Huawei Cloud Infrastructure-as-Code modules

47 verified ansible / terraform modules for Huawei Cloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 47 Huawei Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 46 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Huawei Cloud modules

Static validatedLive test pending

huawei-bastion

A CBH instance. The console administrator password is a required argument, so it is written to Terraform state in plain text and whoever reads that state administers every recorded session in the estate; the module will not build until that is acknowledged. period is ForceNew, so changing the term destroys and rebuilds the appliance rather than renewing it.

View module
Static validatedLive test pending

huawei-cbr-backup

A Cloud Backup and Recovery policy that backs up nightly and keeps thirty days, bound to a server vault spread across zones (single-zone by name) that auto-expands rather than stopping when full (a fixed size by name), crash-consistent unless the CBR agent is on every server, with the servers in the map protected. Pay-per-use.

View module
Static validatedLive test pending

huawei-cdn

A Huawei Cloud CDN domain in front of your OBS bucket or origin host, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from Cloud Certificate Manager, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, cache headers followed from the origin, and the origin fetched over HTTPS. The CNAME is exported.

View module
Static validatedLive test pending

huawei-csms-secret

A secret in Huawei Cloud Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the account's default CSMS key (the default by name), with an expiry after which CSMS flags it (none by name) and event subscriptions that notice version changes and expiry.

View module
Static validatedLive test pending

huawei-tls-certificate

A public TLS certificate bought through Huawei CCM, and its application. Applying is a purchase, so brand, type and validity have no defaults and every combination rule is checked at plan. It does not renew itself. The provider accepts Huawei's privacy terms on every application, so the module waits for a person to. Validation records appear one refresh after the first apply.

View module
Static validatedLive test pending

huawei-css-cluster

A CSS cluster with security_mode true, since false means the cluster answers anyone who can reach it with no credentials while the console reports it healthy. HTTPS requires security mode and the API says so late, so the module says so first; disks are encrypted at creation, and public access without a whitelist is refused.

View module
Static validatedLive test pending

huawei-dcs-redis

A Distributed Cache Service Redis instance in your VPC with primary and standby across two zones (one by name), TLS required (plaintext by name), the whitelist on with your ranges, a password from a secret store never output, weekly backups kept seven days, a maintenance window, and flushall, flushdb, keys and hgetall renamed so an accident cannot type them.

View module
Static validatedLive test pending

huawei-database-migration

A DRS job with the lag alarm armed to an SMN topic, since without one the console shows the same green whether the job is current or hours behind. The target is held read-only, because anything writing to it produces conflicts the job cannot see or repair; multi_write and a FULL_TRANS-only snapshot both have to be chosen by name.

View module
Static validatedLive test pending

huawei-dws

A DWS cluster keeping its manual snapshots when it is deleted, since the default of zero deletes the backups along with the thing they were backing up and turns a mistaken delete into a permanent one. Disks are encrypted at creation because they cannot be later, audit logging to LTS is on, and there is no public endpoint unless you ask for one.

View module
Static validatedLive test pending

huawei-elb

The default TLS policy accepts TLS 1.0; a pool without a monitor resource is never unhealthy and sends traffic to every member forever; an HTTPS listener does nothing about port 80 until an L7 policy redirects it; and deletion protection is off. tls-1-2-strict, an HTTP monitor on a path, a redirect on 80 whenever a certificate is given, two zones unless one is accepted, deletion protection on.

View module
Static validatedLive test pending

huawei-waf

A dedicated WAF of two anti-affinity instances in your subnet (one by name), pay-per-use, with a policy in block mode (log mode by name) that turns on basic web protection, CC attack protection, precise protection, web shell detection, anti-crawler and data masking, and the protected domain with your certificate, TLS 1.2, cipher suite 2 and PCI DSS checks, forwarding to origins over HTTPS.

View module
Static validatedLive test pending

huawei-fgs-function

A FunctionGraph v2 function running as the IAM agency you name, in your VPC when a subnet is given, logging every invocation to the LTS group and stream you name, with plain environment variables in user_data and secrets in encrypted_user_data under your KMS key (which also encrypts the code), fetched from an OBS URL. A ceiling on instances is an input.

View module
Static validatedLive test pending

huawei-dns-zone

A Huawei Cloud public DNS zone with the flat record map grouped into the record sets Huawei expects (one per name and type, several values), DNSSEC on with the DS record for the registrar, and the nameservers exported. Private zones bound to a VPC are a different zone type and not this module.

View module
Static validatedLive test pending

huawei-vpc

A Huawei Cloud VPC whose range is checked against RFC 1918 (a public range by name), with subnets placed in the zones you name, each with its gateway at the first address and DHCP handing out Huawei's resolvers so the platform's service names resolve. Nothing egresses: a NAT gateway (huawei-nat-gateway) or an EIP is a separate decision.

View module
Static validatedLive test pending

huawei-kms-key

rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its pending window with everything encrypted under it, on a service with no flag to refuse the schedule. Rotation on at your interval, a 30-day window, and an output that says no deletion-protection flag exists.

View module
Static validatedLive test pending

huawei-kafka-streaming

A DMS Kafka instance with enable_auto_topic off, because a producer that misspells a topic otherwise creates one: the messages go somewhere real, nothing errors, and nobody consumes them. TLS and SASL are both on, which is what makes the user mean anything; the disk is encrypted at creation; and what happens when the disk fills is a decision you take.

View module
Static validatedLive test pending

huawei-machine-learning

A ModelArts workspace and notebook with allowed_access_ips required, since empty means any address and the notebook has your training data mounted and your credentials in its environment. auth_type PUBLIC means every user in the account rather than the internet. There is no auto-stop argument, and the module says so rather than implying a protection it cannot give.

View module
Static validatedLive test pending

huawei-dds-mongodb

A Document Database Service instance with ssl true, since false accepts plaintext client connections and nothing in the console says so, a named backup window and retention, and disk encryption that cannot be added afterwards. Sharding needs mongos, shard and config flavors and the module checks the combination before the apply rather than after.

View module
Static validatedLive test pending

huawei-private-ca

A CCM private CA, root or subordinate. CRL publication is off by default, and without it you can press revoke while every client keeps trusting the certificate until it expires - so the module refuses that unless it is accepted. Deleting a CA starts a 7 to 30 day clock rather than deleting, and the product exists in two regions only.

View module
Static validatedLive test pending

huawei-nat-gateway

A pay-per-use public NAT gateway for an existing Huawei Cloud VPC, with a traffic-billed elastic IP whose bandwidth cap every subnet shares, and an SNAT rule for each subnet listed, because a gateway with no SNAT rule forwards nothing. The spec is a concurrency tier (10,000 to a million connections) and what an idle gateway costs per hour.

View module
Static validatedLive test pending

huawei-security-group

Every new security group comes with default rules - all egress allowed and ingress from its own members - that nobody wrote and few remove; SSH from 0.0.0.0/0 is the first rule offered; and the group is attached by the instance, which it cannot see. Default rules deleted so the group holds only what the module wrote, egress stated, SSH from anywhere refused unless accepted.

View module
Static validatedLive test pending

huawei-org-policy

An Organizations policy and its attachments. The type - service control, tag or AI service - decides what the JSON means, and the same document in the wrong type either fails to attach or attaches and does nothing recognisable. An SCP is a ceiling that cannot grant, an unattached policy enforces nothing, and a root attachment reaches the management account.

View module
Static validatedLive test pending

huawei-static-site

An OBS bucket serving a static website, published by an OBS-format bucket policy rather than a public-read ACL, so the file list stays private. Encryption is off on purpose: every byte is published deliberately, and an anonymous reader holds no permission on your key, so a key of your own hides nothing and stops the site working.

View module
Static validatedLive test pending

huawei-vpcep-endpoint

A Huawei Cloud VPC endpoint (interface type) to an endpoint service, with a private IP in your subnet, the whitelist on and set to the CIDRs you name (an empty whitelist admits the whole VPC and has to be accepted by name), and the service's domain registered in the VPC's private DNS.

View module
Static validatedLive test pending

huawei-vpc-peering

A peering connection between two VPCs with a route written into every route table you list, on both sides, for every CIDR of the other side. A cross-tenant peering sits in PENDING_ACCEPTANCE and its other side is out of reach of this provider, so the module refuses an accepter route table list in that case rather than failing at apply.

View module
Static validatedLive test pending

huawei-direct-connect

A Direct Connect virtual gateway on a VPC and a virtual interface on a connection you already have. bgp_md5 is the only authentication the session has and it is optional in the API, so it is required here. The two endpoint groups are where this goes wrong quietly: a wrong prefix gives a circuit that is up, a session established, and traffic that disappears.

View module
Static validatedLive test pending

huawei-network-firewall

Address groups and ACL rules on a Cloud Firewall protected object, with antivirus turned on since it is a separate resource and a complete rule set says nothing about it. Huawei takes a placement rather than a position, so order is not determined by the file: place_at_top pins the one rule that matters and the module says plainly that the rest must not overlap.

View module
Static validatedLive test pending

huawei-api-gateway

A Huawei Cloud APIG dedicated instance, group, environment and published APIs. The provider defaults an API to no authentication; this module defaults to signed app requests and takes open or plaintext APIs one at a time. Every published API gets the required rate limit, the gateway stays off the internet unless asked, and the debug hostname stays off.

View module
Static validatedLive test pending

huawei-vpn-gateway

A Huawei Cloud Enterprise VPN gateway in active-active mode across two zones with two EIPs, a customer gateway, and a static-route connection from each EIP to the peer on IKEv2 negotiating AES-256-GCM, SHA2-256 and DH group 14 in both phases (the weak options refused, IKEv1 by name), with dead peer detection and network quality checks on.

View module
Static validatedLive test pending

huawei-app-platform

A CAE environment, application and components. deploy_after_create is off in the API, so a component exists with a source, a runtime and a replica count and serves nothing; it is on here. The runtime list still offers Java8, Nodejs8 and Php7, which the module names and asks about, and 500m of CPU cannot take 4Gi of memory.

View module
Static validatedLive test pending

huawei-ecs-instance

An ECS instance in your subnet with login by key pair and no password, no elastic IP unless one is accepted by name, the system disk encrypted with your KMS key (the platform key by name), an IAM agency as its identity so code on it needs no stored access key (none by name), the Cloud Eye agent on, and the instance stopped before destroy with its disks. Pay-per-use.

View module
Static validatedLive test pending

huawei-evs-disk

A backup on Huawei Cloud is a vault, a policy and a resource list that exist separately, so the common state is a policy with no vault or a vault with no disks; and a disk is encrypted only when a KMS key is given. The vault created with the policy applied and the disk as its resource (none by name), a key expected (none by name), attached to the instance you give.

View module
Static validatedLive test pending

huawei-enterprise-router

A Huawei Cloud Enterprise Router across two zones with default association and propagation off, the route tables you name, and a VPC attachment per VPC each associated with one table and propagating into the tables you list, with routes to the router written into each VPC. Shared attachments from other accounts wait for you unless auto-accept is turned on by name.

View module
Static validatedLive test pending

huawei-iam-agency

An IAM agency that the Huawei Cloud service you name (ECS, FunctionGraph, CCE) assumes on your behalf, so instances and functions that name it need no stored access key, with roles scoped to the projects you list; account-wide roles and Tenant Administrator are each accepted by name. The delegation to a service does not expire.

View module
Static validatedLive test pending

huawei-image

A Huawei Cloud private image captured from an ECS instance's system disk on the current IMS resource, with memory bounds for instances launched from it. Encryption follows the source disk (an unencrypted source has to be accepted by name), and the name carries the build. Build the source clean and stop it first.

View module
Static validatedLive test pending

huawei-mapreduce

A MapReduce Service cluster with safe_mode true, since false turns Kerberos off and leaves a cluster where Manager answers and nothing authenticates anybody. A node credential is required rather than left to the API, MRS Manager stays off the internet unless asked, and log collection is on so a cluster that fails to build does not take the reason with it.

View module
Static validatedLive test pending

huawei-obs-bucket

Public access is two switches: a private ACL still leaves a bucket policy free to grant anonymous reads, and only Block Public Access refuses both; versioning and encryption are both off by default; abandoned uploads bill until a rule aborts them. Private ACL plus BPA with public by name, versioning on, encrypted with the region's key or yours, incomplete uploads freed after a week.

View module
Static validatedLive test pending

huawei-landing-zone

An organization, its units and its accounts. enabled_policy_types is what makes a service control policy attachable at all: without it a policy is created and fails to attach, at apply, behind a clean plan, and neither console connects the two. The account email and phone are the recovery path, so an account with none is listed as an output.

View module
Static validatedLive test pending

huawei-sfs-turbo

A Huawei Cloud SFS Turbo file system (NFS) in your subnet, encrypted with your KMS key (unencrypted has to be accepted by name), behind the security group you name and which the module does not open, on the standard or performance tier with the capacity you provision.

View module
Static validatedLive test pending

huawei-swr

A SoftWare Repository for Container organization, which is the namespace images are addressed under, with the repositories you list created in it, each private unless a public one is accepted by name. Who may push and pull is an IAM decision per organization or repository, made outside the module.

View module
Static validatedLive test pending

huawei-monitoring-alarms

Cloud Eye alarm rules from a map of namespaces, metrics, dimensions and thresholds, each firing after three consecutive periods and quiet for an hour after, sending on alarm and on recovery to an SMN topic created here and subscribed by the addresses you name (each confirms by email). A topic with no subscribers has to be accepted by name.

View module
Static validatedLive test pending

huawei-security-posture

HSS host protection and a vulnerability scan policy. status close writes a policy with a period and a range that never runs. specific_host with an empty list scans nothing. The protection tiers are different products rather than different quotas and all of them report as protected. Protection needs the agent online, and the waiting behaviour is off in the API.

View module
Static validatedLive test pending

huawei-cce-cluster

CCE Kubernetes with VPC/subnet, node pool, and EIP-attached ingress.

View module
Live-tested

ansible-huawei-koocli

Huawei's hcloud on EL 10 from a versioned path on Huawei's download host (the docs give only latest), refused by get_url unless the tarball's SHA-256 is the pinned one; Huawei's .sha256 names a build-server path, so the live test reads it and asserts its first field is the pin. The privacy statement stays per user; the role accepts it for nobody. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

huawei-rds-postgresql

One availability zone is one node whose failure is downtime; ssl_enable defaults to false, so clients speak plain TCP; the data volume is encrypted only when a KMS key is given; and the backup window and retention are the platform's. Two zones (one by name), SSL on, a KMS key expected (none by name), minor versions auto-upgraded, daily backups in your window with your retention.

View module
Static validatedLive test pending

huawei-cts

The Cloud Trace Service system tracker (one per region, adopted rather than duplicated) delivering every management event to an OBS bucket you own, each file signed so tampering is detectable, gzip-compressed, sorted by service, encrypted with your KMS key (the bucket default by name), and also sent to LTS for queries. Excluding services from the trace is accepted by name.

View module
Static validatedLive test pending

huawei-vpc-flow-logs

Flow logs for a VPC, subnet or port written into an LTS log group and stream the module creates with the retention you choose, all traffic rather than only what was accepted, and VPC-wide rather than the per-port capture that quietly leaves most traffic unrecorded. A flow log that exists but is disabled records nothing; disabling it has to be accepted by name.

View module

Compare across clouds

All solutions →

See how the services Huawei Cloud covers here compare on other providers.

Other providers