OVHcloud Infrastructure-as-Code modules
10 verified ansible / terraform modules for OVHcloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 10 OVHcloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 9 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All OVHcloud modules
ovh-iam-policy
An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.
ovh-private-network
A private network is a vRack VLAN that carries no addresses until a subnet hands them out; a subnet without a gateway address has no way to the internet; and nothing filters traffic on the segment. The subnet's RFC 1918 range required, DHCP with the resolvers you chose, an OVH gateway created by default so instances reach out without a public address, the network named as unfiltered.
ovh-container-registry
A registry's endpoint is public and every address may try a login until an IP restriction exists; the registry user is the credential and its password lands in state; and the plan is the storage ceiling. Allowed ranges expected with none accepted by name, one user created for the pipeline with its password as a sensitive output, and the plan looked up by name.
ovh-object-storage
Versioning is off by default; encryption is off until an algorithm is named; and a user's S3 credential reaches every container in the project unless a policy narrows it. Versioning on with off by name, object lock decided at creation, AES256, abandoned uploads freed after a week, and a user of its own whose S3 policy allows this container and nothing else.
ansible-ovhcloud-cli
ovhcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in OVHcloud's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a login stops at 'ovhcloud login'. Original role, live-tested on Rocky Linux 10.
ovh-managed-database
Managed PG/MySQL/Kafka with users, IP restrictions, and private network egress.
ovh-managed-k8s
MKS cluster with node pools and private-network (vRack) attachment.
ovh-dns-zone
Records and DNSSEC on an existing OVHcloud DNS zone, since OVH zones come with the domain or an order and cannot be created from a plain resource. Every record is in one map with MX and SRV priority written into the target as OVH expects, and DNSSEC is on; a domain registered elsewhere needs the DS record copied to its registrar.
ovh-key-manager
A secret without an expiration is valid until somebody deletes it, which is the rotation nobody does; a payload from a Terraform variable lands in state; and the service has no flag that refuses deletion. An expiration expected per secret (none by name), values optional so payloads can come from a pipeline, and outputs naming what terraform wrote and what the service lacks.
ovh-ip-firewall
Every OVH public IP has an edge firewall that is disabled until enabled, so rules written to it filter nothing; twenty ordered rules where the first match wins and a list without a deny permits what it does not mention; and SSH from anywhere is the first rule offered. Enabled, your permits in sequence with a deny last, SSH from anywhere refused unless accepted.
Compare across clouds
All solutions →See how the services OVHcloud covers here compare on other providers.