AWS Infrastructure-as-Code modules

143 verified ansible / terraform modules for AWS, spanning AWS, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

45 of 143 AWS modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 98 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All AWS modules

Static validatedLive test pending

aws-mq

deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.

View module
Static validatedLive test pending

aws-budgets

A budget with no notification tracks correctly and tells nobody, so the invoice is the first notice; ACTUAL-only alerts arrive after the money is gone. And include_credit defaults true, so a budget on a credited account reports runway rather than spend - until the credits end and nothing crosses a threshold.

View module
Static validatedLive test pending

aws-codebuild

privileged_mode hands the build the Docker socket, so anything it runs can read every environment variable and assume the service role. Off by default, and a PLAINTEXT variable whose name looks like a secret is refused.

View module
Static validatedLive test pending

aws-keyspaces

point_in_time_recovery defaults to DISABLED and Keyspaces has no snapshots or automated backups, so off means a dropped table is simply gone. PITR on, a customer-managed key, and the two one-way doors - client-side timestamps and TTL - named rather than set quietly.

View module
Static validatedLive test pending

aws-fis

FIS refuses a template with no stop condition, which reads like a guarantee - and source = 'none' is a legal stop condition meaning the experiment never halts by itself. Refused here, along with targets that grow at run time and an empty-target mode that reports success for having tested nothing.

View module
Static validatedLive test pending

aws-cloudhsm

Cluster and HSMs, with the parts nobody mentions: AWS holds no copy of your keys, Terraform cannot initialise the cluster, and an uninitialised cluster bills per HSM per hour while being unable to store anything.

View module
Static validatedLive test pending

aws-config

Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.

View module
Static validatedLive test pending

aws-control-tower

A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.

View module
Static validatedLive test pending

aws-grafana

account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.

View module
Static validatedLive test pending

aws-database-proxy

Amazon RDS Proxy in front of an RDS instance or Aurora cluster: TLS required, clients authenticate with IAM tokens while the proxy reads the password from Secrets Manager, through a role limited to those secrets. Debug logging writes SQL statement text to the logs, so it is off unless that is accepted. End-to-end IAM removes the stored password entirely.

View module
Static validatedLive test pending

aws-kinesis-firehose

Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.

View module
Static validatedLive test pending

aws-dax-cache

DynamoDB Accelerator with TLS and encryption at rest. DAX leaves both off by default, and neither can be turned on for an existing cluster, so a fix means a new cluster. This module also creates its own security group (DAX otherwise uses the VPC default), a service role limited to the named tables and their indexes, and states that writes bypassing DAX leave stale reads until the TTL.

View module
Static validatedLive test pending

aws-image-builder

A pipeline with no schedule builds when somebody clicks, so the golden image ages until a person remembers it; image tests are the switch turned off to save an hour and scanning is off unless enabled; and the build instance's metadata service can hand its credentials to whatever a step downloads. Weekly rebuilds when a dependency changed, tests and scanning on, IMDSv2-only builds.

View module
Static validatedLive test pending

aws-neptune

Neptune has no user, no password and no GRANT. Authorization is IAM and it defaults to OFF, so anything that can reach port 8182 can read every edge and drop the lot. IAM auth on, storage encrypted, and the audit log driven from one variable because its two halves live in different resources and either alone logs nothing.

View module
Static validatedLive test pending

aws-appsync

introspection_config defaults to ENABLED, handing any caller a complete map of every type, field and argument, and query_depth_limit defaults to 0, which means no limit - so one nested query multiplies into thousands of resolver calls. Both closed here, with request bodies kept out of CloudWatch and a WAF association for the rate nothing else bounds.

View module
Static validatedLive test pending

aws-bedrock-guardrail

Creating a guardrail does not apply it: the application must send guardrailIdentifier and guardrailVersion on every call, and DRAFT is mutable. This publishes a numbered version, outputs the two values your code needs, and refuses a guardrail with no policies at all - which attaches successfully, filters nothing, and reports as active.

View module
Static validatedLive test pending

aws-lightsail-instance

A Lightsail instance is created with 22 and 80 open to every address; its public address changes when it stops unless a static IP is attached, and every DNS record pointing at it is then wrong; and automatic snapshots are off. The port list replaced by your rules with SSH from anywhere accepted by name, a static IP attached, and the daily AutoSnapshot add-on on at the hour you choose.

View module
Static validatedLive test pending

aws-prometheus

Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.

View module
Static validatedLive test pending

aws-dms

ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.

View module
Static validatedLive test pending

aws-sagemaker-notebook

AWS defaults a notebook to direct internet access AND root access: a root shell with a path off the network that misses your NAT, routing and DNS firewall, holding a role chosen to read your training data. Both off here, IMDSv2 only.

View module
Static validatedLive test pending

aws-codeartifact

A repository with a public external connection serves whatever the public registry holds for any name it does not. This puts the connection on its own repository, reached through an upstream, and emits the origin-control commands Terraform cannot apply.

View module
Static validatedLive test pending

aws-ssm-patch-manager

A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.

View module
Static validatedLive test pending

aws-verified-permissions

validation_settings.mode defaults to OFF, so a Cedar policy naming an action the schema does not define is accepted and then never matches. A broken permit fails closed and somebody complains; a broken forbid fails OPEN and nobody does. STRICT here, with the schema that makes it possible.

View module
Static validatedLive test pending

aws-quicksight

A QuickSight subscription on Enterprise edition through IAM Identity Center, with admin, author and reader groups, termination protection on because unsubscribing deletes every dashboard, and a VPC connection with its own role so a private database stays private. The authentication method is permanent; Standard edition and QuickSight-managed users are accepted by name.

View module
Static validatedLive test pending

aws-appconfig

AppConfig exists to deploy a configuration slowly and roll it back automatically, and both halves are opt-in - the predefined AllAtOnce strategy is 100% of the fleet with zero bake time. Gradual here, and a precondition refuses an environment with no alarms, where automatic rollback has nothing to fire on.

View module
Static validatedLive test pending

aws-route53-health-check

A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.

View module
Static validatedLive test pending

aws-opensearch-serverless

A collection cannot exist without an encryption policy and the quickest one uses the AWS-owned key; the network policy decides whether the endpoint answers on the internet; without a data access policy nobody can read or write, with a wide one everyone can; indexes grow until a policy expires them. Private through VPC endpoints (public by name), your key when given, principals named.

View module
Static validatedLive test pending

aws-elasticache-serverless

ElastiCache Serverless for Valkey. With no user group, any client that reaches the endpoint connects as the default user with no password, so this module always attaches a Valkey user group whose users sign in with IAM. It sets a storage and ECPU ceiling, since AWS sets none, and keeps 7 days of snapshots. It also says destroy takes no final snapshot.

View module
Static validatedLive test pending

aws-redshift-serverless

An Amazon Redshift Serverless namespace and workgroup: customer-managed encryption, SSL required, all three logs exported, and the admin password generated and held by Secrets Manager. AWS accepts plaintext connections by default and a usage limit's default action only logs the breach, so SSL is set at creation and the spend limit's action has to be chosen: alert or stop.

View module
Static validatedLive test pending

aws-vpc-lattice

auth_type defaults to NONE, so any client in any associated VPC can call any service with no identity and no policy - and associating one more VPC silently grants everything in it. Defaults to AWS_IAM and requires per-VPC security groups.

View module
Static validatedLive test pending

aws-app-runner

auto_deployments takes every push to the image tag straight to production with no review, which quietly makes the deployment gate "who can push". Off by default, egress routed through your VPC, and the pull role kept separate from the run role.

View module
Static validatedLive test pending

aws-emr-serverless

Without network_configuration the application runs on AWS-managed networking: it cannot reach a private database, and its egress skips your routing, NAT and DNS firewall. Monitoring is absent by default too, so a failed job leaves no executor logs, and no maximum_capacity makes the account quota the only ceiling.

View module
Static validatedLive test pending

aws-datasync

preserve_deleted_files = REMOVE deletes files at the DESTINATION that are absent from the source, so an unmounted share or a renamed path empties the destination on schedule and the task reports success. PRESERVE here, with verification on, a bandwidth ceiling so it cannot take the whole Direct Connect, and a per-file report of what failed.

View module
Static validatedLive test pending

aws-rolesanywhere

Any certificate chaining to the trust anchor can exchange itself for AWS credentials, so the CA is the perimeter - and it is usually run by people who were never told. The profile carries the scope, sessions are narrowed below the role, the caller cannot name itself in CloudTrail, and CA expiry warns before every workload loses credentials at once.

View module
Static validatedLive test pending

aws-vpc-peering

A VPC peering between two VPCs in one account and region, accepted in the same apply, with DNS resolution across it and routes written in every listed route table on both sides for every CIDR of the other. A default route through a peering is refused (CKV2_AWS_44). Peering is not transitive; past a handful of VPCs the transit gateway is the product.

View module
Static validatedLive test pending

aws-athena

Query results are a copy of the data, written to S3. Without enforce_workgroup_configuration - the AWS default - a client sends its own location and encryption and every setting becomes a suggestion.

View module
Live-tested

aws-acm

Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.

View module
Static validatedLive test pending

aws-private-ca

A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.

View module
Live-tested

aws-apigateway-http

HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.

View module
Live-tested

aws-apigateway-rest

A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.

View module
Live-tested

ansible-aws-cli-v2

The AWS CLI v2 from the upstream zip, verified with gpg against the AWS CLI Team key (pinned by fingerprint, in a GnuPG home of its own) before it is unpacked. EL 10 has no package; most installs run curl | unzip and never read the signature. Pinned version, tab completion, and a live test that runs an API call to 'Unable to locate credentials'. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

aws-s3-bucket

Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.

View module
Static validatedLive test pending

aws-account-baseline

The IAM password policy, S3 account-wide Block Public Access and, per region, default EBS encryption, snapshot and AMI sharing blocks, IMDSv2 as the default and the serial console off. Five of these are per region, so the module covers a list. The password policy follows NIST SP 800-63-4, and the module says which settings destroying it turns back off.

View module
Static validatedLive test pending

aws-mwaa

webserver_access_mode defaults to PUBLIC_ONLY, and the Airflow UI is not a dashboard: anyone who reaches it can trigger a DAG, which is arbitrary Python running as the execution role. PRIVATE_ONLY here, all five log streams on, and a precondition refuses an unpinned requirements.txt or plugins.zip - where bucket write access is otherwise the same permission as code execution.

View module
Static validatedLive test pending

aws-amplify-app

Every branch build is served at a public amplifyapp.com URL, and basic auth, the switch that puts a password on it, is off; auto branch creation builds every branch anyone pushes; the repository token lands in state; and environment variables are plaintext. Basic auth on every non-production branch (public by name), auto creation off, exactly one production branch, the custom domain attached.

View module
Static validatedLive test pending

aws-elastic-beanstalk

AWS Elastic Beanstalk with the defaults turned the right way: managed platform updates are ON (AWS leaves them off, so the platform is never patched), health reporting is enhanced rather than basic, logs stream to CloudWatch and survive termination, IMDSv1 is disabled, deployments go out in batches instead of all at once, and application versions are pruned before they hit the quota.

View module
Static validatedLive test pending

aws-cloudtrail-lake

A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.

View module
Static validatedLive test pending

aws-gateway-load-balancer

A Gateway Load Balancer for firewall or IDS appliances, its endpoint service and endpoints. AWS turns cross-zone off, keeps flows on failed appliances and leaves deletion protection off by default; this module turns cross-zone and protection on and makes flow failover an explicit choice. It also says plainly that nothing is inspected until route tables point at the endpoints.

View module
Live-tested

aws-alb

ALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.

View module
Live-tested

aws-aurora

Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.

View module
Static validatedLive test pending

aws-backup

A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.

View module
Static validatedLive test pending

aws-batch

Batch does not retry by default, so a reclaimed spot instance or a timed-out image pull ends as FAILED - reported as if the job failed on its merits, which is how somebody ends up debugging working code. Retries infrastructure failures and exits on real ones.

View module
Static validatedLive test pending

aws-client-vpn

Remote-access VPN endpoint with certificate or SAML authentication, split tunnelling, per-group authorization rules and connection logging. There is no allow-all shortcut: an endpoint with no rule reaches nothing.

View module
Static validatedLive test pending

aws-cloud-map

Private DNS, public DNS or API-only namespaces and the services registered in them. Documents the health-check trap: a private namespace gets a custom check that something else must update, and one nobody updates reports healthy forever.

View module
Static validatedLive test pending

aws-cloud-wan

A global network whose segments, routing and attachment placement live in one policy document rather than per-region route tables. The policy VERSION is executed as a second step, so a change cannot report success while the network still runs the previous one.

View module
Static validatedLive test pending

aws-cloudfront-site

Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.

View module
Static validatedLive test pending

aws-cloudtrail

Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.

View module
Live-tested

aws-cloudwatch

A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.

View module
Static validatedLive test pending

aws-signer

Signing profiles for Lambda packages and container images, plus the code signing configuration that enforces them. Defaults to Enforce rather than the API default Warn, which logs an untrusted artifact and deploys it anyway.

View module
Live-tested

aws-codedeploy

CodeDeploy application, deployment groups, and the platform-correct service role for automated EC2/ECS/Lambda rollouts with auto-rollback on failure.

View module
Live-tested

aws-codepipeline

AWS-native CI/CD: CodePipeline orchestrating a CodeBuild project, with an encrypted private artifact bucket and least-privilege roles. Sources from S3 (or GitHub).

View module
Live-tested

aws-cognito

A secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.

View module
Static validatedLive test pending

aws-conformance-packs

AWS Config conformance packs for one account or a whole organisation, with a ten-rule baseline of AWS managed rules taken from AWS's CIS sample pack. AWS Audit Manager no longer takes new customers and points them here. The module says a pack evaluates nothing without a configuration recorder and that Terraform cannot detect a pack edited in the console.

View module
Static validatedLive test pending

aws-cost-anomaly-detection

AWS Cost Anomaly Detection with monitors and the alerts that make them useful. A monitor alone leaves anomalies in the console; AWS sends immediate alerts only over SNS and summaries only by email, so this module builds both, with a topic encrypted by a key the service may use. It needs a cost threshold, and says an account holds one AWS services monitor.

View module
Static validatedLive test pending

aws-dns-firewall

Domain lists, rule group, rules and VPC associations. Fail-open is an availability decision wearing a security name: closed makes a firewall fault a DNS outage, open resolves unfiltered without saying so. The module makes you choose.

View module
Static validatedLive test pending

aws-lake-formation

AWS Lake Formation with its own permissions switched on for new databases and tables: admins, registered S3 locations and explicit grants. AWS ships it in IAM-only mode, and its settings resource clears any admin it is not given, so admins are required and the settings are protected from destroy. Existing databases keep IAM-only access until revoked outside Terraform, and it says so.

View module
Static validatedLive test pending

aws-detective

Builds an investigable graph from CloudTrail, VPC flow logs and GuardDuty findings, with member accounts and organization delegation. It detects nothing itself - it makes an existing finding into a timeline.

View module
Static validatedLive test pending

aws-direct-connect

Gateway, connections, virtual interfaces and associations. A private circuit is a private path, not a private conversation: traffic crosses it in clear text unless MACsec is on, and should_encrypt quietly falls back to clear text.

View module
Static validatedLive test pending

aws-documentdb

A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.

View module
Live-tested

aws-dynamodb-table

DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.

View module
Live-tested

aws-ec2-instance

EC2 instance with IMDSv2, encrypted EBS, instance profile, and EIP - secure defaults out of the box.

View module
Live-tested

aws-autoscaling

EC2 launch template and Auto Scaling group with IMDSv2 enforced, encrypted gp3 root volume, an egress-only security group, and scale-to-zero defaults so it applies cleanly with no compute cost.

View module
Live-tested

aws-ecr

ECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.

View module
Live-tested

aws-ecs-fargate-service

Full Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.

View module
Live-tested

aws-efs

An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.

View module
Live-tested

aws-eks

Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.

View module
Live-tested

aws-elasticache-redis

A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.

View module
Static validatedLive test pending

aws-ebs-volume

Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.

View module
Live-tested

aws-eventbridge

A custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.

View module
Static validatedLive test pending

aws-fsx-lustre

A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.

View module
Static validatedLive test pending

aws-firewall-manager

WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.

View module
Static validatedLive test pending

aws-vpc-flow-logs

Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.

View module
Static validatedLive test pending

aws-global-accelerator

Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.

View module
Static validatedLive test pending

aws-glue

A bookmark records exactly where a job reached in your data - which partitions, which keys - and it is written in plain text unless a security configuration says otherwise. That configuration is attached at job CREATION, so adding one later means rebuilding every job.

View module
Static validatedLive test pending

aws-guardduty

Threat detection with each protection plan - S3, EKS, RDS, Lambda, malware, runtime - a separate decision with its billing dimension stated, plus organization delegation and findings filtered by severity into EventBridge.

View module
Static validatedLive test pending

aws-iam-access-analyzer

Finds what a principal outside your zone of trust could actually reach, which is the question policy reviews get wrong by reading JSON. External analysis is free; unused-access analysis is a separate, billed analyzer.

View module
Live-tested

aws-iam-roles

Least-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.

View module
Static validatedLive test pending

aws-ipam

Amazon VPC IPAM with a top-level pool, a pool per region with netmask bounds and required tags, and optional sharing through AWS RAM. IPAM forces nothing on its own - a VPC can still take a hand-typed CIDR - so the module outputs the SCP AWS documents for requiring a pool. The provider defaults to the Advanced tier, billed per active IP, so the tier has no default here.

View module
Static validatedLive test pending

aws-s3-tables

Amazon S3 Tables: a table bucket, its namespaces and Iceberg tables. Three maintenance jobs run by default and together they set how long history survives - snapshots expire at 120 hours, unreferenced objects are deleted permanently 13 days later, compaction targets 512 MB. This module makes each an input and returns the resulting window, and validates the numbers the provider does not.

View module
Static validatedLive test pending

aws-iam-identity-center

Permission sets with managed policy, inline policy and permissions boundaries, and the account assignments that actually grant them - written out as auditable (set, account, principal) triples rather than buried in a console.

View module
Static validatedLive test pending

aws-inspector

Continuous scanning for EC2, ECR images, Lambda dependencies and Lambda code, each its own decision with its own billing dimension, plus organization delegation and findings routed at CRITICAL and HIGH.

View module
Live-tested

aws-jenkins

Self-hosted Jenkins controller on a hardened EC2 instance - restricted security group, IMDSv2 enforced, SSM access, encrypted root volume, Jenkins auto-installed via user-data.

View module
Live-tested

aws-kms

Customer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.

View module
Live-tested

aws-kinesis

A Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.

View module
Live-tested

aws-lambda

Lambda with execution role, log group, triggers, aliases, and zip/container packaging handled.

View module
Live-tested

aws-msk

An MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.

View module
Static validatedLive test pending

aws-macie

Sensitive-data discovery for S3 with targeted classification jobs, sampling for surveying a large bucket first, and findings filters that archive an expected result with its reason. No scan-everything default: Macie bills per GB inspected.

View module
Static validatedLive test pending

aws-directory-service

A managed directory with security log forwarding and cross-account sharing. The admin password has no default and no example value anywhere in the module, and the README is explicit that Terraform state holds it regardless.

View module
Static validatedLive test pending

aws-transfer-family

SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.

View module
Static validatedLive test pending

aws-memorydb

Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.

View module
Static validatedLive test pending

aws-nat-gateway

NAT gateways for an existing VPC, one per availability zone with its own Elastic IP, and the private route tables routed through the gateway in the same zone. A single gateway for every zone pays cross-zone charges on every byte and loses egress with that zone; it has to be accepted by name. Private (no address) mode for transit paths; gateway_count says what bills by the hour.

View module
Static validatedLive test pending

aws-fsx-ontap

Amazon FSx for NetApp ONTAP: a file system, one storage virtual machine and its volumes. The provider defaults daily volume backups to OFF where the AWS API keeps 30 days, and AWS attaches the VPC's default security group when none is given. This module sets 30 days, builds the security group from AWS's port table per protocol, and writes throughput to the field that updates in place.

View module
Static validatedLive test pending

aws-network-acl

Network ACLs are stateless, which is why most of them do not work: the reply to an allowed outbound connection is a new inbound packet nothing lets in. This generates the matching ephemeral-range rule for every TCP and UDP allow.

View module
Static validatedLive test pending

aws-network-firewall

Managed stateful firewall with Suricata rule groups, stateless pre-filters and logging. An empty policy drops rather than passes, and rules evaluate in strict order so "allow these, deny the rest" behaves the way it reads.

View module
Live-tested

aws-nlb

A Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.

View module
Static validatedLive test pending

aws-opensearch

A VPC domain with fine-grained access control and the three encryption settings that cannot be added afterwards. Building a public endpoint takes an explicit opt-in, because a public domain with a permissive policy is how this service leaks databases.

View module
Static validatedLive test pending

aws-fsx-openzfs

Amazon FSx for OpenZFS. With no export set, AWS shares the root volume read-write to every client the network admits, and the Terraform provider turns automatic backups off where AWS keeps 30 days. This module writes the export to named networks, refuses a wildcard and no_root_squash, keeps 30 days of backups, opens the NFS ports AWS lists and requires route tables for Multi-AZ.

View module
Static validatedLive test pending

aws-organizations

The organization, its organizational units, member accounts and the service control policies attached to them. Root attachment is off by default, because an SCP sets the ceiling on what anybody may do - including the account root user who would have to undo it.

View module
Live-tested

aws-vpc

Battle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.

View module
Live-tested

aws-rds

Single-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.

View module
Live-tested

aws-redshift

A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.

View module
Static validatedLive test pending

aws-route53-resolver

Endpoints that carry DNS across the VPC boundary, with a precondition requiring addresses in two different subnets - the part the API does not check, and the reason a zone failure becomes every application failing at once.

View module
Static validatedLive test pending

aws-ram

A share, what is in it and who it reaches. External principals are off, so a mistyped account number is an error rather than a silent share with a stranger - and access ends when an account leaves the organization, which AWS defaults the other way.

View module
Live-tested

aws-route53

A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.

View module
Live-tested

aws-ses

An SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.

View module
Live-tested

aws-sns

SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.

View module
Live-tested

aws-sqs

SQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.

View module
Live-tested

ansible-amazon-ssm-agent

The AWS Systems Manager Agent on EL 10, where rpm refuses the SSM signing key (a SHA-1 self-signature) and dnf fails its GPG check, so the usual answer is --nogpgcheck. This role verifies the detached signature with gpg against a pinned fingerprint first, pins the version (latest differs by region), and registers a hybrid activation once. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

aws-ssm-parameter-store

Map-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.

View module
Static validatedLive test pending

aws-eventbridge-scheduler

The default retry policy tries for a day and then discards the run silently, so a target that was down never hears what it missed; the scheduler's role is the blast radius and a wide one lets a schedule do more than invoke; and a flexible time window turns 03:00 into sometime that hour. A dead-letter queue every schedule uses, a role allowing one action on the targets, exact times by default.

View module
Live-tested

aws-secrets-manager

Secrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.

View module
Live-tested

aws-security-group

Security groups with named rule presets (https, postgres, redis...) using modern standalone rule resources.

View module
Static validatedLive test pending

aws-security-hub

Posture management with standards named explicitly rather than defaulted on, cross-region finding aggregation, organization delegation, and suppression expressed as automation rules that keep the finding and the reason.

View module
Static validatedLive test pending

aws-security-lake

Organization security logs normalised to OCSF in S3, with the storage-class transitions that decide what it costs, optional replication, and subscribers whose external id is validated as the confused-deputy guard it is.

View module
Static validatedLive test pending

aws-account-contacts

The alternate contacts AWS uses when something is wrong with an account. Without a security contact, abuse reports and vulnerability notices go only to the root user's mailbox - what Security Hub's Account.1 and CIS v5.0.0 control 1.2 check for. The module refuses to run without one unless told to, and validates what the API accepts, which is not what the provider checks.

View module
Static validatedLive test pending

aws-ssm-session-manager

Session Manager works with no configuration and records nothing: CloudTrail holds StartSession, not the commands. This builds the session document that turns logging on, and refuses to build one with no destination unless you say so.

View module
Static validatedLive test pending

aws-shield

Protections, protection groups, response-team access and the automatic layer-7 response. That response can be enabled and do nothing: COUNT labels the request and lets it through, so this defaults to BLOCK and names the counting ones.

View module
Static validatedLive test pending

aws-site-to-site-vpn

Customer gateway, IPsec connection and routes, attached to a VPN gateway or a Transit Gateway. IKEv2 only, DH group 14 and above, AES-256 and SHA-2 - the API still permits DH 2, AES-128 and SHA-1.

View module
Live-tested

aws-step-functions

A Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.

View module
Static validatedLive test pending

aws-workspaces-applications

Amazon WorkSpaces Applications, formerly AppStream 2.0. AWS enables every session action by default, including copying out, file download and local printing, and never disconnects idle users. This module sets all eight actions with the outbound ones off, a 15-minute idle timeout and no default internet access, and can keep streaming on an interface endpoint.

View module
Static validatedLive test pending

aws-privatelink-service

An endpoint service, who may attach and the private DNS it answers on. A wildcard principal offers the service to every AWS account, so the module refuses it unless said out loud - and warns that zone names differ per account.

View module
Static validatedLive test pending

aws-xray

AWS X-Ray sampling rules, trace groups and trace encryption. Sampling rates are percentages here, as in the console: the API takes a fraction and the provider validates nothing, so a rate of 5 means 500 percent. Groups get Insights on, because a group without it is a saved search. Encryption is an account setting whose provider delete does nothing, so the module can leave it alone.

View module
Static validatedLive test pending

aws-transit-gateway

Hub-and-spoke Transit Gateway with its own route tables, VPC attachments, static and blackhole routes, and RAM sharing. Default route table association and propagation are off, so an attachment joins a routing domain because you said so rather than by default.

View module
Static validatedLive test pending

aws-vpc-endpoints

Free gateway endpoints for S3 and DynamoDB, interface endpoints for everything else, and a security group that opens 443 to the VPC rather than the world. Interface endpoints are listed explicitly because each bills per hour per availability zone.

View module
Static validatedLive test pending

aws-verified-access

Per-request access to internal applications evaluated against identity and device posture, with Cedar policy groups, endpoints and logging that records which identity and posture produced each decision.

View module
Static validatedLive test pending

aws-workspaces

Amazon WorkSpaces Personal with a registered directory, an IP access group and encrypted desktops. AWS makes every user a local administrator by default and can only encrypt a WorkSpace at launch, so admin rights are off and a KMS key is required. It also says the IP group limits streaming but not API actions like rebuild, and only named client types may connect.

View module
Live-tested

aws-waf

A WAFv2 web ACL (REGIONAL or CLOUDFRONT) with a default-allow posture, configurable AWS managed rule groups blocking by default, and a rate-based rule that throttles abusive IPs.

View module
Static validatedLive test pending

aws-fsx-windows

Amazon FSx for Windows File Server joined to AWS Managed Microsoft AD. The provider leaves file and share access auditing disabled and keeps 7 days of backups where the API keeps 30; this module audits both to CloudWatch Logs for a year, keeps 30 days with tags copied, and builds the security group from AWS's port table, with remote PowerShell closed by default.

View module
Live-tested

ansible-aws-iam-authenticator

aws-iam-authenticator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs token -i with no credentials and the metadata service disabled and expects it to stop at 'get credentials'. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cfn-lint

cfn-lint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a template with a property the S3 bucket schema lacks (E3002, exit 2) and a clean one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-chamber

chamber on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs list with no credentials and the metadata service off, expecting 'no EC2 IMDS role found', and exercises the null backend (a list answered, a read refused). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-eksctl

eksctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs eksctl get cluster with no credentials and expects it to stop at 'get credentials'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kops

kops on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has create -f load a Cluster manifest against a local state store and stop at the EC2 credential lookup with the metadata service off. Pinned. Original role, live-tested on Rocky Linux 10.

View module

AWS reference architectures

All stacks →

Curated stacks of these verified modules, in the order they wire together.

Compare across clouds

All solutions →

See how the services AWS covers here compare on other providers.

Other providers