UpCloud Infrastructure-as-Code modules

12 verified ansible / terraform modules for UpCloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 12 UpCloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 11 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All UpCloud modules

Static validatedLive test pending

upcloud-load-balancer

The backend health check defaults to TCP, which a process that stopped serving still passes; TLS is a certificate bundle nobody creates; a port-80 frontend forwards unless a rule redirects it; and a public network puts the frontend on the internet. HTTP checks on a path (TCP by name), a Let's Encrypt bundle for the hostnames you list, a 301 from 80 whenever it exists, and public by name.

View module
Static validatedLive test pending

upcloud-kubernetes

An UpCloud Managed Kubernetes cluster whose API answers only the ranges you list (0.0.0.0/0 by name), with private node groups off the public internet, node storage encrypted at rest (unencrypted by name), anti-affinity across hosts, manual upgrades, and node groups from a map with labels and taints. The plan is the control plane's redundancy and bill.

View module
Static validatedLive test pending

upcloud-valkey

An UpCloud Managed Valkey service attached to your SDN private network with public access off (on by name) and an IP filter of the ranges that may connect, TLS on, RDB persistence with a nightly backup, an eviction policy set, service logs on, a maintenance window you chose, and termination protection (off by name). The password is generated and the URI is a sensitive output.

View module
Static validatedLive test pending

upcloud-network

A private network on a public range is the surprise at the first NAT, and dhcp_default_route defaults to false, so servers get an address and no route, right for an isolated segment and wrong for one behind a router. An RFC 1918 range required, DHCP handing out the resolvers you chose, a router created and the default route set when you ask, and an output that says the network filters nothing.

View module
Static validatedLive test pending

upcloud-firewall

The firewall is a per-server rule list evaluated top to bottom, attached by definition but only applied while the server's firewall flag is on; the last rule decides; and SSH from 0.0.0.0/0 is the first rule offered. Your accepts in order with a drop of everything else appended, SSH from anywhere refused unless accepted, egress open until rules narrow it.

View module
Static validatedLive test pending

upcloud-storage

encrypt defaults to false and cannot change after creation; and the backup rule is the rare schedule that lives on the device itself, so it cannot be forgotten separately but can still be left out. Encryption on, a daily backup at 02:00 UTC kept 30 days unless told otherwise (none by name), filesystem resize opt-in, and the device attached from the server side in its zone.

View module
Static validatedLive test pending

upcloud-nat-gateway

An UpCloud network gateway with the NAT feature attached to a router, so every private network on that router gets a way out; the router (upcloud-network creates one) is the input. The gateway is zonal and starts with the apply; the plan (advanced or production) is the throughput ceiling and the hourly bill from creation.

View module
Static validatedLive test pending

upcloud-storage-template

An UpCloud storage template made from a server's storage, which is UpCloud's custom image, labelled by role and build (unlabelled has to be accepted by name). The template lives in the zone of its source and is the storage at that moment, secrets and all: build the source clean and stop the server first.

View module
Static validatedLive test pending

upcloud-object-storage

A service answers on the networks attached to it, and a public network makes the S3 endpoint an internet endpoint; a user has no access until a policy is attached and no key until one is created; and the service has no versioning and no lifecycle. Private by default with public by name, buckets, a user with the policy you name and one key, and outputs that say what is not available.

View module
Live-tested

ansible-upcloud-cli

upctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in UpCloud's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without credentials stops at 'user credentials not found'. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

upcloud-managed-database

Managed PG/MySQL with properties tuning, users, and logical DBs.

View module
Static validatedLive test pending

upcloud-server-stack

Servers on SDN private network with storage, router, and firewall rules.

View module

Compare across clouds

All solutions →

See how the services UpCloud covers here compare on other providers.

Other providers