Scaleway Infrastructure-as-Code modules
23 verified ansible / terraform modules for Scaleway, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 23 Scaleway modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 22 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Scaleway modules
scaleway-block-volume
iops is required, is the price per GB, and cannot change after creation; snapshots exist as a resource you take and nothing on the platform schedules one; the volume is zonal and attaches from the server side. The tier validated to the two that exist, a baseline snapshot when asked, and an output that says no schedule exists.
scaleway-object-bucket
Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.
scaleway-load-balancer
A Scaleway Load Balancer on a flexible IP with a Let's Encrypt certificate it issues itself (so the DNS must point at it first), TLS at the modern compatibility level (older clients by name), HTTP/3, the port 80 frontend answering only a 301 to HTTPS, and backends named by their Private Network address and probed over HTTP on a path you chose.
scaleway-container-registry
is_public makes every image in the namespace pullable by anyone, and the key CI pushes with is usually a person's API key with every permission that person has and no expiry. Private unless public is accepted by name, and on request an IAM application whose only permission is registry access in one project, with an API key that expires on the date you set.
scaleway-image
A Scaleway instance image built from a snapshot the module takes of the root volume you name, private (public lists it for every Scaleway account and has to be accepted by name), for x86_64 or arm64, in one zone. Stop the server first so the file system is consistent.
scaleway-public-gateway
A Scaleway Public Gateway on a reserved address, attached to a Private Network with masquerade and the default route pushed to the hosts, since a gateway with no gateway network forwards nothing. The bastion (SSH into the network through the gateway) is off and accepted by name; outbound SMTP is off so a compromised host cannot send mail under your name.
scaleway-redis
A Scaleway Managed Database for Redis cluster attached to your Private Network with no public endpoint (one by name), TLS required (plaintext by name), a password from a secret store never output, an ACL of the ranges that may connect (required), an eviction policy set, and three nodes so the data has three copies (fewer by name).
scaleway-dns-zone
A Scaleway DNS zone (the root zone of the domain unless a subdomain is named) with every record in one map and the nameservers Scaleway assigns exported for the registrar. Geo-routed, weighted and health-checked records are kept out so a plain zone stays plain; a domain registered with Scaleway is delegated already.
scaleway-instance
A Scaleway instance on a Private Network with a required security group (the project default allows everything inbound), no public address unless a flexible IP is accepted by name, the project's SSH keys and no password, a Block Storage root volume deleted with the instance, cloud-init, and protection from deletion (off by name).
scaleway-security-group
The default inbound policy is accept, so a group with no rules admits every packet on every port and your rules are exceptions to accept-all; SSH from everywhere is the first rule offered; and the group filters the public interface only. Drop by default, SSH from a /0 refused unless accepted, the SMTP block kept unless a relay says otherwise, and outputs that say the Private Network is unfiltered.
scaleway-function
A Scaleway Serverless Function in its own namespace, private so an IAM token is needed to invoke it (public by name), plain HTTP redirected to HTTPS, secrets in the encrypted secret variables rather than the plain ones, idling at zero instances with a ceiling you chose, and the zip archive uploaded at apply with its hash so a changed archive redeploys.
scaleway-static-site
A Scaleway Object Storage bucket serving a static website. A bucket policy here is version 2023-04-17, not the AWS 2012-10-17 that every S3 example carries and Scaleway has deprecated, and the module checks which one you passed. Without a policy the public-read ACL also publishes the file list, which file_list_is_public reports.
scaleway-transactional-email
A Scaleway Transactional Email domain with the SPF, DKIM, DMARC and MX records it needs exported (and written automatically when the domain is in Scaleway DNS), the terms of service accepted by name, and a validation step that polls until the records resolve so an apply fails rather than pretends when they are not published yet.
scaleway-vpc
A Private Network created without a subnet gets a /22 the platform picked, the one most likely to collide with the office or the next network; VPC routing forwards between every Private Network, and the ACL that filters that traffic does not exist until you create it. Subnets required per network, a named VPC rather than the project default, and a drop-by-default ACL from the rules you give.
scaleway-cdn
Edge Services is a chain of stages, each naming the one it forwards to, and every stage is content to exist naming nothing: a half-wired pipeline shows a name and a status in the console and answers no requests. This builds the whole chain, subscribes the plan without which nothing serves, and puts a certificate and your own domain in front of a bucket.
scaleway-iam-application
A Scaleway IAM application, the non-human identity a workload authenticates as, with a policy of rules granting permission sets in the projects you name (organisation scope and the full-access sets by name) and an API key that expires at a time you set (no expiry by name), whose secret is a sensitive output.
scaleway-queue
A Messaging and Queuing SQS queue with a dead-letter queue that receives a message after five failed receives, long polling so an idle consumer costs nothing, and two credentials: one that can manage, held by Terraform to create the queues, and one that can only publish and receive, exported for the application so it never holds a key that can delete queues.
scaleway-cockpit
Scaleway Cockpit custom metrics and logs sources with retention set to a month rather than defaulted, and the alert manager enabled with the contact addresses you name (none by name) and the preconfigured alerts you choose, because an alert with no contact point reaches nobody. Retention is the storage half of the bill.
ansible-scaleway-cli
scw on EL 10 from the GitHub release, a bare binary refused by Ansible's get_url unless its SHA-256 is the one in Scaleway's SHA256SUMS, re-checked by the live test. The CLI sends usage telemetry unless told not to: the role exports SCW_SEND_TELEMETRY=false for every login shell. Pinned; an API call without credentials stops at the credentials. Original role, live-tested on Rocky Linux 10.
scaleway-kapsule-cluster
Kapsule Kubernetes with pools, private network, and autoscaling/autoheal presets.
scaleway-rdb-instance
RDB PostgreSQL/MySQL with HA, private-network endpoint, users, and ACLs.
scaleway-serverless-container
Container namespace, deployed container, custom domain, and registry wiring.
scaleway-secret-manager
protected defaults to false, so one API call deletes a secret and every version; an ephemeral policy that expires a version is the rotation deadline most teams do not have; and a value from a Terraform variable lands in state as well as the manager. Protection on and off by name, a ttl per secret, values optional so first versions can come from a pipeline, and the secrets terraform wrote named.
Compare across clouds
All solutions →See how the services Scaleway covers here compare on other providers.