Vultr Infrastructure-as-Code modules
12 verified ansible / terraform modules for Vultr, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 12 Vultr modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 11 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Vultr modules
vultr-firewall
A firewall group filters inbound on the public interface only: outbound is always open and the VPC interface is never filtered. It is attached by the instance, so the group cannot see whether any uses it, and SSH from a /0 is the first rule offered. Named sources or Cloudflare's edge, SSH from anywhere refused unless accepted, and outputs that say attachment is not proven and outbound is open.
vultr-load-balancer
The default health check is TCP on the backend port, which a process that stopped serving still passes; ssl_redirect defaults to false, so the site stays in clear on 80; and a balancer with no instances is a public address that fails. HTTP checks on a path, redirect on whenever HTTPS exists, backends required, and a Let's Encrypt certificate from auto_ssl_domain rather than a pasted key in state.
vultr-database
A managed database gets a public hostname and trusted_ips is optional: left empty, any address on the internet may try the password; the backup hour is picked for you; and a plan with no replicas is one node whose failure is downtime. Trusted ranges required (a /0 refused unless accepted), a VPC attachment, one standby by default, both windows set, and the password as a sensitive output.
vultr-container-registry
A Vultr container registry that is private (public, which lets anyone pull every image, is accepted by name), on the plan you chose (start_up is free and small; the paid plans bill monthly from creation), in the region your clusters are in. The root user Vultr creates is not output; a robot user per cluster is the credential to hand out.
vultr-vpc
v4_subnet is optional, so a VPC created without it gets whatever range was free, the one most likely to collide with the office network or next year's VPN; and a VPC is a range, not a network - instances on it reach each other on every port and firewall groups do not filter the VPC interface. The range required, and outputs that say nothing inside is filtered and nothing peers across regions.
vultr-dns-zone
A Vultr DNS zone with every record in one map, DNSSEC on (the DS record still has to go to the registrar), and the nameservers exported because the zone answers nothing until the registrar delegates to them. The apex A record Vultr offers to write at creation is not used, so nothing exists outside the map.
vultr-snapshot
A Vultr snapshot of an instance, which is Vultr's custom image: global, deployable in any region, billed per gigabyte stored. The snapshot is the instance at that moment, secrets and all, so build the source clean and stop it first; the description carries the build.
vultr-block-storage
Instance snapshots and automatic backups image the primary disk only, block storage has no snapshot of its own, and an attach without live = true reboots the instance. NVMe or HDD by name, attached live, and two outputs that say the volume is in no snapshot, so whatever consumes the module cannot assume a copy exists.
vultr-object-storage
A subscription is one S3 key pair with full rights over every bucket, written to state; versioning is off by default, so an overwrite is the end of the object; and object lock, once on, is on forever. The cluster looked up by hostname, versioning on for every bucket and off by name, lock per bucket and refused without versioning, and an output that says the keys are not scoped per bucket.
ansible-vultr-cli
vultr-cli on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Vultr's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a key stops at VULTR_API_KEY. Original role, live-tested on Rocky Linux 10.
vultr-compute-stack
Instances with VPC, firewall, block storage, and reserved IP.
vultr-vke-cluster
VKE Kubernetes with node pools, VPC, and firewall in one module.
Compare across clouds
All solutions →See how the services Vultr covers here compare on other providers.