Alibaba Cloud Infrastructure-as-Code modules

49 verified ansible / terraform modules for Alibaba Cloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 49 Alibaba Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 48 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Alibaba Cloud modules

Static validatedLive test pending

alicloud-bastion

A Bastionhost instance, its exposure and the directory its operators come from. Public access with an empty allow list is refused: that is a login page for production. Without AD or LDAP every account is local and outlives the person who left. Destroying it needs Alibaba to white-list the account first, which is documented provider behaviour and reported as an output.

View module
Static validatedLive test pending

alicloud-cdn

An Alibaba Cloud CDN domain in front of your OSS bucket or origin host, serving outside mainland China unless an ICP-filed scope is accepted by name, with the certificate from Certificate Management, every HTTP request redirected, HSTS, HTTP/2, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

View module
Static validatedLive test pending

alicloud-cen-transit-router

An Alibaba Cloud CEN instance with an Enterprise Edition transit router, the route tables you name, and a VPC attachment per VPC with an interface per zone (one zone by name), each associated with one route table and propagating into the tables you list. The default route table is never used, so no VPC reaches another until you say so.

View module
Static validatedLive test pending

alicloud-ssl-certificate

A certificate uploaded into Certificate Management Service for SLB, ALB, CDN and API Gateway to reference. The private key is an argument, so it lands in the Terraform state and the README says so plainly. SM2 is a signing pair plus an encryption pair and the module refuses a half-filled set, which would upload something no client can handshake with.

View module
Static validatedLive test pending

alicloud-org-policy

A Resource Management control policy and the folders or accounts it attaches to, which are separate resources: an unattached policy appears in the console list with a name and a document and constrains nobody. A control policy is a ceiling, so the module counts Deny statements and asks about Allow ones, which grant nothing. Attaching to the root reaches the management account.

View module
Static validatedLive test pending

alicloud-database-migration

A DTS instance and synchronization job with delay_notice on, since a job that has fallen behind reports the same RUNNING as one that has not. Structure, data and synchronization are three separate required flags and the module names what each leaves out. The provider does not mark the endpoint passwords sensitive, so these variables do.

View module
Static validatedLive test pending

alicloud-workflows

A Serverless Workflow flow and its schedules. role_arn is optional in the API, so a flow without one is created, reads correctly in the console and fails at the first task that touches another service - at execution time. The module refuses that, and turns schedules on, because the API default is off and a disabled schedule shows its cron expression anyway.

View module
Static validatedLive test pending

alicloud-fc-function

A Function Compute 3.0 function running as the RAM role you name, with internet access off (on by name), in your VPC when a vpc_config is given, logging every invocation to a Log Service project and logstore (none by name), with code fetched from an OSS object you uploaded. Memory, CPU, disk, timeout and instance concurrency are inputs.

View module
Static validatedLive test pending

alicloud-kms-key

automatic_rotation defaults to Disabled, so today's key material encrypts everything for the life of the account; a key scheduled for deletion is gone after its window with everything encrypted under it; and deletion_protection, the switch that refuses the schedule, defaults to off. Rotation on at your interval, deletion protection on and off by name, the maximum pending window, and an alias.

View module
Static validatedLive test pending

alicloud-kms-secret

A secret in Alibaba Cloud KMS Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the service key (the service key by name), with a version label that rotates the value when changed and a recovery window of up to thirty days before a deleted secret is gone; force deletion is accepted by name.

View module
Static validatedLive test pending

alicloud-maxcompute

A MaxCompute project with allow_full_scan off, so a query with no partition predicate fails rather than quietly reading the whole table and billing per byte - the single most effective cost control MaxCompute has, and the one people turn on after the invoice. Storage encryption is a creation-time choice, and an unset IP white list admits every address rather than none.

View module
Static validatedLive test pending

alicloud-nas-file-system

An Alibaba Cloud NAS file system (NFS) encrypted with your KMS key (NAS-managed without one; unencrypted is not offered), a mount target in your vSwitch behind an access group whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 by name), and a recycle bin that keeps deleted files two weeks (none by name).

View module
Static validatedLive test pending

alicloud-machine-learning

A PAI workspace and the people in it. Created with no members the workspace belongs to whoever ran the apply and the team seeing nothing reads as a permissions problem elsewhere. env_types is fixed at creation and decides whether a dev-to-prod pipeline is even possible, and the role names are the permission model, so each member names their own.

View module
Static validatedLive test pending

alicloud-patch-manager

An OOS patch baseline: which updates are acceptable on one operating system. A baseline is a policy and an OOS task has to run it, which the module reports rather than letting the word imply a schedule. ALLOW_AS_DEPENDENCY makes a rejection advisory - the patch installs anyway when something approved needs it - so BLOCK is the default.

View module
Static validatedLive test pending

alicloud-privatelink-endpoint

An Alibaba Cloud PrivateLink endpoint to a PrivateLink service or an Alibaba Cloud service, with an elastic network interface in each vSwitch you name (one zone has to be accepted by name), behind the security groups you name, and protected from deletion until the protection is turned off.

View module
Static validatedLive test pending

alicloud-ram-role

A RAM role assumable by the services or accounts you name and nothing else (a wildcard principal is refused), with a custom policy written from your statements, the system policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

View module
Static validatedLive test pending

alicloud-container-registry

Namespaces, repositories, VPC access and an internet allowlist on an Alibaba Cloud Container Registry Enterprise Edition instance. Repositories are private and their tags immutable unless set otherwise, auto-create is off, and the internet endpoint is only switched on - by the resource existing - when you give it CIDRs. Image cleanup is deliberately not managed.

View module
Static validatedLive test pending

alicloud-landing-zone

A Resource Directory with its folders and member accounts. Two switches decide whether it works: control policies are off until the directory enables them, so a policy written elsewhere attaches to nothing; and member deletion is off by default, which makes every account this creates permanent and terraform destroy fail on it. Both are on here.

View module
Static validatedLive test pending

alicloud-security-group

inner_access_policy defaults to Accept, so every instance in a group talks to every other on every port and one compromised web node is a route to the database beside it; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Members isolated unless told otherwise, SSH from anywhere refused unless accepted, egress open until rules narrow it.

View module
Static validatedLive test pending

alicloud-transactional-email

A DirectMail sending domain and the addresses that send from it. Creating the domain does not verify it: nothing sends until the SPF, DKIM, MX and ownership records exist in DNS, which is usually not this Terraform, and the status output is how you find out. trigger and batch are different products with the same name and are throttled and reviewed differently.

View module
Static validatedLive test pending

alicloud-sae-application

A Serverless App Engine namespace and application with auto_config false, which makes the VPC, vSwitch and security group required rather than letting SAE create three resources that live in your account and nobody's Terraform. Two replicas so a deploy is not an outage, min_ready_instances set so a rollout is actually rolling, and typed liveness and readiness probes.

View module
Static validatedLive test pending

alicloud-static-site

An OSS bucket serving a static website. The ACL stays private and a bucket policy publishes the objects, because a public-read ACL also lets anyone list every file you ever put there. The website endpoint is plain HTTP on an Alibaba domain and no certificate can go on it, so serves_https is an output and it says false.

View module
Static validatedLive test pending

alicloud-tablestore

A Tablestore instance whose accessed_by is Vpc rather than the Any the API defaults to, so an AccessKey and the public endpoint are not enough to read it, plus the tables you declare - each with server-side encryption on, which cannot be added later, and each naming a time to live, because a table set to never expire grows forever.

View module
Static validatedLive test pending

alicloud-vpc-peering

A peer connection between two VPCs with a route entry written into every route table you list, on both sides, for every CIDR of the other side, because an Activated peering carries nothing until the routes exist. A default route through a peering is refused, and a cross-account peering that the other account has yet to accept has to be taken by name.

View module
Static validatedLive test pending

alicloud-vpn-gateway

An Alibaba Cloud VPN gateway (pay-as-you-go; subscription by name) with a customer gateway and one IPsec connection on IKEv2 negotiating AES-256, SHA-256 and DH group 14 in both phases, the weak options refused by validation and IKEv1 accepted only by name, dead peer detection and NAT traversal on, and the remote subnets' routes written for you.

View module
Static validatedLive test pending

alicloud-express-connect

A virtual border router on a physical connection you already have, with BFD on so a dead circuit is noticed in milliseconds rather than at the BGP hold timer, and an optional Express Connect Router attachment. Without that attachment the circuit terminates at the border router, which looks like a working connection and routes nothing. Sitelink is billed and off.

View module
Static validatedLive test pending

alicloud-hbr-backup

A Cloud Backup vault encrypted with your KMS key (the HBR-managed key by name), zone-redundant, with WORM on so a compromised account cannot delete the copies (off by name, and it cannot be turned on again later), a policy that backs up daily and keeps thirty days, and a binding for every ECS instance in the map, because a vault with no policy and no binding backs up nothing.

View module
Static validatedLive test pending

alicloud-ack-cluster

Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.

View module
Live-tested

ansible-aliyun-cli

aliyun on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Alibaba's SHASUMS256.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a profile stops at 'aliyun configure'. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

alicloud-vpc-foundation

Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.

View module
Static validatedLive test pending

alicloud-alb

The default TLS policy accepts TLS 1.0; a server group's health check can be turned off and then sends traffic to every member forever; an HTTPS listener does nothing about port 80; and deletion protection is off. A TLS 1.2/1.3 policy created and attached, an HTTP health check on a path, a redirect on 80 whenever a certificate exists, two zones unless one is accepted, deletion protection on.

View module
Static validatedLive test pending

alicloud-api-gateway

An API Gateway group, the APIs in it, and an access control list created WITH its attachment, since an unattached list looks exactly like protection in the console. auth_type ANONYMOUS means anybody with the URL calls the backend and has to be taken per API; force_nonce_check is on for every app-authenticated API, because without it a captured signed request can be replayed.

View module
Static validatedLive test pending

alicloud-actiontrail

An ActionTrail trail that records every region and both reads and writes (narrower by name), delivered to an OSS bucket you own through the service role and, when a project is given, to Log Service for queries. The console keeps ninety days and forgets; the trail is what keeps more. An organization trail collects every member account from the management account.

View module
Static validatedLive test pending

alicloud-dns-zone

An Alibaba Cloud DNS zone with every record in one map, all on the default resolution line so every resolver gets the same answer, and the nameservers Alidns assigns exported for the registrar. DNSSEC is a console setting on paid editions rather than a resource; dnssec_available says so.

View module
Static validatedLive test pending

alicloud-redis

An ApsaraDB for Redis instance in your VPC with the replica in a second zone, TLS required, the security_ips allow-list written from your ranges (0.0.0.0/0 by name), a password from a secret store never output, transparent encryption with your KMS key (the service's by name), daily backups, a maintenance window, and release protection on. Pay-as-you-go.

View module
Static validatedLive test pending

alicloud-image

An Alibaba Cloud custom image captured from an ECS instance into an image family, so instances and scaling groups that name the family get the newest image (no family has to be accepted by name). The snapshots the capture created are deleted with the image. Build the source clean and stop it first.

View module
Static validatedLive test pending

alicloud-ecs-instance

An ECS instance in your vSwitch with login by key pair and no password, no public address unless bandwidth above zero is accepted by name, the system disk encrypted with your KMS key (the service key by name), the metadata service on IMDSv2 only with a hop limit of one, the Security Center agent on, and deletion protection. Pay-as-you-go.

View module
Static validatedLive test pending

alicloud-emr-cluster

An E-MapReduce cluster with security_mode KERBEROS, because NORMAL is the default and a NORMAL cluster comes up, answers on YARN and HDFS, runs Spark, and never checks that a submitter is who they say they are. Both disk encryption flags are on, deletion protection is on, and spot instances on a MASTER or CORE group are refused.

View module
Static validatedLive test pending

alicloud-elasticsearch

An Elasticsearch cluster on the current node-configuration blocks rather than the deprecated flat fields. enable_kibana_public_network defaults to true in this provider and is false here, the search endpoint is private, the data disks are encrypted, and an empty private whitelist is refused because Alibaba reads it as every address that can reach the VPC.

View module
Static validatedLive test pending

alicloud-ecs-disk

An automatic snapshot policy is one resource and its attachment to a disk is another, so a policy in the console with no disks is the usual state; encrypted defaults to false and cannot change after creation; and delete_auto_snapshot can take the snapshots with the disk. Encrypted always, a policy created or yours attached (none by name), the disk and its snapshots outliving the instance.

View module
Static validatedLive test pending

alicloud-nat-gateway

An enhanced, pay-as-you-go NAT gateway for an existing Alibaba Cloud VPC, with a PayByTraffic elastic IP whose bandwidth cap every subnet shares, and an SNAT entry for each vSwitch listed, because a gateway with no SNAT entry forwards nothing. Deletion protection is on for the gateway and the address; off has to be accepted by name.

View module
Static validatedLive test pending

alicloud-mns-queue

A Message Service queue with a dead-letter queue that receives a message after five failed receives, long polling, logging on (it is off by default and is the only record of what was sent), and server-side encryption with your KMS key on both queues (the service key by name).

View module
Static validatedLive test pending

alicloud-oss-bucket

Public access is two switches: a private ACL still leaves a bucket policy or an object ACL free to grant anonymous reads, and only Block Public Access refuses both; versioning is off by default and once on can only be suspended. Private ACL through its own resource plus Block Public Access, public by name, versioning always on, encrypted, abandoned uploads aborted.

View module
Static validatedLive test pending

alicloud-security-posture

Security Center defence rules and baseline checks. A rule naming no servers defends nothing while Alibaba's default keeps running, so it is refused. The block-forever value is 52560000 minutes sitting at the end of a list of ordinary numbers, so the module takes words. SQL Server interception is off by default, which is where the interesting passwords are.

View module
Static validatedLive test pending

alicloud-network-firewall

Address books and control policies with their evaluation order declared, since the list is read top down and a broad accept above a narrow drop silently disables it. The intrusion prevention engine ships in observation mode, where it inspects, logs and blocks nothing while every dashboard looks right; block is the default here. Rules whose action is log are counted and reported.

View module
Static validatedLive test pending

alicloud-monitoring-alarms

CloudMonitor alarm rules from a map of metrics and thresholds, each firing at the critical level after three consecutive breaches and quiet for an hour after, effective all day, and all sending to a contact group created here with the contacts you name. A group with no contacts notifies nobody and has to be accepted by name.

View module
Static validatedLive test pending

alicloud-rds-postgresql

security_ips is the whole allow list and the console's first suggestion is 0.0.0.0/0; ssl_action defaults to Close, so clients speak plain TCP; the SQL audit log and connection logging are off; Basic edition is one node; and deletion protection is off. Ranges required (a /0 by name), SSL open, 180 days of audit log, connection logging on, a standby zone, deletion protection on.

View module
Static validatedLive test pending

alicloud-vpc-flow-logs

Flow logs for a VPC, vSwitch or elastic network interface written into a Log Service project and logstore the module creates with the retention you choose, all traffic rather than only what was allowed, at one-minute resolution rather than ten, and your KMS key on the logstore if you hold one. A narrower capture has to be accepted by name.

View module
Static validatedLive test pending

alicloud-waf

WAF 3.0 in front of a domain on the pay-as-you-go instance the account has (adopted, not purchased), listening on HTTPS only with your certificate (plain HTTP by name), TLS 1.2 and 1.3 with a modern cipher suite, HTTP/2 and IPv6, the client address trusted from the first X-Forwarded-For hop, and origins reached over HTTPS with SNI, keepalive and retries.

View module

Compare across clouds

All solutions →

See how the services Alibaba Cloud covers here compare on other providers.

Other providers