UpCloud Infrastructure-as-Code modules
12 verified ansible / terraform modules for UpCloud, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 12 UpCloud modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 11 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All UpCloud modules
upcloud-load-balancer
The backend health check defaults to TCP, which a process that stopped serving still passes; TLS is a certificate bundle nobody creates; a port-80 frontend forwards unless a rule redirects it; and a public network puts the frontend on the internet. HTTP checks on a path (TCP by name), a Let's Encrypt bundle for the hostnames you list, a 301 from 80 whenever it exists, and public by name.
upcloud-kubernetes
An UpCloud Managed Kubernetes cluster whose API answers only the ranges you list (0.0.0.0/0 by name), with private node groups off the public internet, node storage encrypted at rest (unencrypted by name), anti-affinity across hosts, manual upgrades, and node groups from a map with labels and taints. The plan is the control plane's redundancy and bill.
upcloud-valkey
An UpCloud Managed Valkey service attached to your SDN private network with public access off (on by name) and an IP filter of the ranges that may connect, TLS on, RDB persistence with a nightly backup, an eviction policy set, service logs on, a maintenance window you chose, and termination protection (off by name). The password is generated and the URI is a sensitive output.
upcloud-network
A private network on a public range is the surprise at the first NAT, and dhcp_default_route defaults to false, so servers get an address and no route, right for an isolated segment and wrong for one behind a router. An RFC 1918 range required, DHCP handing out the resolvers you chose, a router created and the default route set when you ask, and an output that says the network filters nothing.
upcloud-firewall
The firewall is a per-server rule list evaluated top to bottom, attached by definition but only applied while the server's firewall flag is on; the last rule decides; and SSH from 0.0.0.0/0 is the first rule offered. Your accepts in order with a drop of everything else appended, SSH from anywhere refused unless accepted, egress open until rules narrow it.
upcloud-storage
encrypt defaults to false and cannot change after creation; and the backup rule is the rare schedule that lives on the device itself, so it cannot be forgotten separately but can still be left out. Encryption on, a daily backup at 02:00 UTC kept 30 days unless told otherwise (none by name), filesystem resize opt-in, and the device attached from the server side in its zone.
upcloud-nat-gateway
An UpCloud network gateway with the NAT feature attached to a router, so every private network on that router gets a way out; the router (upcloud-network creates one) is the input. The gateway is zonal and starts with the apply; the plan (advanced or production) is the throughput ceiling and the hourly bill from creation.
upcloud-storage-template
An UpCloud storage template made from a server's storage, which is UpCloud's custom image, labelled by role and build (unlabelled has to be accepted by name). The template lives in the zone of its source and is the storage at that moment, secrets and all: build the source clean and stop the server first.
upcloud-object-storage
A service answers on the networks attached to it, and a public network makes the S3 endpoint an internet endpoint; a user has no access until a policy is attached and no key until one is created; and the service has no versioning and no lifecycle. Private by default with public by name, buckets, a user with the policy you name and one key, and outputs that say what is not available.
ansible-upcloud-cli
upctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in UpCloud's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without credentials stops at 'user credentials not found'. Original role, live-tested on Rocky Linux 10.
upcloud-managed-database
Managed PG/MySQL with properties tuning, users, and logical DBs.
upcloud-server-stack
Servers on SDN private network with storage, router, and firewall rules.
Compare across clouds
All solutions →See how the services UpCloud covers here compare on other providers.