A collection of reusable, opinionated Terraform modules for provisioning AWS infrastructure in a consistent, composable way.
This repository provides building blocks for common AWS primitives (networking, compute, storage, security, and observability) so that environments can be created quickly with minimal repetition and strong defaults.
Each module aims to be:
- Composable — small, focused building blocks that can be combined
- Configurable — sane defaults with overrideable inputs
- Secure-by-default — least-privilege IAM, encryption, logging, and tagging
- Documented — clear input/output variables and examples
- Standardize AWS infrastructure across projects and environments
- Reduce copy-paste Terraform code and module drift
- Encourage best practices around IAM, networking, logging, and tagging
- Make it easy to spin up dev/stage/prod with minimal changes
aws-terraform-modules/
├── README.md
├── modules/
│ ├── networking/
│ │ ├── vpc/
│ │ ├── subnet/
│ │ └── vpc_endpoints/
│ ├── security/
│ │ ├── iam_role/
│ │ ├── iam_policy/
│ │ └── security_group/
│ ├── compute/
│ │ ├── ec2/
│ │ ├── asg/
│ │ └── ecs_service/
│ ├── storage/
│ │ ├── s3_bucket/
│ │ ├── rds_instance/
│ │ └── dynamodb_table/
│ ├── observability/
│ │ ├── cloudwatch_log_group/
│ │ └── cloudwatch_alarms/
│ └── networking_baseline/
├── examples/
│ ├── single-vpc/
│ ├── ecs-service/
│ └── static-site-s3-cloudfront/
├── environments/
│ ├── dev/
│ ├── stage/
│ └── prod/
└── terraform.tfvars.exampleAdjust modules and examples to match your actual layout.
- Terraform CLI 1.5+
- AWS account and credentials (IAM user or role)
- Optional:
tflint,tfsec/checkov,pre-commitfor validation
From any example or consumer root module:
cd examples/single-vpc
terraform initInspect variables.tf and terraform.tfvars.example for required inputs such as:
aws_regionprojectenvironment- CIDR ranges and subnet configuration
Create your own terraform.tfvars (or use -var-file):
aws_region = "us-east-1"
project = "my-project"
environment = "dev"
vpc_cidr_block = "10.0.0.0/16"terraform plan -out=tfplan
terraform apply tfplanOr directly:
terraform applymodule "vpc" {
source = "../modules/networking/vpc"
name = "${var.project}-${var.environment}"
cidr_block = var.vpc_cidr_block
az_count = 3
enable_nat_gateways = true
tags = {
Project = var.project
Environment = var.environment
ManagedBy = "terraform"
}
}module "logs_bucket" {
source = "../modules/storage/s3_bucket"
bucket_name = "${var.project}-${var.environment}-logs"
versioning_enabled = true
force_destroy = false
sse_algorithm = "aws:kms"
enable_access_logging = true
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
tags = {
Project = var.project
Environment = var.environment
DataClass = "logs"
}
}- Naming: modules should accept
project,environment, andnameorsuffixinputs for consistent resource naming - Tagging: every resource should support a
tagsmap and merge common tags - Security: default to private subnets, restricted security groups, encrypted storage, and least-privilege IAM policies
- Observability: where applicable, enable CloudWatch logs, metrics, and alarms
- Inputs/Outputs: expose only what callers need (e.g., IDs, ARNs, endpoints)
- Use semantic versioning for this module library (e.g., tags like
v0.1.0) - Consumers should pin module versions using
refor a registry version when publishing
Suggested tools:
terraform fmt -recursive
terraform validate
tflint
tfsec # or: checkovExample pre-commit usage:
pre-commit install
pre-commit run --all-files- Use
terraform planin CI to detect drift and breaking changes - For critical modules, consider Terratest or similar tools for automated tests
The environments/ directory can hold root modules for dev, stage, and prod that compose shared modules with environment-specific values.
Example structure:
environments/dev/
├── main.tf
├── variables.tf
└── terraform.tfvars- Add more AWS service modules (EKS, Lambda, API Gateway, CloudFront, etc.)
- Add opinionated blueprints (e.g., “ECS service behind ALB”, “Serverless API”)
- Publish selected modules to a Terraform registry namespace
- Add CI workflows for format, validate, lint, and security checks
- Add documentation site or module registry docs
Choose a license that fits your intended use, such as MIT, Apache-2.0, or a private internal license.