Scaleway Infrastructure-as-Code modules

23 verified ansible / terraform modules for Scaleway, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 23 Scaleway modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 22 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Scaleway modules

Static validatedLive test pending

scaleway-block-volume

iops is required, is the price per GB, and cannot change after creation; snapshots exist as a resource you take and nothing on the platform schedules one; the volume is zonal and attaches from the server side. The tier validated to the two that exist, a baseline snapshot when asked, and an output that says no schedule exists.

View module
Static validatedLive test pending

scaleway-object-bucket

Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.

View module
Static validatedLive test pending

scaleway-load-balancer

A Scaleway Load Balancer on a flexible IP with a Let's Encrypt certificate it issues itself (so the DNS must point at it first), TLS at the modern compatibility level (older clients by name), HTTP/3, the port 80 frontend answering only a 301 to HTTPS, and backends named by their Private Network address and probed over HTTP on a path you chose.

View module
Static validatedLive test pending

scaleway-container-registry

is_public makes every image in the namespace pullable by anyone, and the key CI pushes with is usually a person's API key with every permission that person has and no expiry. Private unless public is accepted by name, and on request an IAM application whose only permission is registry access in one project, with an API key that expires on the date you set.

View module
Static validatedLive test pending

scaleway-image

A Scaleway instance image built from a snapshot the module takes of the root volume you name, private (public lists it for every Scaleway account and has to be accepted by name), for x86_64 or arm64, in one zone. Stop the server first so the file system is consistent.

View module
Static validatedLive test pending

scaleway-public-gateway

A Scaleway Public Gateway on a reserved address, attached to a Private Network with masquerade and the default route pushed to the hosts, since a gateway with no gateway network forwards nothing. The bastion (SSH into the network through the gateway) is off and accepted by name; outbound SMTP is off so a compromised host cannot send mail under your name.

View module
Static validatedLive test pending

scaleway-redis

A Scaleway Managed Database for Redis cluster attached to your Private Network with no public endpoint (one by name), TLS required (plaintext by name), a password from a secret store never output, an ACL of the ranges that may connect (required), an eviction policy set, and three nodes so the data has three copies (fewer by name).

View module
Static validatedLive test pending

scaleway-dns-zone

A Scaleway DNS zone (the root zone of the domain unless a subdomain is named) with every record in one map and the nameservers Scaleway assigns exported for the registrar. Geo-routed, weighted and health-checked records are kept out so a plain zone stays plain; a domain registered with Scaleway is delegated already.

View module
Static validatedLive test pending

scaleway-instance

A Scaleway instance on a Private Network with a required security group (the project default allows everything inbound), no public address unless a flexible IP is accepted by name, the project's SSH keys and no password, a Block Storage root volume deleted with the instance, cloud-init, and protection from deletion (off by name).

View module
Static validatedLive test pending

scaleway-security-group

The default inbound policy is accept, so a group with no rules admits every packet on every port and your rules are exceptions to accept-all; SSH from everywhere is the first rule offered; and the group filters the public interface only. Drop by default, SSH from a /0 refused unless accepted, the SMTP block kept unless a relay says otherwise, and outputs that say the Private Network is unfiltered.

View module
Static validatedLive test pending

scaleway-function

A Scaleway Serverless Function in its own namespace, private so an IAM token is needed to invoke it (public by name), plain HTTP redirected to HTTPS, secrets in the encrypted secret variables rather than the plain ones, idling at zero instances with a ceiling you chose, and the zip archive uploaded at apply with its hash so a changed archive redeploys.

View module
Static validatedLive test pending

scaleway-static-site

A Scaleway Object Storage bucket serving a static website. A bucket policy here is version 2023-04-17, not the AWS 2012-10-17 that every S3 example carries and Scaleway has deprecated, and the module checks which one you passed. Without a policy the public-read ACL also publishes the file list, which file_list_is_public reports.

View module
Static validatedLive test pending

scaleway-transactional-email

A Scaleway Transactional Email domain with the SPF, DKIM, DMARC and MX records it needs exported (and written automatically when the domain is in Scaleway DNS), the terms of service accepted by name, and a validation step that polls until the records resolve so an apply fails rather than pretends when they are not published yet.

View module
Static validatedLive test pending

scaleway-vpc

A Private Network created without a subnet gets a /22 the platform picked, the one most likely to collide with the office or the next network; VPC routing forwards between every Private Network, and the ACL that filters that traffic does not exist until you create it. Subnets required per network, a named VPC rather than the project default, and a drop-by-default ACL from the rules you give.

View module
Static validatedLive test pending

scaleway-cdn

Edge Services is a chain of stages, each naming the one it forwards to, and every stage is content to exist naming nothing: a half-wired pipeline shows a name and a status in the console and answers no requests. This builds the whole chain, subscribes the plan without which nothing serves, and puts a certificate and your own domain in front of a bucket.

View module
Static validatedLive test pending

scaleway-iam-application

A Scaleway IAM application, the non-human identity a workload authenticates as, with a policy of rules granting permission sets in the projects you name (organisation scope and the full-access sets by name) and an API key that expires at a time you set (no expiry by name), whose secret is a sensitive output.

View module
Static validatedLive test pending

scaleway-queue

A Messaging and Queuing SQS queue with a dead-letter queue that receives a message after five failed receives, long polling so an idle consumer costs nothing, and two credentials: one that can manage, held by Terraform to create the queues, and one that can only publish and receive, exported for the application so it never holds a key that can delete queues.

View module
Static validatedLive test pending

scaleway-cockpit

Scaleway Cockpit custom metrics and logs sources with retention set to a month rather than defaulted, and the alert manager enabled with the contact addresses you name (none by name) and the preconfigured alerts you choose, because an alert with no contact point reaches nobody. Retention is the storage half of the bill.

View module
Live-tested

ansible-scaleway-cli

scw on EL 10 from the GitHub release, a bare binary refused by Ansible's get_url unless its SHA-256 is the one in Scaleway's SHA256SUMS, re-checked by the live test. The CLI sends usage telemetry unless told not to: the role exports SCW_SEND_TELEMETRY=false for every login shell. Pinned; an API call without credentials stops at the credentials. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

scaleway-kapsule-cluster

Kapsule Kubernetes with pools, private network, and autoscaling/autoheal presets.

View module
Static validatedLive test pending

scaleway-rdb-instance

RDB PostgreSQL/MySQL with HA, private-network endpoint, users, and ACLs.

View module
Static validatedLive test pending

scaleway-serverless-container

Container namespace, deployed container, custom domain, and registry wiring.

View module
Static validatedLive test pending

scaleway-secret-manager

protected defaults to false, so one API call deletes a secret and every version; an ephemeral policy that expires a version is the rotation deadline most teams do not have; and a value from a Terraform variable lands in state as well as the manager. Protection on and off by name, a ttl per secret, values optional so first versions can come from a pipeline, and the secrets terraform wrote named.

View module

Compare across clouds

All solutions →

See how the services Scaleway covers here compare on other providers.

Other providers