Civo Infrastructure-as-Code modules
9 verified ansible / terraform modules for Civo, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 9 Civo modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 8 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Civo modules
civo-dns-zone
A Civo DNS zone with every record in one map, each with the TTL Civo requires per record, and the nameservers exported for the registrar. Civo does not sign zones and has no CAA or NS record types; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.
civo-firewall
create_default_rules defaults to true and the rules it writes allow all inbound traffic on every port from every address, which turns a firewall into a name on a list; SSH from 0.0.0.0/0 is the first rule offered; and with the defaults off a firewall with no egress rule blocks all outbound. Defaults off, SSH from anywhere refused unless accepted, egress opened unless outbound rules narrow it.
civo-database
firewall_id is optional and a database without one answers to every address that can reach its endpoint; nodes = 1 is one node whose failure is downtime; and backups are the platform's, not configurable here. Firewall and network required, two nodes (one by name), the password as a sensitive output, and an output that says no backup schedule can be set.
civo-network
Every resource created without a network_id lands in the region's default network beside everything the team ever made there; cidr_v4 is optional, so a network created without it gets whatever range was free, the one most likely to collide with the office or the VPN. A named network, a required range, the resolvers you chose, and an output that says the network itself filters nothing.
civo-volume
A volume belongs to a network and attaches only to instances in it; this provider exposes no volume snapshot and no schedule, so data on it is backed up by something on the instance or not at all; and a volume attached without attach_at_boot does not come back after a reboot. Network required, attached at boot, and an output that says snapshots are not available.
civo-object-store
A store is a bucket with a size ceiling that turns into refused writes far from the cause; a store created without a credential gets the account's default one; and the service has no versioning, no lifecycle and no object lock, so an overwrite is the end of the object. The ceiling set, a credential of its own, and outputs that say versioning and lifecycle are not available.
ansible-civo-cli
civo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Civo's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at 'no API key is supplied'. Original role, live-tested on Rocky Linux 10.
civo-compute-stack
Instances with network, firewall, volume, and reserved IP.
civo-k3s-cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
Compare across clouds
All solutions →See how the services Civo covers here compare on other providers.