IaC Bazaar

Module reference

Every published module in one table, grouped by the cloud it targets. Use it to answer the question a library index actually gets asked: do you cover the thing I run, and what has been proven about it.

Reading the two columns

Functional is whether the current version was really applied to a cloud account, asserted against, and destroyed with the teardown confirmed. Anything short of that reads Static-validated, which is what every published module clears at minimum.

What a blank is not

No policy applies means the scanner has no rules for that provider. It is absence of coverage, not a clean result, so it is never counted as a pass. A finding is printed in red on the module that has it rather than left out to keep the column tidy.

183 modules

Every published IaC Bazaar module, grouped by cloud provider, with its verification state.
ModuleCategoryToolVersionFunctionalSecurity scan
AWS39
aws-acmRequests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.Secrets & KMSTerraformv1.1.0Live-testedPassed
aws-apigateway-httpHTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.API GatewayTerraformv1.1.0Live-testedPassed
aws-apigateway-restA REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.API GatewayTerraformv1.1.0Live-testedPassed
aws-s3-bucketPrivate S3 bucket with encryption, versioning, public-access block, and TLS-only policy.StorageTerraformv1.1.0Live-testedPassed
aws-albALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.Load BalancingTerraformv1.1.0Live-testedPassed
aws-auroraAurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.DatabasesTerraformv1.1.0Live-testedPassed
aws-cloudfront-siteComplete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.CDN & EdgeTerraformv1.1.0Static-validatedPassed
aws-cloudwatchA self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.ObservabilityTerraformv1.1.0Live-testedPassed
aws-codedeployCodeDeploy application, deployment groups, and the platform-correct service role for automated EC2/ECS/Lambda rollouts with auto-rollback on failure.CI/CD & AutomationTerraformv1.1.0Live-testedPassed
aws-codepipelineAWS-native CI/CD: CodePipeline orchestrating a CodeBuild project, with an encrypted private artifact bucket and least-privilege roles. Sources from S3 (or GitHub).CI/CD & AutomationTerraformv1.1.0Live-testedPassed
aws-cognitoA secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.Security & IdentityTerraformv1.1.0Live-testedPassed
aws-dynamodb-tableDynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.DatabasesTerraformv1.1.0Live-testedPassed
aws-ec2-instanceEC2 instance with IMDSv2, encrypted EBS, instance profile, and EIP - secure defaults out of the box.Compute & VMsTerraformv1.1.0Live-testedPassed
aws-autoscalingEC2 launch template and Auto Scaling group with IMDSv2 enforced, encrypted gp3 root volume, an egress-only security group, and scale-to-zero defaults so it applies cleanly with no compute cost.Compute & VMsTerraformv1.1.0Live-testedPassed
aws-ecrECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.Container RegistryTerraformv1.1.0Live-testedPassed
aws-ecs-fargate-serviceFull Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.Serverless & ContainersTerraformv1.1.0Live-testedPassed
aws-efsAn EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.StorageTerraformv1.1.0Live-testedPassed
aws-eksOpinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.KubernetesTerraformv1.1.0Live-testedPassed
aws-elasticache-redisA cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.DatabasesTerraformv1.1.0Live-testedPassed
aws-eventbridgeA custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-iam-rolesLeast-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.Security & IdentityTerraformv1.1.0Live-testedPassed
aws-jenkinsSelf-hosted Jenkins controller on a hardened EC2 instance - restricted security group, IMDSv2 enforced, SSM access, encrypted root volume, Jenkins auto-installed via user-data.CI/CD & AutomationTerraformv1.1.0Live-testedPassed
aws-kmsCustomer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.Secrets & KMSTerraformv1.1.0Live-testedPassed
aws-kinesisA Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-lambdaLambda with execution role, log group, triggers, aliases, and zip/container packaging handled.Serverless & ContainersTerraformv1.1.0Live-testedPassed
aws-mskAn MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-nlbA Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.Load BalancingTerraformv1.1.0Live-testedPassed
aws-vpcBattle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.Networking & VPCTerraformv1.1.0Live-testedPassed
aws-rdsSingle-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.DatabasesTerraformv1.1.0Live-testedPassed
aws-redshiftA production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.DatabasesTerraformv1.1.0Live-testedPassed
aws-route53A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.DNSTerraformv1.1.0Live-testedPassed
aws-sesAn SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-snsSNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-sqsSQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.Messaging & StreamingTerraformv1.1.0Live-testedPassed
aws-ssm-parameter-storeMap-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.Secrets & KMSTerraformv1.1.0Live-testedPassed
aws-secrets-managerSecrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.Secrets & KMSTerraformv1.1.0Live-testedPassed
aws-security-groupSecurity groups with named rule presets (https, postgres, redis...) using modern standalone rule resources.Security & IdentityTerraformv1.1.0Live-testedPassed
aws-step-functionsA Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.Serverless & ContainersTerraformv1.1.0Live-testedPassed
aws-wafA WAFv2 web ACL (REGIONAL or CLOUDFRONT) with a default-allow posture, configurable AWS managed rule groups blocking by default, and a rate-based rule that throttles abusive IPs.Security & IdentityTerraformv1.1.0Live-testedPassed
Azure37
azure-api-managementAn API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.API GatewayTerraformv1.1.0Live-testedPassed
azure-application-gatewayRegional L7 load balancer with WAF v2 policy, TLS termination from Key Vault, autoscaling and health probes.Load BalancingTerraformv1.1.0Live-testedPassed
azure-app-serviceApp Service plan + Linux web app with deployment slots, custom domain + managed TLS, VNet integration and autoscale.Serverless & ContainersTerraformv1.1.0Live-testedPassed
azure-bastion-jumpboxBastion (Developer/Basic/Standard SKU) with optional hardened Linux VM, JIT-style NSG rules and boot diagnostics for secure VM access without public IPs.Security & IdentityTerraformv1.1.0Live-testedPassed
azure-redis-cacheAzure Cache for Redis done cheap by default - the Basic C0 tier with TLS 1.2 minimum and the non-SSL port disabled - scaling cleanly up to Standard and Premium via precondition-guarded inputs.DatabasesTerraformv1.1.0Static-validatedPassed
azure-container-appsContainer Apps environment with workload profiles, Dapr, KEDA scale rules, ACR pull identity and custom domain.Serverless & ContainersTerraformv1.1.0Live-testedNo policy applies
azure-container-instancesRuns one or more containers on Azure Container Instances without VMs or an orchestrator - secure by default with no privileged containers, redacted secret fields, and an optional managed identity.Serverless & ContainersTerraformv1.1.0Live-testedPassed
azure-acrACR with geo-replication, retention/trust policies, private endpoint and AcrPull role wiring for AKS/Container Apps.Container RegistryTerraformv1.1.0Live-testedPassed
azure-cosmos-dbCosmos DB (NoSQL or MongoDB API) with multi-region failover, autoscale throughput, private endpoint and backup policy.DatabasesTerraformv1.1.0Live-testedPassed
azure-devopsBootstraps an Azure DevOps project with an initialized Git repository and a YAML build pipeline - repeatable team setup as code.CI/CD & AutomationTerraformv1.1.0Live-testedPassed
azure-front-doorGlobal entry point: Front Door profile, endpoints, origin groups, custom domains with managed TLS and WAF policy.Load BalancingTerraformv1.1.0Live-testedNo policy applies
azure-functionsFunction app (Flex Consumption or Premium) with storage, Application Insights, managed identity and VNet integration.Serverless & ContainersTerraformv1.1.0Live-testedPassed
azure-key-vaultRBAC-mode Key Vault with private endpoint, diagnostics, and managed keys/secrets/certificates scaffolding.Secrets & KMSTerraformv1.1.0Live-testedPassed
azure-aksHardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.KubernetesTerraformv1.1.0Live-testedPassed
azure-landing-zone-coreManagement-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.Landing Zones & FoundationsTerraformv1.1.0Live-testedPassed
azure-vmssA self-contained Linux VM Scale Set (Uniform orchestration) on Azure - one apply creates the resource group, VNet, subnet, NSG and an SSH-key-only scale set with deny-all-inbound and no public IPs.Compute & VMsTerraformv1.1.0Live-testedPassed
azure-virtual-machineA fully self-contained general-purpose Linux VM on Azure - one apply creates the resource group, VNet, subnet, NSG, NIC, optional public IP and an SSH-key-only VM with a system-assigned identity.Compute & VMsTerraformv1.1.0Live-testedPassed
azure-monitor-baselineCentral Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).ObservabilityTerraformv1.1.0Live-testedNo policy applies
azure-private-dnsA self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.DNSTerraformv1.1.0Live-testedPassed
azure-private-endpointAn Azure Private Endpoint giving a target PaaS resource a private IP inside your VNet so traffic stays on the Microsoft backbone - wire to existing subnet/target or run fully self-contained.Networking & VPCTerraformv1.1.0Live-testedPassed
azure-dns-zoneAn Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.DNSTerraformv1.1.0Live-testedNo policy applies
azure-sql-databaseLogical SQL server + database with Entra-only auth, firewall/private endpoint, auditing, TDE and failover-group option.DatabasesTerraformv1.1.0Live-testedPassed
azure-load-balancerAn Azure Standard L4 load balancer with a self-created static public IP frontend, a backend address pool, health probes and load-balancing rules - Standard SKU throughout.Load BalancingTerraformv1.1.0Live-testedNo policy applies
azure-static-web-appGlobally distributed hosting for static sites and SPAs on Azure Static Web Apps with optional serverless APIs, free auto-renewing TLS, and a built-in global CDN - defaulting to the cost-free Free SKU.Serverless & ContainersTerraformv1.1.0Live-testedNo policy applies
azure-storage-accountStorage account with containers/file shares, lifecycle rules, network rules, CMK encryption and private endpoint options - Azure's most-deployed resource done right.StorageTerraformv1.1.0Live-testedPassed
azure-traffic-managerGlobal, DNS-based load balancing with a Traffic Manager profile and map-driven external endpoints - Performance, Priority, Weighted, Geographic, Subnet or MultiValue routing with an HTTPS health probe.Load BalancingTerraformv1.1.0Live-testedNo policy applies
azure-vnetProduction VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.Networking & VPCTerraformv1.1.0Live-testedPassed
azure-entra-id-baselineApp registrations, service principals, groups and federated credentials (OIDC for GitHub/Terraform) - the identity plumbing every Azure org rebuilds by hand.Security & IdentityTerraformv1.1.0Live-testedPassed
azure-event-gridAn Event Grid custom topic plus event subscriptions with an optional in-module Storage Queue target - SAS auth off (Entra ID), a system-assigned identity, and HTTPS-only TLS 1.2+ storage.Messaging & StreamingTerraformv1.1.0Live-testedPassed
azure-event-hubsAn Event Hubs namespace plus hubs, each with consumer groups and least-privilege SAS rules for high-throughput (Kafka-compatible) ingestion - TLS 1.2 floor and optional default-deny networking.Messaging & StreamingTerraformv1.1.0Live-testedPassed
azure-jenkinsSelf-hosted Jenkins on a hardened Azure Linux VM - self-contained vnet/subnet/NSG, SSH-key auth only, managed-disk encryption, Jenkins installed via cloud-init.CI/CD & AutomationTerraformv1.1.0Live-testedPassed
azure-logic-appAn Azure Logic App (Consumption) workflow with a built-in Recurrence trigger - serverless pay-per-execution automation with a system-assigned managed identity and inbound IP allowlists.Serverless & ContainersTerraformv1.1.0Live-testedNo policy applies
azure-mysql-flexibleAzure Database for MySQL Flexible Server with TLS required by default, correct delegated-subnet + private DNS zone ordering, an Entra administrator, databases, and cheapest-by-default Burstable sizing.DatabasesTerraformv1.1.0Live-testedPassed
azure-postgresql-flexibleFlexible Server with HA option, private VNet delegation, Entra auth, firewall and tuned server parameters.DatabasesTerraformv1.1.0Live-testedPassed
azure-resource-group-baselineOpinionated resource group factory with CAF-compliant naming, mandatory tags, locks and budget alert.OtherTerraformv1.1.0Live-testedNo policy applies
azure-service-busAn Azure Service Bus namespace with queues, topics and subscriptions on the Standard SKU - SAS local auth off (Entra ID + RBAC), TLS 1.2+ minimum, and dead-lettering of expired messages.Messaging & StreamingTerraformv1.1.0Live-testedPassed
azure-managed-identityA map-driven module creating one or many user-assigned managed identities, each with optional workload identity federation (OIDC) and least-privilege RBAC role assignments - no secrets to rotate.Security & IdentityTerraformv1.1.0Live-testedNo policy applies
Google Cloud37
gcp-api-gatewayA serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.API GatewayTerraformv1.1.0Live-testedNo policy applies
gcp-alloydbAlloyDB cluster with primary + read-pool instances, PSC connectivity, automated backups and columnar/vector engine flags.DatabasesTerraformv1.1.0Live-testedPassed
gcp-artifact-registryDocker/Maven/npm repos with cleanup policies, remote and virtual repositories, CMEK and reader/writer IAM.Container RegistryTerraformv1.1.0Live-testedPassed
gcp-bigquery-datasetDatasets with partitioned/clustered tables, authorized views, CMEK and dataset-level access controls.DatabasesTerraformv1.1.0Live-testedPassed
gcp-certificate-managerA Certificate Manager certificate map for external HTTPS load balancers, with an optional Google-managed certificate and DNS authorization provisioned when you supply a domain you control.Secrets & KMSTerraformv1.1.0Live-testedNo policy applies
gcp-cloud-armorA global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.Security & IdentityTerraformv1.1.0Live-testedPassed
gcp-bigtableA single-cluster Cloud Bigtable instance (one 1-node SSD cluster, the smallest footprint) plus a table with column families, IAM-only access, optional CMEK, and deletion protection on.DatabasesTerraformv1.1.0Live-testedPassed
gcp-composerManaged Apache Airflow on Cloud Composer 2 with small-by-default sizing, worker autoscaling pinned for predictable cost, and an opt-in private environment posture.CI/CD & AutomationTerraformv1.1.0Live-testedNo policy applies
gcp-cloud-dnsPublic/private managed zones with record sets, DNSSEC, forwarding and peering configs.DNSTerraformv1.1.0Live-testedPassed
gcp-filestoreA managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.StorageTerraformv1.1.0Live-testedNo policy applies
gcp-kmsKeyrings and rotation-enabled crypto keys with per-key IAM for CMEK across GCS, BigQuery, Cloud SQL and disks.Secrets & KMSTerraformv1.1.0Live-testedPassed
gcp-monitoringA self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.ObservabilityTerraformv1.1.0Static-validatedPassed
gcp-cloud-natA regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.Networking & VPCTerraformv1.1.0Live-testedNo policy applies
gcp-cloud-functionEvent-driven or HTTP gen2 function with source upload, dedicated runtime SA and Eventarc trigger wiring.Serverless & ContainersTerraformv1.1.0Live-testedPassed
gcp-cloud-run-jobA Cloud Run v2 Job for batch and run-to-completion workloads with a dedicated runtime service account, auto-wired Secret Manager accessor grants, VPC egress, bounded retries and per-task timeout.Serverless & ContainersTerraformv1.1.0Live-testedNo policy applies
gcp-cloud-run-serviceCloud Run v2 service with autoscaling, secret and VPC egress wiring, custom domain and invoker IAM done right.Serverless & ContainersTerraformv1.1.0Live-testedPassed
gcp-cloud-sqlRegional-HA Cloud SQL with private IP (PSA/PSC), automated backups, PITR, read replicas and IAM database auth.DatabasesTerraformv1.1.0Live-testedPassed
gcp-cloud-schedulerA Cloud Scheduler cron job that calls an HTTP(S) endpoint on a schedule, with a bounded attempt deadline, capped exponential-backoff retries, and per-invocation OIDC/OAuth service-account auth.Messaging & StreamingTerraformv1.1.0Live-testedNo policy applies
gcp-spannerA regional Cloud Spanner instance at the smallest billable size (100 processing units) plus a database with optional starter schema, drop protection, and Terraform deletion protection on.DatabasesTerraformv1.1.0Live-testedPassed
gcp-gcs-bucketHardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.StorageTerraformv1.1.0Live-testedPassed
gcp-cloud-tasksA Cloud Tasks queue with capped dispatch rate and concurrency, a bounded exponential-backoff retry policy, and full Stackdriver logging so failed dispatches are observable rather than silent.Messaging & StreamingTerraformv1.1.0Live-testedNo policy applies
gcp-workflowsA Cloud Workflows workflow that runs as a dedicated least-privilege service account instead of the broad Compute Engine default, with inline YAML, deletion protection, and call logging.CI/CD & AutomationTerraformv1.1.0Live-testedNo policy applies
gcp-compute-instanceA hardened Compute Engine VM on Debian 12 with Shielded VM (Secure Boot, vTPM, integrity monitoring), OS Login for IAM-managed SSH, no external IP by default, and deletion protection on.Compute & VMsTerraformv1.1.0Live-testedPassed
gcp-dataprocA single-node Dataproc cluster (1 master, 0 workers), the cheapest managed Spark/Hadoop cluster that still applies and destroys cleanly, with internal-only IPs and deletion protection on.CI/CD & AutomationTerraformv1.1.0Live-testedPassed
gcp-eventarcAn Eventarc Pub/Sub trigger wired into a self-contained pipeline - a Cloud Run target, a dedicated delivery service account, and the run.invoker and eventReceiver grants Eventarc silently requires.Messaging & StreamingTerraformv1.1.0Live-testedPassed
gcp-project-factoryOpinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.Landing Zones & FoundationsTerraformv1.1.0Live-testedPassed
gcp-vpcProduction VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.Networking & VPCTerraformv1.1.0Live-testedPassed
gcp-gke-clusterPrivate, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.KubernetesTerraformv1.1.0Live-testedPassed
gcp-http-load-balancerGlobal ALB with managed TLS certs, URL map, serverless/instance NEG backends, optional Cloud CDN and Cloud Armor policy.Load BalancingTerraformv1.1.0Live-testedPassed
gcp-ha-vpn99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.Networking & VPCTerraformv1.1.0Live-testedPassed
gcp-internal-lbAn internal passthrough L4 load balancer - health check, regional backend service and forwarding rule - that stands up before any backends exist, preserving client source IPs, with optional global access.Load BalancingTerraformv1.1.0Live-testedPassed
gcp-managed-instance-groupA zonal Managed Instance Group built from a hardened Shielded-VM instance template, private by default, with optional CPU autoscaling, autohealing, and zero-downtime rolling template updates.Compute & VMsTerraformv1.1.0Live-testedPassed
gcp-memorystorePrivate Memorystore instance or cluster (Redis or Valkey) with auth, TLS and maintenance policy on your VPC.DatabasesTerraformv1.1.0Live-testedPassed
gcp-pubsubTopics with schemas, push/pull/BigQuery subscriptions, dead-letter queues and retry policies preconfigured.Messaging & StreamingTerraformv1.1.0Live-testedPassed
gcp-secret-managerSecrets with versions, replication policy, rotation schedules, expiry and accessor IAM.Secrets & KMSTerraformv1.1.0Live-testedNo policy applies
gcp-service-accounts-iamService accounts with least-privilege project/resource IAM and optional Workload Identity Federation for keyless CI/CD (GitHub Actions).Security & IdentityTerraformv1.1.0Live-testedPassed
gcp-vertex-aiA Vertex AI Endpoint for online prediction with optional CMEK, optional Private Service Access networking and request/response logging - model deployment left to you, so it stands up for cents.AI & MLTerraformv1.1.0Live-testedPassed
Oracle Cloud18
oci-api-gatewayManaged API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.API GatewayTerraformv1.1.0Static-validatedPassed
oci-autonomous-databaseATP/ADW/JSON/APEX autonomous database with private endpoint, mTLS wallet output, ACLs, auto-scaling and backup config.DatabasesTerraformv1.1.0Static-validatedPassed
oci-base-databaseOracle Database VM system with DB home, TDE via Vault, automated backups and optional Data Guard standby.DatabasesTerraformv1.1.0Static-validatedFailed
oci-bastionZero-footprint managed bastion with session-managed SSH/port-forward access to private subnets - replaces jump hosts.Security & IdentityTerraformv1.1.0Static-validatedPassed
oci-dns-zonePublic/private DNS zones with record sets, failover/geo steering policies and health-check probes.DNSTerraformv1.1.0Static-validatedPassed
oci-drg-hubDynamic Routing Gateway with VCN attachments, custom DRG route tables, remote peering and IPSec/FastConnect attach points.Networking & VPCTerraformv1.1.0Static-validatedPassed
oci-file-storageElastic NFSv3 file system with mount target, export options, snapshots and NSG-scoped access.StorageTerraformv1.1.0Static-validatedPassed
oci-load-balancerHTTPS load balancer with backend sets, health checks, TLS certificates, rule sets and WAF-ready listeners.Load BalancingTerraformv1.1.0Static-validatedPassed
oci-functions-appServerless Fn application with functions, provisioned concurrency, invoke logging and Events-rule trigger wiring.Serverless & ContainersTerraformv1.1.0Static-validatedPassed
oci-instance-pool-autoscalingSelf-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.Compute & VMsTerraformv1.1.0Static-validatedPassed
oci-mysql-heatwaveManaged MySQL with optional HeatWave analytics cluster, HA, backups, configuration and inbound replication channel.DatabasesTerraformv1.1.0Static-validatedPassed
oci-compute-instanceOpinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.Compute & VMsTerraformv1.1.0Static-validatedPassed
oci-iam-foundationTenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.Landing Zones & FoundationsTerraformv1.1.0Static-validatedPassed
oci-network-load-balancerLow-latency pass-through NLB with TCP/UDP listeners, backend health checks and preserved client IPs.Load BalancingTerraformv1.1.0Static-validatedPassed
oci-vcnProduction VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.Networking & VPCTerraformv1.1.0Static-validatedPassed
oci-okeEnhanced OKE cluster with managed + virtual node pools, private API endpoint, NSGs, addons and OIDC - flagship OCI workload platform.KubernetesTerraformv1.1.0Static-validatedPassed
oci-object-storage-bucketBucket with versioning, lifecycle/auto-tiering, retention rules, replication and pre-authenticated request support.StorageTerraformv1.1.0Static-validatedPassed
oci-vault-kmsKMS vault with HSM/software master keys, key rotation and secret lifecycle management for app credentials.Secrets & KMSTerraformv1.1.0Static-validatedPassed
Linode9
linode-volumeAttachable, resizable NVMe block volume with safe attach/detach lifecycle handling.StorageTerraformv1.1.0Static-validatedPassed
linode-firewallOpinionated stateful firewall with deny-by-default inbound, curated allow rules, and multi-device attachment.Security & IdentityTerraformv1.1.0Static-validatedPassed
linode-instanceHardened Linode VM with cloud-init, disk encryption, reverse DNS, backups, and firewall attachment in one apply.Compute & VMsTerraformv1.1.0Static-validatedPassed
linode-domainComplete DNS zone with typed record management and sane TTL defaults on Linode's free DNS Manager.DNSTerraformv1.1.0Static-validatedPassed
linode-lke-clusterProduction LKE cluster with autoscaling node pools, HA control plane, disk encryption, ACL, and optional Enterprise tier.KubernetesTerraformv1.1.0Static-validatedPassed
linode-databaseHA managed database cluster with allowlists, maintenance windows, and fork/restore support on the new Aiven platform.DatabasesTerraformv1.1.0Static-validatedPassed
linode-nodebalancerManaged L4/L7 load balancer with TLS termination, health checks, session stickiness, and UDP support.Load BalancingTerraformv1.1.0Static-validatedPassed
linode-object-storageS3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.StorageTerraformv1.1.0Static-validatedPassed
linode-vpcIsolated VPC network with labeled subnets ready for instances, LKE, and NodeBalancer backends.Networking & VPCTerraformv1.1.0Static-validatedPassed
Akamai8
akamai-appsec-wafSecurity configuration with policy, WAF mode, match targets, rate controls, and IP/geo blocking, activated to staging or production.Security & IdentityTerraformv1.1.0Static-validatedPassed
akamai-cps-dv-certificateAutomated Domain Validated TLS enrollment with DNS/HTTP challenge outputs wired for Edge DNS.Secrets & KMSTerraformv1.1.0Static-validatedPassed
akamai-edge-dns-zoneAuthoritative Edge DNS zone with full recordset management on Akamai's DDoS-resilient anycast network.DNSTerraformv1.1.0Live-testedPassed
akamai-cloudlets-edge-redirectorRule-driven edge redirects (vanity URLs, migrations) managed as code with versioned policy activation.CDN & EdgeTerraformv1.1.0Static-validatedPassed
akamai-edgeworkerDeploy JavaScript at the edge with bundle versioning, EdgeKV namespace, and network activation in one module.Serverless & ContainersTerraformv1.1.0Static-validatedPassed
akamai-gtm-failoverGlobal Traffic Management domain with datacenters and failover or weighted-round-robin properties plus liveness tests.DNSTerraformv1.1.0Static-validatedPassed
akamai-property-ionEnd-to-end Ion CDN property: origin, edge hostname, caching/performance rule tree, CP code, and staging/production activation.CDN & EdgeTerraformv1.1.0Static-validatedPassed
akamai-network-listsVersioned IP and geo block/allow lists with activation, ready to feed WAF policies and property rules.Security & IdentityTerraformv1.1.0Live-testedPassed
DigitalOcean4
do-app-platformDeclarative App Platform deployment with services, workers, domains, and alerts.Serverless & ContainersTerraformv1.1.0Static-validatedNo policy applies
do-doks-clusterProduction DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.KubernetesTerraformv1.1.0Static-validatedNo policy applies
do-droplet-stackHardened droplet(s) with VPC, firewall, volume, reserved IP, and cloud-init bootstrap.Compute & VMsTerraformv1.1.0Static-validatedPassed
do-managed-databaseManaged PG/MySQL/Valkey cluster with firewall trust list, users, DBs, and replicas.DatabasesTerraformv1.1.0Static-validatedNo policy applies
Cloudflare3
cloudflare-dnsZone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.DNSTerraformv1.1.0Static-validatedNo policy applies
cloudflare-workers-platformWorker with KV/R2/D1 bindings, routes, custom domain, and secrets - full edge app scaffold.Serverless & ContainersTerraformv1.1.0Static-validatedNo policy applies
cloudflare-zero-trust-accessAccess application with policies, identity provider wiring, and a cloudflared tunnel to private origins.Security & IdentityTerraformv1.1.0Static-validatedNo policy applies
Hetzner3
hetzner-lb-web-tierManaged LB with health checks, cert, and label-selected server targets.Load BalancingTerraformv1.1.0Static-validatedNo policy applies
hetzner-private-networkPrivate network with subnets, routes, and a NAT gateway server for egress-only fleets.Networking & VPCTerraformv1.1.0Static-validatedNo policy applies
hetzner-server-fleetN-server fleet with placement group, firewall, primary IPs, and cloud-init - Hetzner's price/perf with guardrails.Compute & VMsTerraformv1.1.0Static-validatedNo policy applies
Scaleway3
scaleway-kapsule-clusterKapsule Kubernetes with pools, private network, and autoscaling/autoheal presets.KubernetesTerraformv1.1.0Static-validatedNo policy applies
scaleway-rdb-instanceRDB PostgreSQL/MySQL with HA, private-network endpoint, users, and ACLs.DatabasesTerraformv1.1.0Static-validatedNo policy applies
scaleway-serverless-containerContainer namespace, deployed container, custom domain, and registry wiring.Serverless & ContainersTerraformv1.1.0Static-validatedNo policy applies
Alibaba Cloud2
alicloud-ack-clusterManaged ACK Kubernetes with node pools, VPC integration, and RAM roles.KubernetesTerraformv1.1.0Static-validatedNo policy applies
alicloud-vpc-foundationMulti-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.Networking & VPCTerraformv1.1.0Static-validatedPassed
Civo2
civo-compute-stackInstances with network, firewall, volume, and reserved IP.Compute & VMsTerraformv1.1.0Static-validatedNo policy applies
civo-k3s-clusterFast-launch k3s cluster with node pools, firewall rules, and network.KubernetesTerraformv1.1.0Static-validatedNo policy applies
Exoscale2
exoscale-dbaasManaged PG/MySQL/Kafka with IP filters and TF-managed users.DatabasesTerraformv1.1.0Static-validatedNo policy applies
exoscale-sks-clusterSKS Kubernetes with node pools, security groups, and anti-affinity.KubernetesTerraformv1.1.0Static-validatedNo policy applies
IBM Cloud2
ibm-iks-clusterIKS cluster on VPC Gen2 with worker pools and COS-backed registry namespace.KubernetesTerraformv1.1.0Static-validatedNo policy applies
ibm-vpc-landingVPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.Networking & VPCTerraformv1.1.0Static-validatedPassed
OVHcloud2
ovh-managed-databaseManaged PG/MySQL/Kafka with users, IP restrictions, and private network egress.DatabasesTerraformv1.1.0Static-validatedNo policy applies
ovh-managed-k8sMKS cluster with node pools and private-network (vRack) attachment.KubernetesTerraformv1.1.0Static-validatedNo policy applies
Tencent Cloud2
tencent-vpc-foundationVPC with subnets, route tables, NAT, and security groups across AZs.Networking & VPCTerraformv1.1.0Static-validatedPassed
tencent-tke-clusterManaged TKE Kubernetes with node pools and VPC-CNI networking.KubernetesTerraformv1.1.0Static-validatedPassed
UpCloud2
upcloud-managed-databaseManaged PG/MySQL with properties tuning, users, and logical DBs.DatabasesTerraformv1.1.0Static-validatedNo policy applies
upcloud-server-stackServers on SDN private network with storage, router, and firewall rules.Compute & VMsTerraformv1.1.0Static-validatedNo policy applies
Vultr2
vultr-compute-stackInstances with VPC, firewall, block storage, and reserved IP.Compute & VMsTerraformv1.1.0Static-validatedNo policy applies
vultr-vke-clusterVKE Kubernetes with node pools, VPC, and firewall in one module.KubernetesTerraformv1.1.0Static-validatedNo policy applies
Huawei Cloud1
huawei-cce-clusterCCE Kubernetes with VPC/subnet, node pool, and EIP-attached ingress.KubernetesTerraformv1.1.0Static-validatedNo policy applies
Multi-cloud & platform-agnostic5
ansible-base-hardeningSSH hardening drop-in, sysctl security profile, login banner, and time sync. Original, live-tested (Molecule) role.Security & IdentityAnsiblev1.1.0Live-testedNo policy applies
ansible-nginxVerified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.Web & App ServersAnsiblev1.1.0Live-testedNo policy applies
ansible-postgresqlPostgreSQL server with guarded initdb, SCRAM-SHA-256 auth, managed conf.d drop-in, templated pg_hba, and app database + owner provisioning. Original, live-tested (Molecule/podman) role.DatabasesAnsiblev1.1.0Live-testedNo policy applies
ansible-node-exporterOfficial node_exporter release (pinned v1.11.1) with sha256 checksum-verified install, dedicated shell-less system user, and a systemd unit on :9100; live-tested for idempotence with a functional /metrics verification.ObservabilityAnsiblev1.1.0Live-testedNo policy applies
vault-policiesVault policies, auth backends, and secret engine configuration as code.Secrets & KMSTerraformv1.1.0Static-validatedNo policy applies

What is on the module page

Follow any row for the full record: the verification receipts for that release, the published SHA-256 and its cosign signature, the provider versions it was tested against, and the compatibility panel. The declared input and output contract and the source itself need an account.