Tencent Cloud Infrastructure-as-Code modules

47 verified ansible / terraform modules for Tencent Cloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 47 Tencent Cloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 46 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Tencent Cloud modules

Static validatedLive test pending

tencent-bastion

A Tencent Bastion Host deployment. cidr_block is a range the service claims inside your VPC and an overlap is found by whatever stops working, not by the plan. resource_node is both the bill and the ceiling: registering more assets than you bought fails at registration, months later. time_unit is months and nothing else.

View module
Static validatedLive test pending

tencent-budget

A billing budget with thresholds and a scope. fee_type picks which figure is counted: COST is list price you were never going to pay, CASH ignores everything settled with vouchers and credits and reports you under budget until they run out, REAL_COST is what you pay. A budget stops nothing and stops_spending says so.

View module
Static validatedLive test pending

tencent-cam-role

A CAM role assumable by the services or root accounts you name and nothing else (a wildcard principal is refused), console login off because a role is for workloads, a custom policy written from your statements, the preset policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

View module
Static validatedLive test pending

tencent-cdn

A Tencent Cloud CDN domain in front of your COS bucket or origin hosts, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from SSL Certificate Service, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

View module
Static validatedLive test pending

tencent-cfs-file-system

A Tencent Cloud CFS file system (NFS) in your subnet behind its own access group, whose one rule admits the CIDR you name read-write with root squashed (0.0.0.0/0 has to be accepted by name), on the standard or high-performance tier. CFS encrypts at rest with keys it holds, which the module says rather than hides.

View module
Static validatedLive test pending

tencent-clb

A listener's health check is a switch that, off, sends traffic to every target forever; a port-80 listener forwards unless a redirection resource points it at 443; and delete_protect defaults to false. HTTP health checks on a path through listener rules, a 301 from 80 to 443 whenever a certificate is given, deletion protection on, access logs when a CLS topic is given.

View module
Static validatedLive test pending

tencent-cos-bucket

A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.

View module
Static validatedLive test pending

tencent-image

A Tencent Cloud custom image captured from a CVM instance into an image family, so instances that name the family get the newest image (no family by name). The capture refuses a running instance rather than powering it off, and takes the system disk only unless data disks are named.

View module
Static validatedLive test pending

tencent-cvm-instance

A CVM instance in your subnet with login by key pair and no password, ordered security groups, no public address (one by name), the system disk encrypted with your KMS key (the service key by name), the Cloud Workload Protection and Cloud Monitor agents left on, a CAM role when you name one, and API termination refused. Pay-as-you-go by the hour.

View module
Static validatedLive test pending

tencent-clickhouse

A ClickHouse cluster with high availability on, since without it each shard has one replica and losing a data node is losing its data. A COS cold tier is set, because without one every partition stays on the most expensive storage the cluster has while the cluster reports healthy and the invoice is the only signal. Single-zone and PREPAID both have to be taken by name.

View module
Static validatedLive test pending

tencent-ccn

A Tencent Cloud CCN (pay-as-you-go; prepaid bandwidth by name) with the route tables you name and a VPC attachment per VPC on the current v2 resource, each bound to one table so the default routing domain is never used. Route propagation policies between tables are the next resource to add.

View module
Static validatedLive test pending

tencent-cloud-audit

A CloudAudit tracking set scoped to every resource type, action and event name (narrower by name), compressed and delivered to a COS bucket you own under a prefix. The console keeps ninety days and forgets; the tracking set is what keeps more. Organization tracking collects every member account from the management account.

View module
Static validatedLive test pending

tencent-org-policy

A Tencent Cloud Organization service control policy and its attachments. It refuses a policy attached to nothing, an allow statement read as a grant, and an unasked-for root attachment. Destroying the policy-type switch disables every control policy in the organisation, so the module leaves it alone by default and protects it from destroy when asked to manage it.

View module
Static validatedLive test pending

tencent-customer-identity

A Tencent CIAM user store and its groups. The provider exposes the store and nothing about how a customer signs in: login methods, password rules, MFA and social providers are console-only and invisible to Terraform, which configures_authentication reports. The logo appears on the customer sign-in page, so it must be HTTPS.

View module
Static validatedLive test pending

tencent-dns-zone

A Tencent Cloud DNSPod zone with every record in one map, all on the default resolution line so every resolver gets the same answer, MX priority carried on the record, and the free-grade nameservers exported for the registrar. DNSSEC is not a resource in the provider; dnssec_available says so.

View module
Static validatedLive test pending

tencent-direct-connect

A Direct Connect gateway terminating a dedicated circuit into a VPC or a CCN. Attaching one to a CCN creates the attachment and no routes, so the CCN has no way back to your premises while everything reports healthy; an empty route list on a CCN gateway is refused here. NAT mode rewrites your addresses and has to be chosen rather than inherited.

View module
Static validatedLive test pending

tencent-ssl-certificate

A free domain-validated certificate from Tencent Cloud SSL. DNS_AUTO writes the record for you and silently only works when the domain is on DNSPod, so the module refuses it unless you confirm that. The issued private key is a computed attribute and therefore in state, and the resource finishes before the certificate is issued, so read the status output.

View module
Static validatedLive test pending

tencent-api-gateway

An API Gateway service with net_type INNER rather than OUTER, https rather than the http that stays plaintext to the gateway, and QPS ceilings required - without a limit one caller can spend the whole backend's capacity. auth_type NONE and CORS are both named per API, since either turns an endpoint into an open one.

View module
Static validatedLive test pending

tencent-kms-key

key_rotation_enabled defaults to false, so today's key material encrypts everything for the life of the account; and a key scheduled for deletion is gone after its window with everything encrypted under it, on a service that has no flag to refuse the schedule. Rotation on for symmetric keys, a 30-day window (the maximum), and an output that says no deletion-protection flag exists.

View module
Static validatedLive test pending

tencent-mongodb

A MongoDB instance with TDE storage encryption on, which the API cannot add after creation, three nodes so the set can elect a new primary, and a VPC, subnet and security group all required, because an instance created without them lands in the classic network where nothing can fence it. PREPAID rebuilds the instance, so POSTPAID is the default.

View module
Static validatedLive test pending

tencent-nat-gateway

A standard NAT gateway for an existing Tencent Cloud VPC, with a traffic-billed elastic IP, a bandwidth and concurrency tier of its own, and a default route entry written in every route table listed, because a gateway no table routes to forwards nothing. The elastic IP's cap and the gateway's tier are the two numbers to raise when downloads crawl.

View module
Static validatedLive test pending

tencent-vpc-peering

A peering connection between two VPCs with a route table entry written into every route table you list, on both sides, for every CIDR of the other side, because an Active peering carries nothing until the routes exist. POSTPAID by default: PREPAID buys a bandwidth tier for a term that can be raised and never lowered, so it has to be accepted by name.

View module
Static validatedLive test pending

tencent-privatelink-endpoint

A Tencent Cloud Private Link endpoint to an endpoint service, with a VIP in the subnet you name behind the security groups you name; an endpoint with no security group is reachable from the whole VPC and has to be accepted by name. One subnet per endpoint; a second zone is a second endpoint.

View module
Static validatedLive test pending

tencent-tdmq-queue

A TDMQ for Pulsar cluster and its namespaces. msg_ttl is how long an UNACKNOWLEDGED message lives, not how long consumed ones are kept: too short silently drops work when a consumer is slow, too long turns a stuck consumer into unbounded backlog, and both extremes are refused. Retention is the separate thing that lets a new subscription read history.

View module
Static validatedLive test pending

tencent-security-posture

A CSIP risk scan. Every setting in this API is an integer and 0 means a full scan in one field, a periodic task in another and off in a third, so the module takes words and writes the numbers. A full scan is an active probe of production and weakpass attempts passwords, so both are asked for by name; without configrisk there are no posture findings at all.

View module
Static validatedLive test pending

tencent-secrets-manager

A secret in Tencent Cloud Secrets Manager as the two resources it is: the container with your KMS key (the service key by name) and a recovery window of up to thirty days, and the version that carries the value, a sensitive variable supplied at apply time and never output. A new version label is how the value rotates; immediate deletion is accepted by name.

View module
Static validatedLive test pending

tencent-security-group

Rules are ordered and the first match wins, so an ACCEPT from 0.0.0.0/0 anywhere in the list admits everything from that line down; one rule-set resource replaces the whole list on every apply; and SSH from everywhere is the first rule offered. Your rules in order with an explicit DROP appended, SSH from a /0 refused unless accepted, egress open until rules narrow it.

View module
Static validatedLive test pending

tencent-ses

A Tencent Cloud SES domain, its addresses and its templates. The module exposes the exact DNS records Tencent is waiting for, because that is the thing you need next and it lives outside this Terraform. DKIM is on, since unsigned mail is accepted by the API, filed as spam and reported as sent; and a template is reviewed manually before it works.

View module
Static validatedLive test pending

tencent-scf-function

A Serverless Cloud Function running as the CAM role you name, with public network access off (on by name), in your VPC when a subnet is given, logging every invocation to a CLS logset and topic (none by name), synchronous only, with code fetched from a COS object you uploaded. Memory and timeout are inputs.

View module
Static validatedLive test pending

tencent-backup-policy

A CBS snapshot policy and the disks it runs against, because an unattached policy has a schedule and a retention and protects nothing. The hours are UTC, not your clock. Retention is always set, since a policy without one keeps every snapshot forever, and retained_snapshots_per_disk is the number the storage bill is made of.

View module
Static validatedLive test pending

tencent-static-site

A COS bucket serving a static website. The public-read ACL that makes the objects readable also lets anyone list the bucket, and file_list_is_public says so; pass a bucket policy to publish the objects alone. redirect_all_requests_to on COS is a protocol rather than a hostname, which is why it is not exposed here.

View module
Static validatedLive test pending

tencent-database-migration

A DTS sync job and its configuration, created together, because creating the job alone starts billing a replication instance that replicates nothing - the easiest thing in this product to leave behind. encrypt_conn is on at both ends, retry is set so a transient fault does not end the job, and object mode All has to be taken by name.

View module
Static validatedLive test pending

tencent-tcr

A Tencent Container Registry basic instance (pay-as-you-go; the premium editions are a purchase) with public network access off unless accepted by name and a security policy of allowed ranges when it is on, deletion protection on, versioned storage, and namespaces from a map that are private, scan every pushed image and refuse to pull one at or above the severity you set, with their repositories.

View module
Static validatedLive test pending

tencent-redis

A TencentDB for Redis instance in your VPC with a replica per shard (none by name), a password required rather than no_auth, security groups attached (none by name), no public address, and a recycle window that holds a deleted instance for seven days; force deletion is accepted by name. Pay-as-you-go.

View module
Static validatedLive test pending

tencent-vpn-gateway

A Tencent Cloud VPN gateway (pay-by-hour; prepaid by name) with a customer gateway and one policy-based IPsec connection on IKEv2 negotiating AES-CBC-256, SHA-256 and DH group 14 in both phases. Tencent's own defaults are 3DES, MD5 and group 1; the validations refuse them, IKEv1 is accepted only by name, and dead peer detection restarts a dead tunnel.

View module
Static validatedLive test pending

tencent-waf

A domain on a Tencent Cloud SaaS WAF, rules set to block, with block and allow lists. It reads back the CNAME, the mode the WAF reports and the addresses the WAF forwards from, so the origin can refuse everything else. An allowlist here lets addresses through; it does not make a site private. The client IP is taken from the connection unless you say a proxy sits in front.

View module
Static validatedLive test pending

tencent-emr-cluster

An EMR cluster with need_master_wan set to NOT_NEED, because the API defaults to NEED and that puts the node running YARN's resource manager and the cluster web interfaces on the internet. support_ha is on, since one master is not a failover, and the security group the API leaves optional is required here.

View module
Static validatedLive test pending

tencent-elasticsearch

An Elasticsearch cluster with basic_security_type 2, because 1 is no username and no password at all and anything that can reach the cluster could read and delete every index. The search API, Kibana and Cerebro each have their own public switch and all three are closed; automatic backup to COS is on, and destroy protection with it.

View module
Static validatedLive test pending

tencent-cbs-disk

A snapshot policy and its attachment are separate resources, so a policy in the console with no disks is the usual state; encrypt defaults to false and cannot be changed after creation; and force_delete takes a disk with data on it. Encrypted always with your KMS key or Tencent's, a policy created or yours attached (none by name), attached to the instance you give, never force-deleted.

View module
Static validatedLive test pending

tencent-landing-zone

Tencent organization nodes and members. policy_type takes one value and it is Financial: what a membership grants is numbered billing permissions, not a governance boundary, and is_a_policy_boundary says false. The permissions are taken as words and written as the integers Tencent wants, and the one that moves money is asked about.

View module
Static validatedLive test pending

tencent-monitoring-alarms

Cloud Monitor alarm policies from a map of namespaces and rules, each bound to every instance in its namespace so a new instance is covered the day it exists, firing after three consecutive breaches, and all sending to an alarm notice created here with the sub-users and channels you name. A notice with no recipients has to be accepted by name.

View module
Static validatedLive test pending

tencent-network-firewall

Address templates and edge policies in a declared order, the intrusion prevention mode set to block rather than the observation mode it ships in, and the edge firewall switch turned on for the addresses you name. Writing policies and leaving that switch off produces a complete, correct and entirely inactive rule set, so naming no addresses is refused here.

View module
Static validatedLive test pending

tencent-postgresql

The public endpoint is a switch that puts the instance one password from the internet; SSL is a separate resource nobody creates; a primary with no standby is downtime at the first zone failure; and deletion protection is off. Private unless accepted, SSL config created, a standby zone required unless one node is accepted, daily backups in your window with your retention, deletion protection on.

View module
Live-tested

ansible-tccli

The Tencent Cloud CLI (tccli) pinned in /opt/tccli, a virtual environment apart from the system Python. No package exists; pip into the system Python is the documented install. The live test runs pip check, calls the API with a SecretId that is not one and expects Tencent's AuthFailure.SecretIdNotFound, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

tencent-vpc-foundation

VPC with subnets, route tables, NAT, and security groups across AZs.

View module
Static validatedLive test pending

tencent-tke-cluster

Managed TKE Kubernetes with node pools and VPC-CNI networking.

View module
Static validatedLive test pending

tencent-vpc-flow-logs

Flow logs for a VPC, subnet, interface, CCN, NAT or direct connect gateway written into a CLS logset and topic the module creates with the retention you choose, ALL traffic rather than only what was accepted. A vpc_id is required for every resource type except CCN, and the module refuses the wrong pair rather than letting the API do it at apply time.

View module

Compare across clouds

All solutions →

See how the services Tencent Cloud covers here compare on other providers.

Other providers