Google Cloud Infrastructure-as-Code modules
37 verified terraform modules for Google Cloud, spanning Google Cloud. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish gate before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
37 of 37 Google Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 0 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Google Cloud modules
API Gateway (OpenAPI 2.0)
A serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.
AlloyDB for PostgreSQL Cluster
AlloyDB cluster with primary + read-pool instances, PSC connectivity, automated backups and columnar/vector engine flags.
Artifact Registry Repositories
Docker/Maven/npm repos with cleanup policies, remote and virtual repositories, CMEK and reader/writer IAM.
BigQuery Dataset & Tables
Datasets with partitioned/clustered tables, authorized views, CMEK and dataset-level access controls.
Certificate Manager (certificate map)
A Certificate Manager certificate map for external HTTPS load balancers, with an optional Google-managed certificate and DNS authorization provisioned when you supply a domain you control.
Cloud Armor Security Policy (WAF)
A global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.
Cloud Bigtable Instance & Table
A single-cluster Cloud Bigtable instance (one 1-node SSD cluster, the smallest footprint) plus a table with column families, IAM-only access, optional CMEK, and deletion protection on.
Cloud Composer 2 (managed Airflow)
Managed Apache Airflow on Cloud Composer 2 with small-by-default sizing, worker autoscaling pinned for predictable cost, and an opt-in private environment posture.
Cloud DNS Zones & Records
Public/private managed zones with record sets, DNSSEC, forwarding and peering configs.
Cloud Filestore NFS Share
A managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.
Cloud KMS Keyring & Keys
Keyrings and rotation-enabled crypto keys with per-key IAM for CMEK across GCS, BigQuery, Cloud SQL and disks.
Cloud Monitoring, Alerting & Log Export
A self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.
Cloud NAT Gateway
A regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.
Cloud Run Function (gen2)
Event-driven or HTTP gen2 function with source upload, dedicated runtime SA and Eventarc trigger wiring.
Cloud Run Job (v2)
A Cloud Run v2 Job for batch and run-to-completion workloads with a dedicated runtime service account, auto-wired Secret Manager accessor grants, VPC egress, bounded retries and per-task timeout.
Cloud Run Service
Cloud Run v2 service with autoscaling, secret and VPC egress wiring, custom domain and invoker IAM done right.
Cloud SQL (PostgreSQL/MySQL) HA Instance
Regional-HA Cloud SQL with private IP (PSA/PSC), automated backups, PITR, read replicas and IAM database auth.
Cloud Scheduler HTTP Cron Job
A Cloud Scheduler cron job that calls an HTTP(S) endpoint on a schedule, with a bounded attempt deadline, capped exponential-backoff retries, and per-invocation OIDC/OAuth service-account auth.
Cloud Spanner Instance & Database
A regional Cloud Spanner instance at the smallest billable size (100 processing units) plus a database with optional starter schema, drop protection, and Terraform deletion protection on.
Cloud Storage Bucket
Hardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.
Cloud Tasks Queue
A Cloud Tasks queue with capped dispatch rate and concurrency, a bounded exponential-backoff retry policy, and full Stackdriver logging so failed dispatches are observable rather than silent.
Cloud Workflows (least-privilege identity)
A Cloud Workflows workflow that runs as a dedicated least-privilege service account instead of the broad Compute Engine default, with inline YAML, deletion protection, and call logging.
Compute Engine VM (Shielded, private)
A hardened Compute Engine VM on Debian 12 with Shielded VM (Secure Boot, vTPM, integrity monitoring), OS Login for IAM-managed SSH, no external IP by default, and deletion protection on.
Dataproc Single-Node Cluster
A single-node Dataproc cluster (1 master, 0 workers), the cheapest managed Spark/Hadoop cluster that still applies and destroys cleanly, with internal-only IPs and deletion protection on.
Eventarc Pub/Sub Trigger
An Eventarc Pub/Sub trigger wired into a self-contained pipeline - a Cloud Run target, a dedicated delivery service account, and the run.invoker and eventReceiver grants Eventarc silently requires.
GCP Project Factory
Opinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.
GCP VPC Network Foundation
Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.
GKE Cluster (Autopilot & Standard)
Private, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.
Global External HTTPS Load Balancer
Global ALB with managed TLS certs, URL map, serverless/instance NEG backends, optional Cloud CDN and Cloud Armor policy.
HA VPN (Site-to-Site)
99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.
Internal Passthrough Load Balancer (L4)
An internal passthrough L4 load balancer - health check, regional backend service and forwarding rule - that stands up before any backends exist, preserving client source IPs, with optional global access.
Managed Instance Group (autoscaling, autohealing)
A zonal Managed Instance Group built from a hardened Shielded-VM instance template, private by default, with optional CPU autoscaling, autohealing, and zero-downtime rolling template updates.
Memorystore Redis/Valkey
Private Memorystore instance or cluster (Redis or Valkey) with auth, TLS and maintenance policy on your VPC.
Pub/Sub Topics & Subscriptions
Topics with schemas, push/pull/BigQuery subscriptions, dead-letter queues and retry policies preconfigured.
Secret Manager Secrets
Secrets with versions, replication policy, rotation schedules, expiry and accessor IAM.
Service Accounts & IAM Bindings
Service accounts with least-privilege project/resource IAM and optional Workload Identity Federation for keyless CI/CD (GitHub Actions).
Vertex AI Endpoint
A Vertex AI Endpoint for online prediction with optional CMEK, optional Private Service Access networking and request/response logging - model deployment left to you, so it stands up for cents.
Google Cloud reference architectures
All stacks →Curated stacks of these verified modules, in the order they wire together.
Compare across clouds
All solutions →See how the services Google Cloud covers here compare on other providers.