indexes one document with a refresh, finds it by a search, deletes the index and checks the keystore belongs to the service; the release tree stays read-only. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OpenTelemetry Collector On Loopback, A Metric In And Out

ansible-otel-collector

The OpenTelemetry Collector (contrib) from the upstream release (sha256-verified) as a hardened system service on loopback: OTLP in, a Prometheus endpoint out, your whole configuration checked by the collector before it lands. The live test pushes a gauge over OTLP and reads it back from the Prometheus exporter with its labels and value. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OpenTofu, SHA256SUMS Signed By OpenTofu's Key

ansible-opentofu

tofu on EL 10 from the GitHub release. The role imports OpenTofu's OpenPGP key into a GnuPG home of its own, refuses a keyring whose fingerprint is not the pinned one, verifies the SHA256SUMS signature, and only then lets Ansible's get_url check the zip against that file. The live test re-verifies the signature and runs tofu init. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open OpenZFS File Storage That Is Not Exported to Every Client

aws-fsx-openzfs

Amazon FSx for OpenZFS. With no export set, AWS shares the root volume read-write to every client the network admits, and the Terraform provider turns automatic backups off where AWS keeps 30 days. This module writes the export to named networks, refuses a wildcard and no_root_squash, keeps 30 days of backups, opens the NFS ports AWS lists and requires route tables for Multi-AZ.

Static validated · Live test pendingAWSTerraform
Open Organizations, OUs and Service Control Policies

aws-organizations

The organization, its organizational units, member accounts and the service control policies attached to them. Root attachment is off by default, because an SCP sets the ceiling on what anybody may do - including the account root user who would have to undo it.

Static validated · Live test pendingAWSTerraform
Open PHP-FPM, A Pool On A Socket That Cannot Shell Out

ansible-php-fpm

php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Packer, SHA256SUMS Signed By HashiCorp

ansible-packer-cli

packer on EL 10 from releases.hashicorp.com, the SHA256SUMS signature verified against HashiCorp's key in a GnuPG home of its own, pinned by fingerprint, before get_url checks the zip against that file. Pinned; the live test re-verifies the signature and runs packer validate to its 'no config file' answer. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Password Aging That Reaches The Accounts A Host Already Has

ansible-login-defs

EL ships PASS_MAX_DAYS 99999, so no password expires, and INACTIVE -1 in a second file, so one that does expire still lets you in. This role sets both, then brings the accounts created before it into the policy, which login.defs alone never does. The live test creates an account first, records what it was given, and proves the change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Password Quality Scored At The Boundary

ansible-password-quality

A pwquality drop-in on EL 10 with the length, class and dictionary rules an auditor asks for. Nothing validates pwquality.conf, so the live test scores four passwords and reads why each was refused: a dictionary word by the dictionary check, a password one under the minimum by its length, the same at the minimum accepted, and a passphrase accepted. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Password Reuse, Refused By A Host That Remembers

ansible-pam-pwhistory

EL remembers nothing: pam_pwhistory is not in the authentication stack, the history file is empty, and a password can be put straight back. Measured, three changes, there and back. This role writes the policy, adds the module through authselect, and proves the refusal by attempting the reuse and reading the reason PAM gives for it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Pluto, A Deprecated apiVersion Found

ansible-pluto

pluto on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which writes an Ingress at extensions/v1beta1 and has pluto detect-files name the replacement and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open PocketBase On Loopback, A Collection Round-Tripped

ansible-pocketbase

PocketBase, the backend in one binary, from the upstream release (sha256-verified), a hardened system service on loopback, its data under one directory. The live test creates a superuser with PocketBase's own command, sees a wrong password refused, makes a collection and a record, reads it back, sees an anonymous read refused, deletes the collection. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Polaris, An Audit With Danger In It

ansible-polaris

polaris on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which audits a minimal Deployment from disk with --set-exit-code-on-danger and expects the danger items and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Postfix That Only Sends, And Only Encrypted

ansible-postfix-null-client

Postfix as a send-only relay: no local delivery (a stock install spools root's mail on the box), one smarthost, TLS required rather than opportunistic, SASL credentials in a root-only lmdb map, local recipients rewritten to a real mailbox. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open PostgreSQL Flexible Server

azure-postgresql-flexible

Flexible Server with HA option, private VNet delegation, Entra auth, firewall and tuned server parameters.

Live-testedAzureTerraform
Open PostgreSQL Server (EL)

ansible-postgresql

PostgreSQL server with guarded initdb, SCRAM-SHA-256 auth, managed conf.d drop-in, templated pg_hba, and app database + owner provisioning. Original, live-tested (Molecule/podman) role.

Live-testedMulti-cloud & platform-agnosticAnsible
Open PostgreSQL that Is Private, Standby-Backed, TLS-Only and Backed Up on Your Schedule

tencent-postgresql

The public endpoint is a switch that puts the instance one password from the internet; SSL is a separate resource nobody creates; a primary with no standby is downtime at the first zone failure; and deletion protection is off. Private unless accepted, SSL config created, a standby zone required unless one node is accepted, daily backups in your window with your retention, deletion protection on.

Static validated · Live test pendingTencent CloudTerraform
Open PowerDNS, A Zone It Answers For, From SQLite

ansible-powerdns

PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Privileged Roles that Are Eligible, Time-Boxed and Approved Into

azure-pim

Azure defaults for an activation policy require MFA and a justification and no approval, so an eligible Owner activates alone at 3am with the reason fix; and eligibility itself is permanent unless somebody sets an end date. Manages the role policy per scope with approval required for Owner-class roles, gives every eligible assignment an expiry, and time-boxes the active ones kept for break-glass.

Static validated · Live test pendingAzureTerraform
Open Production VPC (Multi-AZ)

aws-vpc

Battle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.

Live-testedAWSTerraform
Open Prometheus On Loopback, Retention Written Down

ansible-prometheus-server

Prometheus from the upstream release (EL 10 has no package), sha256-verified, on loopback: the binary listens everywhere and authenticates nobody. Retention time and size as explicit flags, lifecycle and admin endpoints off (the live test POSTs to both), prometheus.yml checked by the promtool it installs. Pairs with grafana-server and node-exporter. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Prometheus node_exporter (verified)

ansible-node-exporter

Official node_exporter release (pinned v1.11.1) with sha256 checksum-verified install, dedicated shell-less system user, and a systemd unit on :9100; live-tested for idempotence with a functional /metrics verification.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Pub/Sub Topics & Subscriptions

gcp-pubsub

Topics with schemas, push/pull/BigQuery subscriptions, dead-letter queues and retry policies preconfigured.

Live-testedGoogle CloudTerraform
Open Pushgateway, Pushes Persisted To Disk

ansible-pushgateway

Prometheus Pushgateway from the upstream release (sha256-verified) as a hardened system service on loopback with pushed metrics written to disk every five minutes, so a restart does not lose a batch job's last push. The live test pushes a metric, reads it back with its job label, deletes the job and reads it gone. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Qdrant, A Vector Search Engine Proven By A Nearest Neighbour

ansible-qdrant

Qdrant on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, HTTP only (gRPC off); the live test creates a collection, upserts two points with payloads, searches and gets the matching point back at score 1 with its payload. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open RDS Instance (PostgreSQL/MySQL)

aws-rds

Single-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.

Live-testedAWSTerraform
Open RDS PostgreSQL that Is Standby-Backed, TLS-Only, Encrypted and Backed Up

huawei-rds-postgresql

One availability zone is one node whose failure is downtime; ssl_enable defaults to false, so clients speak plain TCP; the data volume is encrypted only when a KMS key is given; and the backup window and retention are the platform's. Two zones (one by name), SSL on, a KMS key expected (none by name), minor versions auto-upgraded, daily backups in your window with your retention.

Static validated · Live test pendingHuawei CloudTerraform
Open RDS PostgreSQL that Is Whitelisted, Encrypted in Transit, Audited and Protected

alicloud-rds-postgresql

security_ips is the whole allow list and the console's first suggestion is 0.0.0.0/0; ssl_action defaults to Close, so clients speak plain TCP; the SQL audit log and connection logging are off; Basic edition is one node; and deletion protection is off. Ranges required (a /0 by name), SSL open, 180 days of audit log, connection logging on, a standby zone, deletion protection on.

Static validated · Live test pendingAlibaba CloudTerraform
Open Records and DNSSEC on an OVHcloud Zone You Already Have

ovh-dns-zone

Records and DNSSEC on an existing OVHcloud DNS zone, since OVH zones come with the domain or an order and cannot be created from a plain resource. Every record is in one map with MX and SRV priority written into the target as OVH expects, and DNSSEC is on; a domain registered elsewhere needs the DS record copied to its registrar.

Static validated · Live test pendingOVHcloudTerraform
Open Redshift Cluster (encrypted, private)

aws-redshift

A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.

Live-testedAWSTerraform
Open Rekor CLI, The Public Transparency Log Verified And Read

ansible-rekor

rekor-cli on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has loginfo verify rekor.sigstore.dev's signed tree head against the embedded root ('Verification Successful!'), fetches entry 1 as JSON, and sees a dead server refused. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Repositories that Are Declared, Private and Immutable

oci-container-registry

The registry creates a repository for any push to an unknown name by default - private, and unmanaged - and a tag can be overwritten unless the repository is immutable, so a deployment pinned to v1.4.2 runs whatever last claimed it. Manages the tenancy-wide create-on-push switch off, creates repositories immutable and private, and lists any that are public or mutable when that is accepted.

Static validated · Live test pendingOracle CloudTerraform
Open Resolver Endpoints, Forwarding, Query Logs and DNSSEC

aws-route53-resolver

Endpoints that carry DNS across the VPC boundary, with a precondition requiring addresses in two different subnets - the part the API does not check, and the reason a zone failure becomes every application failing at once.

Static validated · Live test pendingAWSTerraform
Open Resource Group + Naming/Tagging Baseline

azure-resource-group-baseline

Opinionated resource group factory with CAF-compliant naming, mandatory tags, locks and budget alert.

Live-testedAzureTerraform
Open Resource Shares that Stop at the Organization

aws-ram

A share, what is in it and who it reaches. External principals are off, so a mistyped account number is an error rather than a silent share with a stranger - and access ends when an account leaves the organization, which AWS defaults the other way.

Static validated · Live test pendingAWSTerraform
Open Route 53 Hosted Zone & Records

aws-route53

A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.

Live-testedAWSTerraform
Open SES v2 Sending Stack

aws-ses

An SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.

Live-testedAWSTerraform
Open SNS Topic with Subscriptions

aws-sns

SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.

Live-testedAWSTerraform
Open SOPS, Checked, And Not Phoning Home

ansible-sops

sops on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test. sops --version asks GitHub for newer releases unless told not to; the live test says not to, then decrypts a file that was never encrypted and expects 'sops metadata not found'. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open SQS Queue with DLQ

aws-sqs

SQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.

Live-testedAWSTerraform
Open SSH without a Bastion, a Public IP, or an Open Port

gcp-iap-tunnel

IAP TCP forwarding reaches an instance from one Google range after the user is authenticated and authorised, and a firewall rule that also admits 0.0.0.0/0 on port 22 has the bastion's problem back. The range is a literal, tunnel access is granted per instance rather than to every instance in the project, and OS Login is set so the SSH identity is the IAM identity rather than whoever holds a key.

Static validated · Live test pendingGoogle CloudTerraform
Open SSM Agent That rpm On EL 10 Cannot Verify, Verified

ansible-amazon-ssm-agent

The AWS Systems Manager Agent on EL 10, where rpm refuses the SSM signing key (a SHA-1 self-signature) and dnf fails its GPG check, so the usual answer is --nogpgcheck. This role verifies the detached signature with gpg against a pinned fingerprint first, pins the version (latest differs by region), and registers a hybrid activation once. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open SSM Parameter Store (map-driven)

aws-ssm-parameter-store

Map-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.

Live-testedAWSTerraform
Open Samba That Encrypts Every Session

ansible-samba-share

Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Scaleway CLI, Checked And Quiet

ansible-scaleway-cli

scw on EL 10 from the GitHub release, a bare binary refused by Ansible's get_url unless its SHA-256 is the one in Scaleway's SHA256SUMS, re-checked by the live test. The CLI sends usage telemetry unless told not to: the role exports SCW_SEND_TELEMETRY=false for every login shell. Pinned; an API call without credentials stops at the credentials. Original role, live-tested on Rocky Linux 10.

Live-testedScalewayAnsible
Open Scaleway Kapsule Cluster

scaleway-kapsule-cluster

Kapsule Kubernetes with pools, private network, and autoscaling/autoheal presets.

Static validated · Live test pendingScalewayTerraform
Open Scaleway Managed Database

scaleway-rdb-instance

RDB PostgreSQL/MySQL with HA, private-network endpoint, users, and ACLs.

Static validated · Live test pendingScalewayTerraform
Open Scaleway Serverless Container

scaleway-serverless-container

Container namespace, deployed container, custom domain, and registry wiring.

Static validated · Live test pendingScalewayTerraform
Open Schedules with a Scoped Role, a Retry Ceiling and a Dead-Letter Queue

aws-eventbridge-scheduler

The default retry policy tries for a day and then discards the run silently, so a target that was down never hears what it missed; the scheduler's role is the blast radius and a wide one lets a schedule do more than invoke; and a flexible time window turns 03:00 into sometime that hour. A dead-letter queue every schedule uses, a role allowing one action on the targets, exact times by default.

Static validated · Live test pendingAWSTerraform
Open SeaweedFS, Master, Volume, Filer And S3 On Loopback

ansible-seaweedfs

SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Secret Manager Secrets

gcp-secret-manager

Secrets with versions, replication policy, rotation schedules, expiry and accessor IAM.

Live-testedGoogle CloudTerraform
Open Secrets Manager Secret

aws-secrets-manager

Secrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.

Live-testedAWSTerraform
Open Secrets that Cannot Be Deleted in One Call and Versions that Expire

scaleway-secret-manager

protected defaults to false, so one API call deletes a secret and every version; an ephemeral policy that expires a version is the rotation deadline most teams do not have; and a value from a Terraform variable lands in state as well as the manager. Protection on and off by name, a ttl per secret, values optional so first versions can come from a pipeline, and the secrets terraform wrote named.

Static validated · Live test pendingScalewayTerraform
Open Secrets that Expire on a Date You Set

ovh-key-manager

A secret without an expiration is valid until somebody deletes it, which is the rotation nobody does; a payload from a Terraform variable lands in state; and the service has no flag that refuses deletion. An expiration expected per secret (none by name), values optional so payloads can come from a pipeline, and outputs naming what terraform wrote and what the service lacks.

Static validated · Live test pendingOVHcloudTerraform
Open Security Group with Rule Presets

aws-security-group

Security groups with named rule presets (https, postgres, redis...) using modern standalone rule resources.

Live-testedAWSTerraform
Open Security Hub with Chosen Standards

aws-security-hub

Posture management with standards named explicitly rather than defaulted on, cross-region finding aggregation, organization delegation, and suppression expressed as automation rules that keep the finding and the reason.

Static validated · Live test pendingAWSTerraform
Open Security Lake with Lifecycle Control

aws-security-lake

Organization security logs normalised to OCSF in S3, with the storage-class transitions that decide what it costs, optional replication, and subscribers whose external id is validated as the confused-deputy guard it is.

Static validated · Live test pendingAWSTerraform
Open Security Mail That Reaches Someone Awake

aws-account-contacts

The alternate contacts AWS uses when something is wrong with an account. Without a security contact, abuse reports and vulnerability notices go only to the root user's mailbox - what Security Hub's Account.1 and CIS v5.0.0 control 1.2 check for. The module refuses to run without one unless told to, and validates what the API accepts, which is not what the provider checks.

Static validated · Live test pendingAWSTerraform
Open Semgrep, A Local Rule, A Finding, No Phone Home

ansible-semgrep

semgrep on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a one-rule file against a matching module with metrics off and the version check off (exit 1) and against a clean one (exit 0); nothing is fetched from the registry. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Sending Mail that Receivers Trust, from Approved Senders

oci-email-delivery

A domain without DKIM sends mail that looks forged and lands in spam; without a custom return path, bounces go to Oracle's domain and DMARC alignment fails; and a From address that is not an approved sender is refused by the API. DKIM key created, return path created, senders listed and checked against the domain, and every DNS record to publish exported in one output.

Static validated · Live test pendingOracle CloudTerraform
Open Sentinel, A Policy That Passes, Fails And Tests

ansible-sentinel

sentinel on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then applies a policy with a passing value (Pass, exit 0) and a failing one (Fail with trace, exit 1), runs sentinel test (PASS) and has fmt -check flag an unformatted file. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Service Accounts & IAM Bindings

gcp-service-accounts-iam

Service accounts with least-privilege project/resource IAM and optional Workload Identity Federation for keyless CI/CD (GitHub Actions).

Live-testedGoogle CloudTerraform
Open Service Bus Namespace, Queues & Topics

azure-service-bus

An Azure Service Bus namespace with queues, topics and subscriptions on the Standard SKU - SAS local auth off (Entra ID + RBAC), TLS 1.2+ minimum, and dead-lettering of expired messages.

Live-testedAzureTerraform
Open Service Logs that Are Actually Being Written

oci-logging

Every OCI service log is off until somebody turns it on: a VCN records no flow log, a load balancer no access log, a bucket no read log. Each log here is one service, one resource, one category, created enabled; a log created with is_enabled = false appears in the list and records nothing, and has to be accepted by name. Retention is 30 days by default and the shortest is reported.

Static validated · Live test pendingOracle CloudTerraform
Open Shared VPC where Attached Projects Can Actually Use a Subnet

gcp-shared-vpc

Attaching a service project is the visible half: its instances land in a shared subnet only when the creating principal holds networkUser on that subnet, and for GKE, Cloud Run or Dataflow that principal is the service agent, not a person. Takes the per-subnet grants with the attachments, refuses a project attached with none, and adds the host-level grant GKE needs.

Static validated · Live test pendingGoogle CloudTerraform
Open Shell Access with No Bastion, and a Transcript

aws-ssm-session-manager

Session Manager works with no configuration and records nothing: CloudTrail holds StartSession, not the commands. This builds the session document that turns logging on, and refuses to build one with no destination unless you say so.

Static validated · Live test pendingAWSTerraform
Open Shield Advanced that Blocks Rather than Counts

aws-shield

Protections, protection groups, response-team access and the automatic layer-7 response. That response can be enabled and do nothing: COUNT labels the request and lets it through, so this defaults to BLOCK and names the counting ones.

Static validated · Live test pendingAWSTerraform
Open Site-to-Site VPN with Modern Crypto

aws-site-to-site-vpn

Customer gateway, IPsec connection and routes, attached to a VPN gateway or a Transit Gateway. IKEv2 only, DH group 14 and above, AES-256 and SHA-2 - the API still permits DH 2, AES-128 and SHA-1.

Static validated · Live test pendingAWSTerraform
Open Skaffold, A Config Upgraded Across Schema Versions Offline

ansible-skaffold

skaffold on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has skaffold fix upgrade a v2beta29 config to the current schema, turns metrics off and reads the config back; the update check is off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Slot Reservations with a Ceiling, Assigned to the Projects that Use Them

gcp-bigquery-reservation

A reservation with capacity and no assignment bills for slots nobody can run a query on while every query keeps paying on-demand; autoscale without a ceiling in mind is on-demand pricing with a subscription on top. Assignments come with the reservation and are refused when empty, baseline and autoscale slots are both explicit, and the most the reservation can bill for at once is an output.

Static validated · Live test pendingGoogle CloudTerraform
Open Sonobuoy, A Conformance Run Rendered, Not Run

ansible-sonobuoy

sonobuoy on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has gen render a conformance run for Kubernetes 1.32 (the conformance image and at least five resources expected) and gen plugin render a plugin definition, offline. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Step Functions State Machine

aws-step-functions

A Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.

Live-testedAWSTerraform
Open Streamed Applications That Do Not Leak Data by Default

aws-workspaces-applications

Amazon WorkSpaces Applications, formerly AppStream 2.0. AWS enables every session action by default, including copying out, file download and local printing, and never disconnects idle users. This module sets all eight actions with the outbound ones off, a 15-minute idle timeout and no default internet access, and can keep streaming on an interface endpoint.

Static validated · Live test pendingAWSTerraform
Open SurrealDB, A Record Written And Read Back

ansible-surrealdb

SurrealDB (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous query and a wrong password refused, defines a namespace and a database, creates a record and reads it back, and checks the version endpoint; the root credentials live in the unit environment. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Syft, Checked Against The Published Checksums

ansible-syft

syft on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs a real SBOM scan of an empty directory and expects 'No packages discovered'. Anchore also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open TFLint, Checked Against The Published Checksums

ansible-tflint

tflint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then lints a one-resource module with no required_providers and expects the bundled rule to say so. Provider rulesets are plugins, per repository, not this role. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Tags that Are Bound to Something

gcp-resource-tags

Tag keys and values are definitions; conditional IAM, organisation policies and firewall rules read bindings, and a tag bound to nothing governs nothing while appearing fully defined. Bindings come with the keys - to folders, so every project beneath inherits - and the values that attach nowhere are listed in an output, along with the namespaced names conditions need.

Static validated · Live test pendingGoogle CloudTerraform
Open Tags that Are Required, Validated and Tracked

oci-tag-namespace

A tag default with is_required = false applies a value silently and lets anyone overwrite or blank it; required is the only enforcement OCI tagging has, and a required free-text tag enforces presence and nothing about meaning. Every default is required and validated against an allowed list unless accepted otherwise; the ten cost-tracking slots are counted; retirement is the only delete that works.

Static validated · Live test pendingOracle CloudTerraform
Open Task, A Taskfile Run

ansible-task

task (go-task) on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in task_checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-task Taskfile and runs it, expecting the task's output. Shell completions ship in the tarball and are not installed. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Tekton CLI, Run To The Point It Needs A Cluster

ansible-tkn

tkn on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs tkn pipeline list with no kubeconfig and expects 'no configuration has been provided'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Telegraf, A Metrics Agent Proven By A Metric Through It

ansible-telegraf

Telegraf on EL 10 from the vendor's release, pinned by the SHA-256 in InfluxData's release notes, as a hardened systemd service on loopback; the live test writes line protocol to the HTTP input and reads the metric from the Prometheus output; a malformed write is refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Telemetry that Is Not Silently Thrown Away

azure-application-insights

When the daily cap is hit everything after it is discarded until midnight and the dashboard goes flat, and the one email that says so has its own switch. Ingestion sampling stacks on the SDK's sampling and the metrics rescale. Both are refused without being named, and availability tests are created with the alerts that make an outage reach a person rather than a chart.

Static validated · Live test pendingAzureTerraform
Open Tempo Single Binary, A Trace Stored And Found

ansible-tempo

Grafana Tempo from the upstream release (sha256-verified) as a single-binary hardened system service on loopback with local block storage, an OTLP/HTTP receiver, a block retention written down and usage reporting off. The live test sends one span over OTLP and reads the trace back by id with its service.name. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Tencent Cloud CLI In A venv Of Its Own

ansible-tccli

The Tencent Cloud CLI (tccli) pinned in /opt/tccli, a virtual environment apart from the system Python. No package exists; pip into the system Python is the documented install. The live test runs pip check, calls the API with a SecretId that is not one and expects Tencent's AuthFailure.SecretIdNotFound, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

Live-testedTencent CloudAnsible
Open Tencent Cloud VPC Foundation

tencent-vpc-foundation

VPC with subnets, route tables, NAT, and security groups across AZs.

Static validated · Live test pendingTencent CloudTerraform
Open Tencent TKE Cluster

tencent-tke-cluster

Managed TKE Kubernetes with node pools and VPC-CNI networking.

Static validated · Live test pendingTencent CloudTerraform
Open Terraform CLI, SHA256SUMS Signed By HashiCorp

ansible-terraform-cli

terraform on EL 10 from releases.hashicorp.com. HashiCorp's security key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again. BSL-licensed since 1.6; opentofu in this catalogue is the MPL alternative. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Terragrunt, Checked Against Gruntwork's Checksums

ansible-terragrunt-cli

terragrunt on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Gruntwork's SHA256SUMS, and re-checked with sha256sum -c by the live test. The asset is the bare binary; the checksum file covers every build. Needs a tofu or terraform in the PATH; pair it with opentofu or terraform-cli. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Terramate, A Stack Created, Listed And Generated

ansible-terramate

terramate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then makes a git repository, has terramate create a stack, list it from another directory and generate a file from a generate_hcl block, read back. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Terrascan, A Public Bucket Found, Exit Code 3

ansible-terrascan

terrascan on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then fetches the policy set once at install and scans a public-read bucket, expecting 'Violated Policies', exit 3 and allUsersReadAccess in the JSON. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open The Activity Log Exported Before Azure Forgets It, All Eight Categories

azure-activity-log

The subscription's Activity Log exported to a Log Analytics workspace, a storage account and/or an Event Hub, because Azure keeps it for ninety days and then forgets. All eight categories go; dropping Administrative, Security or Policy, the three an investigation asks for, is accepted by name. The workspace's retention is the workspace's setting; the years live in the storage account.

Static validated · Live test pendingAzureTerraform
Open The Addresses Google Actually Writes To

gcp-essential-contacts

Without Essential Contacts, security notices, suspension warnings, billing problems and API shutdowns go to whoever holds Owner - a service account and an alias nobody reads - and the list is empty by default. Contacts per category, with a refusal when any category is left uncovered and an output naming the ones that still fall through to the Owner path.

Static validated · Live test pendingGoogle CloudTerraform
Open The App Engine Application: One per Project, Forever

gcp-app-engine

The application cannot be deleted and its region cannot be changed - destroy removes it from state and nothing else - and the region pins Firestore for the project. Without IAP every service is public on its appspot hostname. The permanent region must be accepted by name, IAP fronts every service unless public is stated, and a disabled serving status is a choice rather than an accident.

Static validated · Live test pendingGoogle CloudTerraform
Open The CTS System Tracker Configured: Signed Files, Your Key, Your Bucket

huawei-cts

The Cloud Trace Service system tracker (one per region, adopted rather than duplicated) delivering every management event to an OBS bucket you own, each file signed so tampering is detectable, gzip-compressed, sorted by service, encrypted with your KMS key (the bucket default by name), and also sent to LTS for queries. Excluding services from the trace is accepted by name.

Static validated · Live test pendingHuawei CloudTerraform
Open The Edge Firewall on a Public IP, Enabled, Ending in a Deny

ovh-ip-firewall

Every OVH public IP has an edge firewall that is disabled until enabled, so rules written to it filter nothing; twenty ordered rules where the first match wins and a list without a deny permits what it does not mention; and SSH from anywhere is the first rule offered. Enabled, your permits in sequence with a deny last, SSH from anywhere refused unless accepted.

Static validated · Live test pendingOVHcloudTerraform
Open The One Peering Where the Routes Are Programmed for You, and What That Costs You Instead

do-vpc-peering

A peering between two DigitalOcean VPCs. DigitalOcean programmes the routes on both sides once the peering is ACTIVE, which is why this module takes no route table lists and every other module in this hub does. Overlapping IP ranges are refused at apply, and there is no transit product, so a fourth network means three more peerings.

Static validated · Live test pendingDigitalOceanTerraform
Open The Provider Side of PrivateLink, Not Open to Everyone

aws-privatelink-service

An endpoint service, who may attach and the private DNS it answers on. A wildcard principal offers the service to every AWS account, so the module refuses it unless said out loud - and warns that zone names differ per account.

Static validated · Live test pendingAWSTerraform
Open The Rule that Wins over Every Allow

gcp-iam-deny-policy

A deny policy is evaluated before any allow and stops the request whatever roles the caller holds, Owner included - the only way to say nobody deletes the audit bucket and mean it. public:all with the break-glass group excepted is the shape; a rule with no exceptions locks out break-glass too and says so; a rule conditioned on a tag denies nothing until the tag is attached, and is counted.

Static validated · Live test pendingGoogle CloudTerraform
Open The System Crypto Policy, Proven To Govern The Handshake

ansible-crypto-policy

One EL 10 setting that decides what OpenSSL, GnuTLS, NSS, OpenSSH and Java will negotiate, applied only when it differs and read back from both files that record it. The live test runs one TLS 1.2 handshake three times, under the configured policy, under FUTURE, and under the policy again, so the refusal in the middle is the policy's doing. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open The Zone Settings that Make the Padlock Mean Something

cloudflare-zone-hardening

ssl = flexible encrypts the visitor's half and speaks plain HTTP to the origin while showing a padlock; DNSSEC is off until turned on at Cloudflare and again at the registrar; and TLS 1.0, HTTP without redirect and no HSTS are the defaults. Strict SSL with weaker modes accepted by name, TLS 1.2 minimum, HTTPS forced, HSTS (preload by name), DNSSEC on with the DS record exposed.

Static validated · Live test pendingCloudflareTerraform
Open The dnf Signature Check That Is Off By Default

ansible-dnf-security

dnf checks the signature on a package it downloads and not on one you hand it: localpkg_gpgcheck is absent from dnf.conf and defaults to off, and so is repo_gpgcheck. This role sets both and proves each by what it prevents, refusing an unsigned package and an unsigned repository it builds, then checking the distribution's repositories still verify. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Tracing That Samples What You Asked For

aws-xray

AWS X-Ray sampling rules, trace groups and trace encryption. Sampling rates are percentages here, as in the console: the API takes a fraction and the provider validates nothing, so a rate of 5 means 500 percent. Groups get Insights on, because a group without it is a saved search. Encryption is an account setting whose provider delete does nothing, so the module can leave it alone.

Static validated · Live test pendingAWSTerraform
Open Transit Gateway Hub with Explicit Routing

aws-transit-gateway

Hub-and-spoke Transit Gateway with its own route tables, VPC attachments, static and blackhole routes, and RAM sharing. Default route table association and propagation are off, so an attachment joins a routing domain because you said so rather than by default.

Static validated · Live test pendingAWSTerraform
Open Transit Keys that Rotate and Cannot Be Deleted or Exported

vault-transit

A Transit key never rotates by itself, so the key from day one encrypts everything for the life of the mount; deletion_allowed takes every ciphertext with the key; exportable means the material has left Vault; and min_decryption_version left at 1 keeps every retired version alive. Rotation every 90 days, deletion and export refused unless accepted by name, the retirement version taken.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open Trivy, Checked Against The Published Checksums

ansible-trivy

trivy on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Aqua's checksums file, and re-checked with sha256sum -c by the live test, which then runs a license scan of /etc, the one scanner that needs no database, and expects the report. The vulnerability database is fetched on first use, not by the role. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open TruffleHog, A Planted Key Found, A Clean Tree Clean

ansible-trufflehog

trufflehog on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which plants an AWS key, sees it reported and --fail exit 183, and sees a clean tree exit 0. No verification calls, no self-update. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Typesense, A Search Engine Proven By An Indexed Search

ansible-typesense

Typesense on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, the Raft peering port on loopback too; the live test creates a collection, indexes a document, searches and finds it, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Unattended Updates That Are Actually Applied

ansible-dnf-automatic

dnf-automatic with apply_updates on: the package downloads updates daily and installs none, and enables no timer. This role installs security advisories on the one timer that reads the configuration, switches the other three off so nothing runs twice, staggers a fleet, and leaves the reboot policy an explicit choice. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open UpCloud CLI, Checked Against UpCloud's Checksums

ansible-upcloud-cli

upctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in UpCloud's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without credentials stops at 'user credentials not found'. Original role, live-tested on Rocky Linux 10.

Live-testedUpCloudAnsible
Open UpCloud Managed Database

upcloud-managed-database

Managed PG/MySQL with properties tuning, users, and logical DBs.

Static validated · Live test pendingUpCloudTerraform
Open UpCloud Server Stack

upcloud-server-stack

Servers on SDN private network with storage, router, and firewall rules.

Static validated · Live test pendingUpCloudTerraform
Open Uptime Checks That Page Someone When More Than One Probe Fails

azure-uptime-check

Application Insights Standard tests with the metric alert that makes them tell somebody. Microsoft says a test without an alert rule only notifies the portal, recommends five locations and alerting at locations minus two, and retires URL ping tests on 30 September 2026. The module follows all three, checks certificate lifetime, and lets content, not only a 200, decide what up means.

Static validated · Live test pendingAzureTerraform
Open Uptime Monitors that Probe from Three Places and Feed an Alarm

oci-health-checks

A monitor can be created disabled and probes nothing; one vantage point reports the site down when that location is; and a monitor is a metric, not an alarm - nothing pages until Monitoring reads it. Enabled monitors over HTTPS from three regions by default, and the MQL query each one needs in an alarm exported for the oci-monitoring-alarms module.

Static validated · Live test pendingOracle CloudTerraform
Open User-Assigned Managed Identities

azure-managed-identity

A map-driven module creating one or many user-assigned managed identities, each with optional workload identity federation (OIDC) and least-privilege RBAC role assignments - no secrets to rotate.

Live-testedAzureTerraform
Open VCN Flow Logs per Subnet, All Traffic, with Retention Past the Default Month

oci-vcn-flow-logs

VCN flow logs for the subnets you list, since OCI logs per subnet and a subnet added later has none: a log per subnet in a log group created or given, category all rather than reject, ninety days of retention rather than the thirty-day default, and the subnet map as the list to update. Flow logs are the largest log in a tenancy; the map is also the bill.

Static validated · Live test pendingOracle CloudTerraform
Open VPC Endpoints (Gateway + PrivateLink)

aws-vpc-endpoints

Free gateway endpoints for S3 and DynamoDB, interface endpoints for everything else, and a security group that opens 443 to the VPC rather than the world. Interface endpoints are listed explicitly because each bills per hour per availability zone.

Static validated · Live test pendingAWSTerraform
Open VPC Flow Logs to a Cloud Log Service Topic, All Traffic, with the Retention You Choose

tencent-vpc-flow-logs

Flow logs for a VPC, subnet, interface, CCN, NAT or direct connect gateway written into a CLS logset and topic the module creates with the retention you choose, ALL traffic rather than only what was accepted. A vpc_id is required for every resource type except CCN, and the module refuses the wrong pair rather than letting the API do it at apply time.

Static validated · Live test pendingTencent CloudTerraform
Open VPC Flow Logs to a Log Service Logstore, All Traffic, at One Minute, with Retention

alicloud-vpc-flow-logs

Flow logs for a VPC, vSwitch or elastic network interface written into a Log Service project and logstore the module creates with the retention you choose, all traffic rather than only what was allowed, at one-minute resolution rather than ten, and your KMS key on the logstore if you hold one. A narrower capture has to be accepted by name.

Static validated · Live test pendingAlibaba CloudTerraform
Open VPC Flow Logs to a Log Tank Service Stream, All Traffic, VPC-Wide Rather Than per Port

huawei-vpc-flow-logs

Flow logs for a VPC, subnet or port written into an LTS log group and stream the module creates with the retention you choose, all traffic rather than only what was accepted, and VPC-wide rather than the per-port capture that quietly leaves most traffic unrecorded. A flow log that exists but is disabled records nothing; disabling it has to be accepted by name.

Static validated · Live test pendingHuawei CloudTerraform
Open VPC Peering in Both Directions with the Routes Stated

gcp-vpc-peering

A peering is two resources or it is nothing - INACTIVE until both halves exist - and custom routes learned from a VPN or Interconnect cross only when one side exports and the other imports, so a spoke that forgot to import has an ACTIVE peering and a hub it cannot reach through. Both halves created, both directions of route exchange set explicitly, and an output that says it is not transitive.

Static validated · Live test pendingGoogle CloudTerraform
Open VPC Public Gateways per Zone with the Subnets Attached

ibm-public-gateway

IBM Cloud VPC public gateways, one per zone you list because a gateway serves its own zone only, with the subnets in the map attached to the gateway of their zone (a gateway with no subnet forwards nothing) and a reserved floating IP per zone when you pass one so the egress address survives recreation. gateway_count says what bills by the hour.

Static validated · Live test pendingIBM CloudTerraform
Open Valkey With A Password, A Limit And A Log

ansible-valkey-server

Valkey, the Redis successor EL 10 ships in place of a redis package that no longer exists. The package sets no password, no maxmemory and no append-only log; this role sets all three, on loopback, with the drop-in given the last word over the package configuration. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Vault CLI, SHA256SUMS Signed By HashiCorp

ansible-vault-cli

vault on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs vault status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Vault Policies & Auth

vault-policies

Vault policies, auth backends, and secret engine configuration as code.

Static validated · Live test pendingMulti-cloud & platform-agnosticTerraform
Open Vault Server With Integrated Storage, Initialised In The Lane

ansible-vault-server

HashiCorp Vault as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Vault, Keys & Secrets

oci-vault-kms

KMS vault with HSM/software master keys, key rotation and secret lifecycle management for app credentials.

Static validated · Live test pendingOracle CloudTerraform
Open Vector, A Data Pipeline Proven By A Line Through It

ansible-vector

Vector on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback, its configuration checked by vector validate before it lands; the live test appends a line to the file source and reads it out of the JSON file sink. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Velero CLI, Checked Against The Published Checksums

ansible-velero-cli

The velero client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's CHECKSUM file, and re-checked with sha256sum -c by the live test, which then runs velero backup get with no kubeconfig and expects 'no configuration has been provided'. The server is a per-cluster install, not this role. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Verified Access (VPN-less Application Access)

aws-verified-access

Per-request access to internal applications evaluated against identity and device posture, with Cedar policy groups, endpoints and logging that records which identity and posture produced each decision.

Static validated · Live test pendingAWSTerraform
Open Vertex AI Endpoint

gcp-vertex-ai

A Vertex AI Endpoint for online prediction with optional CMEK, optional Private Service Access networking and request/response logging - model deployment left to you, so it stands up for cents.

Live-testedGoogle CloudTerraform
Open VictoriaMetrics On Loopback, Retention Written Down

ansible-victoria-metrics

VictoriaMetrics single-node from the upstream release (sha256-verified) as a hardened system service on loopback with an explicit retention period in the unit. The live test imports one sample through the Prometheus import API, flushes, and queries it back with PromQL, stamped two minutes in the past because queries do not see points younger than the latency offset. Live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Virtual Desktops Where Users Are Not Local Administrators

aws-workspaces

Amazon WorkSpaces Personal with a registered directory, an IP access group and encrypted desktops. AWS makes every user a local administrator by default and can only encrypt a WorkSpace at launch, so admin rights are off and a KMS key is required. It also says the IP group limits streaming but not API actions like rebuild, and only named client types may connect.

Static validated · Live test pendingAWSTerraform
Open Vulnerability Scanning that Is Scanning Something

oci-vulnerability-scanning

scan_level = NONE is legal for both the agent scan and the port scan, so a recipe with both at NONE runs on schedule, updates its last-run time, and finds nothing because it looked for nothing. A recipe is not a target either: one with no target scans no instance. Refuses a recipe that scans for nothing and always creates the target with it.

Static validated · Live test pendingOracle CloudTerraform
Open Vultr CLI, Checked Against Vultr's Checksums

ansible-vultr-cli

vultr-cli on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Vultr's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at VULTR_API_KEY. Original role, live-tested on Rocky Linux 10.

Live-testedVultrAnsible
Open Vultr Compute Stack

vultr-compute-stack

Instances with VPC, firewall, block storage, and reserved IP.

Static validated · Live test pendingVultrTerraform
Open Vultr VKE Cluster

vultr-vke-cluster

VKE Kubernetes with node pools, VPC, and firewall in one module.

Static validated · Live test pendingVultrTerraform
Open WAF 3.0 in Front of a Domain: HTTPS Only, TLS 1.2+, the Origin over HTTPS

alicloud-waf

WAF 3.0 in front of a domain on the pay-as-you-go instance the account has (adopted, not purchased), listening on HTTPS only with your certificate (plain HTTP by name), TLS 1.2 and 1.3 with a modern cipher suite, HTTP/2 and IPv6, the client address trusted from the first X-Forwarded-For hop, and origins reached over HTTPS with SNI, keepalive and retries.

Static validated · Live test pendingAlibaba CloudTerraform
Open WAFv2 Web ACL (managed rules + rate limit)

aws-waf

A WAFv2 web ACL (REGIONAL or CLOUDFRONT) with a default-allow posture, configurable AWS managed rule groups blocking by default, and a rate-based rule that throttles abusive IPs.

Live-testedAWSTerraform
Open Who May Schedule Work, And The Crontabs That Outlive The Answer

ansible-cron-access

cronie ships an empty cron.deny and no cron.allow, so every account may schedule work, and at is the same. This role writes both allow files and clears the spools of accounts that may no longer use them, because the access check is in the crontab command: a crontab installed earlier keeps running. The live test watches one run, then stop. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open Windows File Shares That Record Who Opened What

aws-fsx-windows

Amazon FSx for Windows File Server joined to AWS Managed Microsoft AD. The provider leaves file and share access auditing disabled and keeps 7 days of backups where the API keeps 30; this module audits both to CloudWatch Logs for a year, keeps 30 days with tags copied, and builds the security group from AWS's port table, with remote PowerShell closed by default.

Static validated · Live test pendingAWSTerraform
Open Yor, A Resource Tagged, Read Back, Left Alone The Second Time

ansible-yor

yor on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has yor tag add yor_trace and yor_name to a Terraform resource, reads the file back, and runs it again expecting zero updated resources; telemetry off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open access.conf, In The Stack And Proven With PAM Itself

ansible-pam-access

EL ships /etc/security/access.conf with no active rule and pam_access is not in the stack to read it, so every account is admitted from anywhere. This role writes the policy, adds the module through authselect, and refuses to write a rule set that would lock out the account running it. The live test asks PAM, with the origin set. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open actionlint, A Typo In An Expression Caught

ansible-actionlint

actionlint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then writes a workflow reading github.evnt and expects actionlint to say the property is not defined. shellcheck and pyflakes are optional and not installed. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open age, A Round Trip And A Wrong Key Refused

ansible-age

age and age-keygen on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then makes two identities, encrypts to one, decrypts with it, and sees the other refused; the ciphertext carries the age-encryption.org/v1 header. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open ansible-lint In A venv Of Its Own

ansible-ansible-lint

ansible-lint pinned in /opt/ansible-lint, a virtual environment with its own ansible-core, apart from the system Python and the host's Ansible. The live test runs pip check, lints an unnamed play offline and expects name[play] among the findings, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open apache_exporter, A Real mod_status Seen Up And Down

ansible-apache-exporter

apache_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up httpd with server-status on loopback as a fixture, sees apache_up 1 with the worker gauges, stops httpd and sees apache_up 0. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open aws-iam-authenticator, Run To Its First AWS Call

ansible-aws-iam-authenticator

aws-iam-authenticator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs token -i with no credentials and the metadata service disabled and expects it to stop at 'get credentials'. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open bind_exporter, A Query Counted Through BIND's Statistics Channel

ansible-bind-exporter

bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open cfn-lint, One Error Found, One Clean Pass

ansible-cfn-lint

cfn-lint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a template with a property the S3 bucket schema lacks (E3002, exit 2) and a clean one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open chamber, Run To Its First SSM Call, And Through The Null Backend

ansible-chamber

chamber on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs list with no credentials and the metadata service off, expecting 'no EC2 IMDS role found', and exercises the null backend (a list answered, a read refused). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open chrony With NTS, Time Nobody On The Path Can Move

ansible-chrony-nts

chrony on EL 10 taking time over NTS (RFC 8915), so every measurement is authenticated and the NTP listener is closed. The live test waits for an NTS source to be selected, restarts chronyd to make it dump its NTS cookies and finds them, checks the daemon is not controlling a clock that is not its own, and asserts nothing listens on UDP 123. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open consul-template, Rendered Offline, Stopped At Consul's Door

ansible-consul-template

consul-template on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then renders env and file templates with -once (to stdout, then to disk, read back) and runs a key template against a dead Consul with retries off, to 'connection refused'. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open cosign, Checked Against The Published Checksums

ansible-cosign

cosign on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Sigstore's cosign_checksums.txt, and re-checked with sha256sum -c by the live test, which then asks cosign to verify a blob with a key that does not exist and expects it to stop at loading the key. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open crane, An Image Built Offline, A Registry Asked

ansible-crane

crane on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then builds an image tarball from one layer with append --oci-empty-base, lists its manifest.json, and has crane ls reach a registry on a dead port (connection refused). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open detect-secrets, A Planted Key Found By The Scan, Refused By The Hook

ansible-detect-secrets

detect-secrets on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a file with an AWS-shaped key (reported as AWS Access Key), has the commit hook refuse it (exit 1) and pass a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open dive, An Image Analysed With No Daemon

ansible-dive

dive on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a one-layer image in docker-archive form and has dive --ci analyse it (PASS) and export the analysis as JSON, asserting the layer and the file in it. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open doctl, Checked Against DigitalOcean's Checksums

ansible-doctl

doctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in DigitalOcean's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a token stops at 'access token is required'. Original role, live-tested on Rocky Linux 10.

Live-testedDigitalOceanAnsible
Open eksctl, Run To Its First AWS Call

ansible-eksctl

eksctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs eksctl get cluster with no credentials and expects it to stop at 'get credentials'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open elasticsearch_exporter, A Real OpenSearch Node And A Document Counted

ansible-elasticsearch-exporter

elasticsearch_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up an OpenSearch node first (the exporter holds its listener while its target does not answer), sees the cluster health up and green, indexes one document and reads it counted for the index with the node's version. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open etcd Single Member, Compaction On, Data Dir 0700

ansible-etcd

etcd from the upstream release (sha256-verified) as a single-member hardened system service on loopback with hourly auto-compaction and a data directory only the service can read; etcdctl and etcdutl are installed beside it. The live test writes a key with etcdctl, reads it back, checks the member's health and deletes the key. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open fail2ban, A Ban That Exists In The Kernel

ansible-fail2ban

fail2ban from EPEL on EL 10, banning into nftables, with the jails and the server settings as .local files beside the package's own. The live test drives a jail past its limit and reads the ban out of nft rather than out of a status page, unbans it and reads the rule's absence, and checks that the same burst from an address in ignoreip is never banned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open flyctl, Checked, And Not Updating Itself

ansible-flyctl

flyctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Fly.io's checksum file, re-checked by the live test. flyctl replaces its own binary unless told not to: the role exports FLY_NO_UPDATE_CHECK=1 for every login shell. Pinned; an API call without a token stops at 'no access token available'. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open gator, A Gatekeeper Policy Evaluated With No Cluster

ansible-gator

gator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a ConstraintTemplate, a constraint requiring an owner label and two namespaces, and has gator test report the violation (exit 1) and pass the labelled one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open graphite_exporter, Graphite Samples That Became Metrics

ansible-graphite-exporter

graphite_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends plaintext samples over TCP and UDP and reads them back from /metrics with the dotted names flattened. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open hadolint, A Dockerfile Linted

ansible-hadolint

hadolint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which lints a two-line Dockerfile with four things wrong and expects DL3008 among the findings and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open hcledit, An HCL Attribute Read, Set And Read Back

ansible-hcledit

hcledit on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then reads a resource's bucket attribute, sets it in place, reads the file back with the neighbouring block untouched, and lists the blocks. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open istioctl, Checked, And Not Waiting For A Cluster

ansible-istioctl

istioctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Istio's per-asset .sha256, re-checked by the live test against the file's first field (one space, which sha256sum -c refuses). istioctl version waits for a cluster unless told --remote=false; the live test says so, then runs x precheck to the refused connection. Live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open jq, Upstream And Checked Against The Published Checksums

ansible-jq

jq on EL 10 from the project's GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in sha256sum.txt, and re-checked with sha256sum -c by the live test, which then runs a filter and expects its result. The distribution's jq trails upstream by a major series; this one is pinned and installed ahead of it in the PATH. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open json_exporter, JSONPath Over A Real Endpoint

ansible-json-exporter

json_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test serves a JSON document on loopback as a fixture and scrapes it through the shipped module into a scalar and a labelled object metric; a dead target is a 503. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open just, A Recipe Run

ansible-just

just on EL 10 from the GitHub release (the static musl build), refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which writes a justfile, runs a recipe to its echo and lists the recipes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open k9s, Checked Against The Published Checksums

ansible-k9s

k9s on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.sha256, and re-checked with sha256sum -c by the live test. A terminal UI needs a kubeconfig to show anything, so the live test uses k9s version and k9s info, which print the version and the per-user config paths. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kafka_exporter, A Real KRaft Broker And An Offset That Moved

ansible-kafka-exporter

kafka_exporter (SHA-256 pinned per architecture) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up a KRaft broker first (the exporter exits without one), sees kafka_brokers 1, creates a topic, produces three messages and reads the partition's offset at 3. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open keepalived, An Address That Moves, And Is Watched Moving

ansible-keepalived

keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kind, Checked Against The Published Checksums

ansible-kind

kind on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum kind publishes, and re-checked with sha256sum -c by the live test. kind needs a container runtime it does not bring (podman on EL 10); kind get clusters with none stops at 'failed to list clusters'. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kops, Run To AWS's Door With A Parsed Cluster Spec

ansible-kops

kops on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has create -f load a Cluster manifest against a local state store and stop at the EC2 credential lookup with the metadata service off. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedAWSAnsible
Open krew, A Plugin Index Fetched And A Plugin Installed

ansible-krew

krew on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has krew update clone the plugin index and krew install ctx land the plugin under a throwaway KREW_ROOT; a plugin the index lacks is refused. Installed as krew and kubectl-krew. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kube-bench, The CIS Node Checks Run To A Summary

ansible-kube-bench

kube-bench on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then installs the benchmark definitions and runs the cis-1.10 node checks with --exit-code 42: on a host with no kubelet they FAIL, the summary prints, the exit code is 42. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kube-score, A Deployment Scored And Found Wanting

ansible-kube-score

kube-score on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which scores a minimal Deployment and expects the CRITICAL findings (resources, image tag, security context) and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kubeconform, A Real Manifest Refused

ansible-kubeconform

kubeconform on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the CHECKSUMS file, and re-checked by the live test, which validates two Deployments against the upstream schemas: the right one passes, the one with a string replicas is refused at /spec/replicas. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kubectl, Checked Against The Published Hash

ansible-kubectl

kubectl on EL 10 from dl.k8s.io, refused by Ansible's get_url unless its SHA-256 is the one in the kubectl.sha256 file published beside it. The live test hashes the binary on disk against that file again and runs kubectl get nodes with no cluster, expecting the refused connection on localhost:8080. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kubectx And kubens, A Context Switched For Real

ansible-kubectx

kubectx and kubens on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a two-context kubeconfig, has kubectx switch it offline and read it back, and kubens read the namespace. Both tools from one release, both checked. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kubent, A Deprecated API Found In A File

ansible-kubent

kubent on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then reads a policy/v1beta1 PodDisruptionBudget from a file against a 1.32 target, expecting the finding and exit 200, then the same object on policy/v1 with exit 0. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kubeseal, A Secret Sealed Offline

ansible-kubeseal

kubeseal on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then generates a throwaway certificate, seals a one-key Secret against it with no cluster and expects a SealedSecret document. The controller stays per cluster. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open kustomize, Checked Against The Published Checksums

ansible-kustomize

kustomize on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.txt, and re-checked with sha256sum -c by the live test. The tag carries a slash (kustomize/v5.8.1), URL-encoded in the release path. Pinned; kustomize build against a directory with no kustomization stops where it should. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open lego, The ACME Client, Every DNS Provider Listed

ansible-lego

lego on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs the pinned binary and has dnshelp list the DNS-01 providers it can drive (route53, cloudflare, azuredns, gcloud among some two hundred). v5 command tree documented. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open logrotate, A Rotation That Really Happened

ansible-logrotate-policy

logrotate on EL 10: one drop-in for this host's own logs, checked by logrotate before it lands, with the timer the package ships enabled. The live test writes one log past the size limit and one well under it, runs the unit the timer runs rather than forcing it, and asserts the first rotated and was truncated while the second was left alone. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open memcached, The Package's Own Unit, UDP Proven Off

ansible-memcached

memcached from AppStream, configured through the one file its packaged unit reads; the live test stores a value and reads it back over the protocol, checks the statistics report the configured memory and threads, and asserts nothing listens on UDP, the amplification reflector's port. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open memcached_exporter, A Real memcached Seen Up And Down

ansible-memcached-exporter

memcached_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads memcached_up 0 while nothing listens, brings up memcached on loopback as a fixture, sees memcached_up 1, stores one item over the protocol and sees it counted, stops memcached and sees memcached_up 0. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open minikube, Checked Against The Published Checksums

ansible-minikube

minikube on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 the project publishes, and compared again with the binary on disk by the live test, which then runs minikube status with no profile and expects the profile-not-found message. The driver (podman, docker, kvm2) is not this role's. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open mkcert, A Local CA And A Leaf Checked By openssl

ansible-mkcert

mkcert on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then points CAROOT at its own directory, has mkcert make the CA and a certificate for probe.test, verifies the chain with openssl and reads the SANs back; the system trust store is left alone. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open mtail, Log Lines Counted Into Metrics

ansible-mtail

mtail on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test appends three lines to the followed log, one with ERROR, and reads lines_total 3 and errors_total 1; every program directory is compiled by --compile_only before a restart. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open mysqld_exporter, A Real MariaDB Seen Down Then Up

ansible-mysqld-exporter

mysqld_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up MariaDB as a fixture, reads mysql_up 0 before the exporter's user exists, creates it with the monitoring grants, and reads mysql_up 1 with the status counters. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open nftables, Default Deny And A Port That Really Times Out

ansible-nftables

nftables from AppStream on EL 10: default-deny inbound with a port allowlist, in its own table, checked by nft before it loads. The live test opens a listener on an allowed port and on one that is not: the first answers, the second times out, the drop counter moves, and loopback still answers. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open nginx-prometheus-exporter, A Real stub_status Seen Up And Down

ansible-nginx-exporter

nginx-prometheus-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up nginx with stub_status on loopback as a fixture, sees nginx_up 1 with the connection gauges, stops nginx and sees nginx_up 0. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open ntfy On Loopback, Nobody Anonymous, A Message Round-Tripped

ansible-ntfy

ntfy from the upstream release (sha256-verified) as a hardened system service on loopback with a message cache, a user database and deny-all as the default access. The live test sees an anonymous publish and a wrong password refused, creates a user with ntfy's own command, publishes a message and reads it back from the topic. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open pam_faillock, A Lockout Proven To Lock And To Let Go

ansible-pam-faillock

An account lockout on EL 10, put into the authentication stack through authselect because /etc/pam.d/system-auth is a generated symlink. The live test fails one account past the limit and watches the RIGHT password be refused, fails a second one short of the limit and watches it keep working, then resets the first and watches it come back. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open pip-audit, An Old Pin With Advisories, A Clean Pin Without

ansible-pip-audit

pip-audit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then audits a requirements file pinning requests 2.19.0 (PYSEC advisories, exit 1) and one pinning six 1.17.0 ('No known vulnerabilities found', exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open postgres_exporter, A Real PostgreSQL Seen Down Then Up

ansible-postgres-exporter

postgres_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up PostgreSQL 16 as a fixture, reads pg_up 0 before the exporter's role exists, creates it with pg_monitor, and reads pg_up 1 with per-database statistics. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open pre-commit, A Local Hook That Fails, Then Passes

ansible-pre-commit

pre-commit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a repo-local hook over a staged repository: exit 1 naming the offending file, exit 0 with Passed once it is removed. git installed by the role. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open process-exporter, Processes Grouped From /proc

ansible-process-exporter

process-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects systemd and the exporter itself as named process groups with their CPU counters. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open rclone, A Copy Checked With 0 Differences

ansible-rclone

rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open redis_exporter, A Real Valkey Seen Up And A Key Counted

ansible-redis-exporter

redis_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up Valkey on loopback as a fixture, sees redis_up 1, writes a key and sees it counted in db0; the server password lives in an EnvironmentFile. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open restic REST Server On Loopback, The Protocol Spoken By Hand

ansible-rest-server

restic's REST backend server from the upstream release (sha256-verified) as a hardened system service on loopback, append-only and private repositories a variable away. No client is installed, so the live test speaks the protocol: creates a repository, writes its config object, reads it back, deletes it and sees it gone. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open rqlite, SQLite With A Raft Log And A Row That Came Back

ansible-rqlite

rqlite (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous caller and a wrong password refused, writes a row through the HTTP API and reads it back, and finds the node leading its own raft; the users file is always written, because rqlite answers everyone without one. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open rsyslog, A Receiver For Other Hosts' Logs, Over TLS

ansible-rsyslog-remote

rsyslog from AppStream as a remote receiver on EL 10: a plaintext port, RFC 5425's TLS port, and one file per sending host. The live test sends a message to each and finds both in the right file at 0640, pushes plaintext at the TLS port and finds nothing written, and checks that no remote message reached this host's own log. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open s5cmd, Run To Its First Credential Lookup

ansible-s5cmd

s5cmd on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs ls against a dead endpoint with the metadata service disabled, expecting NoCredentialProviders before any connection, and sees a local-to-local cp refused by design. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open slsa-verifier, The Binary Verifies Its Own Provenance

ansible-slsa-verifier

slsa-verifier on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then fetches the release's .intoto.jsonl and has the installed binary verify itself against it through Sigstore ('PASSED'); the wrong source tag is refused. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open snmp_exporter, A Real Agent Walked Through if_mib

ansible-snmp-exporter

snmp_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up net-snmp's snmpd on loopback as a fixture and walks it through the if_mib module with the shipped snmp.yml; a dead target answers 500. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open sql_exporter, Your Own SQL As Metrics, A Count That Moved

ansible-sql-exporter

sql_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads a 500 with no database (nothing invented), brings up PostgreSQL 16 as a fixture, reads the shipped query at 0, inserts three rows and reads 3; the config with the DSN is checked by -config.check before it lands. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open statsd_exporter, StatsD Lines That Became Metrics

ansible-statsd-exporter

statsd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends a counter, a gauge and a timer over UDP and a counter over TCP and reads them back from /metrics as Prometheus metrics. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open step CLI, A Root, A Leaf, A Chain Verified And One Refused

ansible-step

step on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then creates a root CA and a leaf offline, verifies the chain against the right root, sees it refused against another, and inspects the leaf as JSON. The client half of the step-ca role. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open step-ca Private CA, Initialised Once, Proven By Issuing

ansible-step-ca

Smallstep step-ca and the step CLI from the upstream releases (sha256-verified) as a hardened system service on loopback, initialised once by its own user: root and intermediate keys, ca.json and a JWK provisioner. The live test reads the CA's health, has it issue a certificate, verifies it against the root and sees a wrong password refused. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open stern, Checked Against The Published Checksums

ansible-stern

stern on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then runs stern with no kubeconfig and expects the refused connection on localhost:8080. Kubeconfig and contexts are per user. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open sudo, A Policy Checked Before It Lands, Refusals Proven

ansible-sudoers-policy

A sudo policy on EL 10 as a drop-in that visudo checks before it lands, with commands written out with their arguments. The live test runs the allowed command without a password and is refused three ways: another subcommand, the same command with a different argument, and a user outside the group. Both appear in sudo's own log. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open systemd Sandboxing, Measured Against The Job It Must Not Break

ansible-unit-hardening

The scheduler on a stock EL host scores 9.6 UNSAFE and holds every capability the kernel has. This role writes a sandboxing drop-in and proves both halves: systemd's own exposure level came down, and the service still runs its jobs. The capability set that scores best is the one that stops cron working, and the README has the table. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open systemd-journald, A Journal That Survives The Reboot

ansible-journald-retention

systemd-journald on EL 10: a drop-in that moves the journal to persistent storage, seals it, and puts a ceiling on the disk it may take. The live test reads the EFFECTIVE settings back out of systemd rather than the file it wrote, finds a real journal file on disk, round-trips a message through it, and runs a vacuum. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open systemd_exporter, Unit States Read Over D-Bus

ansible-systemd-exporter

systemd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects the exporter's own unit reported active - D-Bus reached as an unprivileged service user. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open talosctl, A Cluster Configuration Generated And Validated

ansible-talosctl

talosctl on EL 10 from the GitHub release (the 118 MB bare binary), refused by Ansible's get_url unless its SHA-256 is the one in Sidero's sha256sum.txt, and re-checked by the live test, which generates a throwaway control-plane, worker and talosconfig set offline and validates the control-plane file for metal. Pinned; a newer release is a variable change. Original role, live-tested on Rocky 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open tenv, An OpenTofu Installed, Signature-Checked, And Run

ansible-tenv

tenv on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has tenv tofu install fetch OpenTofu 1.8.7 (the OpenPGP check runs when cosign is absent), lists it and runs it. Shims are opt-in so nothing shadows the host's tofu. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open terraform-docs, Checked Against The Published Checksums

ansible-terraform-docs

terraform-docs on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's .sha256sum, and re-checked with sha256sum -c by the live test, which then renders an empty module as a Markdown table and expects 'No requirements': parser and renderer both ran, with no terraform binary and no network. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open tfupdate, Two Version Constraints Rewritten And Read Back

ansible-tfupdate

tfupdate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then bumps required_version and the aws provider constraint in a module and reads both back; a file with an unclosed block is refused with 'failed to parse input'. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open vals, A Secret Reference Expanded, One Refused, One Run To AWS

ansible-vals

vals on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then expands a ref+file:// reference in a YAML file, sees a missing file refused, and runs ref+awsssm:// with no credentials to 'no EC2 IMDS role found'. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open yamlfmt, Lint, Format, Lint Again

ansible-yamlfmt

yamlfmt on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a misindented file, expects -lint to exit 1, formats it in place, reads the result back byte for byte and expects the second lint to exit 0. Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open yamllint, A Syntax Error Found, A Clean File Passed

ansible-yamllint

yamllint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a file whose list is indented two ways (parsable output names the syntax error, exit 1) and a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open yq, Pinned From A Checksum File get_url Cannot Read

ansible-yq

Mike Farah's yq on EL 10 from the GitHub release, refused by get_url unless its SHA-256 is the pinned one: yq's checksum files are rhash and BSD forms that get_url cannot parse, so the live test fetches checksums-bsd for the version and asserts the SHA256 line is the pin, then reads a key from a YAML file through yq. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Open zot OCI Registry On Loopback, Config Checked, A Blob Round-Tripped

ansible-zot

zot, the OCI-native registry, from the upstream release binary (sha256-verified, the minimal build by default) as a hardened system service on loopback with dedupe and garbage collection, its config checked by zot verify before it lands. The live test uploads a blob by digest, reads it back, sees the repository in the catalogue, deletes the blob. Original role, live-tested on Rocky Linux 10.

Live-testedMulti-cloud & platform-agnosticAnsible
Verification runs are in early access. What is recorded here is what has run so far.Request access