IBM Cloud Infrastructure-as-Code modules
37 verified ansible / terraform modules for IBM Cloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 37 IBM Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 36 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All IBM Cloud modules
ibm-backup-policy
Backup for VPC: a policy that selects volumes (or instances) carrying the tags you name, a daily plan that keeps snapshots thirty days and copies the user tags across, and a copy of each snapshot to a second region with an encryption key of yours there; a single region is accepted by name. A policy with no plan backs up nothing; the plan is created here.
ibm-block-volume
VPC backup policies match volumes by user tag, so a volume created without the tag sits silently outside the policy; encryption is provider-managed unless a root key CRN is given; and an attachment can delete the volume with the instance. The policy created with its plan and the volume tagged with the tag it matches (none by name), your key when given, the volume kept on instance deletion.
ibm-cos-bucket
Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.
ibm-cloudant
A Cloudant instance on the standard plan with CORS off, and a wildcard origin together with allow_credentials refused outright because it would let any site make authenticated requests as the signed-in user. Legacy username-and-password auth is off, and data events are on, since without them the trail never records that anyone read a document.
ibm-code-engine-app
A Code Engine project and application with managed_domain_mappings local_private, because the field defaults to local_public and an application deployed with no opinion about it answers the world. scale_min_instances is one rather than zero, run_as_user is not root, and a private image without its pull secret is refused - that failure otherwise arrives long after the apply.
ibm-code-engine-function
A Code Engine function in a project created here, callable only from inside the project unless a public URL is accepted by name, with the compute resource token mounted so it obtains IAM tokens through a trusted profile and needs no API key, and CPU, memory, concurrency and execution time capped so a runaway caller cannot drive the bill.
ibm-container-registry
An IBM Cloud Container Registry namespace in the provider's region, with a retention policy that keeps the last ten images per repository and drops untagged ones, because without one every CI run adds an image until the account's storage quota refuses the next push. Quotas and the plan are account-wide and not managed here.
ibm-databases-redis
An IBM Cloud Databases for Redis deployment on the private endpoint only (public by name), with deletion protection on, an allowlist of your ranges (empty by name), disk and backup encryption with Key Protect keys you hold (IBM's keys by name), and the two-member group that is the HA and cannot be reduced. Access is by service credential, a separate resource.
ibm-direct-link
A Direct Link gateway with both default route filters set to deny, because permit accepts every prefix the other side advertises including a default route that would pull the VPC's whole egress across the circuit. The BGP session is authenticated, BFD is on, global routing and metered billing are required inputs, and a virtual connection per VPC is what makes the circuit reach anything.
ibm-vpc-flow-logs
A VPC flow log collector writing into a Cloud Object Storage bucket the module creates with an expiry rule and your Key Protect key if you hold one, plus the is to cloud-object-storage Writer authorization without which a collector reports active and logs nothing - the usual reason an IBM flow log leaves an empty bucket. An inactive collector has to be accepted by name.
ibm-public-certificate
A publicly-trusted certificate issued into Secrets Manager, validated over DNS through Cloud Internet Services, with both configurations created here rather than left to a console. Staging issues a certificate no browser trusts while looking like success, so it is refused by name; auto-rotation and key rotation are on, because a ninety-day certificate nothing renews is a dated outage.
ibm-transit-gateway
An IBM Cloud Transit Gateway local to one region (global by name) with a connection per VPC you name, each denying every prefix by default and permitting the prefix rules you write, since a transit gateway has no route tables and every connection advertises everything otherwise; a connection that permits all has to say so.
ibm-vpn-gateway
An IBM Cloud VPC VPN gateway in policy mode with one connection to your on-premises gateway on IKEv2, with its own IKE and IPsec policies (AES-256, SHA-256, DH group 14) so IBM's auto-negotiation list never admits SHA-1 or a small group, the weak options refused by validation, IKEv1 by name, and dead peer detection that restarts the connection.
ibm-private-ca
A root CA, an intermediate it signs and certificate templates in IBM Cloud Secrets Manager. IBM's examples let a template issue for any name; here templates name their domains, both CAs carry name constraints, and CRLs are built and published. Lifetimes are checked to nest, and the module says plainly that Terraform cannot revoke a CA.
ibm-db2
A Db2 deployment on a private endpoint with high availability on, disk encryption with a key you hold, and named ranges, because Db2 reads an absent allow list as any address rather than none. Autoscaling is off unless configured and its plan limit is the point: it is the difference between a slow hour and an unbounded invoice. Oracle compatibility is fixed at creation.
ibm-databases-elasticsearch
A Databases for Elasticsearch deployment on a private endpoint with deletion protection on, your Key Protect keys for both the data and the backups, and an allowlist that must name ranges because an empty one is read as any address. Three members, fixed rather than offered as a knob with one safe value. The plan, not the module, decides whether field-level security exists.
ibm-dns-zone
An IBM Cloud DNS Services private zone, its permitted networks and its records. The zone and the permission are separate resources: with none, the zone is created, the records are created, everything reports Active, and no VPC can resolve any of it. An empty list is refused. This is private DNS and it is not the public zone, which is CIS.
ibm-key-protect-key
The rotation policy is a separate resource nobody creates, so a key made today encrypts everything for the life of the account; dual_auth_delete, the control that makes deletion a two-person act, is off by default; and force_delete would remove a key buckets still use. Rotation on at your interval, dual authorization on (off by name), force delete never, the instance created when none is given.
ibm-secrets-manager
A secret group and an arbitrary secret in an IBM Cloud Secrets Manager instance you already have, over the private endpoint. The instance is a paid resource created once per account and is an input, so an apply never creates a second bill; the group is the unit IAM grants are made on; the value is a sensitive variable never output; an expiry is expected, none by name.
ibm-security-group
An IBM VPC security group with no rules denies everything in both directions, so a group written with inbound rules only leaves instances that cannot resolve DNS; a group with no targets protects nothing; and SSH from 0.0.0.0/0 is the first rule offered. Outbound explicit with egress open by default, targets attached by the module (none by name), SSH from anywhere refused unless accepted.
ibm-devops
An IBM Cloud CD toolchain, Tekton pipeline, definition and triggers. Without a definition the pipeline is enabled and has no tasks while everything looks finished. enable_events_from_forks runs the pipeline with its own credentials for anyone who can open a pull request, so it is off and refused by name, and omitting a concurrency limit disables it entirely.
ibm-trusted-profile
An IAM trusted profile, which is identity without an API key: policies that grant roles on one service and resource group each (Administrator by name), and links to the virtual servers or Kubernetes service accounts that may assume it through the metadata service, since a profile with no link is assumed by nobody (accepted by name).
ibm-image
An IBM Cloud VPC custom image made from a boot volume, wrapped with the Key Protect or HPCS key you name (provider-managed encryption has to be accepted by name), with deprecation and obsolescence dates so the fleet is told when to move on and cannot launch an obsolete image. Stop the instance first.
ibm-file-share
An IBM Cloud VPC file share (NFS) wrapped with your Key Protect or HPCS key (provider-managed by name), with one mount target on a virtual network interface in your subnet behind the security groups you name, using user-managed transit encryption (plain NFS has to be accepted by name). One zone; a fleet in two mounts across or replicates.
ibm-vpc-load-balancer
type defaults to public, so a load balancer created without one gets an internet address; the pool's health check can be a TCP handshake; a port-80 listener forwards unless a listener policy redirects it; and logging is off. Private with public by name, an HTTP check on a path, a 301 policy on 80 whenever a Secrets Manager certificate is given, two subnets unless one is accepted, logging on.
ibm-vsi-instance
A VPC virtual server in your subnet with the SSH keys you name and no password, security groups on the primary interface, no floating IP, the boot volume encrypted with a Key Protect key (IBM's key by name), secure boot on, and the metadata service on so a trusted profile can be the instance identity instead of a stored API key.
ibm-vpe-gateway
An IBM Cloud VPC virtual private endpoint gateway to a cloud service, with a reserved IP in each subnet you name (one zone has to be accepted by name), behind the security groups you name (the VPC default group by name), and DNS resolution binding enabled so the VPC resolves the service to the gateway.
ibm-waf
The CIS managed and OWASP core rulesets deployed on an IBM Cloud Internet Services domain, with the OWASP threshold, action and paranoia level set. The resource owns the whole managed phase, so console rules are overwritten, and destroying it leaves the WAF running - the module says so and makes turning it off an explicit step. The deprecated legacy WAF resources are not used.
ibm-static-site
An IBM Cloud Object Storage bucket serving a static website. The public policy grants Object Reader, which IBM documents as download without listing, rather than Content Reader, which lists. It names the two account settings that silently switch public access off, says the endpoint is plain HTTP, requires you to accept that everything in it is public, and expires old versions.
ibm-activity-tracker
Activity Tracker Event Routing with a COS target written service-to-service (no API key stored), a route that sends every location's events to it (a narrower list by name), and the account settings that keep routing metadata in your region, make the target the default, and answer the routing API on private endpoints only. Without a route, events go nowhere you keep.
ibm-customer-identity
IBM Cloud App ID's customer directory, redirect URLs, token lifetimes, and MFA, password policy and activity tracking. The provider lets anyone sign up by default, so that input has no default here. Redirect URLs refuse plaintext and wildcards unless accepted, as IBM advises. MFA, password policy and tracking are billed, graduated-tier-only features, so they need an explicit yes.
ibm-databases-postgresql
service_endpoints decides whether the deployment answers on the internet and public is the default; deletion_protection defaults to false; an empty allowlist means any address that can reach the endpoint; and disk and backup encryption use IBM's keys unless yours are given. Private with public by name, deletion protection on, ranges expected (empty by name), both key CRNs taken, two members.
ibm-event-streams
An IBM Cloud Event Streams (Kafka) instance on the standard multi-tenant plan (enterprise is a dedicated cluster and a purchase), with the brokers on private endpoints only (public by name), and topics from a map with partitions, retention in hours and a cleanup policy, a week and three partitions by default. Producer and consumer credentials are a separate resource.
ansible-ibmcloud-cli
ibmcloud on EL 10 from IBM's download host, refused by get_url unless the tarball's SHA-256 is the one pinned beside the version: IBM publishes no checksum, and the ibmcloud.sig inside the tarball has no public key to check it against. The live test hashes the tarball again and runs ibmcloud target before any endpoint is set. Original role, live-tested on Rocky Linux 10.
ibm-iks-cluster
IKS cluster on VPC Gen2 with worker pools and COS-backed registry namespace.
ibm-vpc-landing
VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.
ibm-public-gateway
IBM Cloud VPC public gateways, one per zone you list because a gateway serves its own zone only, with the subnets in the map attached to the gateway of their zone (a gateway with no subnet forwards nothing) and a reserved floating IP per zone when you pass one so the egress address survives recreation. gateway_count says what bills by the hour.
Compare across clouds
All solutions →See how the services IBM Cloud covers here compare on other providers.