DigitalOcean Infrastructure-as-Code modules

17 verified ansible / terraform modules for DigitalOcean, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 17 DigitalOcean modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 16 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All DigitalOcean modules

Static validatedLive test pending

do-volume

Droplet backups copy the boot disk and nothing attached to it, so a database whose data lives on a volume is an empty server to the backup; there is no snapshot schedule for volumes either. A formatted, attached, regional volume with two outputs that say exactly that, so whatever consumes the module cannot assume a copy exists.

View module
Static validatedLive test pending

do-cdn

A DigitalOcean CDN endpoint in front of a Spaces bucket, served on your domain with a DigitalOcean-managed certificate you name (the cdn.digitaloceanspaces.com name is accepted by name), with a cache TTL you chose. The CDN serves the bucket's public objects; a private object stays private through it.

View module
Static validatedLive test pending

do-firewall

A firewall with no droplets and no tags applies to nothing while the console shows it active; SSH from 0.0.0.0/0 is the first rule the console offers; and with no outbound rule nothing leaves, DNS included. Droplets or tags expected, port 22 from everywhere refused unless accepted, and an outbound default that allows what a server needs.

View module
Static validatedLive test pending

do-container-registry

Docker credentials for the registry never expire unless told to, so the login a CI job wrote to disk two years ago still pushes today; there is one registry per account; and the tier is a storage ceiling that turns into a failed push far from the cause. The registry, read-only credentials that live a day and read-write ones that live an hour, both re-issued on the next apply after expiry.

View module
Static validatedLive test pending

do-dns-zone

A DigitalOcean domain and its records. Creating the zone does not delegate it: until the registrar's nameservers point here the zone is correct, complete and serving nobody, which looks exactly like a working zone. The domain's ip_address shortcut, which hides an apex A record from your records map, is deliberately not used, and a CNAME at the apex is refused.

View module
Static validatedLive test pending

do-custom-image

A DigitalOcean custom image imported from a URL (raw, qcow2, vhdx, vdi or vmdk) into the regions you name, one region by name. Host the file in a Space you own: a URL nobody controls is an image nobody controls. The name carries the build.

View module
Static validatedLive test pending

do-load-balancer

The default health check is a TCP handshake, which a process that stopped serving still passes; redirect_http_to_https defaults to false, so the site stays in clear on 80; and a balancer with no tag and no droplets is a public address that 503s. HTTP checks on a path, redirect on whenever HTTPS exists, STRONG ciphers, backends required, and a Let's Encrypt certificate made from your domains.

View module
Static validatedLive test pending

do-vpc

Every resource created without a vpc_uuid lands in the region's default VPC beside everything the team ever made there; an auto-assigned ip_range is the one most likely to collide with the next peer; and a peering between overlapping ranges is accepted and carries nothing. A named VPC, a required range, overlaps refused at plan time, and an output that says nothing inside the VPC is filtered.

View module
Static validatedLive test pending

do-spaces-bucket

A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.

View module
Static validatedLive test pending

do-monitoring

An alert policy with no email and no Slack webhook is valid, evaluated and triggers to nobody; CPU, memory and disk metrics exist only where the agent runs; and an uptime check without its alert resource is a status page. A recipient required, CPU/memory/disk defaults by tag, the agent-dependent alerts listed, and a down alert plus optional latency and certificate-expiry alerts on every check.

View module
Static validatedLive test pending

do-uptime-check

An uptime check and its alerts, which are separate resources: a check on its own draws a graph somebody would have to go and look at and pages nobody, and it looks identical to one that does. Three regions by default, since one cannot tell the target being down apart from that region's path to it. The latency alert is the one that catches the slow death.

View module
Static validatedLive test pending

do-app-platform

Declarative App Platform deployment with services, workers, domains, and alerts.

View module
Static validatedLive test pending

do-doks-cluster

Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.

View module
Static validatedLive test pending

do-droplet-stack

Hardened droplet(s) with VPC, firewall, volume, reserved IP, and cloud-init bootstrap.

View module
Static validatedLive test pending

do-managed-database

Managed PG/MySQL/Valkey cluster with firewall trust list, users, DBs, and replicas.

View module
Static validatedLive test pending

do-vpc-peering

A peering between two DigitalOcean VPCs. DigitalOcean programmes the routes on both sides once the peering is ACTIVE, which is why this module takes no route table lists and every other module in this hub does. Overlapping IP ranges are refused at apply, and there is no transit product, so a fourth network means three more peerings.

View module
Live-tested

ansible-doctl

doctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in DigitalOcean's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a token stops at 'access token is required'. Original role, live-tested on Rocky Linux 10.

View module

Compare across clouds

All solutions →

See how the services DigitalOcean covers here compare on other providers.

Other providers