Module catalog
Find infrastructure. Inspect the evidence.
Modules matching these filters
azure-b2c
An Azure AD B2C tenant created where its customer directory should live, on PremiumP1 or P2, linked to the subscription that pays per monthly active user. Data residency and the onmicrosoft.com name are chosen once and cannot change; user flows, policies and app registrations are configured inside the tenant with an azuread provider pointed at the exported tenant ID.
ibm-backup-policy
Backup for VPC: a policy that selects volumes (or instances) carrying the tags you name, a daily plan that keeps snapshots thirty days and copies the user tags across, and a copy of each snapshot to a second region with an encryption key of yours there; a single region is accepted by name. A policy with no plan backs up nothing; the plan is created here.
gcp-backup-dr
The vault and the plan are what the console shows; the association is what makes a backup exist, and a plan associated with nothing backs up nothing. Enforced retention is the setting ransomware cannot undo - no backup younger than it can be deleted by anyone - and WITHIN_PROJECT access lets a compromised owner restore everything. Resources come with the plan; 14 days enforced; org-scoped.
tencent-bastion
A Tencent Bastion Host deployment. cidr_block is a range the service claims inside your VPC and an overlap is found by whatever stops working, not by the plan. resource_node is both the bill and the ceiling: registering more assets than you bought fails at registration, months later. time_unit is months and nothing else.
alicloud-bastion
A Bastionhost instance, its exposure and the directory its operators come from. Public access with an empty allow list is refused: that is a login page for production. Without AD or LDAP every account is local and outlives the person who left. Destroying it needs Alibaba to white-list the account first, which is documented provider behaviour and reported as an output.
huawei-bastion
A CBH instance. The console administrator password is a required argument, so it is written to Terraform state in plain text and whoever reads that state administers every recorded session in the estate; the module will not build until that is acknowledged. period is ForceNew, so changing the term destroys and rebuilds the appliance rather than renewing it.
gcp-billing-budget
The API accepts a budget with default recipients disabled and no channel, topic or threshold rule - a number that is tracked and never sent anywhere. Refuses that, insists on a FORECASTED_SPEND rule, and defaults credit_types_treatment to EXCLUDE_ALL_CREDITS, because a budget that counts credits measures your runway, not your spend, and looks healthy until the month they run out.
exoscale-block-storage
Snapshots exist as a resource you take and nothing on the platform schedules one; a volume attaches from the instance side, one instance at a time, in its zone; and a volume made from a snapshot is the restore path. A baseline snapshot when asked, restore from a snapshot when given, and an output that says no schedule exists.
ibm-block-volume
VPC backup policies match volumes by user tag, so a volume created without the tag sits silently outside the policy; encryption is provider-managed unless a root key CRN is given; and an attachment can delete the volume with the instance. The policy created with its plan and the volume tagged with the tag it matches (none by name), your key when given, the volume kept on instance deletion.
oci-block-volume
Every tenancy ships Bronze, Silver and Gold policies and a volume follows one only through a separate assignment - the page reads Backup policy: none for the many never assigned. Assigns a policy to the volume it creates and refuses one without. Custom schedules add destination_region and retention lock, which Oracle policies lack: same-region backups are a copy of the failure.
do-volume
Droplet backups copy the boot disk and nothing attached to it, so a database whose data lives on a volume is an empty server to the backup; there is no snapshot schedule for volumes either. A formatted, attached, regional volume with two outputs that say exactly that, so whatever consumes the module cannot assume a copy exists.
scaleway-block-volume
iops is required, is the price per GB, and cannot change after creation; snapshots exist as a resource you take and nothing on the platform schedules one; the volume is zonal and attaches from the server side. The tier validated to the two that exist, a baseline snapshot when asked, and an output that says no schedule exists.
aws-mq
deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.
scaleway-object-bucket
Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.
oci-budget
The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.
azure-budget
Azure requires a notification block, which makes the problem look solved: a notification can be created disabled, and contact_roles = Owner emails whoever holds the role, which is often a service principal with no mailbox. Insists on an enabled notification with a real address or action group, and on a Forecasted threshold so the first message arrives while there is still a month to act.
aws-budgets
A budget with no notification tracks correctly and tells nobody, so the invoice is the first notice; ACTUAL-only alerts arrive after the money is gone. And include_credit defaults true, so a budget on a credited account reports runway rather than spend - until the credits end and nothing crosses a threshold.
tencent-budget
A billing budget with thresholds and a scope. fee_type picks which figure is counted: COST is list price you were never going to pay, CASH ignores everything settled with vouchers and credits and reports you under budget until they run out, REAL_COST is what you pay. A budget stops nothing and stops_spending says so.
aws-codebuild
privileged_mode hands the build the Docker socket, so anything it runs can read every environment variable and assume the service role. Off by default, and a PLAINTEXT variable whose name looks like a secret is refused.
tencent-cam-role
A CAM role assumable by the services or root accounts you name and nothing else (a wildcard principal is refused), console login off because a role is for workloads, a custom policy written from your statements, the preset policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.
huawei-cbr-backup
A Cloud Backup and Recovery policy that backs up nightly and keeps thirty days, bound to a server vault spread across zones (single-zone by name) that auto-expands rather than stopping when full (a fixed size by name), crash-consistent unless the CBR agent is on every server, with the servers in the map protected. Pay-per-use.
gcp-datastream
A stream is created NOT_STARTED and replicates nothing until somebody starts it; the source password is a literal in state unless it is a Secret Manager reference; public connectivity means the database admits Google's published ranges; and backfill_none is change capture with no history. Running from apply, private connection peered into your VPC, secret required, backfill on.
tencent-cdn
A Tencent Cloud CDN domain in front of your COS bucket or origin hosts, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from SSL Certificate Service, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.
huawei-cdn
A Huawei Cloud CDN domain in front of your OBS bucket or origin host, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from Cloud Certificate Manager, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, cache headers followed from the origin, and the origin fetched over HTTPS. The CNAME is exported.
alicloud-cdn
An Alibaba Cloud CDN domain in front of your OSS bucket or origin host, serving outside mainland China unless an ICP-filed scope is accepted by name, with the certificate from Certificate Management, every HTTP request redirected, HSTS, HTTP/2, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.
do-cdn
A DigitalOcean CDN endpoint in front of a Spaces bucket, served on your domain with a DigitalOcean-managed certificate you name (the cdn.digitaloceanspaces.com name is accepted by name), with a cache TTL you chose. The CDN serves the bucket's public objects; a private object stays private through it.
alicloud-cen-transit-router
An Alibaba Cloud CEN instance with an Enterprise Edition transit router, the route tables you name, and a VPC attachment per VPC with an interface per zone (one zone by name), each associated with one route table and propagating into the tables you list. The default route table is never used, so no VPC reaches another until you say so.
tencent-cfs-file-system
A Tencent Cloud CFS file system (NFS) in your subnet behind its own access group, whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 has to be accepted by name), on the standard or high-performance tier. CFS encrypts at rest with keys it holds, which the module says rather than hides.
tencent-clb
A listener's health check is a switch that, off, sends traffic to every target forever; a port-80 listener forwards unless a redirection resource points it at 443; and delete_protect defaults to false. HTTP health checks on a path through listener rules, a 301 from 80 to 443 whenever a certificate is given, deletion protection on, access logs when a CLS topic is given.
tencent-cos-bucket
A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.
ibm-cos-bucket
Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.
huawei-csms-secret
A secret in Huawei Cloud Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the account's default CSMS key (the default by name), with an expiry after which CSMS flags it (none by name) and event subscriptions that notice version changes and expiry.
tencent-image
A Tencent Cloud custom image captured from a CVM instance into an image family, so instances that name the family get the newest image (no family by name). The capture refuses a running instance rather than powering it off, and takes the system disk only unless data disks are named.
tencent-cvm-instance
A CVM instance in your subnet with login by key pair and no password, ordered security groups, no public address (one by name), the system disk encrypted with your KMS key (the service key by name), the Cloud Workload Protection and Cloud Monitor agents left on, a CAM role when you name one, and API termination refused. Pay-as-you-go by the hour.
oci-cache
One node is a primary with no replica, so a node failure or a maintenance window is an outage that empties the cache; and the cluster is reachable by anything that can route to its subnet unless an NSG says otherwise, because it has no other access control. Three nodes across availability domains, an NSG required, Valkey or Redis, sharded or not - decided at creation.
aws-keyspaces
point_in_time_recovery defaults to DISABLED and Keyspaces has no snapshots or automated backups, so off means a dropped table is simply gone. PITR on, a customer-managed key, and the two one-way doors - client-side timestamps and TTL - named rather than set quietly.
huawei-tls-certificate
A public TLS certificate bought through Huawei CCM, and its application. Applying is a purchase, so brand, type and validity have no defaults and every combination rule is checked at plan. It does not renew itself. The provider accepts Huawei's privacy terms on every application, so the module waits for a person to. Validation records appear one refresh after the first apply.
alicloud-ssl-certificate
A certificate uploaded into Certificate Management Service for SLB, ALB, CDN and API Gateway to reference. The private key is an argument, so it lands in the Terraform state and the README says so plainly. SM2 is a signing pair plus an encryption pair and the module refuses a half-filled set, which would upload something no client can handshake with.
azure-chaos-studio
Chaos Studio has no stop condition: an experiment runs for its actions' duration or until somebody presses Stop, so the duration is the only guardrail and every action here is capped. The experiment acts as its own identity and fails safely without a role on each target; every fault it can inject is a capability somebody enabled on an onboarded target, so the scope cannot quietly widen.
aws-fis
FIS refuses a template with no stop condition, which reads like a guarantee - and source = 'none' is a legal stop condition meaning the experiment never halts by itself. Refused here, along with targets that grow at run time and an empty-target mode that reports success for having tested nothing.
civo-dns-zone
A Civo DNS zone with every record in one map, each with the TTL Civo requires per record, and the nameservers exported for the registrar. Civo does not sign zones and has no CAA or NS record types; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.
tencent-clickhouse
A ClickHouse cluster with high availability on, since without it each shard has one replica and losing a data node is losing its data. A COS cold tier is set, because without one every partition stays on the most expensive storage the cluster has while the cluster reports healthy and the invoice is the only signal. Single-zone and PREPAID both have to be taken by name.
tencent-ccn
A Tencent Cloud CCN (pay-as-you-go; prepaid bandwidth by name) with the route tables you name and a VPC attachment per VPC on the current v2 resource, each bound to one table so the default routing domain is never used. Route propagation policies between tables are the next resource to add.
do-firewall
A firewall with no droplets and no tags applies to nothing while the console shows it active; SSH from 0.0.0.0/0 is the first rule the console offers; and with no outbound rule nothing leaves, DNS included. Droplets or tags expected, port 22 from everywhere refused unless accepted, and an outbound default that allows what a server needs.
oci-cloud-guard
Oracle ships every responder rule in USERACTION mode: a Remediate button appears on each problem and nothing happens until a person clicks it, so a tenancy with hundreds of findings has by default fixed none of them. Sets AUTOACTION per rule and exports the IAM statements each auto-action needs, since one without its policy fails on every execution.
huawei-css-cluster
A CSS cluster with security_mode true, since false means the cluster answers anyone who can reach it with no credentials while the console reports it healthy. HTTPS requires security mode and the API says so late, so the module says so first; disks are encrypted at creation, and public access without a whitelist is refused.
tencent-cloud-audit
A CloudAudit tracking set scoped to every resource type, action and event name (narrower by name), compressed and delivered to a COS bucket you own under a prefix. The console keeps ninety days and forgets; the tracking set is what keeps more. Organization tracking collects every member account from the management account.
aws-cloudhsm
Cluster and HSMs, with the parts nobody mentions: AWS holds no copy of your keys, Terraform cannot initialise the cluster, and an uninitialised cluster bills per HSM per hour while being unable to store anything.
ibm-cloudant
A Cloudant instance on the standard plan with CORS off, and a wildcard origin together with allow_credentials refused outright because it would let any site make authenticated requests as the signed-in user. Legacy username-and-password auth is off, and data events are on, since without them the trail never records that anyone read a document.
ansible-cloudflared-tunnel
cloudflared from Cloudflare's signed repository (a 2025 key rpm on EL 10 accepts), pinned, run as a hardened unit that reads the tunnel token from a root-only file, not from the unit or ps. Never self-updating. The live test greps the unit and the connector's command lines for the token and expects nothing. Original role, live-tested on Rocky Linux 10.
ibm-code-engine-app
A Code Engine project and application with managed_domain_mappings local_private, because the field defaults to local_public and an application deployed with no opinion about it answers the world. scale_min_instances is one rather than zero, run_as_user is not root, and a private image without its pull secret is refused - that failure otherwise arrives long after the apply.
ibm-code-engine-function
A Code Engine function in a project created here, callable only from inside the project unless a public URL is accepted by name, with the compute resource token mounted so it obtains IAM tokens through a trusted profile and needs no API key, and CPU, memory, concurrency and execution time capped so a runaway caller cannot drive the bill.
oci-security-zone
The opposite of every other guardrail here: a security zone does not detect or report, it REFUSES - the API call fails. There is no dry-run mode. So the risk inverts too: applied to a compartment that already holds non-compliant resources, the team that owns them discovers they can no longer change them.
aws-config
Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.
oci-service-connector
OCI Logging keeps a log for at most six months; a service connector from a log group to Object Storage is the archive, and it can be created INACTIVE, which is how one that was set up has moved nothing since. Created active, reads a whole log group so new logs are included, writes to a bucket, stream, function, topic, metric or Log Analytics, and exports the IAM statement the hub needs.
gcp-org-policy
dry_run_spec is a separate configuration from spec and only spec enforces, so a dry-run policy appears in the console, evaluates everything and denies nothing. inherit_from_parent defaults to false, which makes a local addition silently REPLACE the organization policy rather than add to it.
oci-container-instances
A container with no health check is restarted only when its process exits, so a deadlocked one stays; containers run as root unless the security context says otherwise; and a public IP on the instance is an internet-facing container with only an NSG in front. Every container gets a check that restarts it and runs non-root on a read-only filesystem; the instance stays private.
ibm-container-registry
An IBM Cloud Container Registry namespace in the provider's region, with a retention policy that keeps the last ten images per repository and drops untagged ones, because without one every CI run adds an image until the account's storage quota refuses the next push. Quotas and the plan are account-wide and not managed here.
do-container-registry
Docker credentials for the registry never expire unless told to, so the login a CI job wrote to disk two years ago still pushes today; there is one registry per account; and the tier is a storage ceiling that turns into a failed push far from the cause. The registry, read-only credentials that live a day and read-write ones that live an hour, both re-issued on the next apply after expiry.
tencent-org-policy
A Tencent Cloud Organization service control policy and its attachments. It refuses a policy attached to nothing, an allow statement read as a grant, and an unasked-for root attachment. Destroying the policy-type switch disables every control policy in the organisation, so the module leaves it alone by default and protects it from destroy when asked to manage it.
alicloud-org-policy
A Resource Management control policy and the folders or accounts it attaches to, which are separate resources: an unattached policy appears in the console list with a name and a document and constrains nobody. A control policy is a ceiling, so the module counts Deny statements and asks about Allow ones, which grant nothing. Attaching to the root reaches the management account.
aws-control-tower
A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.
oci-remote-peering
A remote peering connection is half a link until the requestor connects to the acceptor, and a PEERED connection with no DRG route import and no VCN route rule passes nothing while reading as connected. Acceptor and requestor halves from one module, the peering status exported, and an output that lists the routes and security rules that live outside it and are the usual reason no packets cross.
oci-custom-image
A custom Compute image from exactly one source: an instance you built (its boot volume, secrets and all, so build it clean) or a QCOW2 or VMDK object in Object Storage with its operating system named, in the launch mode the workload needs (NATIVE for images built on OCI, PARAVIRTUALIZED for imports). OCI has no image family; the name carries the build.
gcp-compute-image
A custom Compute Engine image from a disk, snapshot, image or raw tarball (exactly one), in a family instances resolve, encrypted with your Cloud KMS key, stored in the location you choose and shared by a compute.imageUser binding. The guest features default to a current distribution image; no family and the Google-managed key are each accepted by name.
oci-customer-identity
An OCI identity domain on the external-user licence. license_type is not updatable, so changing it replaces the domain with an empty one and every customer account is gone - and the admin email is create-time only too. A domain must be deactivated before it can be deleted, which the module exposes, and it stays off your staff sign-in page.
tencent-customer-identity
A Tencent CIAM user store and its groups. The provider exposes the store and nothing about how a customer signs in: login methods, password rules, MFA and social providers are console-only and invisible to Terraform, which configures_authentication reports. The logo appears on the customer sign-in page, so it must be HTTPS.
cloudflare-d1-database
Where a D1 primary lives is decided at creation, near whoever ran the create unless a hint or jurisdiction says otherwise; read replication is off by default; and backups are Time Travel with a window the plan decides (30 days paid, 7 free) and no export schedule. Hint or jurisdiction set, replication by name, the recovery window as an output, and an output that says no export is scheduled.
huawei-dcs-redis
A Distributed Cache Service Redis instance in your VPC with primary and standby across two zones (one by name), TLS required (plaintext by name), the whitelist on with your ranges, a password from a secret store never output, weekly backups kept seven days, a maintenance window, and flushall, flushdb, keys and hgetall renamed so an accident cannot type them.
azure-ddos-protection-plan
The plan is a fixed monthly charge of roughly three thousand dollars from the moment it exists, attached VNets or not; it protects only the VNets that reference it; and DDoS IP Protection on the addresses themselves is an order of magnitude cheaper for a handful. The charge accepted by name before the plan is created, the plan ID exported for azure-vnet, an output that says it bills unattached.
gcp-resolver-policy
A Cloud DNS server policy bound to no network resolves for nobody, and query logging is off by default, so nothing records which host resolved which name - the first question in most incidents. Refuses a policy with no networks, logs every query, and can add a response policy that answers listed domains with a sinkhole address before recursion, for every workload on every governed network at once.
do-dns-zone
A DigitalOcean domain and its records. Creating the zone does not delegate it: until the registrar's nameservers point here the zone is correct, complete and serving nobody, which looks exactly like a working zone. The domain's ip_address shortcut, which hides an apex A record from your records map, is deliberately not used, and a CNAME at the apex is refused.
tencent-dns-zone
A Tencent Cloud DNSPod zone with every record in one map, all on the default resolution line so every resolver gets the same answer, MX priority carried on the record, and the free-grade nameservers exported for the registrar. DNSSEC is not a resource in the provider; dnssec_available says so.
huawei-database-migration
A DRS job with the lag alarm armed to an SMN topic, since without one the console shows the same green whether the job is current or hours behind. The target is held read-only, because anything writing to it produces conflicts the job cannot see or repair; multi_write and a FULL_TRANS-only snapshot both have to be chosen by name.
alicloud-database-migration
A DTS instance and synchronization job with delay_notice on, since a job that has fallen behind reports the same RUNNING as one that has not. Structure, data and synchronization are three separate required flags and the module names what each leaves out. The provider does not mark the endpoint passwords sensitive, so these variables do.
huawei-dws
A DWS cluster keeping its manual snapshots when it is deleted, since the default of zero deletes the backups along with the thing they were backing up and turns a mistaken delete into a permanent one. Disks are encrypted at creation because they cannot be later, audit logging to LTS is on, and there is no public endpoint unless you ask for one.
aws-grafana
account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.
azure-data-factory
The managed virtual network cannot be turned on after creation, and without it the integration runtime that copies your data reaches every source over public endpoints; the studio endpoint is public by default; and a factory with no git repository keeps its pipelines only in the service, with no review. Managed VNet on, studio private, git required, Key Vault linked for secrets.
oci-data-integration
An OCI Data Integration workspace attached to your VCN and subnet so pipelines reach databases that have no public path (internet-only sources by name), with a private DNS server when your names live there. The workspace is the boundary for pipelines and the hourly bill from creation; the pipelines themselves are built inside it.
azure-database-migration
An Azure Database Migration Service instance placed in a subnet that must reach both source and target, on the Premium SKU that runs online migrations with continuous sync so a cutover is minutes (the Standard tiers are offline), with a migration project per source and target pair from a map. Tasks and credentials are supplied when a migration runs, not here.
aws-database-proxy
Amazon RDS Proxy in front of an RDS instance or Aurora cluster: TLS required, clients authenticate with IAM tokens while the proxy reads the password from Secrets Manager, through a role limited to those secrets. Debug logging writes SQL statement text to the logs, so it is off unless that is accepted. End-to-end IAM removes the stored password entirely.
gcp-firestore
Type, location and CMEK cannot be changed after creation - getting one wrong means exporting every document into a new database and repointing every client. delete_protection defaults OFF, and Firestore has no snapshots: point-in-time recovery is the only way back and only covers incidents after it was enabled.
ibm-databases-redis
An IBM Cloud Databases for Redis deployment on the private endpoint only (public by name), with deletion protection on, an allowlist of your ranges (empty by name), disk and backup encryption with Key Protect keys you hold (IBM's keys by name), and the two-member group that is the HA and cannot be reduced. Access is by service credential, a separate resource.
azure-databricks
The default deployment puts the clusters in a managed network you cannot see with a public IP per node, and the workspace URL - notebooks, jobs, tokens - is reachable from the internet. VNet injection into your subnets with no public IPs, the workspace endpoint off the internet, and one Key Vault key wired to all four encryption settings including the DBFS root, a separate resource.
gcp-dataflow
on_delete defaults to cancel, which discards every element in flight on a streaming pipeline the moment the job is destroyed or replaced; workers get public IPs by default; and the default worker identity is the Compute Engine default account. Drain on delete, private workers with Private Google Access, a dedicated service account with the default refused, and a customer-managed key.
huawei-elb
The default TLS policy accepts TLS 1.0; a pool without a monitor resource is never unhealthy and sends traffic to every member forever; an HTTPS listener does nothing about port 80 until an L7 policy redirects it; and deletion protection is off. tls-1-2-strict, an HTTP monitor on a path, a redirect on 80 whenever a certificate is given, two zones unless one is accepted, deletion protection on.
huawei-waf
A dedicated WAF of two anti-affinity instances in your subnet (one by name), pay-per-use, with a policy in block mode (log mode by name) that turns on basic web protection, CC attack protection, precise protection, web shell detection, anti-crawler and data masking, and the protected domain with your certificate, TLS 1.2, cipher suite 2 and PCI DSS checks, forwarding to origins over HTTPS.
gcp-cloud-deploy
require_approval defaults to false on every target, so a release rolls into production the moment somebody promotes it with nobody signing off; the verify flag defaults off, so skaffold verify has never run. Treats the last stage as production and refuses a pipeline whose last target skips approval, verifies after every rollout, and refuses the Compute default service account as the runner.
aws-kinesis-firehose
Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.
oci-devops
The project, repository and pipeline are separate resources and none reacts to a commit until a trigger ties a push to the pipeline; builds run as the DevOps service and fail on the first step without a dynamic group and policy; and the runner is on Oracle's network unless given a subnet. Trigger created, runner attached to your subnet, and the IAM rule and statements exported.
do-custom-image
A DigitalOcean custom image imported from a URL (raw, qcow2, vhdx, vdi or vmdk) into the regions you name, one region by name. Host the file in a Space you own: a URL nobody controls is an image nobody controls. The name carries the build.
tencent-direct-connect
A Direct Connect gateway terminating a dedicated circuit into a VPC or a CCN. Attaching one to a CCN creates the attachment and no routes, so the CCN has no way back to your premises while everything reports healthy; an empty route list on a CCN gateway is refused here. NAT mode rewrites your addresses and has to be chosen rather than inherited.
ibm-direct-link
A Direct Link gateway with both default route filters set to deny, because permit accepts every prefix the other side advertises including a default route that would pull the VPC's whole egress across the circuit. The BGP session is authenticated, BFD is on, global routing and metered billing are required inputs, and a virtual connection per VPC is what makes the circuit reach anything.
aws-dax-cache
DynamoDB Accelerator with TLS and encryption at rest. DAX leaves both off by default, and neither can be turned on for an existing cluster, so a fix means a new cluster. This module also creates its own security group (DAX otherwise uses the VPC default), a service role limited to the named tables and their indexes, and states that writes bypassing DAX leave stale reads until the TTL.
oci-fastconnect
One virtual circuit is one cable that goes down for maintenance, and the SLA assumes two; BFD is off by default, leaving a failed link to BGP hold timers for up to ninety seconds; and a circuit without a gateway is PROVISIONED and reaches no VCN. BFD on, the DRG required, a redundant partner circuit declared or the single circuit accepted by name, and the redundancy metadata exported.
azure-file-share
A share inherits its security boundary from the storage account, which defaults to public access and TLS 1.0; the quota is the price on premium; and a share is backed up only when a Recovery Services vault protects it through a policy and an assignment. A private account with TLS 1.2, the quota deliberate, share soft delete on, vault, policy and protection created together (none by name).
vultr-firewall
A firewall group filters inbound on the public interface only: outbound is always open and the VPC interface is never filtered. It is attached by the instance, so the group cannot see whether any uses it, and SSH from a /0 is the first rule offered. Named sources or Cloudflare's edge, SSH from anywhere refused unless accepted, and outputs that say attachment is not proven and outbound is open.
gcp-firewall-policy
A global network firewall policy exists independently of any network; an association puts it in the path, and a policy with a hundred rules and none governs nobody while rendering as fully configured. enable_logging defaults to false on every rule, so a deny that fires leaves no evidence. Refuses a policy with no network, logs every rule unless told not to, and counts the disabled ones.
civo-firewall
create_default_rules defaults to true and the rules it writes allow all inbound traffic on every port from every address, which turns a firewall into a name on a list; SSH from 0.0.0.0/0 is the first rule offered; and with the defaults off a firewall with no egress rule blocks all outbound. Defaults off, SSH from anywhere refused unless accepted, egress opened unless outbound rules narrow it.
azure-firewall
Every security feature on this service defaults to telling you, not to stopping it: threat_intelligence_mode defaults to Alert, which logs traffic to known-malicious destinations and forwards it, and intrusion detection does the same. Deny for both here, with the DNS proxy on so FQDN rules and the client agree on an answer.
oci-backup-policy
A block volume backup policy that many volumes share: incremental daily backups kept thirty days and full weekly backups kept a year, each copied to a second region (one region by name) and encrypted there with a key of yours when given, deletion prevented until retention ends (deletable by name), and every volume in the map assigned, because a policy with no assignment backs up nothing.
ibm-vpc-flow-logs
A VPC flow log collector writing into a Cloud Object Storage bucket the module creates with an expiry rule and your Key Protect key if you hold one, plus the is to cloud-object-storage Writer authorization without which a collector reports active and logs nothing - the usual reason an IBM flow log leaves an empty bucket. An inactive collector has to be accepted by name.
alicloud-workflows
A Serverless Workflow flow and its schedules. role_arn is optional in the API, so a flow without one is created, reads correctly in the console and fails at the first task that touches another service - at execution time. The module refuses that, and turns schedules on, because the API default is off and a disabled schedule shows its cron expression anyway.
azure-managed-certificate
A free App Service managed certificate for a custom subdomain, with its hostname binding, the SNI binding that puts it to use, and optionally the DNS records. Microsoft blocks issuance and renewal when the CNAME passes through anything before the app, so the module writes the direct record and refuses the wildcards, apex names and long hostnames the product does not support.
tencent-ssl-certificate
A free domain-validated certificate from Tencent Cloud SSL. DNS_AUTO writes the record for you and silently only works when the domain is on DNSPod, so the module refuses it unless you confirm that. The issued private key is a computed attribute and therefore in state, and the resource finishes before the certificate is issued, so read the status output.
alicloud-fc-function
A Function Compute 3.0 function running as the RAM role you name, with internet access off (on by name), in your VPC when a vpc_config is given, logging every invocation to a Log Service project and logstore (none by name), with code fetched from an OSS object you uploaded. Memory, CPU, disk, timeout and instance concurrency are inputs.
huawei-fgs-function
A FunctionGraph v2 function running as the IAM agency you name, in your VPC when a subnet is given, logging every invocation to the LTS group and stream you name, with plain environment variables in user_data and secrets in encrypted_user_data under your KMS key (which also encrypts the code), fetched from an OBS URL. A ceiling on instances is an input.
tencent-api-gateway
An API Gateway service with net_type INNER rather than OUTER, https rather than the http that stays plaintext to the gateway, and QPS ceilings required - without a limit one caller can spend the whole backend's capacity. auth_type NONE and CORS are both named per API, since either turns an endpoint into an open one.
aws-image-builder
A pipeline with no schedule builds when somebody clicks, so the golden image ages until a person remembers it; image tests are the switch turned off to save an hour and scanning is off unless enabled; and the build instance's metadata service can hand its credentials to whatever a step downloads. Weekly rebuilds when a dependency changed, tests and scanning on, IMDSv2-only builds.
oci-goldengate
is_public puts the GoldenGate console and REST API on the internet; the admin password is a vault secret or a literal in state; a deployment with no backup schedule keeps extracts, replicats and checkpoints in one place; and without a maintenance window upgrades land whenever Oracle schedules them. Private behind an NSG, secret required, daily backups to a bucket, and a window you chose.
azure-grafana
API keys are long-lived, unscoped bearer tokens that read every dashboard and end up in CI variables; the login page is public by default; and the Essential SKU is a single instance with no SLA. Keys off, login over a private endpoint, Standard SKU zone-redundant, fixed outbound addresses for data-source allow lists, and the identity it reads with exported for its Monitoring Reader grant.
aws-neptune
Neptune has no user, no password and no GRANT. Authorization is IAM and it defaults to OFF, so anything that can reach port 8182 can read every edge and drop the lot. IAM auth on, storage encrypted, and the audit log driven from one variable because its two halves live in different resources and either alone logs nothing.
aws-appsync
introspection_config defaults to ENABLED, handing any caller a complete map of every type, field and argument, and query_depth_limit defaults to 0, which means no limit - so one nested query multiplies into thousands of resolver calls. Both closed here, with request bodies kept out of CloudWatch and a WAF association for the rate nothing else bounds.
aws-bedrock-guardrail
Creating a guardrail does not apply it: the application must send guardrailIdentifier and guardrailVersion on every call, and DRAFT is mutable. This publishes a numbered version, outputs the two values your code needs, and refuses a guardrail with no policies at all - which attaches successfully, filters nothing, and reports as active.
hetzner-firewall
A firewall applied to no server protects nothing; SSH from everywhere is the default suggestion; and once one outbound rule exists Hetzner drops every other outbound packet, DNS included. Servers or a label selector expected, port 22 from everywhere refused unless accepted, a DNS and HTTPS baseline added once outbound is restricted, and an output that says the private network is not filtered.
hetzner-snapshot
A Hetzner snapshot of a server, which is Hetzner's custom image, labelled by role and build so hcloud_image data sources can select the newest (unlabelled has to be accepted by name). The snapshot is the server at that moment, secrets and all: build the source clean and power it off first.
huawei-dns-zone
A Huawei Cloud public DNS zone with the flat record map grouped into the record sets Huawei expects (one per name and type, several values), DNSSEC on with the DS record for the registrar, and the nameservers exported. Private zones bound to a VPC are a different zone type and not this module.
huawei-vpc
A Huawei Cloud VPC whose range is checked against RFC 1918 (a public range by name), with subnets placed in the zones you name, each with its gateway at the first address and DHCP handing out Huawei's resolvers so the platform's service names resolve. Nothing egresses: a NAT gateway (huawei-nat-gateway) or an EIP is a separate decision.
gcp-network-connectivity-center
A hub with no spokes connects nothing; a VPC spoke advertises every subnet to every other spoke unless told otherwise, which is how a sandbox learns the production database range; and site-to-site data transfer routes branches through Google at its rates. Spokes come with the hub, each VPC spoke narrows its exports or says why not, and branch transit is off unless accepted.
exoscale-kms-key
A key is zonal unless multi-zone, which is the surprise at the first cross-zone restore; and the service has no automatic rotation setting and no flag that refuses deletion, so a key is deleted in one call. Multi-zone unless told otherwise, and outputs that say rotation and deletion protection are not available, so nothing downstream assumes a control that is not there.
alicloud-kms-key
automatic_rotation defaults to Disabled, so today's key material encrypts everything for the life of the account; a key scheduled for deletion is gone after its window with everything encrypted under it; and deletion_protection, the switch that refuses the schedule, defaults to off. Rotation on at your interval, deletion protection on and off by name, the maximum pending window, and an alias.
huawei-kms-key
rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its pending window with everything encrypted under it, on a service with no flag to refuse the schedule. Rotation on at your interval, a 30-day window, and an output that says no deletion-protection flag exists.
tencent-kms-key
key_rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its window with everything encrypted under it, on a service that has no flag to refuse the schedule. Rotation on for symmetric keys, a 30-day window (the maximum), and an output that says no deletion-protection flag exists.
alicloud-kms-secret
A secret in Alibaba Cloud KMS Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the service key (the service key by name), with a version label that rotates the value when changed and a recovery window of up to thirty days before a deleted secret is gone; force deletion is accepted by name.
vault-kv-engine
KV v1 overwrites in place, so a bad write is the end of the previous secret; cas_required defaults to false, so two writers that read the same version both succeed and the second silently replaces the first; and version history is unbounded by default. v2 always, check-and-set on (off by name), versions bounded by count and age, the mount's lease ceilings set rather than inherited.
huawei-kafka-streaming
A DMS Kafka instance with enable_auto_topic off, because a producer that misspells a topic otherwise creates one: the messages go somewhere real, nothing errors, and nobody consumes them. TLS and SASL are both on, which is what makes the user mean anything; the disk is encrypted at creation; and what happens when the disk fills is a decision you take.
azure-data-explorer
The Dev(No SLA) SKUs say it in the name and are what a proof of concept becomes production on; public network access is on by default; disk and double encryption are off by default and set only at creation. Standard SKU with two instances across zones, private endpoints, both encryption layers on, a customer-managed key, and purge enabled because it is the only way to honour an erasure request.
ibm-public-certificate
A publicly-trusted certificate issued into Secrets Manager, validated over DNS through Cloud Internet Services, with both configurations created here rather than left to a console. Staging issues a certificate no browser trusts while looking like success, so it is refused by name; auto-rotation and key rotation are on, because a ninety-day certificate nothing renews is a dated outage.
aws-lightsail-instance
A Lightsail instance is created with 22 and 80 open to every address; its public address changes when it stops unless a static IP is attached, and every DNS record pointing at it is then wrong; and automatic snapshots are off. The port list replaced by your rules with SSH from anywhere accepted by name, a static IP attached, and the daily AutoSnapshot add-on on at the hour you choose.
linode-image
A Linode image captured from an instance disk, replicated to the regions you name (one region has to be accepted by name), cloud-init ready, with the label carrying the build. The image is the disk at that moment, secrets and all: build the source clean.
vultr-load-balancer
The default health check is TCP on the backend port, which a process that stopped serving still passes; ssl_redirect defaults to false, so the site stays in clear on 80; and a balancer with no instances is a public address that fails. HTTP checks on a path, redirect on whenever HTTPS exists, backends required, and a Let's Encrypt certificate from auto_ssl_domain rather than a pasted key in state.
do-load-balancer
The default health check is a TCP handshake, which a process that stopped serving still passes; redirect_http_to_https defaults to false, so the site stays in clear on 80; and a balancer with no tag and no droplets is a public address that 503s. HTTP checks on a path, redirect on whenever HTTPS exists, STRONG ciphers, backends required, and a Let's Encrypt certificate made from your domains.
upcloud-load-balancer
The backend health check defaults to TCP, which a process that stopped serving still passes; TLS is a certificate bundle nobody creates; a port-80 frontend forwards unless a rule redirects it; and a public network puts the frontend on the internet. HTTP checks on a path (TCP by name), a Let's Encrypt bundle for the hostnames you list, a 301 from 80 whenever it exists, and public by name.
scaleway-load-balancer
A Scaleway Load Balancer on a flexible IP with a Let's Encrypt certificate it issues itself (so the DNS must point at it first), TLS at the modern compatibility level (older clients by name), HTTP/3, the port 80 frontend answering only a 301 to HTTPS, and backends named by their Private Network address and probed over HTTP on a path you chose.
cloudflare-load-balancer
A pool with no monitor is healthy forever and keeps sending traffic to a dead origin; the fallback pool is required and the easiest value is the same pool that just failed; the notification email that says a pool went down is optional. Every pool uses the module's HTTPS monitor, a fallback that is also a default is refused, an address is told, and the balancer is proxied so origins stay hidden.
oci-local-peering
A local peering gateway with no peer stays NEW forever, and a PEERED pair with no route rule sending the other CIDR to the gateway passes nothing while reading as connected. Both gateways created and connected from one call, a route table with the rule to the peer created on each side for the subnets that should reach across, overlap refused, and an output that says it is not transitive.
ansible-unbound-resolver
Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.
ibm-transit-gateway
An IBM Cloud Transit Gateway local to one region (global by name) with a connection per VPC you name, each denying every prefix by default and permitting the prefix rules you write, since a transit gateway has no route tables and every connection advertises everything otherwise; a connection that permits all has to say so.
gcp-log-sink
Creating a sink creates a service account for it and grants that account nothing, so until it holds a role on the destination every export fails - the sink shows active, the destination stays empty, and the errors are logged into the project that was supposed to be exported. Grants the role with the sink, refuses an empty filter, and can manage _Default retention past 30 days.
gcp-looker
A Looker (Google Cloud core) instance reachable over Private Service Connect from the VPCs you allow, no public address, sign-in limited to your email domains, encrypted with your Cloud KMS key, in a maintenance window you chose. The OAuth client secret is sensitive and never output; the edition has no default because the annual editions commit for a year.
oci-lustre
OCI File Storage with Lustre in your subnet, reachable only through the network security groups you name, encrypted with a Vault key of yours (the Oracle-managed key by name), with root on clients squashed to a UID and GID you chose except for the clients you exempt (NONE by name), on the throughput tier you chose, with capacity checked against the 31,200 GB step before the plan.
azure-entra-domain-services
Microsoft Entra Domain Services with NTLM v1, TLS 1.0 and RC4 off and Kerberos armoring on, the WinRM network security group the service insists on, the AAD DC Administrators group with the members you name, and the Domain Controller Services principal registered, all of which fail late when missing. Notifications go to the admins; filtered sync and LDAPS are inputs.
civo-database
firewall_id is optional and a database without one answers to every address that can reach its endpoint; nodes = 1 is one node whose failure is downtime; and backups are the platform's, not configurable here. Firewall and network required, two nodes (one by name), the password as a sensitive output, and an output that says no backup schedule can be set.
vultr-database
A managed database gets a public hostname and trusted_ips is optional: left empty, any address on the internet may try the password; the backup hour is picked for you; and a plan with no replicas is one node whose failure is downtime. Trusted ranges required (a /0 refused unless accepted), a VPC attachment, one standby by default, both windows set, and the password as a sensitive output.
azure-managed-disk
A managed disk's export SAS works from anywhere until public access is off; your key is a disk encryption set nobody creates; and Azure Backup for disks is a vault, a policy and an instance, where the instance is the assignment most vaults lack. Public export closed, the encryption set taken when given, and vault, policy, role assignments and backup instance created together (none by name).
azure-sql-managed-instance
The public data endpoint turns a private database into one listening on the internet on port 3342; SQL logins put an administrator password in state when Entra-only authentication would remove them entirely; and zone redundancy is off by default. Private, Entra-only with SQL authentication accepted by name, Business Critical across zones, TLS 1.2, and geo-zone-redundant backups.
upcloud-kubernetes
An UpCloud Managed Kubernetes cluster whose API answers only the ranges you list (0.0.0.0/0 by name), with private node groups off the public internet, node storage encrypted at rest (unencrypted by name), anti-affinity across hosts, manual upgrades, and node groups from a map with labels and taints. The plan is the control plane's redundancy and bill.
upcloud-valkey
An UpCloud Managed Valkey service attached to your SDN private network with public access off (on by name) and an IP filter of the ranges that may connect, TLS on, RDB persistence with a nightly backup, an eviction policy set, service logs on, a maintenance window you chose, and termination protection (off by name). The password is generated and the URI is a sensitive output.
alicloud-maxcompute
A MaxCompute project with allow_full_scan off, so a query with no partition predicate fails rather than quietly reading the whole table and billing per byte - the single most effective cost control MaxCompute has, and the one people turn on after the invoice. Storage encryption is a creation-time choice, and an unset IP white list admits every address rather than none.
aws-prometheus
Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.
aws-dms
ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.
azure-cognitive-services
custom_subdomain_name looks cosmetic and decides everything: without it Entra ID auth does not work and no private endpoint can attach, so the account is silently key-only and public - and it is ForceNew. Restricting outbound access is the data-loss-prevention control for an OpenAI account.
huawei-machine-learning
A ModelArts workspace and notebook with allowed_access_ips required, since empty means any address and the notebook has your training data mounted and your credentials in its environment. auth_type PUBLIC means every user in the account rather than the internet. There is no auto-stop argument, and the module says so rather than implying a protection it cannot give.
tencent-mongodb
A MongoDB instance with TDE storage encryption on, which the API cannot add after creation, three nodes so the set can elect a new primary, and a VPC, subnet and security group all required, because an instance created without them lands in the classic network where nothing can fence it. PREPAID rebuilds the instance, so POSTPAID is the default.
huawei-dds-mongodb
A Document Database Service instance with ssl true, since false accepts plaintext client connections and nothing in the console says so, a named backup window and retention, and disk encryption that cannot be added afterwards. Sharding needs mongos, shard and config flavors and the module checks the combination before the apply rather than after.
alicloud-nas-file-system
An Alibaba Cloud NAS file system (NFS) encrypted with your KMS key (NAS-managed without one; unencrypted is not offered), a mount target in your vSwitch behind an access group whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 by name), and a recycle bin that keeps deleted files two weeks (none by name).
oci-nat-gateway
A NAT gateway for an existing VCN with the private route table that sends subnets through it, because a gateway no table points at forwards nothing. The NAT address is ephemeral unless a reserved public IP is attached, and every allow-list that named it breaks on recreation; the ephemeral address is accepted by name. block_traffic, the kill switch, stays off and is exported.
tencent-nat-gateway
A standard NAT gateway for an existing Tencent Cloud VPC, with a traffic-billed elastic IP, a bandwidth and concurrency tier of its own, and a default route entry written in every route table listed, because a gateway no table routes to forwards nothing. The elastic IP's cap and the gateway's tier are the two numbers to raise when downloads crawl.
do-vpc
Every resource created without a vpc_uuid lands in the region's default VPC beside everything the team ever made there; an auto-assigned ip_range is the one most likely to collide with the next peer; and a peering between overlapping ranges is accepted and carries nothing. A named VPC, a required range, overlaps refused at plan time, and an output that says nothing inside the VPC is filtered.
oci-network-firewall
An INSPECT rule hands the flow to the threat engine, and inspection decides what happens next: INTRUSION_PREVENTION drops the session, INTRUSION_DETECTION logs it and forwards it, and the rule reads INSPECT either way. Every inspect rule is prevention unless detection is accepted by name; policy and appliance are both created, and the address the route tables must point at is an output.
exoscale-nlb
A service's health check can be a TCP handshake that a process which stopped serving still passes; an NLB fronts instance pools rather than instances; and it is layer 4, so no listener certificate exists and the one you look for lives on the instances. HTTP or HTTPS checks on a path with TCP accepted by name, a pool per service, and an output that says TLS is not terminated here.
civo-network
Every resource created without a network_id lands in the region's default network beside everything the team ever made there; cidr_v4 is optional, so a network created without it gets whatever range was free, the one most likely to collide with the office or the VPN. A named network, a required range, the resolvers you chose, and an output that says the network itself filters nothing.
oci-nosql
is_auto_reclaimable is the Always Free shape and means the table is dropped, with its data, after 90 days without a read or write - right for a prototype and wrong for a table a quarterly job reads. Never reclaimable unless accepted by name, provisioned capacity with a ceiling set deliberately, and the DDL checked for a primary key before the API complains about syntax.
aws-sagemaker-notebook
AWS defaults a notebook to direct internet access AND root access: a root shell with a path off the network that misses your NAT, routing and DNS firewall, holding a role chosen to read your training data. Both off here, IMDSv2 only.
alicloud-machine-learning
A PAI workspace and the people in it. Created with no members the workspace belongs to whoever ran the apply and the team seeing nothing reads as a permissions problem elsewhere. env_types is fixed at creation and decides whether a dev-to-prod pipeline is even possible, and the role names are the permission model, so each member names their own.
aws-codeartifact
A repository with a public external connection serves whatever the public registry holds for any name it does not. This puts the connection on its own repository, reached through an upstream, and emits the origin-control commands Terraform cannot apply.
cloudflare-pages-project
Every branch pushed gets a public preview URL by default, the half-finished pricing page included; an environment variable is readable in the dashboard unless stored as a secret; and the production branch is whatever the repository's default was. Previews limited to the branches you list (every branch by name), each variable marked secret or plain, bindings per environment, and custom domains.
alicloud-patch-manager
An OOS patch baseline: which updates are acceptable on one operating system. A baseline is a policy and an OOS task has to run it, which the module reports rather than letting the word imply a schedule. ALLOW_AS_DEPENDENCY makes a rejection advisory - the patch installs anyway when something approved needs it - so BLOCK is the default.
aws-ssm-patch-manager
A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.
gcp-os-config-patch
An instance filter that matches nothing patches nothing - the deployment runs on schedule, reports success and touches no host - and reboot_config NEVER installs the kernel and keeps running the old one. Refuses an empty filter, makes all-instances a stated choice because it includes the databases, reboots when the packages need it, and caps the share of a zone patched at once.
azure-update-manager
A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.
tencent-vpc-peering
A peering connection between two VPCs with a route table entry written into every route table you list, on both sides, for every CIDR of the other side, because an Active peering carries nothing until the routes exist. POSTPAID by default: PREPAID buys a bandwidth tier for a term that can be raised and never lowered, so it has to be accepted by name.
gcp-service-perimeter
spec is the dry-run configuration and status is the enforced one - two blocks of the same shape, and a perimeter with only a spec is evaluated on every request, logs violations, and blocks nothing. Empty restricted_services is the other way to have none: the perimeter exists, covers the projects, and governs no API.
gcp-persistent-disk
A snapshot schedule is a resource policy, and its attachment to a disk is a separate resource, so a schedule in the console with no disks is the usual state; encryption is Google-managed unless a KMS key is given. The daily schedule created and attached or yours attached (none by name), your key when given, and the disk attached from its own side so the instance's disk list is left alone.
gcp-parallelstore
A persistent Parallelstore instance on the private services range you already allocated, because a VPC has one service networking peering and a module that made another would break the databases on it. Twelve TiB minimum in steps of four, balanced striping, one zone. SCRATCH, which loses the data on maintenance, is accepted by name; the bucket you import from is the durable copy.
azure-policy
enforce = false is Azure DoNotEnforce: the assignment appears, resources are evaluated, a compliance percentage is charted - and every violating resource is created anyway. From the portal compliance view that is indistinguishable from an enforced policy. Also refuses a silent not_scopes exclusion and an unexplained denial.
aws-verified-permissions
validation_settings.mode defaults to OFF, so a Cedar policy naming an action the schema does not define is accepted and then never matches. A broken permit fails closed and somebody complains; a broken forbid fails OPEN and nobody does. STRICT here, with the schema that makes it possible.
ovh-iam-policy
An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.
ibm-vpn-gateway
An IBM Cloud VPC VPN gateway in policy mode with one connection to your on-premises gateway on IKEv2, with its own IKE and IPsec policies (AES-256, SHA-256, DH group 14) so IBM's auto-negotiation list never admits SHA-1 or a small group, the weak options refused by validation, IKEv1 by name, and dead peer detection that restarts the connection.
oci-postgresql
password_type PLAIN_TEXT writes the admin password into the Terraform state and every plan that shows it; storage that is not regionally durable dies with its availability domain; and a DB system created without a management policy takes no backups. Vault secret reference, regionally durable storage, daily backups optionally copied to another region, a read replica, and an NSG on port 5432.
azure-powerbi-embedded
A Power BI Embedded Gen2 capacity with the administrators who may assign workspaces named (required), in the size you chose with no default because the capacity bills by the hour from creation whether a report is rendered or not. Workspaces are assigned to the capacity in Power BI, which is an admin action outside the module.
huawei-private-ca
A CCM private CA, root or subordinate. CRL publication is off by default, and without it you can press revoke while every client keeps trusting the certificate until it expires - so the module refuses that unless it is accepted. Deleting a CA starts a 7 to 30 day clock rather than deleting, and the product exists in two regions only.
ibm-private-ca
A root CA, an intermediate it signs and certificate templates in IBM Cloud Secrets Manager. IBM's examples let a template issue for any name; here templates name their domains, both CAs carry name constraints, and CRLs are built and published. Lifetimes are checked to nest, and the module says plainly that Terraform cannot revoke a CA.
gcp-certificate-authority
The DevOps tier does not persist the certificates it issues: no record, no CRL, no revocation - a year-long certificate from it can only answer a key compromise by the CA being distrusted whole. ENTERPRISE tier with the CRL published, a 90-day ceiling on every certificate, RSA below 2048 refused, and deletion protection on because deleting a CA invalidates everything it signed.
vault-pki-certificate-authority
Issuing from the root puts every leaf one signature from the root's compromise; a PKI role's defaults issue nothing until somebody reaches for allow_any_name, which issues for every hostname; and without AIA and CRL URLs a leaf is valid and unverifiable. A root that signs one intermediate, roles bound to allowed_domains, 30-day leaves under a 90-day ceiling, URLs on both mounts.
oci-certificate-authority
The CRL bucket is optional: a CA created without one can mark a certificate revoked and never tell anyone, and every client keeps trusting it until it expires. Required here unless no CRL is accepted by name. Issued certificates renew by rule; one without a renewal rule is a countdown and is listed. Leaf validity is capped at 90 days; the signing key is an HSM key in your vault.
ibm-db2
A Db2 deployment on a private endpoint with high availability on, disk encryption with a key you hold, and named ranges, because Db2 reads an absent allow list as any address rather than none. Autoscaling is off unless configured and its plan limit is the point: it is the difference between a slow hour and an unbounded invoice. Oracle compatibility is fixed at creation.
ibm-databases-elasticsearch
A Databases for Elasticsearch deployment on a private endpoint with deletion protection on, your Key Protect keys for both the data and the backups, and an allowlist that must name ranges because an empty one is read as any address. Three members, fixed rather than offered as a knob with one safe value. The plan, not the module, decides whether field-level security exists.
tencent-privatelink-endpoint
A Tencent Cloud Private Link endpoint to an endpoint service, with a VIP in the subnet you name behind the security groups you name; an endpoint with no security group is reachable from the whole VPC and has to be accepted by name. One subnet per endpoint; a second zone is a second endpoint.
exoscale-private-network
A private network without start, end and netmask hands out no addresses: every instance configures its own and two that pick the same one collide silently; and nothing filters traffic on the segment. A managed range required and derived from your RFC 1918 CIDR, addresses reserved at the ends for gateways, and an output that says every attached instance reaches every other.
upcloud-network
A private network on a public range is the surprise at the first NAT, and dhcp_default_route defaults to false, so servers get an address and no route, right for an isolated segment and wrong for one behind a router. An RFC 1918 range required, DHCP handing out the resolvers you chose, a router created and the default route set when you ask, and an output that says the network filters nothing.
ovh-private-network
A private network is a vRack VLAN that carries no addresses until a subnet hands them out; a subnet without a gateway address has no way to the internet; and nothing filters traffic on the segment. The subnet's RFC 1918 range required, DHCP with the resolvers you chose, an OVH gateway created by default so instances reach out without a public address, the network named as unfiltered.
azure-purview
A Microsoft Purview account for the data map with public network access off, the managed Event Hub that bills monthly whether used or not turned off, a system identity, and Storage Blob Data Reader granted to that identity on every storage account it will scan, since a scan fails otherwise. The account bills for data map capacity from creation; public access is accepted by name.
scaleway-container-registry
is_public makes every image in the namespace pullable by anyone, and the key CI pushes with is usually a person's API key with every permission that person has and no expiry. Private unless public is accepted by name, and on request an IAM application whose only permission is registry access in one project, with an API key that expires on the date you set.
ovh-container-registry
A registry's endpoint is public and every address may try a login until an IP restriction exists; the registry user is the credential and its password lands in state; and the plan is the storage ceiling. Allowed ranges expected with none accepted by name, one user created for the pipeline with its password as a sensitive output, and the plan looked up by name.
azure-dns-private-resolver
A resolver is five resources - endpoints, ruleset, rules and VNet links - and the half-built state most sit in resolves Azure names and forwards nothing to on-premises; a ruleset not linked to a VNet applies to nothing; and each endpoint needs its own delegated subnet. All five created, forwarding rules required, VNet links expected (none by name), the inbound address exported.
scaleway-image
A Scaleway instance image built from a snapshot the module takes of the root volume you name, private (public lists it for every Scaleway account and has to be accepted by name), for x86_64 or arm64, in one zone. Stop the server first so the file system is consistent.
vultr-container-registry
A Vultr container registry that is private (public, which lets anyone pull every image, is accepted by name), on the plan you chose (start_up is free and small; the paid plans bill monthly from creation), in the region your clusters are in. The root user Vultr creates is not output; a robot user per cluster is the credential to hand out.
ibm-dns-zone
An IBM Cloud DNS Services private zone, its permitted networks and its records. The zone and the permission are separate resources: with none, the zone is created, the records are created, everything reports Active, and no VPC can resolve any of it. An empty list is refused. This is private DNS and it is not the public zone, which is CIS.
alicloud-privatelink-endpoint
An Alibaba Cloud PrivateLink endpoint to a PrivateLink service or an Alibaba Cloud service, with an elastic network interface in each vSwitch you name (one zone has to be accepted by name), behind the security groups you name, and protected from deletion until the protection is turned off.
scaleway-public-gateway
A Scaleway Public Gateway on a reserved address, attached to a Private Network with masquerade and the default route pushed to the hosts, since a gateway with no gateway network forwards nothing. The bastion (SSH into the network through the gateway) is off and accepted by name; outbound SMTP is off so a compromised host cannot send mail under your name.
huawei-nat-gateway
A pay-per-use public NAT gateway for an existing Huawei Cloud VPC, with a traffic-billed elastic IP whose bandwidth cap every subnet shares, and an SNAT rule for each subnet listed, because a gateway with no SNAT rule forwards nothing. The spec is a concurrency tier (10,000 to a million connections) and what an idle gateway costs per hour.
gcp-static-site
A Cloud Storage bucket serving a static website. Google's own guide notes that objectViewer lets anyone list the bucket, so this module grants legacyObjectReader: read a named file, list nothing. It says plainly that Cloud Storage does not serve your domain over HTTPS, requires you to accept that everything in it is public, and keeps trimmed previous versions as the rollback.
gcp-private-service-connect
ACCEPT_AUTOMATIC admits any project on Google Cloud that knows the attachment URI, which is not a secret and appears in logs. Manual by default with a per-consumer connection limit; an empty accept list is refused too. PROXY protocol is on so backends see the consumer rather than the NAT range, removed consumers are disconnected, and the NAT subnet is created with the attachment.
tencent-tdmq-queue
A TDMQ for Pulsar cluster and its namespaces. msg_ttl is how long an UNACKNOWLEDGED message lives, not how long consumed ones are kept: too short silently drops work when a consumer is slow, too long turns a stuck consumer into unbounded backlog, and both extremes are refused. Retention is the separate thing that lets a new subscription read history.
oci-queue
dead_letter_queue_delivery_count defaults to zero, which is no dead-letter queue: a message a consumer cannot process is redelivered after every visibility timeout until retention expires, a poison message that holds a consumer for a day. Five deliveries then the dead-letter queue, seven days of retention instead of one, and a vault key instead of an Oracle-managed one.
aws-quicksight
A QuickSight subscription on Enterprise edition through IAM Identity Center, with admin, author and reader groups, termination protection on because unsubscribing deletes every dashboard, and a VPC connection with its own role so a private database stays private. The authentication method is permanent; Standard edition and QuickSight-managed users are accepted by name.
alicloud-ram-role
A RAM role assumable by the services or accounts you name and nothing else (a wildcard principal is refused), with a custom policy written from your statements, the system policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.
scaleway-redis
A Scaleway Managed Database for Redis cluster attached to your Private Network with no public endpoint (one by name), TLS required (plaintext by name), a password from a secret store never output, an ACL of the ranges that may connect (required), an eviction policy set, and three nodes so the data has three copies (fewer by name).
alicloud-container-registry
Namespaces, repositories, VPC access and an internet allowlist on an Alibaba Cloud Container Registry Enterprise Edition instance. Repositories are private and their tags immutable unless set otherwise, auto-create is off, and the internet endpoint is only switched on - by the resource existing - when you give it CIDRs. Image cleanup is deliberately not managed.
alicloud-landing-zone
A Resource Directory with its folders and member accounts. Two switches decide whether it works: control policies are off until the directory enables them, so a policy written elsewhere attaches to nothing; and member deletion is off by default, which makes every account this creates permanent and terraform destroy fail on it. Both are on here.
tencent-security-posture
A CSIP risk scan. Every setting in this API is an integer and 0 means a full scan in one field, a periodic task in another and off in a third, so the module takes words and writes the numbers. A full scan is an active probe of production and weakpass attempts passwords, so both are asked for by name; without configrisk there are no posture findings at all.
aws-appconfig
AppConfig exists to deploy a configuration slowly and roll it back automatically, and both halves are opt-in - the predefined AllAtOnce strategy is 100% of the fleet with zero bake time. Gradual here, and a precondition refuses an environment with no alarms, where automatic rollback has nothing to fire on.
ibm-key-protect-key
The rotation policy is a separate resource nobody creates, so a key made today encrypts everything for the life of the account; dual_auth_delete, the control that makes deletion a two-person act, is off by default; and force_delete would remove a key buckets still use. Rotation on at your interval, dual authorization on (off by name), force delete never, the instance created when none is given.
aws-route53-health-check
A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.
azure-sentinel
retention_in_days defaults to 30, against intrusions usually discovered months later - so the first question, when did this start, gets silence rather than an answer. daily_quota_gb is a trap both ways and has no safe default, so the module makes you choose. And onboarding Sentinel connects no data source at all.
scaleway-dns-zone
A Scaleway DNS zone (the root zone of the domain unless a subdomain is named) with every record in one map and the nameservers Scaleway assigns exported for the registrar. Geo-routed, weighted and health-checked records are kept out so a plain zone stays plain; a domain registered with Scaleway is delegated already.
scaleway-instance
A Scaleway instance on a Private Network with a required security group (the project default allows everything inbound), no public address unless a flexible IP is accepted by name, the project's SSH keys and no password, a Block Storage root volume deleted with the instance, cloud-init, and protection from deletion (off by name).
azure-search-service
One replica - the default - is excluded from the availability SLA; the admin key, on by default, reads and writes every index and is revoked only by regenerating it for everyone; and the query endpoint is public by default. Three replicas, Entra ID only, private endpoint, 0.0.0.0/0 refused in the allow list, and optional enforcement that refuses an index without a customer-managed key.
ibm-secrets-manager
A secret group and an arbitrary secret in an IBM Cloud Secrets Manager instance you already have, over the private endpoint. The instance is a paid resource created once per account and is an input, so an apply never creates a second bill; the group is the unit IAM grants are made on; the value is a sensitive variable never output; an expiry is expected, none by name.
tencent-secrets-manager
A secret in Tencent Cloud Secrets Manager as the two resources it is: the container with your KMS key (the service key by name) and a recovery window of up to thirty days, and the version that carries the value, a sensitive variable supplied at apply time and never output. A new version label is how the value rotates; immediate deletion is accepted by name.
alicloud-security-group
inner_access_policy defaults to Accept, so every instance in a group talks to every other on every port and one compromised web node is a route to the database beside it; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Members isolated unless told otherwise, SSH from anywhere refused unless accepted, egress open until rules narrow it.
huawei-security-group
Every new security group comes with default rules - all egress allowed and ingress from its own members - that nobody wrote and few remove; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Default rules deleted so the group holds only what the module wrote, egress stated, SSH from anywhere refused unless accepted.
tencent-security-group
Rules are ordered and the first match wins, so an ACCEPT from 0.0.0.0/0 anywhere in the list admits everything from that line down; one rule-set resource replaces the whole list on every apply; and SSH from everywhere is the first rule offered. Your rules in order with an explicit DROP appended, SSH from a /0 refused unless accepted, egress open until rules narrow it.
scaleway-security-group
The default inbound policy is accept, so a group with no rules admits every packet on every port and your rules are exceptions to accept-all; SSH from everywhere is the first rule offered; and the group filters the public interface only. Drop by default, SSH from a /0 refused unless accepted, the SMTP block kept unless a relay says otherwise, and outputs that say the Private Network is unfiltered.
ibm-security-group
An IBM VPC security group with no rules denies everything in both directions, so a group written with inbound rules only leaves instances that cannot resolve DNS; a group with no targets protects nothing; and SSH from 0.0.0.0/0 is the first rule offered. Outbound explicit with egress open by default, targets attached by the module (none by name), SSH from anywhere refused unless accepted.
exoscale-security-group
A group with no rules admits nothing inbound and everything outbound; SSH from 0.0.0.0/0 is the first rule offered; a rule's source can be another group, which is how tiers reach each other without a CIDR that goes stale; and the private network is never filtered. Named sources or source groups, SSH from anywhere refused unless accepted, egress narrowed only when asked.
tencent-ses
A Tencent Cloud SES domain, its addresses and its templates. The module exposes the exact DNS records Tencent is waiting for, because that is the thing you need next and it lives outside this Terraform. DKIM is on, since unsigned mail is accepted by the API, filed as spam and reported as sent; and a template is reviewed manually before it works.
alicloud-transactional-email
A DirectMail sending domain and the addresses that send from it. Creating the domain does not verify it: nothing sends until the SPF, DKIM, MX and ownership records exist in DNS, which is usually not this Terraform, and the status output is how you find out. trigger and batch are different products with the same name and are throttled and reviewed differently.
upcloud-firewall
The firewall is a per-server rule list evaluated top to bottom, attached by definition but only applied while the server's firewall flag is on; the last rule decides; and SSH from 0.0.0.0/0 is the first rule offered. Your accepts in order with a drop of everything else appended, SSH from anywhere refused unless accepted, egress open until rules narrow it.
alicloud-sae-application
A Serverless App Engine namespace and application with auto_config false, which makes the VPC, vSwitch and security group required rather than letting SAE create three resources that live in your account and nobody's Terraform. Two replicas so a deploy is not an outage, min_ready_instances set so a rollout is actually rolling, and typed liveness and readiness probes.
tencent-scf-function
A Serverless Cloud Function running as the CAM role you name, with public network access off (on by name), in your VPC when a subnet is given, logging every invocation to a CLS logset and topic (none by name), synchronous only, with code fetched from a COS object you uploaded. Memory and timeout are inputs.
aws-opensearch-serverless
A collection cannot exist without an encryption policy and the quickest one uses the AWS-owned key; the network policy decides whether the endpoint answers on the internet; without a data access policy nobody can read or write, with a wide one everyone can; indexes grow until a policy expires them. Private through VPC endpoints (public by name), your key when given, principals named.
scaleway-function
A Scaleway Serverless Function in its own namespace, private so an IAM token is needed to invoke it (public by name), plain HTTP redirected to HTTPS, secrets in the encrypted secret variables rather than the plain ones, idling at zero instances with a ceiling you chose, and the zip archive uploaded at apply with its hash so a changed archive redeploys.
oci-data-flow
An OCI Data Flow application that runs Spark from a file in Object Storage with the driver and executor shapes you size, logs to a bucket you own (required, or the output is lost with the run), reaches your VCN through a Data Flow private endpoint when you give one, stops a run after the ceiling you set and an idle session after thirty minutes, and terminates runs when deleted.
aws-elasticache-serverless
ElastiCache Serverless for Valkey. With no user group, any client that reaches the endpoint connects as the default user with no password, so this module always attaches a Valkey user group whose users sign in with IAM. It sets a storage and ECPU ceiling, since AWS sets none, and keeps 7 days of snapshots. It also says destroy takes no final snapshot.
aws-redshift-serverless
An Amazon Redshift Serverless namespace and workgroup: customer-managed encryption, SSL required, all three logs exported, and the admin password generated and held by Secrets Manager. AWS accepts plaintext connections by default and a usage limit's default action only logs the breach, so SSL is set at creation and the spend limit's action has to be chosen: alert or stop.
huawei-org-policy
An Organizations policy and its attachments. The type - service control, tag or AI service - decides what the JSON means, and the same document in the wrong type either fails to attach or attaches and does nothing recognisable. An SCP is a ceiling that cannot grant, an unattached policy enforces nothing, and a root attachment reaches the management account.
aws-vpc-lattice
auth_type defaults to NONE, so any client in any associated VPC can call any service with no identity and no policy - and associating one more VPC silently grants everything in it. Defaults to AWS_IAM and requires per-VPC security groups.
aws-app-runner
auto_deployments takes every push to the image tag straight to production with no review, which quietly makes the deployment gate "who can push". Off by default, egress routed through your VPC, and the pull role kept separate from the run role.
oci-site-to-site-vpn
Every OCI IPSec tunnel is created with IKE version 1 unless told otherwise, and negotiates from a compatibility list that still accepts SHA-1, AES-128 and DH group 2 - so the weakest option a peer proposes is what it gets, and the tunnel shows UP. IKEv2 on both tunnels, explicit proposals for both phases with the weak ones refused by validation, BGP routing, and one configured tunnel only by name.
azure-vpn-gateway
A connection with no ipsec_policy negotiates from a built-in list that still offers 1024-bit Diffie-Hellman and SHA-1, so a peer that proposes them gets them and the tunnel comes up looking healthy. Always writes an explicit policy and refuses the weak groups. A gateway with no connection bills by the hour for nothing, so the sites come with the gateway; BGP is on, Basic is refused.
gcp-snapshot-schedule
The resource policy is the schedule; a disk follows it only through a separate attachment, so a policy that reads daily-keep-30 in the console and is attached to nothing has never taken a snapshot. Takes the disks with the schedule and refuses one with none. Keeps the snapshots when the disk is deleted, because APPLY_RETENTION_POLICY lets them age out in exactly the window they are needed.
tencent-backup-policy
A CBS snapshot policy and the disks it runs against, because an unattached policy has a schedule and a retention and protects nothing. The hours are UTC, not your clock. Retention is always set, since a policy without one keeps every snapshot forever, and retained_snapshots_per_disk is the number the storage bill is made of.
do-spaces-bucket
A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.
aws-emr-serverless
Without network_configuration the application runs on AWS-managed networking: it cannot reach a private database, and its egress skips your routing, NAT and DNS firewall. Monitoring is absent by default too, so a failed job leaves no executor logs, and no maximum_capacity makes the account quota the only ceiling.
tencent-static-site
A COS bucket serving a static website. The public-read ACL that makes the objects readable also lets anyone list the bucket, and file_list_is_public says so; pass a bucket policy to publish the objects alone. redirect_all_requests_to on COS is a protocol rather than a hostname, which is why it is not exposed here.
huawei-static-site
An OBS bucket serving a static website, published by an OBS-format bucket policy rather than a public-read ACL, so the file list stays private. Encryption is off on purpose: every byte is published deliberately, and an anonymous reader holds no permission on your key, so a key of your own hides nothing and stops the site working.
alicloud-static-site
An OSS bucket serving a static website. The ACL stays private and a bucket policy publishes the objects, because a public-read ACL also lets anyone list every file you ever put there. The website endpoint is plain HTTP on an Alibaba domain and no certificate can go on it, so serves_https is an output and it says false.
scaleway-static-site
A Scaleway Object Storage bucket serving a static website. A bucket policy here is version 2023-04-17, not the AWS 2012-10-17 that every S3 example carries and Scaleway has deprecated, and the module checks which one you passed. Without a policy the public-read ACL also publishes the file list, which file_list_is_public reports.
azure-app-configuration
local_auth_enabled defaults true and the keys carry no identity: a read key reads every value, cannot be scoped, and is revoked only by regenerating it for everybody. Purge protection defaults off, and purging frees the name - which frees the endpoint your applications trust.
oci-streaming
A public stream pool is an FQDN reachable from anywhere with a valid token; auto_create_topics lets any producer create a stream by writing to a new name; retention defaults to 24 hours, so a consumer a day behind loses data with no error on the producer side. Private endpoint behind NSGs, declared streams, seven days of retention, and the stream that loses data soonest reported as an output.
azure-synapse
A Synapse workspace with a dedicated SQL pool and no SQL login: Entra-only authentication with a group as admin, a managed virtual network with data exfiltration protection (neither can be turned on later), public endpoints off, extended auditing and threat detection on the workspace and the pool, and vulnerability scans when you name a container. The pool bills by the hour while online.
tencent-database-migration
A DTS sync job and its configuration, created together, because creating the job alone starts billing a replication instance that replicates nothing - the easiest thing in this product to leave behind. encrypt_conn is on at both ends, retry is set so a transient fault does not end the job, and object mode All has to be taken by name.
tencent-tcr
A Tencent Container Registry basic instance (pay-as-you-go; the premium editions are a purchase) with public network access off unless accepted by name and a security policy of allowed ranges when it is on, deletion protection on, versioned storage, and namespaces from a map that are private, scan every pushed image and refuse to pull one at or above the severity you set, with their repositories.
alicloud-tablestore
A Tablestore instance whose accessed_by is Vpc rather than the Any the API defaults to, so an AccessKey and the public endpoint are not enough to read it, plus the tables you declare - each with server-side encryption on, which cannot be added later, and each naming a time to live, because a table set to never expire grows forever.
ibm-devops
An IBM Cloud CD toolchain, Tekton pipeline, definition and triggers. Without a definition the pipeline is enabled and has no tasks while everything looks finished. enable_events_from_forks runs the pipeline with its own credentials for anyone who can open a pull request, so it is off and refused by name, and omitting a concurrency limit disables it entirely.
tencent-redis
A TencentDB for Redis instance in your VPC with a replica per shard (none by name), a password required rather than no_auth, security groups attached (none by name), no public address, and a recycle window that holds a deleted instance for seven days; force deletion is accepted by name. Pay-as-you-go.
scaleway-transactional-email
A Scaleway Transactional Email domain with the SPF, DKIM, DMARC and MX records it needs exported (and written automatically when the domain is in Scaleway DNS), the terms of service accepted by name, and a validation step that polls until the records resolve so an apply fails rather than pretends when they are not published yet.
gcp-storage-transfer
delete_objects_unique_in_sink turns a backup into a mirror: an object deleted at the source is deleted at the destination on the next run, replicating the event the copy was meant to survive; and a job with no notification fails while its status stays ENABLED. Copies only, refuses mirroring and moving unless accepted, publishes every outcome to a topic, and spells out what the service agent needs.
aws-datasync
preserve_deleted_files = REMOVE deletes files at the DESTINATION that are absent from the source, so an unmounted share or a renamed path empties the destination on schedule and the task reports success. PRESERVE here, with verification on, a bandwidth ceiling so it cannot take the whole Direct Connect, and a per-file report of what failed.
aws-rolesanywhere
Any certificate chaining to the trust anchor can exchange itself for AWS credentials, so the CA is the perimeter - and it is usually run by people who were never told. The profile carries the scope, sessions are narrowed below the role, the caller cannot name itself in CloudTrail, and CA expiry warns before every workload loses credentials at once.
ibm-trusted-profile
An IAM trusted profile, which is identity without an API key: policies that grant roles on one service and resource group each (Administrator by name), and links to the virtual servers or Kubernetes service accounts that may assume it through the metadata service, since a profile with no link is assumed by nobody (accepted by name).
cloudflare-turnstile
The widget secret is the whole check: whoever holds it mints passing verifications for your forms; domains is an allow list of hostnames, so a widget made for production does not render on staging until staging is listed; and the mode decides whether visitors see a checkbox, a spinner or nothing. Hostnames required, the mode validated, and the secret exposed only as a sensitive output.
ibm-image
An IBM Cloud VPC custom image made from a boot volume, wrapped with the Key Protect or HPCS key you name (provider-managed encryption has to be accepted by name), with deprecation and obsolescence dates so the fleet is told when to move on and cannot launch an obsolete image. Stop the instance first.
huawei-vpcep-endpoint
A Huawei Cloud VPC endpoint (interface type) to an endpoint service, with a private IP in your subnet, the whitelist on and set to the CIDRs you name (an empty whitelist admits the whole VPC and has to be accepted by name), and the service's domain registered in the VPC's private DNS.
ibm-file-share
An IBM Cloud VPC file share (NFS) wrapped with your Key Protect or HPCS key (provider-managed by name), with one mount target on a virtual network interface in your subnet behind the security groups you name, using user-managed transit encryption (plain NFS has to be accepted by name). One zone; a fleet in two mounts across or replicates.
ibm-vpc-load-balancer
type defaults to public, so a load balancer created without one gets an internet address; the pool's health check can be a TCP handshake; a port-80 listener forwards unless a listener policy redirects it; and logging is off. Private with public by name, an HTTP check on a path, a 301 policy on 80 whenever a Secrets Manager certificate is given, two subnets unless one is accepted, logging on.
alicloud-vpc-peering
A peer connection between two VPCs with a route entry written into every route table you list, on both sides, for every CIDR of the other side, because an Activated peering carries nothing until the routes exist. A default route through a peering is refused, and a cross-account peering that the other account has yet to accept has to be taken by name.
aws-vpc-peering
A VPC peering between two VPCs in one account and region, accepted in the same apply, with DNS resolution across it and routes written in every listed route table on both sides for every CIDR of the other. A default route through a peering is refused (CKV2_AWS_44). Peering is not transitive; past a handful of VPCs the transit gateway is the product.
huawei-vpc-peering
A peering connection between two VPCs with a route written into every route table you list, on both sides, for every CIDR of the other side. A cross-tenant peering sits in PENDING_ACCEPTANCE and its other side is out of reach of this provider, so the module refuses an accepter route table list in that case rather than failing at apply.
ibm-vsi-instance
A VPC virtual server in your subnet with the SSH keys you name and no password, security groups on the primary interface, no floating IP, the boot volume encrypted with a Key Protect key (IBM's key by name), secure boot on, and the metadata service on so a trusted profile can be the instance identity instead of a stored API key.
scaleway-vpc
A Private Network created without a subnet gets a /22 the platform picked, the one most likely to collide with the office or the next network; VPC routing forwards between every Private Network, and the ACL that filters that traffic does not exist until you create it. Subnets required per network, a named VPC rather than the project default, and a drop-by-default ACL from the rules you give.
vultr-vpc
v4_subnet is optional, so a VPC created without it gets whatever range was free, the one most likely to collide with the office network or next year's VPN; and a VPC is a range, not a network - instances on it reach each other on every port and firewall groups do not filter the VPC interface. The range required, and outputs that say nothing inside is filtered and nothing peers across regions.
alicloud-vpn-gateway
An Alibaba Cloud VPN gateway (pay-as-you-go; subscription by name) with a customer gateway and one IPsec connection on IKEv2 negotiating AES-256, SHA-256 and DH group 14 in both phases, the weak options refused by validation and IKEv1 accepted only by name, dead peer detection and NAT traversal on, and the remote subnets' routes written for you.
tencent-vpn-gateway
A Tencent Cloud VPN gateway (pay-by-hour; prepaid by name) with a customer gateway and one policy-based IPsec connection on IKEv2 negotiating AES-CBC-256, SHA-256 and DH group 14 in both phases. Tencent's own defaults are 3DES, MD5 and group 1; the validations refuse them, IKEv1 is accepted only by name, and dead peer detection restarts a dead tunnel.
gcp-vertex-ai-search
A Vertex AI Search data store in eu, us or global (residency, no default, cannot change), encrypted with a Cloud KMS key of yours (the Google-managed key by name), indexing documents, structured records or a website as you choose, and the search engine over it on the standard tier; the enterprise tier is an input and the LLM add-on, which bills per query, is accepted by name.
alicloud-express-connect
A virtual border router on a physical connection you already have, with BFD on so a dead circuit is noticed in milliseconds rather than at the BGP hold timer, and an optional Express Connect Router attachment. Without that attachment the circuit terminates at the border router, which looks like a working connection and routes nothing. Sitelink is billed and off.
huawei-direct-connect
A Direct Connect virtual gateway on a VPC and a virtual interface on a connection you already have. bgp_md5 is the only authentication the session has and it is optional in the API, so it is required here. The two endpoint groups are where this goes wrong quietly: a wrong prefix gives a circuit that is up, a session established, and traffic that disappears.
ibm-vpe-gateway
An IBM Cloud VPC virtual private endpoint gateway to a cloud service, with a reserved IP in each subnet you name (one zone has to be accepted by name), behind the security groups you name (the VPC default group by name), and DNS resolution binding enabled so the VPC resolves the service to the gateway.
azure-virtual-wan
A hub is billed from the moment it exists and routes nothing until something connects; disable_vpn_encryption sends branch traffic in clear; and a VNet connection without internet security sends 0.0.0.0/0 out its own default route, bypassing the hub firewall. Connections come with it, branch encryption stays on, every connection routes the internet through the hub, and the prefix must be a /23.
civo-volume
A volume belongs to a network and attaches only to instances in it; this provider exposes no volume snapshot and no schedule, so data on it is backed up by something on the instance or not at all; and a volume attached without attach_at_boot does not come back after a reboot. Network required, attached at boot, and an output that says snapshots are not available.
hetzner-volume
delete_protection defaults to off, a deleted volume is gone at once with no soft delete and nothing to restore from, and server snapshots do not include volumes. Protection on and off only by name, a filesystem so automount works, exactly one of server or location, and an output that says volume snapshots do not exist.
vultr-dns-zone
A Vultr DNS zone with every record in one map, DNSSEC on (the DS record still has to go to the registrar), and the nameservers exported because the zone answers nothing until the registrar delegates to them. The apex A record Vultr offers to write at creation is not used, so nothing exists outside the map.
vultr-snapshot
A Vultr snapshot of an instance, which is Vultr's custom image: global, deployable in any region, billed per gigabyte stored. The snapshot is the instance at that moment, secrets and all, so build the source clean and stop it first; the description carries the build.
azure-waf-policy
Detection mode evaluates every rule, logs every match and forwards every request - the dashboard fills with blocked-looking entries while the backend receives them all. Prevention by default, Detection only by name. A policy attached to no listener protects nothing, so the attached listeners are an output; every exclusion is a hole and has to carry a reason.
ibm-waf
The CIS managed and OWASP core rulesets deployed on an IBM Cloud Internet Services domain, with the OWASP threshold, action and paranoia level set. The resource owns the whole managed phase, so console rules are overwritten, and destroying it leaves the WAF running - the module says so and makes turning it off an explicit step. The deprecated legacy WAF resources are not used.
tencent-waf
A domain on a Tencent Cloud SaaS WAF, rules set to block, with block and allow lists. It reads back the CNAME, the mode the WAF reports and the addresses the WAF forwards from, so the origin can refuse everything else. An allowlist here lets addresses through; it does not make a site private. The client IP is taken from the connection unless you say a proxy sits in front.
oci-waf
CHECK is the action that evaluates the rule, logs the match and lets the request through - the console shows the protection rules and every matched attack reached the backend. BLOCK by default, DETECT only by name. The policy and the firewall binding it to a load balancer are separate resources; both are created, and a policy alone has to be asked for.
alicloud-hbr-backup
A Cloud Backup vault encrypted with your KMS key (the HBR-managed key by name), zone-redundant, with WORM on so a compromised account cannot delete the copies (off by name, and it cannot be turned on again later), a policy that backs up daily and keeps thirty days, and a binding for every ECS instance in the map, because a vault with no policy and no binding backs up nothing.
ibm-static-site
An IBM Cloud Object Storage bucket serving a static website. The public policy grants Object Reader, which IBM documents as download without listing, rather than Content Reader, which lists. It names the two account settings that silently switch public access off, says the endpoint is plain HTTP, requires you to accept that everything in it is public, and expires old versions.
gcp-dlp
Sensitive Data Protection on a schedule: an inspection template naming the detectors and a weekly trigger over a bucket or a BigQuery table, sampling ten percent of each file, scanning only what changed since the last run, with findings written to your dataset without the matched values and a summary sent to Security Command Center. A full scan, billed per byte, is accepted by name.
oci-os-management-patching
An OS Management Hub scheduled job that installs every available update (security-only and the other partial operations by name) on the managed instance groups or compartments you name, weekly by an RRULE from a first run you set in the future, with a reboot window per instance and retries. Instances have to run the agent and be registered with a software source to be seen.
aws-athena
Query results are a copy of the data, written to S3. Without enforce_workgroup_configuration - the AWS default - a client sends its own location and encryption and every setting becomes a suggestion.
cloudflare-waf
A paid plan makes the Cloudflare Managed Ruleset and the OWASP Core Ruleset available; a zone runs them only when a rule in the managed phase executes them, so a subscribed zone with no such rule is protected by the free ruleset alone. Both executed here with the OWASP threshold set, custom rules that block rather than log, and a per-client rate limit in its own phase.
gcp-recaptcha
A key with a testing score returns that score for every assessment, bots included - right for staging and, on a production key, a filter that filters nothing; allow_all_domains lets any site consume your assessments against your quota. Testing mode refused without acceptance, domains required on web keys, invisible scoring by default; only a backend assessment call turns a token into a decision.
huawei-network-firewall
Address groups and ACL rules on a Cloud Firewall protected object, with antivirus turned on since it is a separate resource and a complete rule set says nothing about it. Huawei takes a placement rather than a position, so order is not determined by the file: place_at_top pins the one rule that matters and the module says plainly that the rest must not overlap.
aws-acm
Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.
aws-private-ca
A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
oci-api-gateway
Managed API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.
gcp-api-gateway
A serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.
aws-apigateway-http
HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.
aws-apigateway-rest
A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.
azure-api-management
An API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.
ansible-aws-cli-v2
The AWS CLI v2 from the upstream zip, verified with gpg against the AWS CLI Team key (pinned by fingerprint, in a GnuPG home of its own) before it is unpacked. EL 10 has no package; most installs run curl | unzip and never read the signature. Pinned version, tab completion, and a live test that runs an API call to 'Unable to locate credentials'. Original role, live-tested on Rocky Linux 10.
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
aws-account-baseline
The IAM password policy, S3 account-wide Block Public Access and, per region, default EBS encryption, snapshot and AMI sharing blocks, IMDSv2 as the default and the serial console off. Five of these are per region, so the module covers a list. The password policy follows NIST SP 800-63-4, and the module says which settings destroying it turns back off.
ibm-activity-tracker
Activity Tracker Event Routing with a COS target written service-to-service (no API key stored), a route that sends every location's events to it (a narrower list by name), and the account settings that keep routing metadata in your region, make the target the default, and answer the routing API on private endpoints only. Without a route, events go nowhere you keep.
akamai-appsec-waf
Security configuration with policy, WAF mode, match targets, rate controls, and IP/geo blocking, activated to staging or production.
ansible-akamai-cli
akamai on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one pinned beside the version: the value Akamai publishes as a .sig file, which is not a signature but the bare hash of the binary. The live test checksums the asset again and runs the CLI to its command list. Sub-CLIs and credentials are per user. Original role, live-tested on Rocky Linux 10.
akamai-cps-dv-certificate
Automated Domain Validated TLS enrollment with DNS/HTTP challenge outputs wired for Edge DNS.
akamai-edge-dns-zone
Authoritative Edge DNS zone with full recordset management on Akamai's DDoS-resilient anycast network.
akamai-cloudlets-edge-redirector
Rule-driven edge redirects (vanity URLs, migrations) managed as code with versioned policy activation.
akamai-edgeworker
Deploy JavaScript at the edge with bundle versioning, EdgeKV namespace, and network activation in one module.
akamai-gtm-failover
Global Traffic Management domain with datacenters and failover or weighted-round-robin properties plus liveness tests.
akamai-property-ion
End-to-end Ion CDN property: origin, edge hostname, caching/performance rule tree, CP code, and staging/production activation.
akamai-network-lists
Versioned IP and geo block/allow lists with activation, ready to feed WAF policies and property rules.
oci-monitoring-alarms
An email subscription delivers nothing until somebody clicks its confirmation link, and until then every alarm publishes to a subscriber who is not there; repeat_notification_duration is null by default, so an alarm fires once at 3am and is never mentioned again. Creates the topic, subscriptions and alarms together, repeats while firing, and lists the subscriptions still waiting on a click.
ansible-alertmanager
Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.
do-monitoring
An alert policy with no email and no Slack webhook is valid, evaluated and triggers to nobody; CPU, memory and disk metrics exist only where the agent runs; and an uptime check without its alert resource is a status page. A recipient required, CPU/memory/disk defaults by tag, the agent-dependent alerts listed, and a down alert plus optional latency and certificate-expiry alerts on every check.
alicloud-ack-cluster
Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.
ansible-aliyun-cli
aliyun on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Alibaba's SHASUMS256.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a profile stops at 'aliyun configure'. Original role, live-tested on Rocky Linux 10.
alicloud-vpc-foundation
Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.
ansible-alloy
Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.
gcp-alloydb
AlloyDB cluster with primary + read-pool instances, PSC connectivity, automated backups and columnar/vector engine flags.
alicloud-alb
The default TLS policy accepts TLS 1.0; a server group's health check can be turned off and then sends traffic to every member forever; an HTTPS listener does nothing about port 80; and deletion protection is off. A TLS 1.2/1.3 policy created and attached, an HTTP health check on a path, a redirect on 80 whenever a certificate exists, two zones unless one is accepted, deletion protection on.
huawei-api-gateway
A Huawei Cloud APIG dedicated instance, group, environment and published APIs. The provider defaults an API to no authentication; this module defaults to signed app requests and takes open or plaintext APIs one at a time. Every published API gets the required rate limit, the gateway stays off the internet unless asked, and the debug hostname stays off.
alicloud-api-gateway
An API Gateway group, the APIs in it, and an access control list created WITH its attachment, since an unattached list looks exactly like protection in the console. auth_type ANONYMOUS means anybody with the URL calls the backend and has to be taken per API; force_nonce_check is on for every app-authenticated API, because without it a captured signed request can be replayed.
alicloud-actiontrail
An ActionTrail trail that records every region and both reads and writes (narrower by name), delivered to an OSS bucket you own through the service role and, when a project is given, to Log Service for queries. The console keeps ninety days and forgets; the trail is what keeps more. An organization trail collects every member account from the management account.
huawei-vpn-gateway
A Huawei Cloud Enterprise VPN gateway in active-active mode across two zones with two EIPs, a customer gateway, and a static-route connection from each EIP to the peer on IKEv2 negotiating AES-256-GCM, SHA2-256 and DH group 14 in both phases (the weak options refused, IKEv1 by name), with dead peer detection and network quality checks on.
aws-mwaa
webserver_access_mode defaults to PUBLIC_ONLY, and the Airflow UI is not a dashboard: anyone who reaches it can trigger a DAG, which is arbitrary Python running as the execution role. PRIVATE_ONLY here, all five log streams on, and a precondition refuses an unpinned requirements.txt or plugins.zip - where bucket write access is otherwise the same permission as code execution.
alicloud-dns-zone
An Alibaba Cloud DNS zone with every record in one map, all on the default resolution line so every resolver gets the same answer, and the nameservers Alidns assigns exported for the registrar. DNSSEC is a console setting on paid editions rather than a resource; dnssec_available says so.
aws-amplify-app
Every branch build is served at a public amplifyapp.com URL, and basic auth, the switch that puts a password on it, is off; auto branch creation builds every branch anyone pushes; the repository token lands in state; and environment variables are plaintext. Basic auth on every non-production branch (public by name), auto creation off, exactly one production branch, the custom domain attached.
oci-analytics
The network endpoint is public by default with no allow list; the encryption key is Oracle's unless a vault key is given; and an instance with no notification email is upgraded and restarted with nobody told. Private endpoint in your VCN behind NSGs, a vault key expected, a notification address required, and capacity set as OCPUs or users on purpose.
huawei-app-platform
A CAE environment, application and components. deploy_after_create is off in the API, so a component exists with a source, a runtime and a replica count and serves nothing; it is on here. The runtime list still offers Java8, Nodejs8 and Php7, which the module names and asks about, and 500m of CPU cannot take 4Gi of memory.
aws-elastic-beanstalk
AWS Elastic Beanstalk with the defaults turned the right way: managed platform updates are ON (AWS leaves them off, so the platform is never patched), health reporting is enhanced rather than basic, logs stream to CloudWatch and survive termination, IMDSv1 is disabled, deployments go out in batches instead of all at once, and application versions are pruned before they hit the quota.
alicloud-redis
An ApsaraDB for Redis instance in your VPC with the replica in a second zone, TLS required, the security_ips allow-list written from your ranges (0.0.0.0/0 by name), a password from a secret store never output, transparent encryption with your KMS key (the service's by name), daily backups, a maintenance window, and release protection on. Pay-as-you-go.
aws-cloudtrail-lake
A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.
alicloud-image
An Alibaba Cloud custom image captured from an ECS instance into an image family, so instances and scaling groups that name the family get the newest image (no family has to be accepted by name). The snapshots the capture created are deleted with the image. Build the source clean and stop it first.
alicloud-ecs-instance
An ECS instance in your vSwitch with login by key pair and no password, no public address unless bandwidth above zero is accepted by name, the system disk encrypted with your KMS key (the service key by name), the metadata service on IMDSv2 only with a hop limit of one, the Security Center agent on, and deletion protection. Pay-as-you-go.
huawei-ecs-instance
An ECS instance in your subnet with login by key pair and no password, no elastic IP unless one is accepted by name, the system disk encrypted with your KMS key (the platform key by name), an IAM agency as its identity so code on it needs no stored access key (none by name), the Cloud Eye agent on, and the instance stopped before destroy with its disks. Pay-per-use.
tencent-emr-cluster
An EMR cluster with need_master_wan set to NOT_NEED, because the API defaults to NEED and that puts the node running YARN's resource manager and the cluster web interfaces on the internet. support_ha is on, since one master is not a failover, and the security group the API leaves optional is required here.
alicloud-emr-cluster
An E-MapReduce cluster with security_mode KERBEROS, because NORMAL is the default and a NORMAL cluster comes up, answers on YARN and HDFS, runs Spark, and never checks that a submitter is who they say they are. Both disk encryption flags are on, deletion protection is on, and spot instances on a MASTER or CORE group are refused.
scaleway-cdn
Edge Services is a chain of stages, each naming the one it forwards to, and every stage is content to exist naming nothing: a half-wired pipeline shows a name and a status in the console and answers no requests. This builds the whole chain, subscribes the plan without which nothing serves, and puts a certificate and your own domain in front of a bucket.
gcp-secure-web-proxy
A gateway with no rules allows nothing, and a session matcher of true is an open proxy to the internet; the gateway needs a proxy-only subnet in the region that is yours to make; and without TLS inspection the proxy sees the SNI hostname and nothing inside. Rules built from a URL list of your hosts, allow-all accepted by name only, outputs that say what is allowed and that TLS is not inspected.
tencent-elasticsearch
An Elasticsearch cluster with basic_security_type 2, because 1 is no username and no password at all and anything that can reach the cluster could read and delete every index. The search API, Kibana and Cerebro each have their own public switch and all three are closed; automatic backup to COS is on, and destroy protection with it.
alicloud-elasticsearch
An Elasticsearch cluster on the current node-configuration blocks rather than the deprecated flat fields. enable_kibana_public_network defaults to true in this provider and is false here, the search endpoint is private, the data disks are encrypted, and an empty private whitelist is refused because Alibaba reads it as every address that can reach the VPC.
tencent-cbs-disk
A snapshot policy and its attachment are separate resources, so a policy in the console with no disks is the usual state; encrypt defaults to false and cannot be changed after creation; and force_delete takes a disk with data on it. Encrypted always with your KMS key or Tencent's, a policy created or yours attached (none by name), attached to the instance you give, never force-deleted.
alicloud-ecs-disk
An automatic snapshot policy is one resource and its attachment to a disk is another, so a policy in the console with no disks is the usual state; encrypted defaults to false and cannot change after creation; and delete_auto_snapshot can take the snapshots with the disk. Encrypted always, a policy created or yours attached (none by name), the disk and its snapshots outliving the instance.
huawei-evs-disk
A backup on Huawei Cloud is a vault, a policy and a resource list that exist separately, so the common state is a policy with no vault or a vault with no disks; and a disk is encrypted only when a KMS key is given. The vault created with the policy applied and the disk as its resource (none by name), a key expected (none by name), attached to the instance you give.
upcloud-storage
encrypt defaults to false and cannot change after creation; and the backup rule is the rare schedule that lives on the device itself, so it cannot be forgotten separately but can still be left out. Encryption on, a daily backup at 02:00 UTC kept 30 days unless told otherwise (none by name), filesystem resize opt-in, and the device attached from the server side in its zone.
alicloud-nat-gateway
An enhanced, pay-as-you-go NAT gateway for an existing Alibaba Cloud VPC, with a PayByTraffic elastic IP whose bandwidth cap every subnet shares, and an SNAT entry for each vSwitch listed, because a gateway with no SNAT entry forwards nothing. Deletion protection is on for the gateway and the address; off has to be accepted by name.
huawei-enterprise-router
A Huawei Cloud Enterprise Router across two zones with default association and propagation off, the route tables you name, and a VPC attachment per VPC each associated with one table and propagating into the tables you list, with routes to the router written into each VPC. Shared attachments from other accounts wait for you unless auto-accept is turned on by name.
exoscale-dns-zone
An Exoscale DNS zone with every record in one map (the apex written as the empty name Exoscale expects) and the four nameservers exported for the registrar. Exoscale does not sign zones; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.
exoscale-instance
An Exoscale compute instance on a Private Network with security groups and the SSH keys you name, created private so it has no public interface (public by name), secure boot and the TPM on where the template supports them, IPv6 off, and destroy protection (off by name).
azure-expressroute
A provider circuit is a clear-text path across the provider's network - MACsec is for Direct ports only, and IPsec over the private peering is yours to build - so the module requires that to be stated and exports encrypted = false. The SKU tier decides where the circuit reaches; a circuit with no peering carries nothing once provisioned. Private peering with its /30 pairs and VLAN is created here.
azure-hdinsight-spark
An HDInsight Spark cluster in your virtual network, reached over a private link, on ADLS Gen2 through a user-assigned identity so no storage key sits in state, with encryption in transit and TLS 1.2 on the gateway. There is no scale-to-zero: nodes_at_rest says what bills when the cluster idles. An external Hive metastore makes the cluster disposable; the public gateway is accepted by name.
huawei-iam-agency
An IAM agency that the Huawei Cloud service you name (ECS, FunctionGraph, CCE) assumes on your behalf, so instances and functions that name it need no stored access key, with roles scoped to the projects you list; account-wide roles and Tenant Administrator are each accepted by name. The delegation to a service does not expire.
scaleway-iam-application
A Scaleway IAM application, the non-human identity a workload authenticates as, with a policy of rules granting permission sets in the projects you name (organisation scope and the full-access sets by name) and an API key that expires at a time you set (no expiry by name), whose secret is a sensitive output.
exoscale-iam-role
An Exoscale IAM role that refuses every service it does not name (allow-by-default by name) and allows the ones it does either whole or by CEL rules on the operation, not editable in the console so the module stays the source of truth, with an API key bound to it whose secret is a sensitive output.
gcp-cloud-ids
Creating the endpoint creates no packet mirroring policy, so an endpoint with nothing mirrored is provisioned, billed by the hour, shown with a green check and has never seen a packet. The mirroring policy is created with it and refused when it mirrors nothing. Cloud IDS detects and never blocks; blocks_traffic is an output that is always false.
huawei-image
A Huawei Cloud private image captured from an ECS instance's system disk on the current IMS resource, with memory bounds for instances launched from it. Encryption follows the source disk (an unencrypted source has to be accepted by name), and the name carries the build. Build the source clean and stop it first.
aws-gateway-load-balancer
A Gateway Load Balancer for firewall or IDS appliances, its endpoint service and endpoints. AWS turns cross-zone off, keeps flows on failed appliances and leaves deletion protection off by default; this module turns cross-zone and protection on and makes flow failover an explicit choice. It also says plainly that nothing is inspected until route tables point at the endpoints.
azure-iot-hub
Shared access keys are symmetric credentials that grant everything their policy names and are revoked only by regeneration; the endpoint is public by default; telemetry that matches no route is dropped when the fallback route is off; and the built-in endpoint keeps one day. Keys off, private endpoints, TLS 1.2, the fallback route on so unrouted telemetry lands, and seven days of retention.
azure-machine-learning
The workspace endpoint is public by default, and the managed network compute runs in defaults to Disabled isolation - unrestricted outbound internet from a network that holds training data. Private workspace, outbound isolation on, high-business-impact flag set so less leaves for Microsoft, identity-based storage access, and a customer-managed key; the four dependencies stay yours.
alicloud-mns-queue
A Message Service queue with a dead-letter queue that receives a message after five failed receives, long polling, logging on (it is off by default and is the only record of what was sent), and server-side encryption with your KMS key on both queues (the service key by name).
huawei-mapreduce
A MapReduce Service cluster with safe_mode true, since false turns Kerberos off and leaves a cluster where Manager answers and nothing authenticates anybody. A node credential is required rather than left to the API, MRS Manager stays off the internet unless asked, and log collection is on so a cluster that fails to build does not take the reason with it.
azure-storage-mover
Azure Storage Mover from an NFS share to a blob container: the mover, project, endpoints and job definition, with the agent registered from its Arc machine and granted Storage Blob Data Contributor when its IDs are given. Additive copy mode; Mirror, which deletes at the target what the source no longer has, is accepted by name. The run itself is started outside Terraform.
azure-network-security-group
Every NSG carries default rules nobody wrote; a group with no subnet or NIC association is a rule set in the portal that filters nothing; and SSH and RDP from Internet are the first rules the portal offers. Your allows in priority order with an explicit DenyAllInbound at 4000, subnets associated by the module (none by name), 22 and 3389 from Internet refused unless accepted.
oci-network-security-group
An NSG with no rules admits nothing and sends nothing, so a group written with ingress only has VNICs that cannot resolve DNS; a stateless rule drops every reply that has no matching egress; and the subnet's security list still applies, unioned with the NSG. Stateful always, egress explicit and open by default, SSH from 0.0.0.0/0 refused unless accepted, the security list named as still applying.
huawei-obs-bucket
Public access is two switches: a private ACL still leaves a bucket policy free to grant anonymous reads, and only Block Public Access refuses both; versioning and encryption are both off by default; abandoned uploads bill until a rule aborts them. Private ACL plus BPA with public by name, versioning on, encrypted with the region's key or yours, incomplete uploads freed after a week.
alicloud-oss-bucket
Public access is two switches: a private ACL still leaves a bucket policy or an object ACL free to grant anonymous reads, and only Block Public Access refuses both; versioning is off by default and once on can only be suspended. Private ACL through its own resource plus Block Public Access, public by name, versioning always on, encrypted, abandoned uploads aborted.
civo-object-store
A store is a bucket with a size ceiling that turns into refused writes far from the cause; a store created without a credential gets the account's default one; and the service has no versioning, no lifecycle and no object lock, so an overwrite is the end of the object. The ceiling set, a credential of its own, and outputs that say versioning and lifecycle are not available.
oci-opensearch
security_mode PERMISSIVE runs the security plugin, evaluates every request and lets unauthenticated ones through - the migration mode clusters stay in - and DISABLED does not evaluate at all; both look like a cluster with the plugin. ENFORCING with a master user, three masters because one is no quorum, two or more data nodes, an NSG because it is the only network control, and maintenance emails.
tencent-landing-zone
Tencent organization nodes and members. policy_type takes one value and it is Financial: what a membership grants is numbered billing permissions, not a governance boundary, and is_a_policy_boundary says false. The permissions are taken as words and written as the integers Tencent wants, and the one that moves money is asked about.
huawei-landing-zone
An organization, its units and its accounts. enabled_policy_types is what makes a service control policy attachable at all: without it a policy is created and fails to attach, at apply, behind a clean plan, and neither console connects the two. The account email and phone are the recovery path, so an account with none is listed as an output.
cloudflare-origin-ca-certificate
A certificate for the hop between Cloudflare and your origin. It is trusted by Cloudflare and by nothing else, so it is right only when the origin accepts Cloudflare alone. A CSR is required precisely so the key stays where it was generated, and the validity is one year rather than the fifteen the API offers, since that is how long a leaked key stays usable.
cloudflare-health-check
A health check on an origin with allow_insecure false, since an origin whose certificate expired last week passes a check that was told not to look. expected_body is what tests the application rather than the web server, because an error page, a maintenance page and a page saying the database is unreachable are all 200s. Two consecutive failures, not one.
cloudflare-r2-bucket
R2 has no versioning: an overwrite or delete is the end of the object, and the only control that refuses deletion is a bucket lock rule, which a bucket without one needs to accept by name. Abandoned multipart uploads bill until a lifecycle rule aborts them. Private with no domain attached, lock rules taken, incomplete uploads freed after a week, and the EU or FedRAMP jurisdiction set at creation.
ovh-object-storage
Versioning is off by default; encryption is off until an algorithm is named; and a user's S3 credential reaches every container in the project unless a policy narrows it. Versioning on with off by name, object lock decided at creation, AES256, abandoned uploads freed after a week, and a user of its own whose S3 policy allows this container and nothing else.
huawei-sfs-turbo
A Huawei Cloud SFS Turbo file system (NFS) in your subnet, encrypted with your KMS key (unencrypted has to be accepted by name), behind the security group you name and which the module does not open, on the standard or performance tier with the capacity you provision.
scaleway-queue
A Messaging and Queuing SQS queue with a dead-letter queue that receives a message after five failed receives, long polling so an idle consumer costs nothing, and two credentials: one that can manage, held by Terraform to create the queues, and one that can only publish and receive, exported for the application so it never holds a key that can delete queues.
huawei-swr
A SoftWare Repository for Container organization, which is the namespace images are addressed under, with the repositories you list created in it, each private unless a public one is accepted by name. Who may push and pull is an IAM decision per organization or repository, made outside the module.
upcloud-nat-gateway
An UpCloud network gateway with the NAT feature attached to a router, so every private network on that router gets a way out; the router (upcloud-network creates one) is the input. The gateway is zonal and starts with the apply; the plan (advanced or production) is the throughput ceiling and the hourly bill from creation.
upcloud-storage-template
An UpCloud storage template made from a server's storage, which is UpCloud's custom image, labelled by role and build (unlabelled has to be accepted by name). The template lives in the zone of its source and is the storage at that moment, secrets and all: build the source clean and stop the server first.
do-uptime-check
An uptime check and its alerts, which are separate resources: a check on its own draws a graph somebody would have to go and look at and pages nobody, and it looks identical to one that does. Three regions by default, since one cannot tell the target being down apart from that region's path to it. The latency alert is the one that catches the slow death.
gcp-uptime-check
A Cloud Monitoring uptime check from static-address checkers in several regions, over TLS with the certificate validated (off by default), asserting on the body when you give it text, with failures logged, and the alert policy on check_passed that sends to your notification channels. Plain HTTP and a policy with no channels are each accepted by name.
ansible-kafka
Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.
ansible-httpd-tls
httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.
vault-approle
A secret ID with no TTL and no use limit is a password, and both default to unlimited; a role with no bound CIDRs logs in from anywhere; and a role with no max TTL mints tokens that renew forever. Secret IDs that live an hour and are used once, roles bound to the ranges they run from with unbound accepted by name, and token ceilings set.
azure-application-gateway
Regional L7 load balancer with WAF v2 policy, TLS termination from Key Vault, autoscaling and health probes.
aws-alb
ALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.
ansible-argocd-cli
The argocd client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's cli_checksums.txt, and re-checked with sha256sum -c by the live test, which then runs argocd app list with no server and expects 'server address unspecified'. The server is a cluster install, not this role. Original role, live-tested on Rocky Linux 10.
ansible-argo
argo on EL 10 from the GitHub release; the asset is a bare gzip; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has lint --offline pass a valid Workflow and fail one whose entrypoint is missing (exit 1); list stops at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.
gcp-artifact-registry
Docker/Maven/npm repos with cleanup policies, remote and virtual repositories, CMEK and reader/writer IAM.
ansible-atmos
atmos on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the one in the vendor's SHA256SUMS, and the live test re-checks it, then writes an atmos.yaml, a stack and a component, validates the stacks and describes the component with no Terraform installed. Pinned. Original role, live-tested on Rocky Linux 10.
gcp-audit-logging
Data Access logs are off by default for every service but BigQuery, so a project that never turned them on has no record of who read the bucket, queried the table or fetched the secret. Enables all three log types for allServices, narrows per service where read volume is a real cost, and requires a reason for every exempted member - the setting an intruder with IAM rights would add.
oci-audit
Audit retention set to the 365-day ceiling OCI allows, plus the archive for everything past it: a private bucket with a retention rule (seven years by default, lockable by a date you pass), the service connector that streams every compartment's audit events into it, and the IAM policy without which the connector sits in FAILED. Your Vault key, or the Oracle-managed one by name.
aws-aurora
Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
oci-autonomous-database
ATP/ADW/JSON/APEX autonomous database with private endpoint, mTLS wallet output, ACLs, auto-scaling and backup config.
azure-app-service
App Service plan + Linux web app with deployment slots, custom domain + managed TLS, VNet integration and autoscale.
azure-bastion-jumpbox
Bastion (Developer/Basic/Standard SKU) with optional hardened Linux VM, JIT-style NSG rules and boot diagnostics for secure VM access without public IPs.
ansible-azure-cli
The Azure CLI on EL 10 from Microsoft's rhel/10/prod repository, signed by the 2025 key: the key in most guides carries SHA-1 signatures and fails the GPG check, and the repository in most guides tops out at a 2022 build. Pinned, telemetry and the survey prompt off for every login shell; the live test asserts the SHA-1 key was never imported. Original role, live-tested on Rocky Linux 10.
azure-redis-cache
Azure Cache for Redis done cheap by default - the Basic C0 tier with TLS 1.2 minimum and the non-SSL port disabled - scaling cleanly up to Standard and Premium via precondition-guarded inputs.
azure-container-apps
Container Apps environment with workload profiles, Dapr, KEDA scale rules, ACR pull identity and custom domain.
azure-container-instances
Runs one or more containers on Azure Container Instances without VMs or an orchestrator - secure by default with no privileged containers, redacted secret fields, and an optional managed identity.
azure-acr
ACR with geo-replication, retention/trust policies, private endpoint and AcrPull role wiring for AKS/Container Apps.
azure-cosmos-db
Cosmos DB (NoSQL or MongoDB API) with multi-region failover, autoscale throughput, private endpoint and backup policy.
azure-devops
Bootstraps an Azure DevOps project with an initialized Git repository and a YAML build pipeline - repeatable team setup as code.
azure-front-door
Global entry point: Front Door profile, endpoints, origin groups, custom domains with managed TLS and WAF policy.
azure-functions
Function app (Flex Consumption or Premium) with storage, Application Insights, managed identity and VNet integration.
azure-key-vault
RBAC-mode Key Vault with private endpoint, diagnostics, and managed keys/secrets/certificates scaffolding.
azure-aks
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
azure-landing-zone-core
Management-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.
azure-vmss
A self-contained Linux VM Scale Set (Uniform orchestration) on Azure - one apply creates the resource group, VNet, subnet, NSG and an SSH-key-only scale set with deny-all-inbound and no public IPs.
azure-virtual-machine
A fully self-contained general-purpose Linux VM on Azure - one apply creates the resource group, VNet, subnet, NSG, NIC, optional public IP and an SSH-key-only VM with a system-assigned identity.
azure-monitor-baseline
Central Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).
azure-private-dns
A self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.
azure-private-endpoint
An Azure Private Endpoint giving a target PaaS resource a private IP inside your VNet so traffic stays on the Microsoft backbone - wire to existing subnet/target or run fully self-contained.
azure-dns-zone
An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.
azure-sql-database
Logical SQL server + database with Entra-only auth, firewall/private endpoint, auditing, TDE and failover-group option.
azure-load-balancer
An Azure Standard L4 load balancer with a self-created static public IP frontend, a backend address pool, health probes and load-balancing rules - Standard SKU throughout.
azure-static-web-app
Globally distributed hosting for static sites and SPAs on Azure Static Web Apps with optional serverless APIs, free auto-renewing TLS, and a built-in global CDN - defaulting to the cost-free Free SKU.
azure-storage-account
Storage account with containers/file shares, lifecycle rules, network rules, CMK encryption and private endpoint options - Azure's most-deployed resource done right.
azure-traffic-manager
Global, DNS-based load balancing with a Traffic Manager profile and map-driven external endpoints - Performance, Priority, Weighted, Geographic, Subnet or MultiValue routing with an HTTPS health probe.
azure-vnet
Production VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.
ansible-kubelogin
kubelogin on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the vendor's per-file .sha256, and the live test re-checks it, then converts an azure auth-provider kubeconfig into an exec block and runs get-token until it needs the Azure CLI. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-bind-authoritative
BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.
aws-backup
A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.
azure-backup
Soft delete covers deletion; it does not cover somebody shortening a retention policy so every backup ages out on its own - which deletes nothing, so no soft-delete window opens. immutability is the control that refuses that edit, and it defaults to Disabled. Locked is irreversible and gets its own acknowledgement.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
oci-base-database
Oracle Database VM system with DB home, TDE via Vault, automated backups and optional Data Guard standby.
oci-bastion
Zero-footprint managed bastion with session-managed SSH/port-forward access to private subnets - replaces jump hosts.
aws-batch
Batch does not retry by default, so a reclaimed spot instance or a timed-out image pull ends as FAILED - reported as if the job failed on its merits, which is how somebody ends up debugging working code. Retries infrastructure failures and exits on real ones.
gcp-bigquery-dataset
Datasets with partitioned/clustered tables, authorized views, CMEK and dataset-level access controls.
ansible-blackbox-exporter
Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.
vultr-block-storage
Instance snapshots and automatic backups image the primary disk only, block storage has no snapshot of its own, and an attach without live = true reboots the instance. NVMe or HDD by name, attached live, and two outputs that say the volume is in no snapshot, so whatever consumes the module cannot assume a copy exists.
cloudflare-bot-management
Bot Fight Mode is zone-wide with no path exclusion and no allow list: it challenges CI runners, monitoring, mobile apps and every API client that worked yesterday. Off unless accepted by name, Super Bot Fight Mode with an action per class on paid plans (challenge the definitely automated, admit the rest), AI crawlers blocked, and an output that says whether API clients will be challenged.
azure-vnet-peering
Both halves of a hub-and-spoke VNet peering in one apply, since one half alone sits in Initiated and carries nothing. hub_has_gateway writes allow_gateway_transit on the hub and use_remote_gateways on the spoke, in the order Azure requires; forwarded traffic is on for both halves because a hub firewall forwards by definition. One subscription; both directions bill per gigabyte.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.
alicloud-security-posture
Security Center defence rules and baseline checks. A rule naming no servers defends nothing while Alibaba's default keeps running, so it is refused. The block-forever value is 52560000 minutes sitting at the end of a list of ordinary numbers, so the module takes words. SQL Server interception is off by default, which is where the interesting passwords are.
gcp-cloud-build
A trigger with no service account runs every step - including code from the pull request under test - as the broadest identity in the project; a trigger that deploys on push deploys whatever lands; the shared default pool has external IPs. A dedicated runner with the defaults refused, a private worker pool with no external addresses, and approval required on any trigger marked as deploying.
ansible-cfssl
cfssl and cfssljson on EL 10 from the GitHub release, each refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which mints a root CA from a CSR, writes it as PEM through cfssljson and reads the subject back with certinfo. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
cloudflare-cdn
Cloudflare caches by file extension out of the box, so the hashed assets are cached and the HTML is not, and every page view still reaches the origin while the dashboard reports a healthy hit ratio. A rule that caches is what changes that; a ruleset holding none is refused, and a caching rule matching every request is refused separately.
ansible-caddy-https
Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.
gcp-certificate-manager
A Certificate Manager certificate map for external HTTPS load balancers, with an optional Google-managed certificate and DNS authorization provisioned when you supply a domain you control.
ansible-checkov
Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.
ansible-cilium-cli
cilium on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum Cilium publishes, and re-checked with sha256sum -c by the live test, which then runs cilium config view with no cluster and expects the refused connection. Installing Cilium into a cluster stays yours. Original role, live-tested on Rocky Linux 10.
ansible-civo-cli
civo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Civo's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at 'no API key is supplied'. Original role, live-tested on Rocky Linux 10.
civo-compute-stack
Instances with network, firewall, volume, and reserved IP.
civo-k3s-cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
ansible-clickhouse
ClickHouse on EL 10 from the upstream LTS release (sha512-verified), as a hardened systemd service on loopback with the default user behind a password; the live test creates a MergeTree table, inserts a row and selects it back over HTTP; a query without credentials is refused. Original role, live-tested on Rocky Linux 10.
aws-client-vpn
Remote-access VPN endpoint with certificate or SAML authentication, split tunnelling, per-group authorization rules and connection logging. There is no allow-all shortcut: an endpoint with no rule reaches nothing.
gcp-cloud-armor
A global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.
gcp-bigtable
A single-cluster Cloud Bigtable instance (one 1-node SSD cluster, the smallest footprint) plus a table with column families, IAM-only access, optional CMEK, and deletion protection on.
gcp-cloud-cdn
enable_cdn defaults to false, so a backend bucket behind a global load balancer is served from the bucket on every request; a backend bucket is read as allUsers, which is to say public; the managed certificate stays PROVISIONING until DNS points at the address; and port 80 forwards unless a URL map redirects it. CDN on with negative caching, the bucket named as public, TLS 1.2, a 301 on 80.
gcp-composer
Managed Apache Airflow on Cloud Composer 2 with small-by-default sizing, worker autoscaling pinned for predictable cost, and an opt-in private environment posture.
gcp-cloud-dns
Public/private managed zones with record sets, DNSSEC, forwarding and peering configs.
huawei-monitoring-alarms
Cloud Eye alarm rules from a map of namespaces, metrics, dimensions and thresholds, each firing after three consecutive periods and quiet for an hour after, sending on alarm and on recovery to an SMN topic created here and subscribed by the addresses you name (each confirms by email). A topic with no subscribers has to be accepted by name.
gcp-filestore
A managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.
alicloud-network-firewall
Address books and control policies with their evaluation order declared, since the list is read top down and a broad accept above a narrow drop silently disables it. The intrusion prevention engine ships in observation mode, where it inspects, logs and blocks nothing while every dashboard looks right; block is the default here. Rules whose action is log are counted and reported.
gcp-kms
Keyrings and rotation-enabled crypto keys with per-key IAM for CMEK across GCS, BigQuery, Cloud SQL and disks.
aws-cloud-map
Private DNS, public DNS or API-only namespaces and the services registered in them. Documents the health-check trap: a private namespace gets a custom check that something else must update, and one nobody updates reports healthy forever.
tencent-monitoring-alarms
Cloud Monitor alarm policies from a map of namespaces and rules, each bound to every instance in its namespace so a new instance is covered the day it exists, firing after three consecutive breaches, and all sending to an alarm notice created here with the sub-users and channels you name. A notice with no recipients has to be accepted by name.
gcp-monitoring
A self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.
gcp-cloud-nat
A regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.
gcp-cloud-function
Event-driven or HTTP gen2 function with source upload, dedicated runtime SA and Eventarc trigger wiring.
gcp-cloud-run-job
A Cloud Run v2 Job for batch and run-to-completion workloads with a dedicated runtime service account, auto-wired Secret Manager accessor grants, VPC egress, bounded retries and per-task timeout.
gcp-cloud-run-service
Cloud Run v2 service with autoscaling, secret and VPC egress wiring, custom domain and invoker IAM done right.
gcp-cloud-sql
Regional-HA Cloud SQL with private IP (PSA/PSC), automated backups, PITR, read replicas and IAM database auth.
gcp-cloud-scheduler
A Cloud Scheduler cron job that calls an HTTP(S) endpoint on a schedule, with a bounded attempt deadline, capped exponential-backoff retries, and per-invocation OIDC/OAuth service-account auth.
gcp-spanner
A regional Cloud Spanner instance at the smallest billable size (100 processing units) plus a database with optional starter schema, drop protection, and Terraform deletion protection on.
gcp-gcs-bucket
Hardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.
gcp-cloud-tasks
A Cloud Tasks queue with capped dispatch rate and concurrency, a bounded exponential-backoff retry policy, and full Stackdriver logging so failed dispatches are observable rather than silent.
aws-cloud-wan
A global network whose segments, routing and attachment placement live in one policy document rather than per-region route tables. The policy VERSION is executed as a second step, so a change cannot report success while the network still runs the previous one.
gcp-workflows
A Cloud Workflows workflow that runs as a dedicated least-privilege service account instead of the broad Compute Engine default, with inline YAML, deletion protection, and call logging.
aws-cloudfront-site
Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.
alicloud-monitoring-alarms
CloudMonitor alarm rules from a map of metrics and thresholds, each firing at the critical level after three consecutive breaches and quiet for an hour after, effective all day, and all sending to a contact group created here with the contacts you name. A group with no contacts notifies nobody and has to be accepted by name.
aws-cloudtrail
Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.
aws-cloudwatch
A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.
cloudflare-dns
Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.
cloudflare-notification-policy
An origin marked unreachable, a certificate that failed to renew, a DDoS mitigation on your zone: each is an event the account can notify about and none does until a policy exists, and a policy whose mechanisms block is empty is accepted and notifies nobody. Origin health, certificate and DDoS policies by default, more by alert type, and at least one email or webhook required for all of them.
cloudflare-workers-platform
Worker with KV/R2/D1 bindings, routes, custom domain, and secrets - full edge app scaffold.
cloudflare-zero-trust-access
Access application with policies, identity provider wiring, and a cloudflared tunnel to private origins.
scaleway-cockpit
Scaleway Cockpit custom metrics and logs sources with retention set to a month rather than defaulted, and the alert manager enabled with the contact addresses you name (none by name) and the preconfigured alerts you choose, because an alert with no contact point reaches nobody. Retention is the storage half of the bill.
aws-signer
Signing profiles for Lambda packages and container images, plus the code signing configuration that enforces them. Defaults to Enforce rather than the API default Warn, which logs an untrusted artifact and deploys it anyway.
aws-codedeploy
CodeDeploy application, deployment groups, and the platform-correct service role for automated EC2/ECS/Lambda rollouts with auto-rollback on failure.
aws-codepipeline
AWS-native CI/CD: CodePipeline orchestrating a CodeBuild project, with an encrypted private artifact bucket and least-privilege roles. Sources from S3 (or GitHub).
aws-cognito
A secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.
aws-conformance-packs
AWS Config conformance packs for one account or a whole organisation, with a ten-rule baseline of AWS managed rules taken from AWS's CIS sample pack. AWS Audit Manager no longer takes new customers and points them here. The module says a pack evaluates nothing without a configuration recorder and that Terraform cannot detect a pack edited in the console.
gcp-compute-instance
A hardened Compute Engine VM on Debian 12 with Shielded VM (Secure Boot, vTPM, integrity monitoring), OS Login for IAM-managed SSH, no external IP by default, and deletion protection on.
ansible-conftest
conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.
ansible-consul-cli
consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
ansible-consul-server
HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.
ansible-coredns
CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.
aws-cost-anomaly-detection
AWS Cost Anomaly Detection with monitors and the alerts that make them useful. A monitor alone leaves anomalies in the console; AWS sends immediate alerts only over SNS and summaries only by email, so this module builds both, with a topic encrypted by a key the service may use. It needs a cost threshold, and says an account holds one AWS services monitor.
ibm-customer-identity
IBM Cloud App ID's customer directory, redirect URLs, token lifetimes, and MFA, password policy and activity tracking. The provider lets anyone sign up by default, so that input has no default here. Redirect URLs refuse plaintext and wildcards unless accepted, as IBM advises. MFA, password policy and tracking are billed, graduated-tier-only features, so they need an explicit yes.
gcp-identity-platform
Identity Platform for customer sign-in: email and password with the federated providers you add from a sensitive map, MFA offered (or mandatory), anonymous accounts off and auto-deleted, a daily sign-up quota so a script cannot fill the user table, request logging on, and tenants when one project serves several customer bases. localhost in the redirect list and no quota are accepted by name.
aws-dns-firewall
Domain lists, rule group, rules and VPC associations. Fail-open is an availability decision wearing a security name: closed makes a firewall fault a DNS outage, open resolves unfiltered without saying so. The module makes you choose.
oci-dns-zone
Public/private DNS zones with record sets, failover/geo steering policies and health-check probes.
oci-drg-hub
Dynamic Routing Gateway with VCN attachments, custom DRG route tables, remote peering and IPSec/FastConnect attach points.
aws-lake-formation
AWS Lake Formation with its own permissions switched on for new databases and tables: admins, registered S3 locations and explicit grants. AWS ships it in IAM-only mode, and its settings resource clears any admin it is not given, so admins are required and the settings are protected from destroy. Existing databases keep IAM-only access until revoked outside Terraform, and it says so.
ibm-databases-postgresql
service_endpoints decides whether the deployment answers on the internet and public is the default; deletion_protection defaults to false; an empty allowlist means any address that can reach the endpoint; and disk and backup encryption use IBM's keys unless yours are given. Private with public by name, deletion protection on, ranges expected (empty by name), both key CRNs taken, two members.
gcp-dataproc
A single-node Dataproc cluster (1 master, 0 workers), the cheapest managed Spark/Hadoop cluster that still applies and destroys cleanly, with internal-only IPs and deletion protection on.
azure-defender-for-cloud
A subscription with no Defender plan still has a full Defender for Cloud page: a Secure Score, hundreds of recommendations, a compliance dashboard - and not one threat detection, because those come from the paid plans, each Off until somebody turns it on. Sets Standard per resource type, always creates the security contact, and defaults alert notifications on.
aws-detective
Builds an investigable graph from CloudTrail, VPC flow logs and GuardDuty findings, with member accounts and organization delegation. It detects nothing itself - it makes an existing finding into a timeline.
do-app-platform
Declarative App Platform deployment with services, workers, domains, and alerts.
do-doks-cluster
Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.
do-droplet-stack
Hardened droplet(s) with VPC, firewall, volume, reserved IP, and cloud-init bootstrap.
do-managed-database
Managed PG/MySQL/Valkey cluster with firewall trust list, users, DBs, and replicas.
aws-direct-connect
Gateway, connections, virtual interfaces and associations. A private circuit is a private path, not a private conversation: traffic crosses it in clear text unless MACsec is on, and should_encrypt quietly falls back to clear text.
ansible-dockle
dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.
aws-documentdb
A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.
ansible-dragonfly
Dragonfly on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind a password kept in a flagfile; the live test speaks RESP itself: an unauthenticated PING and a wrong password are refused, AUTH + SET + GET round-trip. Original role, live-tested on Rocky Linux 10.
vault-database-secrets
The credential Vault connects with is still a password somebody knows until Vault rotates it; a role with no max TTL issues credentials that renew forever; and creation statements are the privilege, so a careless one is a superuser factory. Root rotation daily, TTLs per role, statements that grant exactly the PostgreSQL role you name, and the connection verified at apply.
aws-dynamodb-table
DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.
aws-ec2-instance
EC2 instance with IMDSv2, encrypted EBS, instance profile, and EIP - secure defaults out of the box.
aws-autoscaling
EC2 launch template and Auto Scaling group with IMDSv2 enforced, encrypted gp3 root volume, an egress-only security group, and scale-to-zero defaults so it applies cleanly with no compute cost.
aws-ecr
ECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.
aws-ecs-fargate-service
Full Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.
aws-efs
An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.
aws-eks
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
tencent-network-firewall
Address templates and edge policies in a declared order, the intrusion prevention mode set to block rather than the observation mode it ships in, and the edge firewall switch turned on for the addresses you name. Writing policies and leaving that switch off produces a complete, correct and entirely inactive rule set, so naming no addresses is refused here.
azure-nat-gateway
Default outbound access is retired, so a subnet with no NAT gateway has no internet at all and fails as a timeout rather than an error. Each public IP gives 64,512 SNAT ports held for the whole idle timeout; exceed that and connections fail intermittently in a way that looks like the remote service being flaky.
aws-elasticache-redis
A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.
azure-communication-email
Azure Communication Services email from your own domain: the email service, the domain with the DNS records to publish exported, sender addresses as a map, and the Communication Services resource that sends. CustomerManaged rather than the random azurecomm.net subdomain (accepted by name), engagement tracking off, and the key-based connection string sensitive; managed identity is the better path.
aws-ebs-volume
Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.
azure-entra-id-baseline
App registrations, service principals, groups and federated credentials (OIDC for GitHub/Terraform) - the identity plumbing every Azure org rebuilds by hand.
azure-event-grid
An Event Grid custom topic plus event subscriptions with an optional in-module Storage Queue target - SAS auth off (Entra ID), a system-assigned identity, and HTTPS-only TLS 1.2+ storage.
azure-event-hubs
An Event Hubs namespace plus hubs, each with consumer groups and least-privilege SAS rules for high-throughput (Kafka-compatible) ingestion - TLS 1.2 floor and optional default-deny networking.
oci-events-rule
An empty condition is legal and matches the completion of every API call on every resource type in the compartment, flooding the target; a rule can be created disabled, and so can each action inside an enabled rule, which then matches events and does nothing while showing Active. Every rule names its event types, both levels are enabled unless accepted, and the IAM the service needs is exported.
ibm-event-streams
An IBM Cloud Event Streams (Kafka) instance on the standard multi-tenant plan (enterprise is a dedicated cluster and a purchase), with the brokers on private endpoints only (public by name), and topics from a map with partitions, retention in hours and a cleanup policy, a week and three partitions by default. Producer and consumer credentials are a separate resource.
aws-eventbridge
A custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.
gcp-eventarc
An Eventarc Pub/Sub trigger wired into a self-contained pipeline - a Cloud Run target, a dedicated delivery service account, and the run.invoker and eventReceiver grants Eventarc silently requires.
ansible-exoscale-cli
exo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Exoscale's checksum file, re-checked by the live test, with the bash completion the release itself ships installed for every shell. No package exists. Pinned; an API call without configuration stops at 'must be configured before usage'. Original role, live-tested on Rocky Linux 10.
exoscale-dbaas
Managed PG/MySQL/Kafka with IP filters and TF-managed users.
exoscale-sks-cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.
aws-fsx-lustre
A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.
oci-file-storage
Elastic NFSv3 file system with mount target, export options, snapshots and NSG-scoped access.
gcp-security-command-center
The findings page is not a pager: a project accumulates thousands of findings with nobody having received a message, and a mute rule silences a whole category, now and in future, with no record why. Streams CRITICAL and HIGH findings to a Pub/Sub topic as a requirement, refuses a mute without a written reason, and refuses a custom detector created DISABLED, which is listed and evaluates nothing.
gcp-cloud-ngfw
Cloud NGFW Enterprise: a firewall endpoint per zone you list (each billed by the hour plus per gigabyte inspected), associated with your VPC, a threat prevention profile that denies critical and high severity threats and alerts on medium, and the rule added to your network firewall policy with apply_security_profile_group, without which no packet reaches the endpoint.
aws-firewall-manager
WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.
oci-load-balancer
HTTPS load balancer with backend sets, health checks, TLS certificates, rule sets and WAF-ready listeners.
gcp-vpc-flow-logs
VPC Flow Logs configs through the Network Management API, one per network, subnet, VPN tunnel or Interconnect attachment. A config for a target that does not exist is accepted and logs nothing, so a check block warns on it. Filters and sampling are reported by name, and the defaults stay Google's most complete: every flow, 5-second aggregation, all metadata.
aws-vpc-flow-logs
Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.
azure-flow-logs
enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.
ansible-flux-cli
flux on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked with sha256sum -c by the live test, which then runs flux check --pre with no cluster and expects the refused connection. Flux also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.
oci-functions-app
Serverless Fn application with functions, provisioned concurrency, invoke logging and Events-rule trigger wiring.
gcp-project-factory
Opinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.
gcp-vpc
Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.
gcp-gke-cluster
Private, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.
ansible-garage
Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.
ansible-gh-cli
gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.
ansible-glab
glab on EL 10 from the GitLab-hosted release, get_url refuses it unless its SHA-256 is the one in the vendor's checksums file, and the live test re-checks it, then runs auth status to the 401 gitlab.com returns and round-trips a config value offline. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-gitea
Gitea from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; its secrets are generated once and read from files, so app.ini stays root's. The live test creates an administrator with gitea's own command, then a private repository through the API, reads it back, sees it hidden from anonymous eyes, deletes it. Original role, live-tested on Rocky 10.
ansible-gitleaks
gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.
aws-global-accelerator
Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.
gcp-http-load-balancer
Global ALB with managed TLS certs, URL map, serverless/instance NEG backends, optional Cloud CDN and Cloud Armor policy.
aws-glue
A bookmark records exactly where a job reached in your data - which partitions, which keys - and it is written in plain text unless a security configuration says otherwise. That configuration is attached at job CREATION, so adding one later means rebuilding every job.
ansible-goreleaser
goreleaser on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has goreleaser check validate a minimal configuration and refuse one with an unknown field at parse, exit 1. Pinned. Original role, live-tested on Rocky Linux 10.
azure-image-gallery
Community sharing publishes every image version to every Azure customer, unauthenticated, with your publisher email attached; trusted launch supported means a VM may boot without Secure Boot, and an image with no end-of-life date is a 2021 build still being deployed. Private by default, trusted launch required on every definition, an end-of-life date on each, and Hyper-V generation 2 throughout.
ansible-google-cloud-cli
gcloud, gsutil and bq on EL 10 from the versioned tarball, checked against a SHA-256 pinned beside the version: Google's yum key has a SHA-1 self-signature that rpm on EL 10 refuses, so the repository only installs with the GPG check off. Usage reporting and update nagging off installation-wide, read back through gcloud config get. Original role, live-tested on Rocky Linux 10.
ansible-gotify
Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.
ansible-grafana-server
Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.
ansible-k6
k6 on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs a script to 100% checks and one whose threshold cannot hold to exit code 99; usage reporting off from profile.d. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-grafana
Grafana (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads back the datasource this role provisioned, creates a dashboard and finds it by search, sees anonymous and wrong-password requests refused, and reads the build metric naming the version installed. Original role, live-tested on Rocky Linux 10.
ansible-grype
grype on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs grype db status with no database fetched and expects 'database does not exist'. Anchore also signs the checksums with cosign; the role checks the hash. Original role, live-tested on Rocky Linux 10.
aws-guardduty
Threat detection with each protection plan - S3, EKS, RDS, Lambda, malware, runtime - a separate decision with its billing dimension stated, plus organization delegation and findings filtered by severity into EventBridge.
gcp-ha-vpn
99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.
ansible-haproxy-tls
HAProxy terminating TLS 1.2 and 1.3 only with a modern cipher policy, HTTP redirected to HTTPS, HSTS on every response including HAProxy's own error pages (http-after-response, which the live test proved http-response does not cover), a self-signed certificate until yours arrives, stats kept local. Original role, live-tested on Rocky Linux 10.
ansible-resource-limits
Nothing limits an account on a stock EL 10 host: limits.d is empty and what ulimit reports is systemd's ceiling. This role sets hard limits on processes, open files and core dumps in both places that decide, because a systemd service never goes through PAM at all. The live test reads a real login session and a real service, and tries to raise both. Original role, live-tested on Rocky Linux 10.
ansible-headscale
Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.
ansible-helm
helm on EL 10 from get.helm.sh, refused by Ansible's get_url unless its SHA-256 is the one in the .sha256sum file published beside the tarball, and re-checked with sha256sum -c by the live test, which then runs helm list with no cluster and expects 'kubernetes cluster unreachable'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-helmfile
helmfile on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then runs helmfile list on a one-release file with no helm on the host and expects it to read the file and stop at the missing helm; pair it with the helm role. Original role, live-tested on Rocky Linux 10.
ansible-hcloud-cli
hcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Hetzner's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a context stops at 'no active context or token'. Original role, live-tested on Rocky Linux 10.
hetzner-lb-web-tier
Managed LB with health checks, cert, and label-selected server targets.
hetzner-private-network
Private network with subnets, routes, and a NAT gateway server for egress-only fleets.
hetzner-server-fleet
N-server fleet with placement group, firewall, primary IPs, and cloud-init - Hetzner's price/perf with guardrails.
huawei-security-posture
HSS host protection and a vulnerability scan policy. status close writes a policy with a period and a range that never runs. specific_host with an empty list scans nothing. The protection tiers are different products rather than different quotas and all of them report as protected. Protection needs the agent online, and the waiting behaviour is off in the API.
huawei-cce-cluster
CCE Kubernetes with VPC/subnet, node pool, and EIP-attached ingress.
ansible-huawei-koocli
Huawei's hcloud on EL 10 from a versioned path on Huawei's download host (the docs give only latest), refused by get_url unless the tarball's SHA-256 is the pinned one; Huawei's .sha256 names a build-server path, so the live test reads it and asserts its first field is the pin. The privacy statement stays per user; the role accepts it for nobody. Original role, live-tested on Rocky Linux 10.
aws-iam-access-analyzer
Finds what a principal outside your zone of trust could actually reach, which is the question policy reviews get wrong by reading JSON. External analysis is free; unused-access analysis is a separate, billed analyzer.
aws-iam-roles
Least-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.
gcp-iap-web
Identity-Aware Proxy access to a web backend service: the httpsResourceAccessor binding that decides who gets through (nobody by default), re-authentication every eight hours by the method you choose, the Host header check against your domains, and a troubleshooting link on the denied page. IAP guards the path through the load balancer and no other; the backend must still verify the signed header.
ansible-ibmcloud-cli
ibmcloud on EL 10 from IBM's download host, refused by get_url unless the tarball's SHA-256 is the one pinned beside the version: IBM publishes no checksum, and the ibmcloud.sig inside the tarball has no public key to check it against. The live test hashes the tarball again and runs ibmcloud target before any endpoint is set. Original role, live-tested on Rocky Linux 10.
ibm-iks-cluster
IKS cluster on VPC Gen2 with worker pools and COS-backed registry namespace.
ibm-vpc-landing
VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.
aws-ipam
Amazon VPC IPAM with a top-level pool, a pool per region with netmask bounds and required tags, and optional sharing through AWS RAM. IPAM forces nothing on its own - a VPC can still take a hand-typed CIDR - so the module outputs the SCP AWS documents for requiring a pool. The provider defaults to the Advanced tier, billed per active IP, so the tier has no default here.
aws-s3-tables
Amazon S3 Tables: a table bucket, its namespaces and Iceberg tables. Three maintenance jobs run by default and together they set how long history survives - snapshots expire at 120 hours, unreferenced objects are deleted permanently 13 days later, compaction targets 512 MB. This module makes each an input and returns the resulting window, and validates the numbers the provider does not.
aws-iam-identity-center
Permission sets with managed policy, inline policy and permissions boundaries, and the account assignments that actually grant them - written out as auditable (set, account, principal) triples rather than buried in a console.
ansible-influxdb3
InfluxDB 3 Core on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback with file object storage; the binary runs from its release directory (it links the Python it ships); the live test writes a point in line protocol and reads it back with SQL. Original role, live-tested on Rocky Linux 10.
ansible-infracost
infracost on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 Infracost publishes, re-checked by the live test, which then runs a breakdown with no API key and expects it to stop there. The role exports INFRACOST_SKIP_UPDATE_CHECK=true for login shells and the live test reads it back. Original role, live-tested on Rocky Linux 10.
aws-inspector
Continuous scanning for EC2, ECR images, Lambda dependencies and Lambda code, each its own decision with its own billing dimension, plus organization delegation and findings routed at CRITICAL and HIGH.
oci-instance-pool-autoscaling
Self-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.
gcp-interconnect
An interconnect is a private path, not a private conversation: traffic crosses the colocation facility and the partner in clear unless the attachment carries HA VPN. One attachment is no SLA, and a partner attachment is created disabled until somebody flips it. A redundant pair across two edge availability domains, IPsec by default with clear text accepted by name, and enabled unless told.
gcp-internal-lb
An internal passthrough L4 load balancer - health check, regional backend service and forwarding rule - that stands up before any backends exist, preserving client source IPs, with optional global access.
ansible-jaeger
Jaeger v2, the tracing backend built on the OpenTelemetry Collector, from the upstream release (sha256-verified against the right checksum file) as a hardened system service on loopback with badger storage and the query API on loopback. The live test pushes a span over OTLP and reads the trace back by id with its name and service. Original role, live-tested on Rocky Linux 10.
aws-jenkins
Self-hosted Jenkins controller on a hardened EC2 instance - restricted security group, IMDSv2 enforced, SSM access, encrypted root volume, Jenkins auto-installed via user-data.
azure-jenkins
Self-hosted Jenkins on a hardened Azure Linux VM - self-contained vnet/subnet/NSG, SSH-key auth only, managed-disk encryption, Jenkins installed via cloud-init.
ansible-jenkins
Jenkins LTS (sha256-verified war) on Java 21, secured on its first start without the wizard, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees anonymous and wrong-password requests refused, creates a freestyle job through the API with a CSRF crumb, builds it to SUCCESS, reads the console and deletes it. Original role, live-tested on Rocky Linux 10.
aws-kms
Customer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.
ansible-keycloak
Keycloak 26 (SHA-256 pinned) on Java 21, an image the service cannot write to, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test takes an admin token, sees a wrong password and an anonymous admin request refused, creates a realm (201), duplicates it (409), reads its OpenID discovery document and deletes it. Original role, live-tested on Rocky Linux 10.
gcp-workload-identity-federation
attribute_condition is optional, and the issuer is not yours - so omitting it on a GitHub Actions provider trusts every workflow in every repository belonging to anyone on GitHub. It works perfectly in testing, because your workflow is one of the ones it admits. Refused here, along with a wildcard principalSet.
aws-kinesis
A Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.
ansible-kopia
kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-kube-linter
kube-linter on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then lints a Deployment with one container and nothing else, expecting run-as-non-root, no-read-only-root-fs and the two unset-resource checks with exit 1. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-kyverno-cli
The kyverno CLI on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which applies a require-label policy offline: the unlabelled Pod fails, the labelled one passes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
aws-lambda
Lambda with execution role, log group, triggers, aliases, and zip/container packaging handled.
ansible-linkerd
linkerd (edge channel) on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then has install --ignore-cluster render the control plane (at least three Deployments expected) and check --pre stop at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.
linode-volume
Attachable, resizable NVMe block volume with safe attach/detach lifecycle handling.
ansible-linode-cli
The Linode CLI pinned in /opt/linode-cli, a virtual environment apart from the system Python, linked into the PATH. No package exists; pip into the system Python is the documented install. The live test runs pip check, calls the API with a token that is not one and expects Linode's 401, and asserts the system Python cannot import the package. Original role, live-tested on Rocky Linux 10.
linode-firewall
Opinionated stateful firewall with deny-by-default inbound, curated allow rules, and multi-device attachment.
linode-instance
Hardened Linode VM with cloud-init, disk encryption, reverse DNS, backups, and firewall attachment in one apply.
linode-domain
Complete DNS zone with typed record management and sane TTL defaults on Linode's free DNS Manager.
linode-lke-cluster
Production LKE cluster with autoscaling node pools, HA control plane, disk encryption, ACL, and optional Enterprise tier.
linode-database
HA managed database cluster with allowlists, maintenance windows, and fork/restore support on the new Aiven platform.
linode-nodebalancer
Managed L4/L7 load balancer with TLS termination, health checks, session stickiness, and UDP support.
linode-object-storage
S3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.
linode-vpc
Isolated VPC network with labeled subnets ready for instances, LKE, and NodeBalancer backends.
azure-logic-app
An Azure Logic App (Consumption) workflow with a built-in Recurrence trigger - serverless pay-per-execution automation with a system-assigned managed identity and inbound IP allowlists.
ansible-rsyslog-forward
rsyslog ships logs in clear over port 514, which is what most examples do. This role configures the sending side with the gtls driver, the collector's CA and x509/name, so a host with a certificate from elsewhere in the estate cannot collect your logs. The live test watches a line arrive and reads the handshake. Original role, live-tested on Rocky Linux 10.
ansible-loki
Grafana Loki from the upstream release (sha256-verified) as a single-binary system service on loopback with filesystem storage, a TSDB index, retention the compactor enforces and usage reporting off, its configuration checked by loki -verify-config before it lands. The live test pushes one log line and queries it back. Original role, live-tested on Rocky Linux 10.
aws-msk
An MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.
aws-macie
Sensitive-data discovery for S3 with targeted classification jobs, sampling for surveying a large bucket first, and findings filters that archive an expected result with its reason. No scan-everything default: Macie bills per GB inspected.
ansible-postfix-tls
An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.
gcp-managed-instance-group
A zonal Managed Instance Group built from a hardened Shielded-VM instance template, private by default, with optional CPU autoscaling, autohealing, and zero-downtime rolling template updates.
azure-managed-lustre
Azure Managed Lustre with the blob containers that make the data outlive the file system, root squash naming the clients that keep root, a customer-managed key through a user-assigned identity, and the capacity checked against the SKU's step before the plan. No blob integration, root on every client and the platform key are each accepted by name; the file system is zonal.
gcp-managed-ad
Managed Microsoft AD reachable only from the VPCs in authorized_networks, on a reserved /24 that cannot change later, with domain controllers in every region listed and deletion protection on. An empty network list, a single region and a deletable domain each have to be accepted by name; the setupadmin password is set with gcloud and never enters state.
aws-directory-service
A managed directory with security log forwarding and cross-account sharing. The admin password has no default and no example value anywhere in the module, and the README is explicit that Terraform state holds it regardless.
aws-transfer-family
SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.
ansible-mariadb-server
MariaDB bound to loopback (the package listens everywhere), with the mariadb-secure-installation steps applied by the role: anonymous users, the test database and remote root gone, LOAD DATA LOCAL off, reverse DNS off. Provisions an application database and a user that can see nothing else. Original role, live-tested on Rocky Linux 10.
ansible-meilisearch
Meilisearch on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback in production mode behind a master key; the live test creates an index and documents, waits for the indexing task, searches and finds the one match, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.
aws-memorydb
Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.
gcp-memorystore
Private Memorystore instance or cluster (Redis or Valkey) with auth, TLS and maintenance policy on your VPC.
ansible-mimir
Grafana Mimir from the upstream release binary (sha256-verified) in monolithic mode as a hardened system service on loopback with filesystem storage, every ring member on loopback, usage reporting off. The live test pushes a gauge over OTLP, queries it back through the Prometheus API with its labels and sees an unknown metric answered empty. Original role, live-tested on Rocky Linux 10.
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
azure-mysql-flexible
Azure Database for MySQL Flexible Server with TLS required by default, correct delegated-subnet + private DNS zone ordering, an Entra administrator, databases, and cheapest-by-default Burstable sizing.
oci-mysql-heatwave
Managed MySQL with optional HeatWave analytics cluster, HA, backups, configuration and inbound replication channel.
aws-nat-gateway
NAT gateways for an existing VPC, one per availability zone with its own Elastic IP, and the private route tables routed through the gateway in the same zone. A single gateway for every zone pays cross-zone charges on every byte and loses egress with that zone; it has to be accepted by name. Private (no address) mode for transit paths; gateway_count says what bills by the hour.
ansible-nats
nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-nats-server
NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.
aws-fsx-ontap
Amazon FSx for NetApp ONTAP: a file system, one storage virtual machine and its volumes. The provider defaults daily volume backups to OFF where the AWS API keeps 30 days, and AWS attaches the VPC's default security group when none is given. This module sets 30 days, builds the security group from AWS's port table per protocol, and writes throughput to the field that updates in place.
ansible-nsq
NSQ (SHA-256 pinned): nsqd and nsqlookupd as two hardened services from one release on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test publishes four messages, sees the topic count them with the channel holding the last, and asks the directory which broker holds the topic. Original role, live-tested on Rocky Linux 10.
aws-network-acl
Network ACLs are stateless, which is why most of them do not work: the reply to an allowed outbound connection is a new inbound packet nothing lets in. This generates the matching ephemeral-range rule for every TCP and UDP allow.
aws-network-firewall
Managed stateful firewall with Suricata rule groups, stateless pre-filters and logging. An empty policy drops rather than passes, and rules evaluate in strict order so "allow these, deny the rest" behaves the way it reads.
aws-nlb
A Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.
ansible-nginx
Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.
ansible-nomad-cli
nomad on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs nomad status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
ansible-nomad-pack
nomad-pack on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then scaffolds a pack, renders it with a variable override (the job name is read in the output) and lists its variables, all with no Nomad. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-nomad-server
HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback, an explicit advertise block (Nomad refuses to start without one) and its configuration checked by nomad config validate. The live test waits for a leader and round-trips a variable with nomad var. Original role, live-tested on Rocky Linux 10.
ansible-notation
notation on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has cert generate-test mint a key and certificate under a throwaway config home, then lists the trust store and the default key. Pinned. Original role, live-tested on Rocky Linux 10.
oci-data-science
A notebook session with no subnet runs on Oracle's network with internet egress and no path to your VCN, and a session left ACTIVE bills its shape - a GPU, over a weekend - whether or not anyone is in it. Sessions attach to your subnet, the shape and storage are set on purpose, and the sessions that are billing from the moment of apply are listed in an output.
ansible-oci-cli
The Oracle Cloud Infrastructure CLI pinned in /opt/oci-cli, a virtual environment apart from the system Python, linked into the PATH. No package exists; the documented installs are a script piped into bash or pip into the system Python. The live test runs pip check and an API call, and asserts the system Python cannot import the SDK. Original role, live-tested on Rocky Linux 10.
oci-compute-instance
Opinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.
oci-iam-foundation
Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.
oci-network-load-balancer
Low-latency pass-through NLB with TCP/UDP listeners, backend health checks and preserved client IPs.
ansible-registry
The CNCF Distribution registry from the upstream release (sha256-verified) as a hardened system service on loopback with filesystem storage and deletion enabled, for a TLS proxy that authenticates. The live test walks the OCI protocol: starts an upload, puts a blob by digest, reads its headers back and deletes it. Original role, live-tested on Rocky Linux 10.
oci-vcn
Production VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.
vault-oidc-auth
An OIDC role with no bound claims admits every user of the identity provider; a role with no bound audience accepts tokens minted for other services; and the client secret lands in state. Bound claims expected with none accepted by name, an audience required, callbacks listed rather than assumed, token ceilings set, and the write-only secret path named for Terraform 1.11+.
oci-oke
Enhanced OKE cluster with managed + virtual node pools, private API endpoint, NSGs, addons and OIDC - flagship OCI workload platform.
ansible-opa
opa on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 OPA publishes, and re-checked with sha256sum -c by the live test, which then evaluates a one-rule Rego v1 policy against a one-line input with opa eval and expects the denial. The binary only; no opa server. Original role, live-tested on Rocky Linux 10.
ansible-oras
oras on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked by the live test, which then pushes a file as an OCI artifact into a layout on disk and pulls it back byte for byte, no registry needed. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-ovhcloud-cli
ovhcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in OVHcloud's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a login stops at 'ovhcloud login'. Original role, live-tested on Rocky Linux 10.
ovh-managed-database
Managed PG/MySQL/Kafka with users, IP restrictions, and private network egress.
ovh-managed-k8s
MKS cluster with node pools and private-network (vRack) attachment.
oci-object-storage-bucket
Bucket with versioning, lifecycle/auto-tiering, retention rules, replication and pre-authenticated request support.
upcloud-object-storage
A service answers on the networks attached to it, and a public network makes the S3 endpoint an internet endpoint; a user has no access until a policy is attached and no key until one is created; and the service has no versioning and no lifecycle. Private by default with public by name, buckets, a user with the policy you name and one key, and outputs that say what is not available.
vultr-object-storage
A subscription is one S3 key pair with full rights over every bucket, written to state; versioning is off by default, so an overwrite is the end of the object; and object lock, once on, is on forever. The cluster looked up by hostname, versioning on for every bucket and off by name, lock per bucket and refused without versioning, and an output that says the keys are not scoped per bucket.
ansible-ssh-ca
sshd can trust a CA and accept any certificate it signed, so access is granted by signing rather than by editing authorized_keys everywhere. The live test proves it four ways over a real connection: the matching certificate gets in, one for another principal does not, one that expired does not, and a key the CA never signed does not. Original role, live-tested on Rocky Linux 10.
gcp-binary-authorization
DRYRUN_AUDIT_LOG_ONLY admits the image and writes a line about it while the console shows the policy as configured. ALWAYS_ALLOW is the other way to have nothing: a valid, enforced policy that admits everything. Both have to be right, so one output reports over both.
ansible-openbao
OpenBao (the MPL-licensed Vault fork) as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.
ansible-ssh-hardening
An sshd drop-in numbered 01, so it is read before the 50-redhat.conf that asks for X11 forwarding: root login off, passwords off, MaxAuthTries 4, idle timeouts. The live test proves the policy with the daemon rather than the file: a password login refused, a key login accepted, root refused, and the banner delivered before authentication. Original role, live-tested on Rocky Linux 10.
aws-opensearch
A VPC domain with fine-grained access control and the three encryption settings that cannot be added afterwards. Building a public endpoint takes an explicit opt-in, because a public domain with a permissive policy is how this service leaks databases.
ansible-opensearch
OpenSearch 3 (sha512-verified min distribution, bundled JDK), one node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads the root document, indexes one document with a refresh, finds it by a search, deletes the index and checks the keystore belongs to the service; the release tree stays read-only. Original role, live-tested on Rocky Linux 10.
ansible-otel-collector
The OpenTelemetry Collector (contrib) from the upstream release (sha256-verified) as a hardened system service on loopback: OTLP in, a Prometheus endpoint out, your whole configuration checked by the collector before it lands. The live test pushes a gauge over OTLP and reads it back from the Prometheus exporter with its labels and value. Original role, live-tested on Rocky Linux 10.
ansible-opentofu
tofu on EL 10 from the GitHub release. The role imports OpenTofu's OpenPGP key into a GnuPG home of its own, refuses a keyring whose fingerprint is not the pinned one, verifies the SHA256SUMS signature, and only then lets Ansible's get_url check the zip against that file. The live test re-verifies the signature and runs tofu init. Original role, live-tested on Rocky Linux 10.
aws-fsx-openzfs
Amazon FSx for OpenZFS. With no export set, AWS shares the root volume read-write to every client the network admits, and the Terraform provider turns automatic backups off where AWS keeps 30 days. This module writes the export to named networks, refuses a wildcard and no_root_squash, keeps 30 days of backups, opens the NFS ports AWS lists and requires route tables for Multi-AZ.
aws-organizations
The organization, its organizational units, member accounts and the service control policies attached to them. Root attachment is off by default, because an SCP sets the ceiling on what anybody may do - including the account root user who would have to undo it.
ansible-php-fpm
php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.
ansible-packer-cli
packer on EL 10 from releases.hashicorp.com, the SHA256SUMS signature verified against HashiCorp's key in a GnuPG home of its own, pinned by fingerprint, before get_url checks the zip against that file. Pinned; the live test re-verifies the signature and runs packer validate to its 'no config file' answer. Original role, live-tested on Rocky Linux 10.
ansible-login-defs
EL ships PASS_MAX_DAYS 99999, so no password expires, and INACTIVE -1 in a second file, so one that does expire still lets you in. This role sets both, then brings the accounts created before it into the policy, which login.defs alone never does. The live test creates an account first, records what it was given, and proves the change. Original role, live-tested on Rocky Linux 10.
ansible-password-quality
A pwquality drop-in on EL 10 with the length, class and dictionary rules an auditor asks for. Nothing validates pwquality.conf, so the live test scores four passwords and reads why each was refused: a dictionary word by the dictionary check, a password one under the minimum by its length, the same at the minimum accepted, and a passphrase accepted. Original role, live-tested on Rocky Linux 10.
ansible-pam-pwhistory
EL remembers nothing: pam_pwhistory is not in the authentication stack, the history file is empty, and a password can be put straight back. Measured, three changes, there and back. This role writes the policy, adds the module through authselect, and proves the refusal by attempting the reuse and reading the reason PAM gives for it. Original role, live-tested on Rocky Linux 10.
ansible-pluto
pluto on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which writes an Ingress at extensions/v1beta1 and has pluto detect-files name the replacement and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-pocketbase
PocketBase, the backend in one binary, from the upstream release (sha256-verified), a hardened system service on loopback, its data under one directory. The live test creates a superuser with PocketBase's own command, sees a wrong password refused, makes a collection and a record, reads it back, sees an anonymous read refused, deletes the collection. Original role, live-tested on Rocky Linux 10.
ansible-polaris
polaris on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which audits a minimal Deployment from disk with --set-exit-code-on-danger and expects the danger items and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-postfix-null-client
Postfix as a send-only relay: no local delivery (a stock install spools root's mail on the box), one smarthost, TLS required rather than opportunistic, SASL credentials in a root-only lmdb map, local recipients rewritten to a real mailbox. Original role, live-tested on Rocky Linux 10.
azure-postgresql-flexible
Flexible Server with HA option, private VNet delegation, Entra auth, firewall and tuned server parameters.
ansible-postgresql
PostgreSQL server with guarded initdb, SCRAM-SHA-256 auth, managed conf.d drop-in, templated pg_hba, and app database + owner provisioning. Original, live-tested (Molecule/podman) role.
tencent-postgresql
The public endpoint is a switch that puts the instance one password from the internet; SSL is a separate resource nobody creates; a primary with no standby is downtime at the first zone failure; and deletion protection is off. Private unless accepted, SSL config created, a standby zone required unless one node is accepted, daily backups in your window with your retention, deletion protection on.
ansible-powerdns
PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.
azure-pim
Azure defaults for an activation policy require MFA and a justification and no approval, so an eligible Owner activates alone at 3am with the reason fix; and eligibility itself is permanent unless somebody sets an end date. Manages the role policy per scope with approval required for Owner-class roles, gives every eligible assignment an expiry, and time-boxes the active ones kept for break-glass.
aws-vpc
Battle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.
ansible-prometheus-server
Prometheus from the upstream release (EL 10 has no package), sha256-verified, on loopback: the binary listens everywhere and authenticates nobody. Retention time and size as explicit flags, lifecycle and admin endpoints off (the live test POSTs to both), prometheus.yml checked by the promtool it installs. Pairs with grafana-server and node-exporter. Original role, live-tested on Rocky Linux 10.
ansible-node-exporter
Official node_exporter release (pinned v1.11.1) with sha256 checksum-verified install, dedicated shell-less system user, and a systemd unit on :9100; live-tested for idempotence with a functional /metrics verification.
gcp-pubsub
Topics with schemas, push/pull/BigQuery subscriptions, dead-letter queues and retry policies preconfigured.
ansible-pushgateway
Prometheus Pushgateway from the upstream release (sha256-verified) as a hardened system service on loopback with pushed metrics written to disk every five minutes, so a restart does not lose a batch job's last push. The live test pushes a metric, reads it back with its job label, deletes the job and reads it gone. Original role, live-tested on Rocky Linux 10.
ansible-qdrant
Qdrant on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, HTTP only (gRPC off); the live test creates a collection, upserts two points with payloads, searches and gets the matching point back at score 1 with its payload. Original role, live-tested on Rocky Linux 10.
aws-rds
Single-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.
huawei-rds-postgresql
One availability zone is one node whose failure is downtime; ssl_enable defaults to false, so clients speak plain TCP; the data volume is encrypted only when a KMS key is given; and the backup window and retention are the platform's. Two zones (one by name), SSL on, a KMS key expected (none by name), minor versions auto-upgraded, daily backups in your window with your retention.
alicloud-rds-postgresql
security_ips is the whole allow list and the console's first suggestion is 0.0.0.0/0; ssl_action defaults to Close, so clients speak plain TCP; the SQL audit log and connection logging are off; Basic edition is one node; and deletion protection is off. Ranges required (a /0 by name), SSL open, 180 days of audit log, connection logging on, a standby zone, deletion protection on.
ovh-dns-zone
Records and DNSSEC on an existing OVHcloud DNS zone, since OVH zones come with the domain or an order and cannot be created from a plain resource. Every record is in one map with MX and SRV priority written into the target as OVH expects, and DNSSEC is on; a domain registered elsewhere needs the DS record copied to its registrar.
aws-redshift
A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.
ansible-rekor
rekor-cli on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has loginfo verify rekor.sigstore.dev's signed tree head against the embedded root ('Verification Successful!'), fetches entry 1 as JSON, and sees a dead server refused. Pinned. Original role, live-tested on Rocky Linux 10.
oci-container-registry
The registry creates a repository for any push to an unknown name by default - private, and unmanaged - and a tag can be overwritten unless the repository is immutable, so a deployment pinned to v1.4.2 runs whatever last claimed it. Manages the tenancy-wide create-on-push switch off, creates repositories immutable and private, and lists any that are public or mutable when that is accepted.
aws-route53-resolver
Endpoints that carry DNS across the VPC boundary, with a precondition requiring addresses in two different subnets - the part the API does not check, and the reason a zone failure becomes every application failing at once.
azure-resource-group-baseline
Opinionated resource group factory with CAF-compliant naming, mandatory tags, locks and budget alert.
aws-ram
A share, what is in it and who it reaches. External principals are off, so a mistyped account number is an error rather than a silent share with a stranger - and access ends when an account leaves the organization, which AWS defaults the other way.
aws-route53
A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.
aws-ses
An SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.
aws-sns
SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.
ansible-sops
sops on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test. sops --version asks GitHub for newer releases unless told not to; the live test says not to, then decrypts a file that was never encrypted and expects 'sops metadata not found'. Original role, live-tested on Rocky 10.
aws-sqs
SQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.
gcp-iap-tunnel
IAP TCP forwarding reaches an instance from one Google range after the user is authenticated and authorised, and a firewall rule that also admits 0.0.0.0/0 on port 22 has the bastion's problem back. The range is a literal, tunnel access is granted per instance rather than to every instance in the project, and OS Login is set so the SSH identity is the IAM identity rather than whoever holds a key.
ansible-amazon-ssm-agent
The AWS Systems Manager Agent on EL 10, where rpm refuses the SSM signing key (a SHA-1 self-signature) and dnf fails its GPG check, so the usual answer is --nogpgcheck. This role verifies the detached signature with gpg against a pinned fingerprint first, pins the version (latest differs by region), and registers a hybrid activation once. Original role, live-tested on Rocky Linux 10.
aws-ssm-parameter-store
Map-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.
ansible-samba-share
Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.
ansible-scaleway-cli
scw on EL 10 from the GitHub release, a bare binary refused by Ansible's get_url unless its SHA-256 is the one in Scaleway's SHA256SUMS, re-checked by the live test. The CLI sends usage telemetry unless told not to: the role exports SCW_SEND_TELEMETRY=false for every login shell. Pinned; an API call without credentials stops at the credentials. Original role, live-tested on Rocky Linux 10.
scaleway-kapsule-cluster
Kapsule Kubernetes with pools, private network, and autoscaling/autoheal presets.
scaleway-rdb-instance
RDB PostgreSQL/MySQL with HA, private-network endpoint, users, and ACLs.
scaleway-serverless-container
Container namespace, deployed container, custom domain, and registry wiring.
aws-eventbridge-scheduler
The default retry policy tries for a day and then discards the run silently, so a target that was down never hears what it missed; the scheduler's role is the blast radius and a wide one lets a schedule do more than invoke; and a flexible time window turns 03:00 into sometime that hour. A dead-letter queue every schedule uses, a role allowing one action on the targets, exact times by default.
ansible-seaweedfs
SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.
gcp-secret-manager
Secrets with versions, replication policy, rotation schedules, expiry and accessor IAM.
aws-secrets-manager
Secrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.
scaleway-secret-manager
protected defaults to false, so one API call deletes a secret and every version; an ephemeral policy that expires a version is the rotation deadline most teams do not have; and a value from a Terraform variable lands in state as well as the manager. Protection on and off by name, a ttl per secret, values optional so first versions can come from a pipeline, and the secrets terraform wrote named.
ovh-key-manager
A secret without an expiration is valid until somebody deletes it, which is the rotation nobody does; a payload from a Terraform variable lands in state; and the service has no flag that refuses deletion. An expiration expected per secret (none by name), values optional so payloads can come from a pipeline, and outputs naming what terraform wrote and what the service lacks.
aws-security-group
Security groups with named rule presets (https, postgres, redis...) using modern standalone rule resources.
aws-security-hub
Posture management with standards named explicitly rather than defaulted on, cross-region finding aggregation, organization delegation, and suppression expressed as automation rules that keep the finding and the reason.
aws-security-lake
Organization security logs normalised to OCSF in S3, with the storage-class transitions that decide what it costs, optional replication, and subscribers whose external id is validated as the confused-deputy guard it is.
aws-account-contacts
The alternate contacts AWS uses when something is wrong with an account. Without a security contact, abuse reports and vulnerability notices go only to the root user's mailbox - what Security Hub's Account.1 and CIS v5.0.0 control 1.2 check for. The module refuses to run without one unless told to, and validates what the API accepts, which is not what the provider checks.
ansible-semgrep
semgrep on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a one-rule file against a matching module with metrics off and the version check off (exit 1) and against a clean one (exit 0); nothing is fetched from the registry. Pinned. Original role, live-tested on Rocky Linux 10.
oci-email-delivery
A domain without DKIM sends mail that looks forged and lands in spam; without a custom return path, bounces go to Oracle's domain and DMARC alignment fails; and a From address that is not an approved sender is refused by the API. DKIM key created, return path created, senders listed and checked against the domain, and every DNS record to publish exported in one output.
ansible-sentinel
sentinel on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then applies a policy with a passing value (Pass, exit 0) and a failing one (Fail with trace, exit 1), runs sentinel test (PASS) and has fmt -check flag an unformatted file. Pinned. Original role, live-tested on Rocky Linux 10.
gcp-service-accounts-iam
Service accounts with least-privilege project/resource IAM and optional Workload Identity Federation for keyless CI/CD (GitHub Actions).
azure-service-bus
An Azure Service Bus namespace with queues, topics and subscriptions on the Standard SKU - SAS local auth off (Entra ID + RBAC), TLS 1.2+ minimum, and dead-lettering of expired messages.
oci-logging
Every OCI service log is off until somebody turns it on: a VCN records no flow log, a load balancer no access log, a bucket no read log. Each log here is one service, one resource, one category, created enabled; a log created with is_enabled = false appears in the list and records nothing, and has to be accepted by name. Retention is 30 days by default and the shortest is reported.
gcp-shared-vpc
Attaching a service project is the visible half: its instances land in a shared subnet only when the creating principal holds networkUser on that subnet, and for GKE, Cloud Run or Dataflow that principal is the service agent, not a person. Takes the per-subnet grants with the attachments, refuses a project attached with none, and adds the host-level grant GKE needs.
aws-ssm-session-manager
Session Manager works with no configuration and records nothing: CloudTrail holds StartSession, not the commands. This builds the session document that turns logging on, and refuses to build one with no destination unless you say so.
aws-shield
Protections, protection groups, response-team access and the automatic layer-7 response. That response can be enabled and do nothing: COUNT labels the request and lets it through, so this defaults to BLOCK and names the counting ones.
aws-site-to-site-vpn
Customer gateway, IPsec connection and routes, attached to a VPN gateway or a Transit Gateway. IKEv2 only, DH group 14 and above, AES-256 and SHA-2 - the API still permits DH 2, AES-128 and SHA-1.
ansible-skaffold
skaffold on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has skaffold fix upgrade a v2beta29 config to the current schema, turns metrics off and reads the config back; the update check is off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.
gcp-bigquery-reservation
A reservation with capacity and no assignment bills for slots nobody can run a query on while every query keeps paying on-demand; autoscale without a ceiling in mind is on-demand pricing with a subscription on top. Assignments come with the reservation and are refused when empty, baseline and autoscale slots are both explicit, and the most the reservation can bill for at once is an output.
ansible-sonobuoy
sonobuoy on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has gen render a conformance run for Kubernetes 1.32 (the conformance image and at least five resources expected) and gen plugin render a plugin definition, offline. Pinned. Original role, live-tested on Rocky Linux 10.
aws-step-functions
A Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.
aws-workspaces-applications
Amazon WorkSpaces Applications, formerly AppStream 2.0. AWS enables every session action by default, including copying out, file download and local printing, and never disconnects idle users. This module sets all eight actions with the outbound ones off, a 15-minute idle timeout and no default internet access, and can keep streaming on an interface endpoint.
ansible-surrealdb
SurrealDB (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous query and a wrong password refused, defines a namespace and a database, creates a record and reads it back, and checks the version endpoint; the root credentials live in the unit environment. Original role, live-tested on Rocky Linux 10.
ansible-syft
syft on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs a real SBOM scan of an empty directory and expects 'No packages discovered'. Anchore also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.
ansible-tflint
tflint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then lints a one-resource module with no required_providers and expects the bundled rule to say so. Provider rulesets are plugins, per repository, not this role. Original role, live-tested on Rocky Linux 10.
gcp-resource-tags
Tag keys and values are definitions; conditional IAM, organisation policies and firewall rules read bindings, and a tag bound to nothing governs nothing while appearing fully defined. Bindings come with the keys - to folders, so every project beneath inherits - and the values that attach nowhere are listed in an output, along with the namespaced names conditions need.
oci-tag-namespace
A tag default with is_required = false applies a value silently and lets anyone overwrite or blank it; required is the only enforcement OCI tagging has, and a required free-text tag enforces presence and nothing about meaning. Every default is required and validated against an allowed list unless accepted otherwise; the ten cost-tracking slots are counted; retirement is the only delete that works.
ansible-task
task (go-task) on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in task_checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-task Taskfile and runs it, expecting the task's output. Shell completions ship in the tarball and are not installed. Original role, live-tested on Rocky Linux 10.
ansible-tkn
tkn on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs tkn pipeline list with no kubeconfig and expects 'no configuration has been provided'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-telegraf
Telegraf on EL 10 from the vendor's release, pinned by the SHA-256 in InfluxData's release notes, as a hardened systemd service on loopback; the live test writes line protocol to the HTTP input and reads the metric from the Prometheus output; a malformed write is refused. Original role, live-tested on Rocky Linux 10.
azure-application-insights
When the daily cap is hit everything after it is discarded until midnight and the dashboard goes flat, and the one email that says so has its own switch. Ingestion sampling stacks on the SDK's sampling and the metrics rescale. Both are refused without being named, and availability tests are created with the alerts that make an outage reach a person rather than a chart.
ansible-tempo
Grafana Tempo from the upstream release (sha256-verified) as a single-binary hardened system service on loopback with local block storage, an OTLP/HTTP receiver, a block retention written down and usage reporting off. The live test sends one span over OTLP and reads the trace back by id with its service.name. Original role, live-tested on Rocky Linux 10.
ansible-tccli
The Tencent Cloud CLI (tccli) pinned in /opt/tccli, a virtual environment apart from the system Python. No package exists; pip into the system Python is the documented install. The live test runs pip check, calls the API with a SecretId that is not one and expects Tencent's AuthFailure.SecretIdNotFound, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.
tencent-vpc-foundation
VPC with subnets, route tables, NAT, and security groups across AZs.
tencent-tke-cluster
Managed TKE Kubernetes with node pools and VPC-CNI networking.
ansible-terraform-cli
terraform on EL 10 from releases.hashicorp.com. HashiCorp's security key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again. BSL-licensed since 1.6; opentofu in this catalogue is the MPL alternative. Original role, live-tested on Rocky Linux 10.
ansible-terragrunt-cli
terragrunt on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Gruntwork's SHA256SUMS, and re-checked with sha256sum -c by the live test. The asset is the bare binary; the checksum file covers every build. Needs a tofu or terraform in the PATH; pair it with opentofu or terraform-cli. Original role, live-tested on Rocky Linux 10.
ansible-terramate
terramate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then makes a git repository, has terramate create a stack, list it from another directory and generate a file from a generate_hcl block, read back. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-terrascan
terrascan on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then fetches the policy set once at install and scans a public-read bucket, expecting 'Violated Policies', exit 3 and allUsersReadAccess in the JSON. Pinned. Original role, live-tested on Rocky Linux 10.
azure-activity-log
The subscription's Activity Log exported to a Log Analytics workspace, a storage account and/or an Event Hub, because Azure keeps it for ninety days and then forgets. All eight categories go; dropping Administrative, Security or Policy, the three an investigation asks for, is accepted by name. The workspace's retention is the workspace's setting; the years live in the storage account.
gcp-essential-contacts
Without Essential Contacts, security notices, suspension warnings, billing problems and API shutdowns go to whoever holds Owner - a service account and an alias nobody reads - and the list is empty by default. Contacts per category, with a refusal when any category is left uncovered and an output naming the ones that still fall through to the Owner path.
gcp-app-engine
The application cannot be deleted and its region cannot be changed - destroy removes it from state and nothing else - and the region pins Firestore for the project. Without IAP every service is public on its appspot hostname. The permanent region must be accepted by name, IAP fronts every service unless public is stated, and a disabled serving status is a choice rather than an accident.
huawei-cts
The Cloud Trace Service system tracker (one per region, adopted rather than duplicated) delivering every management event to an OBS bucket you own, each file signed so tampering is detectable, gzip-compressed, sorted by service, encrypted with your KMS key (the bucket default by name), and also sent to LTS for queries. Excluding services from the trace is accepted by name.
ovh-ip-firewall
Every OVH public IP has an edge firewall that is disabled until enabled, so rules written to it filter nothing; twenty ordered rules where the first match wins and a list without a deny permits what it does not mention; and SSH from anywhere is the first rule offered. Enabled, your permits in sequence with a deny last, SSH from anywhere refused unless accepted.
do-vpc-peering
A peering between two DigitalOcean VPCs. DigitalOcean programmes the routes on both sides once the peering is ACTIVE, which is why this module takes no route table lists and every other module in this hub does. Overlapping IP ranges are refused at apply, and there is no transit product, so a fourth network means three more peerings.
aws-privatelink-service
An endpoint service, who may attach and the private DNS it answers on. A wildcard principal offers the service to every AWS account, so the module refuses it unless said out loud - and warns that zone names differ per account.
gcp-iam-deny-policy
A deny policy is evaluated before any allow and stops the request whatever roles the caller holds, Owner included - the only way to say nobody deletes the audit bucket and mean it. public:all with the break-glass group excepted is the shape; a rule with no exceptions locks out break-glass too and says so; a rule conditioned on a tag denies nothing until the tag is attached, and is counted.
ansible-crypto-policy
One EL 10 setting that decides what OpenSSL, GnuTLS, NSS, OpenSSH and Java will negotiate, applied only when it differs and read back from both files that record it. The live test runs one TLS 1.2 handshake three times, under the configured policy, under FUTURE, and under the policy again, so the refusal in the middle is the policy's doing. Original role, live-tested on Rocky Linux 10.
cloudflare-zone-hardening
ssl = flexible encrypts the visitor's half and speaks plain HTTP to the origin while showing a padlock; DNSSEC is off until turned on at Cloudflare and again at the registrar; and TLS 1.0, HTTP without redirect and no HSTS are the defaults. Strict SSL with weaker modes accepted by name, TLS 1.2 minimum, HTTPS forced, HSTS (preload by name), DNSSEC on with the DS record exposed.
ansible-dnf-security
dnf checks the signature on a package it downloads and not on one you hand it: localpkg_gpgcheck is absent from dnf.conf and defaults to off, and so is repo_gpgcheck. This role sets both and proves each by what it prevents, refusing an unsigned package and an unsigned repository it builds, then checking the distribution's repositories still verify. Original role, live-tested on Rocky Linux 10.
aws-xray
AWS X-Ray sampling rules, trace groups and trace encryption. Sampling rates are percentages here, as in the console: the API takes a fraction and the provider validates nothing, so a rate of 5 means 500 percent. Groups get Insights on, because a group without it is a saved search. Encryption is an account setting whose provider delete does nothing, so the module can leave it alone.
aws-transit-gateway
Hub-and-spoke Transit Gateway with its own route tables, VPC attachments, static and blackhole routes, and RAM sharing. Default route table association and propagation are off, so an attachment joins a routing domain because you said so rather than by default.
vault-transit
A Transit key never rotates by itself, so the key from day one encrypts everything for the life of the mount; deletion_allowed takes every ciphertext with the key; exportable means the material has left Vault; and min_decryption_version left at 1 keeps every retired version alive. Rotation every 90 days, deletion and export refused unless accepted by name, the retirement version taken.
ansible-trivy
trivy on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Aqua's checksums file, and re-checked with sha256sum -c by the live test, which then runs a license scan of /etc, the one scanner that needs no database, and expects the report. The vulnerability database is fetched on first use, not by the role. Original role, live-tested on Rocky Linux 10.
ansible-trufflehog
trufflehog on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which plants an AWS key, sees it reported and --fail exit 183, and sees a clean tree exit 0. No verification calls, no self-update. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-typesense
Typesense on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, the Raft peering port on loopback too; the live test creates a collection, indexes a document, searches and finds it, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.
ansible-dnf-automatic
dnf-automatic with apply_updates on: the package downloads updates daily and installs none, and enables no timer. This role installs security advisories on the one timer that reads the configuration, switches the other three off so nothing runs twice, staggers a fleet, and leaves the reboot policy an explicit choice. Original role, live-tested on Rocky Linux 10.
ansible-upcloud-cli
upctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in UpCloud's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without credentials stops at 'user credentials not found'. Original role, live-tested on Rocky Linux 10.
upcloud-managed-database
Managed PG/MySQL with properties tuning, users, and logical DBs.
upcloud-server-stack
Servers on SDN private network with storage, router, and firewall rules.
azure-uptime-check
Application Insights Standard tests with the metric alert that makes them tell somebody. Microsoft says a test without an alert rule only notifies the portal, recommends five locations and alerting at locations minus two, and retires URL ping tests on 30 September 2026. The module follows all three, checks certificate lifetime, and lets content, not only a 200, decide what up means.
oci-health-checks
A monitor can be created disabled and probes nothing; one vantage point reports the site down when that location is; and a monitor is a metric, not an alarm - nothing pages until Monitoring reads it. Enabled monitors over HTTPS from three regions by default, and the MQL query each one needs in an alarm exported for the oci-monitoring-alarms module.
azure-managed-identity
A map-driven module creating one or many user-assigned managed identities, each with optional workload identity federation (OIDC) and least-privilege RBAC role assignments - no secrets to rotate.
oci-vcn-flow-logs
VCN flow logs for the subnets you list, since OCI logs per subnet and a subnet added later has none: a log per subnet in a log group created or given, category all rather than reject, ninety days of retention rather than the thirty-day default, and the subnet map as the list to update. Flow logs are the largest log in a tenancy; the map is also the bill.
aws-vpc-endpoints
Free gateway endpoints for S3 and DynamoDB, interface endpoints for everything else, and a security group that opens 443 to the VPC rather than the world. Interface endpoints are listed explicitly because each bills per hour per availability zone.
tencent-vpc-flow-logs
Flow logs for a VPC, subnet, interface, CCN, NAT or direct connect gateway written into a CLS logset and topic the module creates with the retention you choose, ALL traffic rather than only what was accepted. A vpc_id is required for every resource type except CCN, and the module refuses the wrong pair rather than letting the API do it at apply time.
alicloud-vpc-flow-logs
Flow logs for a VPC, vSwitch or elastic network interface written into a Log Service project and logstore the module creates with the retention you choose, all traffic rather than only what was allowed, at one-minute resolution rather than ten, and your KMS key on the logstore if you hold one. A narrower capture has to be accepted by name.
huawei-vpc-flow-logs
Flow logs for a VPC, subnet or port written into an LTS log group and stream the module creates with the retention you choose, all traffic rather than only what was accepted, and VPC-wide rather than the per-port capture that quietly leaves most traffic unrecorded. A flow log that exists but is disabled records nothing; disabling it has to be accepted by name.
gcp-vpc-peering
A peering is two resources or it is nothing - INACTIVE until both halves exist - and custom routes learned from a VPN or Interconnect cross only when one side exports and the other imports, so a spoke that forgot to import has an ACTIVE peering and a hub it cannot reach through. Both halves created, both directions of route exchange set explicitly, and an output that says it is not transitive.
ibm-public-gateway
IBM Cloud VPC public gateways, one per zone you list because a gateway serves its own zone only, with the subnets in the map attached to the gateway of their zone (a gateway with no subnet forwards nothing) and a reserved floating IP per zone when you pass one so the egress address survives recreation. gateway_count says what bills by the hour.
ansible-valkey-server
Valkey, the Redis successor EL 10 ships in place of a redis package that no longer exists. The package sets no password, no maxmemory and no append-only log; this role sets all three, on loopback, with the drop-in given the last word over the package configuration. Original role, live-tested on Rocky Linux 10.
ansible-vault-cli
vault on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs vault status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
vault-policies
Vault policies, auth backends, and secret engine configuration as code.
ansible-vault-server
HashiCorp Vault as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.
oci-vault-kms
KMS vault with HSM/software master keys, key rotation and secret lifecycle management for app credentials.
ansible-vector
Vector on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback, its configuration checked by vector validate before it lands; the live test appends a line to the file source and reads it out of the JSON file sink. Original role, live-tested on Rocky Linux 10.
ansible-velero-cli
The velero client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's CHECKSUM file, and re-checked with sha256sum -c by the live test, which then runs velero backup get with no kubeconfig and expects 'no configuration has been provided'. The server is a per-cluster install, not this role. Original role, live-tested on Rocky Linux 10.
aws-verified-access
Per-request access to internal applications evaluated against identity and device posture, with Cedar policy groups, endpoints and logging that records which identity and posture produced each decision.
gcp-vertex-ai
A Vertex AI Endpoint for online prediction with optional CMEK, optional Private Service Access networking and request/response logging - model deployment left to you, so it stands up for cents.
ansible-victoria-metrics
VictoriaMetrics single-node from the upstream release (sha256-verified) as a hardened system service on loopback with an explicit retention period in the unit. The live test imports one sample through the Prometheus import API, flushes, and queries it back with PromQL, stamped two minutes in the past because queries do not see points younger than the latency offset. Live-tested on Rocky Linux 10.
aws-workspaces
Amazon WorkSpaces Personal with a registered directory, an IP access group and encrypted desktops. AWS makes every user a local administrator by default and can only encrypt a WorkSpace at launch, so admin rights are off and a KMS key is required. It also says the IP group limits streaming but not API actions like rebuild, and only named client types may connect.
oci-vulnerability-scanning
scan_level = NONE is legal for both the agent scan and the port scan, so a recipe with both at NONE runs on schedule, updates its last-run time, and finds nothing because it looked for nothing. A recipe is not a target either: one with no target scans no instance. Refuses a recipe that scans for nothing and always creates the target with it.
ansible-vultr-cli
vultr-cli on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Vultr's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at VULTR_API_KEY. Original role, live-tested on Rocky Linux 10.
vultr-compute-stack
Instances with VPC, firewall, block storage, and reserved IP.
vultr-vke-cluster
VKE Kubernetes with node pools, VPC, and firewall in one module.
alicloud-waf
WAF 3.0 in front of a domain on the pay-as-you-go instance the account has (adopted, not purchased), listening on HTTPS only with your certificate (plain HTTP by name), TLS 1.2 and 1.3 with a modern cipher suite, HTTP/2 and IPv6, the client address trusted from the first X-Forwarded-For hop, and origins reached over HTTPS with SNI, keepalive and retries.
aws-waf
A WAFv2 web ACL (REGIONAL or CLOUDFRONT) with a default-allow posture, configurable AWS managed rule groups blocking by default, and a rate-based rule that throttles abusive IPs.
ansible-cron-access
cronie ships an empty cron.deny and no cron.allow, so every account may schedule work, and at is the same. This role writes both allow files and clears the spools of accounts that may no longer use them, because the access check is in the crontab command: a crontab installed earlier keeps running. The live test watches one run, then stop. Original role, live-tested on Rocky Linux 10.
aws-fsx-windows
Amazon FSx for Windows File Server joined to AWS Managed Microsoft AD. The provider leaves file and share access auditing disabled and keeps 7 days of backups where the API keeps 30; this module audits both to CloudWatch Logs for a year, keeps 30 days with tags copied, and builds the security group from AWS's port table, with remote PowerShell closed by default.
ansible-yor
yor on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has yor tag add yor_trace and yor_name to a Terraform resource, reads the file back, and runs it again expecting zero updated resources; telemetry off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-pam-access
EL ships /etc/security/access.conf with no active rule and pam_access is not in the stack to read it, so every account is admitted from anywhere. This role writes the policy, adds the module through authselect, and refuses to write a rule set that would lock out the account running it. The live test asks PAM, with the origin set. Original role, live-tested on Rocky Linux 10.
ansible-actionlint
actionlint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then writes a workflow reading github.evnt and expects actionlint to say the property is not defined. shellcheck and pyflakes are optional and not installed. Original role, live-tested on Rocky Linux 10.
ansible-age
age and age-keygen on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then makes two identities, encrypts to one, decrypts with it, and sees the other refused; the ciphertext carries the age-encryption.org/v1 header. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-ansible-lint
ansible-lint pinned in /opt/ansible-lint, a virtual environment with its own ansible-core, apart from the system Python and the host's Ansible. The live test runs pip check, lints an unnamed play offline and expects name[play] among the findings, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.
ansible-apache-exporter
apache_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up httpd with server-status on loopback as a fixture, sees apache_up 1 with the worker gauges, stops httpd and sees apache_up 0. Original role, live-tested on Rocky Linux 10.
ansible-aws-iam-authenticator
aws-iam-authenticator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs token -i with no credentials and the metadata service disabled and expects it to stop at 'get credentials'. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-bind-exporter
bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.
ansible-cfn-lint
cfn-lint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a template with a property the S3 bucket schema lacks (E3002, exit 2) and a clean one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-chamber
chamber on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs list with no credentials and the metadata service off, expecting 'no EC2 IMDS role found', and exercises the null backend (a list answered, a read refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-chrony-nts
chrony on EL 10 taking time over NTS (RFC 8915), so every measurement is authenticated and the NTP listener is closed. The live test waits for an NTS source to be selected, restarts chronyd to make it dump its NTS cookies and finds them, checks the daemon is not controlling a clock that is not its own, and asserts nothing listens on UDP 123. Original role, live-tested on Rocky Linux 10.
ansible-consul-template
consul-template on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then renders env and file templates with -once (to stdout, then to disk, read back) and runs a key template against a dead Consul with retries off, to 'connection refused'. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-cosign
cosign on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Sigstore's cosign_checksums.txt, and re-checked with sha256sum -c by the live test, which then asks cosign to verify a blob with a key that does not exist and expects it to stop at loading the key. Original role, live-tested on Rocky Linux 10.
ansible-crane
crane on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then builds an image tarball from one layer with append --oci-empty-base, lists its manifest.json, and has crane ls reach a registry on a dead port (connection refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-detect-secrets
detect-secrets on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a file with an AWS-shaped key (reported as AWS Access Key), has the commit hook refuse it (exit 1) and pass a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-dive
dive on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a one-layer image in docker-archive form and has dive --ci analyse it (PASS) and export the analysis as JSON, asserting the layer and the file in it. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-doctl
doctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in DigitalOcean's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a token stops at 'access token is required'. Original role, live-tested on Rocky Linux 10.
ansible-eksctl
eksctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs eksctl get cluster with no credentials and expects it to stop at 'get credentials'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-elasticsearch-exporter
elasticsearch_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up an OpenSearch node first (the exporter holds its listener while its target does not answer), sees the cluster health up and green, indexes one document and reads it counted for the index with the node's version. Original role, live-tested on Rocky Linux 10.
ansible-etcd
etcd from the upstream release (sha256-verified) as a single-member hardened system service on loopback with hourly auto-compaction and a data directory only the service can read; etcdctl and etcdutl are installed beside it. The live test writes a key with etcdctl, reads it back, checks the member's health and deletes the key. Original role, live-tested on Rocky Linux 10.
ansible-fail2ban
fail2ban from EPEL on EL 10, banning into nftables, with the jails and the server settings as .local files beside the package's own. The live test drives a jail past its limit and reads the ban out of nft rather than out of a status page, unbans it and reads the rule's absence, and checks that the same burst from an address in ignoreip is never banned. Original role, live-tested on Rocky Linux 10.
ansible-flyctl
flyctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Fly.io's checksum file, re-checked by the live test. flyctl replaces its own binary unless told not to: the role exports FLY_NO_UPDATE_CHECK=1 for every login shell. Pinned; an API call without a token stops at 'no access token available'. Original role, live-tested on Rocky Linux 10.
ansible-gator
gator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a ConstraintTemplate, a constraint requiring an owner label and two namespaces, and has gator test report the violation (exit 1) and pass the labelled one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-graphite-exporter
graphite_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends plaintext samples over TCP and UDP and reads them back from /metrics with the dotted names flattened. Original role, live-tested on Rocky Linux 10.
ansible-hadolint
hadolint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which lints a two-line Dockerfile with four things wrong and expects DL3008 among the findings and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-hcledit
hcledit on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then reads a resource's bucket attribute, sets it in place, reads the file back with the neighbouring block untouched, and lists the blocks. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-istioctl
istioctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Istio's per-asset .sha256, re-checked by the live test against the file's first field (one space, which sha256sum -c refuses). istioctl version waits for a cluster unless told --remote=false; the live test says so, then runs x precheck to the refused connection. Live-tested on Rocky Linux 10.
ansible-jq
jq on EL 10 from the project's GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in sha256sum.txt, and re-checked with sha256sum -c by the live test, which then runs a filter and expects its result. The distribution's jq trails upstream by a major series; this one is pinned and installed ahead of it in the PATH. Original role, live-tested on Rocky Linux 10.
ansible-json-exporter
json_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test serves a JSON document on loopback as a fixture and scrapes it through the shipped module into a scalar and a labelled object metric; a dead target is a 503. Original role, live-tested on Rocky Linux 10.
ansible-just
just on EL 10 from the GitHub release (the static musl build), refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which writes a justfile, runs a recipe to its echo and lists the recipes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-k9s
k9s on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.sha256, and re-checked with sha256sum -c by the live test. A terminal UI needs a kubeconfig to show anything, so the live test uses k9s version and k9s info, which print the version and the per-user config paths. Original role, live-tested on Rocky Linux 10.
ansible-kafka-exporter
kafka_exporter (SHA-256 pinned per architecture) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up a KRaft broker first (the exporter exits without one), sees kafka_brokers 1, creates a topic, produces three messages and reads the partition's offset at 3. Original role, live-tested on Rocky Linux 10.
ansible-keepalived
keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.
ansible-kind
kind on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum kind publishes, and re-checked with sha256sum -c by the live test. kind needs a container runtime it does not bring (podman on EL 10); kind get clusters with none stops at 'failed to list clusters'. Original role, live-tested on Rocky Linux 10.
ansible-kops
kops on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has create -f load a Cluster manifest against a local state store and stop at the EC2 credential lookup with the metadata service off. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-krew
krew on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has krew update clone the plugin index and krew install ctx land the plugin under a throwaway KREW_ROOT; a plugin the index lacks is refused. Installed as krew and kubectl-krew. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-kube-bench
kube-bench on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then installs the benchmark definitions and runs the cis-1.10 node checks with --exit-code 42: on a host with no kubelet they FAIL, the summary prints, the exit code is 42. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-kube-score
kube-score on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which scores a minimal Deployment and expects the CRITICAL findings (resources, image tag, security context) and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-kubeconform
kubeconform on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the CHECKSUMS file, and re-checked by the live test, which validates two Deployments against the upstream schemas: the right one passes, the one with a string replicas is refused at /spec/replicas. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-kubectl
kubectl on EL 10 from dl.k8s.io, refused by Ansible's get_url unless its SHA-256 is the one in the kubectl.sha256 file published beside it. The live test hashes the binary on disk against that file again and runs kubectl get nodes with no cluster, expecting the refused connection on localhost:8080. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-kubectx
kubectx and kubens on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a two-context kubeconfig, has kubectx switch it offline and read it back, and kubens read the namespace. Both tools from one release, both checked. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-kubent
kubent on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then reads a policy/v1beta1 PodDisruptionBudget from a file against a 1.32 target, expecting the finding and exit 200, then the same object on policy/v1 with exit 0. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-kubeseal
kubeseal on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then generates a throwaway certificate, seals a one-key Secret against it with no cluster and expects a SealedSecret document. The controller stays per cluster. Original role, live-tested on Rocky Linux 10.
ansible-kustomize
kustomize on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.txt, and re-checked with sha256sum -c by the live test. The tag carries a slash (kustomize/v5.8.1), URL-encoded in the release path. Pinned; kustomize build against a directory with no kustomization stops where it should. Original role, live-tested on Rocky Linux 10.
ansible-lego
lego on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs the pinned binary and has dnshelp list the DNS-01 providers it can drive (route53, cloudflare, azuredns, gcloud among some two hundred). v5 command tree documented. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-logrotate-policy
logrotate on EL 10: one drop-in for this host's own logs, checked by logrotate before it lands, with the timer the package ships enabled. The live test writes one log past the size limit and one well under it, runs the unit the timer runs rather than forcing it, and asserts the first rotated and was truncated while the second was left alone. Original role, live-tested on Rocky Linux 10.
ansible-memcached
memcached from AppStream, configured through the one file its packaged unit reads; the live test stores a value and reads it back over the protocol, checks the statistics report the configured memory and threads, and asserts nothing listens on UDP, the amplification reflector's port. Original role, live-tested on Rocky Linux 10.
ansible-memcached-exporter
memcached_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads memcached_up 0 while nothing listens, brings up memcached on loopback as a fixture, sees memcached_up 1, stores one item over the protocol and sees it counted, stops memcached and sees memcached_up 0. Original role, live-tested on Rocky Linux 10.
ansible-minikube
minikube on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 the project publishes, and compared again with the binary on disk by the live test, which then runs minikube status with no profile and expects the profile-not-found message. The driver (podman, docker, kvm2) is not this role's. Original role, live-tested on Rocky 10.
ansible-mkcert
mkcert on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then points CAROOT at its own directory, has mkcert make the CA and a certificate for probe.test, verifies the chain with openssl and reads the SANs back; the system trust store is left alone. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-mtail
mtail on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test appends three lines to the followed log, one with ERROR, and reads lines_total 3 and errors_total 1; every program directory is compiled by --compile_only before a restart. Original role, live-tested on Rocky Linux 10.
ansible-mysqld-exporter
mysqld_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up MariaDB as a fixture, reads mysql_up 0 before the exporter's user exists, creates it with the monitoring grants, and reads mysql_up 1 with the status counters. Original role, live-tested on Rocky Linux 10.
ansible-nftables
nftables from AppStream on EL 10: default-deny inbound with a port allowlist, in its own table, checked by nft before it loads. The live test opens a listener on an allowed port and on one that is not: the first answers, the second times out, the drop counter moves, and loopback still answers. Original role, live-tested on Rocky Linux 10.
ansible-nginx-exporter
nginx-prometheus-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up nginx with stub_status on loopback as a fixture, sees nginx_up 1 with the connection gauges, stops nginx and sees nginx_up 0. Original role, live-tested on Rocky Linux 10.
ansible-ntfy
ntfy from the upstream release (sha256-verified) as a hardened system service on loopback with a message cache, a user database and deny-all as the default access. The live test sees an anonymous publish and a wrong password refused, creates a user with ntfy's own command, publishes a message and reads it back from the topic. Original role, live-tested on Rocky Linux 10.
ansible-pam-faillock
An account lockout on EL 10, put into the authentication stack through authselect because /etc/pam.d/system-auth is a generated symlink. The live test fails one account past the limit and watches the RIGHT password be refused, fails a second one short of the limit and watches it keep working, then resets the first and watches it come back. Original role, live-tested on Rocky Linux 10.
ansible-pip-audit
pip-audit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then audits a requirements file pinning requests 2.19.0 (PYSEC advisories, exit 1) and one pinning six 1.17.0 ('No known vulnerabilities found', exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-postgres-exporter
postgres_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up PostgreSQL 16 as a fixture, reads pg_up 0 before the exporter's role exists, creates it with pg_monitor, and reads pg_up 1 with per-database statistics. Original role, live-tested on Rocky Linux 10.
ansible-pre-commit
pre-commit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a repo-local hook over a staged repository: exit 1 naming the offending file, exit 0 with Passed once it is removed. git installed by the role. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-process-exporter
process-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects systemd and the exporter itself as named process groups with their CPU counters. Original role, live-tested on Rocky Linux 10.
ansible-rclone
rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-redis-exporter
redis_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up Valkey on loopback as a fixture, sees redis_up 1, writes a key and sees it counted in db0; the server password lives in an EnvironmentFile. Original role, live-tested on Rocky Linux 10.
ansible-rest-server
restic's REST backend server from the upstream release (sha256-verified) as a hardened system service on loopback, append-only and private repositories a variable away. No client is installed, so the live test speaks the protocol: creates a repository, writes its config object, reads it back, deletes it and sees it gone. Original role, live-tested on Rocky Linux 10.
ansible-rqlite
rqlite (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous caller and a wrong password refused, writes a row through the HTTP API and reads it back, and finds the node leading its own raft; the users file is always written, because rqlite answers everyone without one. Original role, live-tested on Rocky Linux 10.
ansible-rsyslog-remote
rsyslog from AppStream as a remote receiver on EL 10: a plaintext port, RFC 5425's TLS port, and one file per sending host. The live test sends a message to each and finds both in the right file at 0640, pushes plaintext at the TLS port and finds nothing written, and checks that no remote message reached this host's own log. Original role, live-tested on Rocky Linux 10.
ansible-s5cmd
s5cmd on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs ls against a dead endpoint with the metadata service disabled, expecting NoCredentialProviders before any connection, and sees a local-to-local cp refused by design. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-slsa-verifier
slsa-verifier on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then fetches the release's .intoto.jsonl and has the installed binary verify itself against it through Sigstore ('PASSED'); the wrong source tag is refused. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-snmp-exporter
snmp_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up net-snmp's snmpd on loopback as a fixture and walks it through the if_mib module with the shipped snmp.yml; a dead target answers 500. Original role, live-tested on Rocky Linux 10.
ansible-sql-exporter
sql_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads a 500 with no database (nothing invented), brings up PostgreSQL 16 as a fixture, reads the shipped query at 0, inserts three rows and reads 3; the config with the DSN is checked by -config.check before it lands. Original role, live-tested on Rocky Linux 10.
ansible-statsd-exporter
statsd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends a counter, a gauge and a timer over UDP and a counter over TCP and reads them back from /metrics as Prometheus metrics. Original role, live-tested on Rocky Linux 10.
ansible-step
step on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then creates a root CA and a leaf offline, verifies the chain against the right root, sees it refused against another, and inspects the leaf as JSON. The client half of the step-ca role. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-step-ca
Smallstep step-ca and the step CLI from the upstream releases (sha256-verified) as a hardened system service on loopback, initialised once by its own user: root and intermediate keys, ca.json and a JWK provisioner. The live test reads the CA's health, has it issue a certificate, verifies it against the root and sees a wrong password refused. Original role, live-tested on Rocky Linux 10.
ansible-stern
stern on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then runs stern with no kubeconfig and expects the refused connection on localhost:8080. Kubeconfig and contexts are per user. Original role, live-tested on Rocky Linux 10.
ansible-sudoers-policy
A sudo policy on EL 10 as a drop-in that visudo checks before it lands, with commands written out with their arguments. The live test runs the allowed command without a password and is refused three ways: another subcommand, the same command with a different argument, and a user outside the group. Both appear in sudo's own log. Original role, live-tested on Rocky Linux 10.
ansible-unit-hardening
The scheduler on a stock EL host scores 9.6 UNSAFE and holds every capability the kernel has. This role writes a sandboxing drop-in and proves both halves: systemd's own exposure level came down, and the service still runs its jobs. The capability set that scores best is the one that stops cron working, and the README has the table. Original role, live-tested on Rocky Linux 10.
ansible-journald-retention
systemd-journald on EL 10: a drop-in that moves the journal to persistent storage, seals it, and puts a ceiling on the disk it may take. The live test reads the EFFECTIVE settings back out of systemd rather than the file it wrote, finds a real journal file on disk, round-trips a message through it, and runs a vacuum. Original role, live-tested on Rocky Linux 10.
ansible-systemd-exporter
systemd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects the exporter's own unit reported active - D-Bus reached as an unprivileged service user. Original role, live-tested on Rocky Linux 10.
ansible-talosctl
talosctl on EL 10 from the GitHub release (the 118 MB bare binary), refused by Ansible's get_url unless its SHA-256 is the one in Sidero's sha256sum.txt, and re-checked by the live test, which generates a throwaway control-plane, worker and talosconfig set offline and validates the control-plane file for metal. Pinned; a newer release is a variable change. Original role, live-tested on Rocky 10.
ansible-tenv
tenv on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has tenv tofu install fetch OpenTofu 1.8.7 (the OpenPGP check runs when cosign is absent), lists it and runs it. Shims are opt-in so nothing shadows the host's tofu. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-terraform-docs
terraform-docs on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's .sha256sum, and re-checked with sha256sum -c by the live test, which then renders an empty module as a Markdown table and expects 'No requirements': parser and renderer both ran, with no terraform binary and no network. Original role, live-tested on Rocky Linux 10.
ansible-tfupdate
tfupdate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then bumps required_version and the aws provider constraint in a module and reads both back; a file with an unclosed block is refused with 'failed to parse input'. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-vals
vals on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then expands a ref+file:// reference in a YAML file, sees a missing file refused, and runs ref+awsssm:// with no credentials to 'no EC2 IMDS role found'. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-yamlfmt
yamlfmt on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a misindented file, expects -lint to exit 1, formats it in place, reads the result back byte for byte and expects the second lint to exit 0. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-yamllint
yamllint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a file whose list is indented two ways (parsable output names the syntax error, exit 1) and a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-yq
Mike Farah's yq on EL 10 from the GitHub release, refused by get_url unless its SHA-256 is the pinned one: yq's checksum files are rhash and BSD forms that get_url cannot parse, so the live test fetches checksums-bsd for the version and asserts the SHA256 line is the pin, then reads a key from a YAML file through yq. Original role, live-tested on Rocky Linux 10.
ansible-zot
zot, the OCI-native registry, from the upstream release binary (sha256-verified, the minimal build by default) as a hardened system service on loopback with dedupe and garbage collection, its config checked by zot verify before it lands. The live test uploads a blob by digest, reads it back, sees the repository in the catalogue, deletes the blob. Original role, live-tested on Rocky Linux 10.