OVHcloud Infrastructure-as-Code modules

10 verified ansible / terraform modules for OVHcloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 10 OVHcloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 9 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All OVHcloud modules

Static validatedLive test pending

ovh-iam-policy

An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.

View module
Static validatedLive test pending

ovh-private-network

A private network is a vRack VLAN that carries no addresses until a subnet hands them out; a subnet without a gateway address has no way to the internet; and nothing filters traffic on the segment. The subnet's RFC 1918 range required, DHCP with the resolvers you chose, an OVH gateway created by default so instances reach out without a public address, the network named as unfiltered.

View module
Static validatedLive test pending

ovh-container-registry

A registry's endpoint is public and every address may try a login until an IP restriction exists; the registry user is the credential and its password lands in state; and the plan is the storage ceiling. Allowed ranges expected with none accepted by name, one user created for the pipeline with its password as a sensitive output, and the plan looked up by name.

View module
Static validatedLive test pending

ovh-object-storage

Versioning is off by default; encryption is off until an algorithm is named; and a user's S3 credential reaches every container in the project unless a policy narrows it. Versioning on with off by name, object lock decided at creation, AES256, abandoned uploads freed after a week, and a user of its own whose S3 policy allows this container and nothing else.

View module
Live-tested

ansible-ovhcloud-cli

ovhcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in OVHcloud's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a login stops at 'ovhcloud login'. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

ovh-managed-database

Managed PG/MySQL/Kafka with users, IP restrictions, and private network egress.

View module
Static validatedLive test pending

ovh-managed-k8s

MKS cluster with node pools and private-network (vRack) attachment.

View module
Static validatedLive test pending

ovh-dns-zone

Records and DNSSEC on an existing OVHcloud DNS zone, since OVH zones come with the domain or an order and cannot be created from a plain resource. Every record is in one map with MX and SRV priority written into the target as OVH expects, and DNSSEC is on; a domain registered elsewhere needs the DS record copied to its registrar.

View module
Static validatedLive test pending

ovh-key-manager

A secret without an expiration is valid until somebody deletes it, which is the rotation nobody does; a payload from a Terraform variable lands in state; and the service has no flag that refuses deletion. An expiration expected per secret (none by name), values optional so payloads can come from a pipeline, and outputs naming what terraform wrote and what the service lacks.

View module
Static validatedLive test pending

ovh-ip-firewall

Every OVH public IP has an edge firewall that is disabled until enabled, so rules written to it filter nothing; twenty ordered rules where the first match wins and a list without a deny permits what it does not mention; and SSH from anywhere is the first rule offered. Enabled, your permits in sequence with a deny last, SSH from anywhere refused unless accepted.

View module

Compare across clouds

All solutions →

See how the services OVHcloud covers here compare on other providers.

Other providers