Exoscale Infrastructure-as-Code modules
11 verified ansible / terraform modules for Exoscale, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 11 Exoscale modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 10 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Exoscale modules
exoscale-block-storage
Snapshots exist as a resource you take and nothing on the platform schedules one; a volume attaches from the instance side, one instance at a time, in its zone; and a volume made from a snapshot is the restore path. A baseline snapshot when asked, restore from a snapshot when given, and an output that says no schedule exists.
exoscale-kms-key
A key is zonal unless multi-zone, which is the surprise at the first cross-zone restore; and the service has no automatic rotation setting and no flag that refuses deletion, so a key is deleted in one call. Multi-zone unless told otherwise, and outputs that say rotation and deletion protection are not available, so nothing downstream assumes a control that is not there.
exoscale-nlb
A service's health check can be a TCP handshake that a process which stopped serving still passes; an NLB fronts instance pools rather than instances; and it is layer 4, so no listener certificate exists and the one you look for lives on the instances. HTTP or HTTPS checks on a path with TCP accepted by name, a pool per service, and an output that says TLS is not terminated here.
exoscale-private-network
A private network without start, end and netmask hands out no addresses: every instance configures its own and two that pick the same one collide silently; and nothing filters traffic on the segment. A managed range required and derived from your RFC 1918 CIDR, addresses reserved at the ends for gateways, and an output that says every attached instance reaches every other.
exoscale-security-group
A group with no rules admits nothing inbound and everything outbound; SSH from 0.0.0.0/0 is the first rule offered; a rule's source can be another group, which is how tiers reach each other without a CIDR that goes stale; and the private network is never filtered. Named sources or source groups, SSH from anywhere refused unless accepted, egress narrowed only when asked.
exoscale-dns-zone
An Exoscale DNS zone with every record in one map (the apex written as the empty name Exoscale expects) and the four nameservers exported for the registrar. Exoscale does not sign zones; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.
exoscale-instance
An Exoscale compute instance on a Private Network with security groups and the SSH keys you name, created private so it has no public interface (public by name), secure boot and the TPM on where the template supports them, IPv6 off, and destroy protection (off by name).
exoscale-iam-role
An Exoscale IAM role that refuses every service it does not name (allow-by-default by name) and allows the ones it does either whole or by CEL rules on the operation, not editable in the console so the module stays the source of truth, with an API key bound to it whose secret is a sensitive output.
ansible-exoscale-cli
exo on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Exoscale's checksum file, re-checked by the live test, with the bash completion the release itself ships installed for every shell. No package exists. Pinned; an API call without configuration stops at 'must be configured before usage'. Original role, live-tested on Rocky Linux 10.
exoscale-dbaas
Managed PG/MySQL/Kafka with IP filters and TF-managed users.
exoscale-sks-cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.
Compare across clouds
All solutions →See how the services Exoscale covers here compare on other providers.