AWS Infrastructure-as-Code modules
143 verified ansible / terraform modules for AWS, spanning AWS, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
45 of 143 AWS modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 98 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All AWS modules
aws-mq
deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.
aws-budgets
A budget with no notification tracks correctly and tells nobody, so the invoice is the first notice; ACTUAL-only alerts arrive after the money is gone. And include_credit defaults true, so a budget on a credited account reports runway rather than spend - until the credits end and nothing crosses a threshold.
aws-codebuild
privileged_mode hands the build the Docker socket, so anything it runs can read every environment variable and assume the service role. Off by default, and a PLAINTEXT variable whose name looks like a secret is refused.
aws-keyspaces
point_in_time_recovery defaults to DISABLED and Keyspaces has no snapshots or automated backups, so off means a dropped table is simply gone. PITR on, a customer-managed key, and the two one-way doors - client-side timestamps and TTL - named rather than set quietly.
aws-fis
FIS refuses a template with no stop condition, which reads like a guarantee - and source = 'none' is a legal stop condition meaning the experiment never halts by itself. Refused here, along with targets that grow at run time and an empty-target mode that reports success for having tested nothing.
aws-cloudhsm
Cluster and HSMs, with the parts nobody mentions: AWS holds no copy of your keys, Terraform cannot initialise the cluster, and an uninitialised cluster bills per HSM per hour while being unable to store anything.
aws-config
Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.
aws-control-tower
A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.
aws-grafana
account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.
aws-database-proxy
Amazon RDS Proxy in front of an RDS instance or Aurora cluster: TLS required, clients authenticate with IAM tokens while the proxy reads the password from Secrets Manager, through a role limited to those secrets. Debug logging writes SQL statement text to the logs, so it is off unless that is accepted. End-to-end IAM removes the stored password entirely.
aws-kinesis-firehose
Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.
aws-dax-cache
DynamoDB Accelerator with TLS and encryption at rest. DAX leaves both off by default, and neither can be turned on for an existing cluster, so a fix means a new cluster. This module also creates its own security group (DAX otherwise uses the VPC default), a service role limited to the named tables and their indexes, and states that writes bypassing DAX leave stale reads until the TTL.
aws-image-builder
A pipeline with no schedule builds when somebody clicks, so the golden image ages until a person remembers it; image tests are the switch turned off to save an hour and scanning is off unless enabled; and the build instance's metadata service can hand its credentials to whatever a step downloads. Weekly rebuilds when a dependency changed, tests and scanning on, IMDSv2-only builds.
aws-neptune
Neptune has no user, no password and no GRANT. Authorization is IAM and it defaults to OFF, so anything that can reach port 8182 can read every edge and drop the lot. IAM auth on, storage encrypted, and the audit log driven from one variable because its two halves live in different resources and either alone logs nothing.
aws-appsync
introspection_config defaults to ENABLED, handing any caller a complete map of every type, field and argument, and query_depth_limit defaults to 0, which means no limit - so one nested query multiplies into thousands of resolver calls. Both closed here, with request bodies kept out of CloudWatch and a WAF association for the rate nothing else bounds.
aws-bedrock-guardrail
Creating a guardrail does not apply it: the application must send guardrailIdentifier and guardrailVersion on every call, and DRAFT is mutable. This publishes a numbered version, outputs the two values your code needs, and refuses a guardrail with no policies at all - which attaches successfully, filters nothing, and reports as active.
aws-lightsail-instance
A Lightsail instance is created with 22 and 80 open to every address; its public address changes when it stops unless a static IP is attached, and every DNS record pointing at it is then wrong; and automatic snapshots are off. The port list replaced by your rules with SSH from anywhere accepted by name, a static IP attached, and the daily AutoSnapshot add-on on at the hour you choose.
aws-prometheus
Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.
aws-dms
ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.
aws-sagemaker-notebook
AWS defaults a notebook to direct internet access AND root access: a root shell with a path off the network that misses your NAT, routing and DNS firewall, holding a role chosen to read your training data. Both off here, IMDSv2 only.
aws-codeartifact
A repository with a public external connection serves whatever the public registry holds for any name it does not. This puts the connection on its own repository, reached through an upstream, and emits the origin-control commands Terraform cannot apply.
aws-ssm-patch-manager
A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.
aws-verified-permissions
validation_settings.mode defaults to OFF, so a Cedar policy naming an action the schema does not define is accepted and then never matches. A broken permit fails closed and somebody complains; a broken forbid fails OPEN and nobody does. STRICT here, with the schema that makes it possible.
aws-quicksight
A QuickSight subscription on Enterprise edition through IAM Identity Center, with admin, author and reader groups, termination protection on because unsubscribing deletes every dashboard, and a VPC connection with its own role so a private database stays private. The authentication method is permanent; Standard edition and QuickSight-managed users are accepted by name.
aws-appconfig
AppConfig exists to deploy a configuration slowly and roll it back automatically, and both halves are opt-in - the predefined AllAtOnce strategy is 100% of the fleet with zero bake time. Gradual here, and a precondition refuses an environment with no alarms, where automatic rollback has nothing to fire on.
aws-route53-health-check
A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.
aws-opensearch-serverless
A collection cannot exist without an encryption policy and the quickest one uses the AWS-owned key; the network policy decides whether the endpoint answers on the internet; without a data access policy nobody can read or write, with a wide one everyone can; indexes grow until a policy expires them. Private through VPC endpoints (public by name), your key when given, principals named.
aws-elasticache-serverless
ElastiCache Serverless for Valkey. With no user group, any client that reaches the endpoint connects as the default user with no password, so this module always attaches a Valkey user group whose users sign in with IAM. It sets a storage and ECPU ceiling, since AWS sets none, and keeps 7 days of snapshots. It also says destroy takes no final snapshot.
aws-redshift-serverless
An Amazon Redshift Serverless namespace and workgroup: customer-managed encryption, SSL required, all three logs exported, and the admin password generated and held by Secrets Manager. AWS accepts plaintext connections by default and a usage limit's default action only logs the breach, so SSL is set at creation and the spend limit's action has to be chosen: alert or stop.
aws-vpc-lattice
auth_type defaults to NONE, so any client in any associated VPC can call any service with no identity and no policy - and associating one more VPC silently grants everything in it. Defaults to AWS_IAM and requires per-VPC security groups.
aws-app-runner
auto_deployments takes every push to the image tag straight to production with no review, which quietly makes the deployment gate "who can push". Off by default, egress routed through your VPC, and the pull role kept separate from the run role.
aws-emr-serverless
Without network_configuration the application runs on AWS-managed networking: it cannot reach a private database, and its egress skips your routing, NAT and DNS firewall. Monitoring is absent by default too, so a failed job leaves no executor logs, and no maximum_capacity makes the account quota the only ceiling.
aws-datasync
preserve_deleted_files = REMOVE deletes files at the DESTINATION that are absent from the source, so an unmounted share or a renamed path empties the destination on schedule and the task reports success. PRESERVE here, with verification on, a bandwidth ceiling so it cannot take the whole Direct Connect, and a per-file report of what failed.
aws-rolesanywhere
Any certificate chaining to the trust anchor can exchange itself for AWS credentials, so the CA is the perimeter - and it is usually run by people who were never told. The profile carries the scope, sessions are narrowed below the role, the caller cannot name itself in CloudTrail, and CA expiry warns before every workload loses credentials at once.
aws-vpc-peering
A VPC peering between two VPCs in one account and region, accepted in the same apply, with DNS resolution across it and routes written in every listed route table on both sides for every CIDR of the other. A default route through a peering is refused (CKV2_AWS_44). Peering is not transitive; past a handful of VPCs the transit gateway is the product.
aws-athena
Query results are a copy of the data, written to S3. Without enforce_workgroup_configuration - the AWS default - a client sends its own location and encryption and every setting becomes a suggestion.
aws-acm
Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.
aws-private-ca
A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.
aws-apigateway-http
HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.
aws-apigateway-rest
A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.
ansible-aws-cli-v2
The AWS CLI v2 from the upstream zip, verified with gpg against the AWS CLI Team key (pinned by fingerprint, in a GnuPG home of its own) before it is unpacked. EL 10 has no package; most installs run curl | unzip and never read the signature. Pinned version, tab completion, and a live test that runs an API call to 'Unable to locate credentials'. Original role, live-tested on Rocky Linux 10.
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
aws-account-baseline
The IAM password policy, S3 account-wide Block Public Access and, per region, default EBS encryption, snapshot and AMI sharing blocks, IMDSv2 as the default and the serial console off. Five of these are per region, so the module covers a list. The password policy follows NIST SP 800-63-4, and the module says which settings destroying it turns back off.
aws-mwaa
webserver_access_mode defaults to PUBLIC_ONLY, and the Airflow UI is not a dashboard: anyone who reaches it can trigger a DAG, which is arbitrary Python running as the execution role. PRIVATE_ONLY here, all five log streams on, and a precondition refuses an unpinned requirements.txt or plugins.zip - where bucket write access is otherwise the same permission as code execution.
aws-amplify-app
Every branch build is served at a public amplifyapp.com URL, and basic auth, the switch that puts a password on it, is off; auto branch creation builds every branch anyone pushes; the repository token lands in state; and environment variables are plaintext. Basic auth on every non-production branch (public by name), auto creation off, exactly one production branch, the custom domain attached.
aws-elastic-beanstalk
AWS Elastic Beanstalk with the defaults turned the right way: managed platform updates are ON (AWS leaves them off, so the platform is never patched), health reporting is enhanced rather than basic, logs stream to CloudWatch and survive termination, IMDSv1 is disabled, deployments go out in batches instead of all at once, and application versions are pruned before they hit the quota.
aws-cloudtrail-lake
A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.
aws-gateway-load-balancer
A Gateway Load Balancer for firewall or IDS appliances, its endpoint service and endpoints. AWS turns cross-zone off, keeps flows on failed appliances and leaves deletion protection off by default; this module turns cross-zone and protection on and makes flow failover an explicit choice. It also says plainly that nothing is inspected until route tables point at the endpoints.
aws-alb
ALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.
aws-aurora
Aurora PostgreSQL/MySQL cluster with instances, parameter groups, Serverless v2 scaling, and enhanced monitoring.
aws-backup
A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.
aws-batch
Batch does not retry by default, so a reclaimed spot instance or a timed-out image pull ends as FAILED - reported as if the job failed on its merits, which is how somebody ends up debugging working code. Retries infrastructure failures and exits on real ones.
aws-client-vpn
Remote-access VPN endpoint with certificate or SAML authentication, split tunnelling, per-group authorization rules and connection logging. There is no allow-all shortcut: an endpoint with no rule reaches nothing.
aws-cloud-map
Private DNS, public DNS or API-only namespaces and the services registered in them. Documents the health-check trap: a private namespace gets a custom check that something else must update, and one nobody updates reports healthy forever.
aws-cloud-wan
A global network whose segments, routing and attachment placement live in one policy document rather than per-region route tables. The policy VERSION is executed as a second step, so a change cannot report success while the network still runs the previous one.
aws-cloudfront-site
Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.
aws-cloudtrail
Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.
aws-cloudwatch
A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.
aws-signer
Signing profiles for Lambda packages and container images, plus the code signing configuration that enforces them. Defaults to Enforce rather than the API default Warn, which logs an untrusted artifact and deploys it anyway.
aws-codedeploy
CodeDeploy application, deployment groups, and the platform-correct service role for automated EC2/ECS/Lambda rollouts with auto-rollback on failure.
aws-codepipeline
AWS-native CI/CD: CodePipeline orchestrating a CodeBuild project, with an encrypted private artifact bucket and least-privilege roles. Sources from S3 (or GitHub).
aws-cognito
A secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.
aws-conformance-packs
AWS Config conformance packs for one account or a whole organisation, with a ten-rule baseline of AWS managed rules taken from AWS's CIS sample pack. AWS Audit Manager no longer takes new customers and points them here. The module says a pack evaluates nothing without a configuration recorder and that Terraform cannot detect a pack edited in the console.
aws-cost-anomaly-detection
AWS Cost Anomaly Detection with monitors and the alerts that make them useful. A monitor alone leaves anomalies in the console; AWS sends immediate alerts only over SNS and summaries only by email, so this module builds both, with a topic encrypted by a key the service may use. It needs a cost threshold, and says an account holds one AWS services monitor.
aws-dns-firewall
Domain lists, rule group, rules and VPC associations. Fail-open is an availability decision wearing a security name: closed makes a firewall fault a DNS outage, open resolves unfiltered without saying so. The module makes you choose.
aws-lake-formation
AWS Lake Formation with its own permissions switched on for new databases and tables: admins, registered S3 locations and explicit grants. AWS ships it in IAM-only mode, and its settings resource clears any admin it is not given, so admins are required and the settings are protected from destroy. Existing databases keep IAM-only access until revoked outside Terraform, and it says so.
aws-detective
Builds an investigable graph from CloudTrail, VPC flow logs and GuardDuty findings, with member accounts and organization delegation. It detects nothing itself - it makes an existing finding into a timeline.
aws-direct-connect
Gateway, connections, virtual interfaces and associations. A private circuit is a private path, not a private conversation: traffic crosses it in clear text unless MACsec is on, and should_encrypt quietly falls back to clear text.
aws-documentdb
A cluster whose two dangerous AWS defaults are inverted: storage encryption is hard-coded on because it cannot be added later, and the master password is never an input - Secrets Manager generates it, so it never reaches the state file.
aws-dynamodb-table
DynamoDB table with GSIs/LSIs, TTL, streams, autoscaling or on-demand, and point-in-time recovery.
aws-ec2-instance
EC2 instance with IMDSv2, encrypted EBS, instance profile, and EIP - secure defaults out of the box.
aws-autoscaling
EC2 launch template and Auto Scaling group with IMDSv2 enforced, encrypted gp3 root volume, an egress-only security group, and scale-to-zero defaults so it applies cleanly with no compute cost.
aws-ecr
ECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.
aws-ecs-fargate-service
Full Fargate stack: cluster, task definition, service with ALB integration, autoscaling, and Cloud Map discovery.
aws-efs
An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.
aws-eks
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
aws-elasticache-redis
A cluster-mode-disabled ElastiCache Redis/Valkey cache with encryption at rest and in transit both on, no public exposure, and the subnet group and security group created for you.
aws-ebs-volume
Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.
aws-eventbridge
A custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.
aws-fsx-lustre
A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.
aws-firewall-manager
WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.
aws-vpc-flow-logs
Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.
aws-global-accelerator
Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.
aws-glue
A bookmark records exactly where a job reached in your data - which partitions, which keys - and it is written in plain text unless a security configuration says otherwise. That configuration is attached at job CREATION, so adding one later means rebuilding every job.
aws-guardduty
Threat detection with each protection plan - S3, EKS, RDS, Lambda, malware, runtime - a separate decision with its billing dimension stated, plus organization delegation and findings filtered by severity into EventBridge.
aws-iam-access-analyzer
Finds what a principal outside your zone of trust could actually reach, which is the question policy reviews get wrong by reading JSON. External analysis is free; unused-access analysis is a separate, billed analyzer.
aws-iam-roles
Least-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.
aws-ipam
Amazon VPC IPAM with a top-level pool, a pool per region with netmask bounds and required tags, and optional sharing through AWS RAM. IPAM forces nothing on its own - a VPC can still take a hand-typed CIDR - so the module outputs the SCP AWS documents for requiring a pool. The provider defaults to the Advanced tier, billed per active IP, so the tier has no default here.
aws-s3-tables
Amazon S3 Tables: a table bucket, its namespaces and Iceberg tables. Three maintenance jobs run by default and together they set how long history survives - snapshots expire at 120 hours, unreferenced objects are deleted permanently 13 days later, compaction targets 512 MB. This module makes each an input and returns the resulting window, and validates the numbers the provider does not.
aws-iam-identity-center
Permission sets with managed policy, inline policy and permissions boundaries, and the account assignments that actually grant them - written out as auditable (set, account, principal) triples rather than buried in a console.
aws-inspector
Continuous scanning for EC2, ECR images, Lambda dependencies and Lambda code, each its own decision with its own billing dimension, plus organization delegation and findings routed at CRITICAL and HIGH.
aws-jenkins
Self-hosted Jenkins controller on a hardened EC2 instance - restricted security group, IMDSv2 enforced, SSM access, encrypted root volume, Jenkins auto-installed via user-data.
aws-kms
Customer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.
aws-kinesis
A Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.
aws-lambda
Lambda with execution role, log group, triggers, aliases, and zip/container packaging handled.
aws-msk
An MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.
aws-macie
Sensitive-data discovery for S3 with targeted classification jobs, sampling for surveying a large bucket first, and findings filters that archive an expected result with its reason. No scan-everything default: Macie bills per GB inspected.
aws-directory-service
A managed directory with security log forwarding and cross-account sharing. The admin password has no default and no example value anywhere in the module, and the README is explicit that Terraform state holds it regardless.
aws-transfer-family
SFTP, FTPS and FTP in front of S3. A generated host key does not survive replacing the server, so every client reports a changed key - the warning that means interception - and after the second time nobody reads it. Supply one.
aws-memorydb
Durable Redis-compatible storage with an ACL holding real users, authenticated through IAM. MemoryDB ships an ACL named open-access that accepts any connection reaching the port with no credentials; this module will not use it.
aws-nat-gateway
NAT gateways for an existing VPC, one per availability zone with its own Elastic IP, and the private route tables routed through the gateway in the same zone. A single gateway for every zone pays cross-zone charges on every byte and loses egress with that zone; it has to be accepted by name. Private (no address) mode for transit paths; gateway_count says what bills by the hour.
aws-fsx-ontap
Amazon FSx for NetApp ONTAP: a file system, one storage virtual machine and its volumes. The provider defaults daily volume backups to OFF where the AWS API keeps 30 days, and AWS attaches the VPC's default security group when none is given. This module sets 30 days, builds the security group from AWS's port table per protocol, and writes throughput to the field that updates in place.
aws-network-acl
Network ACLs are stateless, which is why most of them do not work: the reply to an allowed outbound connection is a new inbound packet nothing lets in. This generates the matching ephemeral-range rule for every TCP and UDP allow.
aws-network-firewall
Managed stateful firewall with Suricata rule groups, stateless pre-filters and logging. An empty policy drops rather than passes, and rules evaluate in strict order so "allow these, deny the rest" behaves the way it reads.
aws-nlb
A Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.
aws-opensearch
A VPC domain with fine-grained access control and the three encryption settings that cannot be added afterwards. Building a public endpoint takes an explicit opt-in, because a public domain with a permissive policy is how this service leaks databases.
aws-fsx-openzfs
Amazon FSx for OpenZFS. With no export set, AWS shares the root volume read-write to every client the network admits, and the Terraform provider turns automatic backups off where AWS keeps 30 days. This module writes the export to named networks, refuses a wildcard and no_root_squash, keeps 30 days of backups, opens the NFS ports AWS lists and requires route tables for Multi-AZ.
aws-organizations
The organization, its organizational units, member accounts and the service control policies attached to them. Root attachment is off by default, because an SCP sets the ceiling on what anybody may do - including the account root user who would have to undo it.
aws-vpc
Battle-tested multi-AZ VPC with public/private/database subnets, NAT, endpoints, and flow logs.
aws-rds
Single-instance or Multi-AZ RDS with subnet/parameter/option groups, backups, and monitoring wired correctly.
aws-redshift
A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.
aws-route53-resolver
Endpoints that carry DNS across the VPC boundary, with a precondition requiring addresses in two different subnets - the part the API does not check, and the reason a zone failure becomes every application failing at once.
aws-ram
A share, what is in it and who it reaches. External principals are off, so a mistyped account number is an error rather than a silent share with a stranger - and access ends when an account leaves the organization, which AWS defaults the other way.
aws-route53
A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.
aws-ses
An SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.
aws-sns
SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.
aws-sqs
SQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.
ansible-amazon-ssm-agent
The AWS Systems Manager Agent on EL 10, where rpm refuses the SSM signing key (a SHA-1 self-signature) and dnf fails its GPG check, so the usual answer is --nogpgcheck. This role verifies the detached signature with gpg against a pinned fingerprint first, pins the version (latest differs by region), and registers a hybrid activation once. Original role, live-tested on Rocky Linux 10.
aws-ssm-parameter-store
Map-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.
aws-eventbridge-scheduler
The default retry policy tries for a day and then discards the run silently, so a target that was down never hears what it missed; the scheduler's role is the blast radius and a wide one lets a schedule do more than invoke; and a flexible time window turns 03:00 into sometime that hour. A dead-letter queue every schedule uses, a role allowing one action on the targets, exact times by default.
aws-secrets-manager
Secrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.
aws-security-group
Security groups with named rule presets (https, postgres, redis...) using modern standalone rule resources.
aws-security-hub
Posture management with standards named explicitly rather than defaulted on, cross-region finding aggregation, organization delegation, and suppression expressed as automation rules that keep the finding and the reason.
aws-security-lake
Organization security logs normalised to OCSF in S3, with the storage-class transitions that decide what it costs, optional replication, and subscribers whose external id is validated as the confused-deputy guard it is.
aws-account-contacts
The alternate contacts AWS uses when something is wrong with an account. Without a security contact, abuse reports and vulnerability notices go only to the root user's mailbox - what Security Hub's Account.1 and CIS v5.0.0 control 1.2 check for. The module refuses to run without one unless told to, and validates what the API accepts, which is not what the provider checks.
aws-ssm-session-manager
Session Manager works with no configuration and records nothing: CloudTrail holds StartSession, not the commands. This builds the session document that turns logging on, and refuses to build one with no destination unless you say so.
aws-shield
Protections, protection groups, response-team access and the automatic layer-7 response. That response can be enabled and do nothing: COUNT labels the request and lets it through, so this defaults to BLOCK and names the counting ones.
aws-site-to-site-vpn
Customer gateway, IPsec connection and routes, attached to a VPN gateway or a Transit Gateway. IKEv2 only, DH group 14 and above, AES-256 and SHA-2 - the API still permits DH 2, AES-128 and SHA-1.
aws-step-functions
A Step Functions state machine (STANDARD or EXPRESS) with a least-privilege execution role, a managed CloudWatch log group, X-Ray tracing, and encryption at rest - working out of the box from a single name.
aws-workspaces-applications
Amazon WorkSpaces Applications, formerly AppStream 2.0. AWS enables every session action by default, including copying out, file download and local printing, and never disconnects idle users. This module sets all eight actions with the outbound ones off, a 15-minute idle timeout and no default internet access, and can keep streaming on an interface endpoint.
aws-privatelink-service
An endpoint service, who may attach and the private DNS it answers on. A wildcard principal offers the service to every AWS account, so the module refuses it unless said out loud - and warns that zone names differ per account.
aws-xray
AWS X-Ray sampling rules, trace groups and trace encryption. Sampling rates are percentages here, as in the console: the API takes a fraction and the provider validates nothing, so a rate of 5 means 500 percent. Groups get Insights on, because a group without it is a saved search. Encryption is an account setting whose provider delete does nothing, so the module can leave it alone.
aws-transit-gateway
Hub-and-spoke Transit Gateway with its own route tables, VPC attachments, static and blackhole routes, and RAM sharing. Default route table association and propagation are off, so an attachment joins a routing domain because you said so rather than by default.
aws-vpc-endpoints
Free gateway endpoints for S3 and DynamoDB, interface endpoints for everything else, and a security group that opens 443 to the VPC rather than the world. Interface endpoints are listed explicitly because each bills per hour per availability zone.
aws-verified-access
Per-request access to internal applications evaluated against identity and device posture, with Cedar policy groups, endpoints and logging that records which identity and posture produced each decision.
aws-workspaces
Amazon WorkSpaces Personal with a registered directory, an IP access group and encrypted desktops. AWS makes every user a local administrator by default and can only encrypt a WorkSpace at launch, so admin rights are off and a KMS key is required. It also says the IP group limits streaming but not API actions like rebuild, and only named client types may connect.
aws-waf
A WAFv2 web ACL (REGIONAL or CLOUDFRONT) with a default-allow posture, configurable AWS managed rule groups blocking by default, and a rate-based rule that throttles abusive IPs.
aws-fsx-windows
Amazon FSx for Windows File Server joined to AWS Managed Microsoft AD. The provider leaves file and share access auditing disabled and keeps 7 days of backups where the API keeps 30; this module audits both to CloudWatch Logs for a year, keeps 30 days with tags copied, and builds the security group from AWS's port table, with remote PowerShell closed by default.
ansible-aws-iam-authenticator
aws-iam-authenticator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs token -i with no credentials and the metadata service disabled and expects it to stop at 'get credentials'. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-cfn-lint
cfn-lint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a template with a property the S3 bucket schema lacks (E3002, exit 2) and a clean one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-chamber
chamber on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs list with no credentials and the metadata service off, expecting 'no EC2 IMDS role found', and exercises the null backend (a list answered, a read refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-eksctl
eksctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs eksctl get cluster with no credentials and expects it to stop at 'get credentials'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-kops
kops on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has create -f load a Cluster manifest against a local state store and stop at the EC2 credential lookup with the metadata service off. Pinned. Original role, live-tested on Rocky Linux 10.
AWS reference architectures
All stacks →Curated stacks of these verified modules, in the order they wire together.
Compare across clouds
All solutions →See how the services AWS covers here compare on other providers.