Oracle Cloud Infrastructure-as-Code modules
61 verified ansible / terraform modules for Oracle Cloud, spanning Cloud Tooling, Oracle Cloud. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 61 Oracle Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 60 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Oracle Cloud modules
oci-block-volume
Every tenancy ships Bronze, Silver and Gold policies and a volume follows one only through a separate assignment - the page reads Backup policy: none for the many never assigned. Assigns a policy to the volume it creates and refuses one without. Custom schedules add destination_region and retention lock, which Oracle policies lack: same-region backups are a copy of the failure.
oci-budget
The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.
oci-cache
One node is a primary with no replica, so a node failure or a maintenance window is an outage that empties the cache; and the cluster is reachable by anything that can route to its subnet unless an NSG says otherwise, because it has no other access control. Three nodes across availability domains, an NSG required, Valkey or Redis, sharded or not - decided at creation.
oci-cloud-guard
Oracle ships every responder rule in USERACTION mode: a Remediate button appears on each problem and nothing happens until a person clicks it, so a tenancy with hundreds of findings has by default fixed none of them. Sets AUTOACTION per rule and exports the IAM statements each auto-action needs, since one without its policy fails on every execution.
oci-security-zone
The opposite of every other guardrail here: a security zone does not detect or report, it REFUSES - the API call fails. There is no dry-run mode. So the risk inverts too: applied to a compartment that already holds non-compliant resources, the team that owns them discovers they can no longer change them.
oci-service-connector
OCI Logging keeps a log for at most six months; a service connector from a log group to Object Storage is the archive, and it can be created INACTIVE, which is how one that was set up has moved nothing since. Created active, reads a whole log group so new logs are included, writes to a bucket, stream, function, topic, metric or Log Analytics, and exports the IAM statement the hub needs.
oci-container-instances
A container with no health check is restarted only when its process exits, so a deadlocked one stays; containers run as root unless the security context says otherwise; and a public IP on the instance is an internet-facing container with only an NSG in front. Every container gets a check that restarts it and runs non-root on a read-only filesystem; the instance stays private.
oci-remote-peering
A remote peering connection is half a link until the requestor connects to the acceptor, and a PEERED connection with no DRG route import and no VCN route rule passes nothing while reading as connected. Acceptor and requestor halves from one module, the peering status exported, and an output that lists the routes and security rules that live outside it and are the usual reason no packets cross.
oci-custom-image
A custom Compute image from exactly one source: an instance you built (its boot volume, secrets and all, so build it clean) or a QCOW2 or VMDK object in Object Storage with its operating system named, in the launch mode the workload needs (NATIVE for images built on OCI, PARAVIRTUALIZED for imports). OCI has no image family; the name carries the build.
oci-customer-identity
An OCI identity domain on the external-user licence. license_type is not updatable, so changing it replaces the domain with an empty one and every customer account is gone - and the admin email is create-time only too. A domain must be deactivated before it can be deleted, which the module exposes, and it stays off your staff sign-in page.
oci-data-integration
An OCI Data Integration workspace attached to your VCN and subnet so pipelines reach databases that have no public path (internet-only sources by name), with a private DNS server when your names live there. The workspace is the boundary for pipelines and the hourly bill from creation; the pipelines themselves are built inside it.
oci-devops
The project, repository and pipeline are separate resources and none reacts to a commit until a trigger ties a push to the pipeline; builds run as the DevOps service and fail on the first step without a dynamic group and policy; and the runner is on Oracle's network unless given a subnet. Trigger created, runner attached to your subnet, and the IAM rule and statements exported.
oci-fastconnect
One virtual circuit is one cable that goes down for maintenance, and the SLA assumes two; BFD is off by default, leaving a failed link to BGP hold timers for up to ninety seconds; and a circuit without a gateway is PROVISIONED and reaches no VCN. BFD on, the DRG required, a redundant partner circuit declared or the single circuit accepted by name, and the redundancy metadata exported.
oci-backup-policy
A block volume backup policy that many volumes share: incremental daily backups kept thirty days and full weekly backups kept a year, each copied to a second region (one region by name) and encrypted there with a key of yours when given, deletion prevented until retention ends (deletable by name), and every volume in the map assigned, because a policy with no assignment backs up nothing.
oci-goldengate
is_public puts the GoldenGate console and REST API on the internet; the admin password is a vault secret or a literal in state; a deployment with no backup schedule keeps extracts, replicats and checkpoints in one place; and without a maintenance window upgrades land whenever Oracle schedules them. Private behind an NSG, secret required, daily backups to a bucket, and a window you chose.
oci-local-peering
A local peering gateway with no peer stays NEW forever, and a PEERED pair with no route rule sending the other CIDR to the gateway passes nothing while reading as connected. Both gateways created and connected from one call, a route table with the rule to the peer created on each side for the subnets that should reach across, overlap refused, and an output that says it is not transitive.
oci-lustre
OCI File Storage with Lustre in your subnet, reachable only through the network security groups you name, encrypted with a Vault key of yours (the Oracle-managed key by name), with root on clients squashed to a UID and GID you chose except for the clients you exempt (NONE by name), on the throughput tier you chose, with capacity checked against the 31,200 GB step before the plan.
oci-nat-gateway
A NAT gateway for an existing VCN with the private route table that sends subnets through it, because a gateway no table points at forwards nothing. The NAT address is ephemeral unless a reserved public IP is attached, and every allow-list that named it breaks on recreation; the ephemeral address is accepted by name. block_traffic, the kill switch, stays off and is exported.
oci-network-firewall
An INSPECT rule hands the flow to the threat engine, and inspection decides what happens next: INTRUSION_PREVENTION drops the session, INTRUSION_DETECTION logs it and forwards it, and the rule reads INSPECT either way. Every inspect rule is prevention unless detection is accepted by name; policy and appliance are both created, and the address the route tables must point at is an output.
oci-nosql
is_auto_reclaimable is the Always Free shape and means the table is dropped, with its data, after 90 days without a read or write - right for a prototype and wrong for a table a quarterly job reads. Never reclaimable unless accepted by name, provisioned capacity with a ceiling set deliberately, and the DDL checked for a primary key before the API complains about syntax.
oci-postgresql
password_type PLAIN_TEXT writes the admin password into the Terraform state and every plan that shows it; storage that is not regionally durable dies with its availability domain; and a DB system created without a management policy takes no backups. Vault secret reference, regionally durable storage, daily backups optionally copied to another region, a read replica, and an NSG on port 5432.
oci-certificate-authority
The CRL bucket is optional: a CA created without one can mark a certificate revoked and never tell anyone, and every client keeps trusting it until it expires. Required here unless no CRL is accepted by name. Issued certificates renew by rule; one without a renewal rule is a countdown and is listed. Leaf validity is capped at 90 days; the signing key is an HSM key in your vault.
oci-queue
dead_letter_queue_delivery_count defaults to zero, which is no dead-letter queue: a message a consumer cannot process is redelivered after every visibility timeout until retention expires, a poison message that holds a consumer for a day. Five deliveries then the dead-letter queue, seven days of retention instead of one, and a vault key instead of an Oracle-managed one.
oci-data-flow
An OCI Data Flow application that runs Spark from a file in Object Storage with the driver and executor shapes you size, logs to a bucket you own (required, or the output is lost with the run), reaches your VCN through a Data Flow private endpoint when you give one, stops a run after the ceiling you set and an idle session after thirty minutes, and terminates runs when deleted.
oci-site-to-site-vpn
Every OCI IPSec tunnel is created with IKE version 1 unless told otherwise, and negotiates from a compatibility list that still accepts SHA-1, AES-128 and DH group 2 - so the weakest option a peer proposes is what it gets, and the tunnel shows UP. IKEv2 on both tunnels, explicit proposals for both phases with the weak ones refused by validation, BGP routing, and one configured tunnel only by name.
oci-streaming
A public stream pool is an FQDN reachable from anywhere with a valid token; auto_create_topics lets any producer create a stream by writing to a new name; retention defaults to 24 hours, so a consumer a day behind loses data with no error on the producer side. Private endpoint behind NSGs, declared streams, seven days of retention, and the stream that loses data soonest reported as an output.
oci-waf
CHECK is the action that evaluates the rule, logs the match and lets the request through - the console shows the protection rules and every matched attack reached the backend. BLOCK by default, DETECT only by name. The policy and the firewall binding it to a load balancer are separate resources; both are created, and a policy alone has to be asked for.
oci-os-management-patching
An OS Management Hub scheduled job that installs every available update (security-only and the other partial operations by name) on the managed instance groups or compartments you name, weekly by an RRULE from a first run you set in the future, with a reboot window per instance and retries. Instances have to run the agent and be registered with a software source to be seen.
oci-api-gateway
Managed API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.
oci-monitoring-alarms
An email subscription delivers nothing until somebody clicks its confirmation link, and until then every alarm publishes to a subscriber who is not there; repeat_notification_duration is null by default, so an alarm fires once at 3am and is never mentioned again. Creates the topic, subscriptions and alarms together, repeats while firing, and lists the subscriptions still waiting on a click.
oci-analytics
The network endpoint is public by default with no allow list; the encryption key is Oracle's unless a vault key is given; and an instance with no notification email is upgraded and restarted with nobody told. Private endpoint in your VCN behind NSGs, a vault key expected, a notification address required, and capacity set as OCPUs or users on purpose.
oci-network-security-group
An NSG with no rules admits nothing and sends nothing, so a group written with ingress only has VNICs that cannot resolve DNS; a stateless rule drops every reply that has no matching egress; and the subnet's security list still applies, unioned with the NSG. Stateful always, egress explicit and open by default, SSH from 0.0.0.0/0 refused unless accepted, the security list named as still applying.
oci-opensearch
security_mode PERMISSIVE runs the security plugin, evaluates every request and lets unauthenticated ones through - the migration mode clusters stay in - and DISABLED does not evaluate at all; both look like a cluster with the plugin. ENFORCING with a master user, three masters because one is no quorum, two or more data nodes, an NSG because it is the only network control, and maintenance emails.
oci-audit
Audit retention set to the 365-day ceiling OCI allows, plus the archive for everything past it: a private bucket with a retention rule (seven years by default, lockable by a date you pass), the service connector that streams every compartment's audit events into it, and the IAM policy without which the connector sits in FAILED. Your Vault key, or the Oracle-managed one by name.
oci-autonomous-database
ATP/ADW/JSON/APEX autonomous database with private endpoint, mTLS wallet output, ACLs, auto-scaling and backup config.
oci-base-database
Oracle Database VM system with DB home, TDE via Vault, automated backups and optional Data Guard standby.
oci-bastion
Zero-footprint managed bastion with session-managed SSH/port-forward access to private subnets - replaces jump hosts.
oci-dns-zone
Public/private DNS zones with record sets, failover/geo steering policies and health-check probes.
oci-drg-hub
Dynamic Routing Gateway with VCN attachments, custom DRG route tables, remote peering and IPSec/FastConnect attach points.
oci-events-rule
An empty condition is legal and matches the completion of every API call on every resource type in the compartment, flooding the target; a rule can be created disabled, and so can each action inside an enabled rule, which then matches events and does nothing while showing Active. Every rule names its event types, both levels are enabled unless accepted, and the IAM the service needs is exported.
oci-file-storage
Elastic NFSv3 file system with mount target, export options, snapshots and NSG-scoped access.
oci-load-balancer
HTTPS load balancer with backend sets, health checks, TLS certificates, rule sets and WAF-ready listeners.
oci-functions-app
Serverless Fn application with functions, provisioned concurrency, invoke logging and Events-rule trigger wiring.
oci-instance-pool-autoscaling
Self-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.
oci-mysql-heatwave
Managed MySQL with optional HeatWave analytics cluster, HA, backups, configuration and inbound replication channel.
oci-data-science
A notebook session with no subnet runs on Oracle's network with internet egress and no path to your VCN, and a session left ACTIVE bills its shape - a GPU, over a weekend - whether or not anyone is in it. Sessions attach to your subnet, the shape and storage are set on purpose, and the sessions that are billing from the moment of apply are listed in an output.
ansible-oci-cli
The Oracle Cloud Infrastructure CLI pinned in /opt/oci-cli, a virtual environment apart from the system Python, linked into the PATH. No package exists; the documented installs are a script piped into bash or pip into the system Python. The live test runs pip check and an API call, and asserts the system Python cannot import the SDK. Original role, live-tested on Rocky Linux 10.
oci-compute-instance
Opinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.
oci-iam-foundation
Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.
oci-network-load-balancer
Low-latency pass-through NLB with TCP/UDP listeners, backend health checks and preserved client IPs.
oci-vcn
Production VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.
oci-oke
Enhanced OKE cluster with managed + virtual node pools, private API endpoint, NSGs, addons and OIDC - flagship OCI workload platform.
oci-object-storage-bucket
Bucket with versioning, lifecycle/auto-tiering, retention rules, replication and pre-authenticated request support.
oci-container-registry
The registry creates a repository for any push to an unknown name by default - private, and unmanaged - and a tag can be overwritten unless the repository is immutable, so a deployment pinned to v1.4.2 runs whatever last claimed it. Manages the tenancy-wide create-on-push switch off, creates repositories immutable and private, and lists any that are public or mutable when that is accepted.
oci-email-delivery
A domain without DKIM sends mail that looks forged and lands in spam; without a custom return path, bounces go to Oracle's domain and DMARC alignment fails; and a From address that is not an approved sender is refused by the API. DKIM key created, return path created, senders listed and checked against the domain, and every DNS record to publish exported in one output.
oci-logging
Every OCI service log is off until somebody turns it on: a VCN records no flow log, a load balancer no access log, a bucket no read log. Each log here is one service, one resource, one category, created enabled; a log created with is_enabled = false appears in the list and records nothing, and has to be accepted by name. Retention is 30 days by default and the shortest is reported.
oci-tag-namespace
A tag default with is_required = false applies a value silently and lets anyone overwrite or blank it; required is the only enforcement OCI tagging has, and a required free-text tag enforces presence and nothing about meaning. Every default is required and validated against an allowed list unless accepted otherwise; the ten cost-tracking slots are counted; retirement is the only delete that works.
oci-health-checks
A monitor can be created disabled and probes nothing; one vantage point reports the site down when that location is; and a monitor is a metric, not an alarm - nothing pages until Monitoring reads it. Enabled monitors over HTTPS from three regions by default, and the MQL query each one needs in an alarm exported for the oci-monitoring-alarms module.
oci-vcn-flow-logs
VCN flow logs for the subnets you list, since OCI logs per subnet and a subnet added later has none: a log per subnet in a log group created or given, category all rather than reject, ninety days of retention rather than the thirty-day default, and the subnet map as the list to update. Flow logs are the largest log in a tenancy; the map is also the bill.
oci-vault-kms
KMS vault with HSM/software master keys, key rotation and secret lifecycle management for app credentials.
oci-vulnerability-scanning
scan_level = NONE is legal for both the agent scan and the port scan, so a recipe with both at NONE runs on schedule, updates its last-run time, and finds nothing because it looked for nothing. A recipe is not a target either: one with no target scans no instance. Refuses a recipe that scans for nothing and always creates the target with it.
Oracle Cloud reference architectures
All stacks →Curated stacks of these verified modules, in the order they wire together.
Compare across clouds
All solutions →See how the services Oracle Cloud covers here compare on other providers.