VxCloud
Terraform · IaC done right

Plan it. Lock it. Apply it.

Multi-cloud Terraform with the boring-but-critical parts done for you: S3 + DynamoDB lock state with KMS-CMK encryption, Vault dynamic secrets resolved per apply, OPA / Sentinel policy gates, drift detection, and audited state ops — driven from the dashboard orvxcli terraform.

0+
providers supported
0 backends
state stores
0h TTL
avg dynamic-cred lease
vxcli terraform apply · prod-api · liveAPPLYING
→Initializing backend (s3 · dynamodb lock · kms)…184ms
✓Backend ready · s3://tf-state-prod/api/terraform.tfstate12ms
backend: s3 · lock: dynamodb · secrets: vault
prod-eu · workspace: api

One workflow · the providers and backends you already trust

HashiCorp
AWS
Azure
GCP
Alibaba Cloud
Linode
Hetzner
OVHcloud
Kubernetes
HashiCorp Vault

State management · pick your backend

State on S3, GCS, Azure Blob, Postgres, Vault, or Consul

Encrypted at rest with your CMK, locked by default, audited on every read and write. Click a backend to see the exact config and what you get for free.

backend.tf · AWS S3encrypted · locked
terraform {
  backend "s3" {
    bucket         = "tf-state-prod"
    key            = "api/terraform.tfstate"
    region         = "us-east-1"
    encrypt        = true
    kms_key_id     = "alias/tf-state-cmk"
    dynamodb_table = "tf-state-locks"
    workspace_key_prefix = "ws"
  }
}
  • Versioning + lifecycle for time-travel rollbacks
  • KMS-CMK encryption at rest, TLS 1.3 in transit
  • DynamoDB table for state locking — no concurrent applies
  • IAM-scoped access per workspace and per environment

Vault · zero long-lived secrets

Dynamic credentials, resolved per apply, revoked on completion

No more AWS_ACCESS_KEY in CI variables. No more shared Postgres passwords in terraform.tfvars. Vault mints fresh credentials for each apply, leases them for an hour or four, and revokes them when the run ends — even if it crashes.

  • AWS / Azure / GCP IAM creds with provider-scoped roles
  • Postgres / MySQL / Mongo dynamic users with deterministic privileges
  • PKI certificates auto-renewed before expiry — no cert outages
  • KV v2 fallback for static secrets that must rotate on schedule
Pairs with the Vault state-encryption backend on the previous tab — same Vault, same audit log.
vault read · dynamic leasesROTATING
awsIAM access key + secret · ec2:*, s3:RW
AKIAJ7CWN…
ttl 1h
databasePostgres role · readwrite on app schema
tf_a3f2bc9d_user
ttl 4h
auto-rotated · revoked on apply complete
vault.prodxcloud.com

Sample code · copy-paste ready

The four files every production Terraform repo needs

A real multi-cloud apply has a main.tf, a hardenedbackend.tf, a Vault-driven vault.tf, and a vxcli wrapper that ties it together with policy and audit. Tabs below show all four — pulled from real production templates.

  • OPA / Sentinel policies enforced before plan reaches apply
  • State diffs rendered in PR comments — readable, not raw HCL
  • Drift detection on a schedule per workspace, paged on regression
  • Pipeline export to GitHub Actions, GitLab, Jenkins — same plan
1# Multi-provider Terraform — same workflow, every cloud.
2terraform {
3 required_version = ">= 1.7"
4 required_providers {
5 aws = { source = "hashicorp/aws", version = "~> 5.0" }
6 azurerm = { source = "hashicorp/azurerm", version = "~> 3.0" }
7 google = { source = "hashicorp/google", version = "~> 5.0" }
8 kubernetes = { source = "hashicorp/kubernetes", version = "~> 2.0" }
9 vault = { source = "hashicorp/vault", version = "~> 4.0" }
10 vxcloud = { source = "prodxcloud/vxcloud", version = "~> 1.0" }
11 }
12}
13
14# Pull AWS creds dynamically from Vault (1h lease, auto-revoked).
15data "vault_aws_access_credentials" "deploy" {
16 backend = "aws"
17 role = "tf-deploy"
18 type = "iam_user"
19}
20
21provider "aws" {
22 region = "us-east-1"
23 access_key = data.vault_aws_access_credentials.deploy.access_key
24 secret_key = data.vault_aws_access_credentials.deploy.secret_key
25}
26
27# A real workload across two clouds.
28module "vpc" {
29 source = "terraform-aws-modules/vpc/aws"
30 version = "~> 5.5"
31 name = "studio-prod-vpc"
32 cidr = "10.0.0.0/16"
33}
34
35resource "vxcloud_vm" "api" {
36 name = "studio-api"
37 cloud = "aws"
38 region = "us-east-1"
39 type = "g3.medium"
40 count = 3
41 vpc_id = module.vpc.vpc_id
42}
✨

Generate Terraform from a goal

vxcli terraform new "EKS cluster + RDS Postgres in 2 AZs" — emits main.tf, backend.tf, vault.tf wired to your defaults.

terraform · v1.7+ · prod
main · backend · vault · vxcli

Module registry

Battle-tested modules, mirrored and signed

The most-pulled community modules, mirrored into your workspace registry with cosign signatures and CVE scans. Plus your private modules, same UX.

terraform-aws-vpc
v5.5.0
4.2M

Production-grade VPC with public/private subnets, NAT, flow logs.

cosign signed · 0 CVEsuse module
terraform-aws-eks
v20.8.0
1.8M

Managed EKS cluster with autoscaling node groups and IRSA roles.

cosign signed · 0 CVEsuse module
terraform-azurerm-aks
v9.1.0
912k

AKS with Azure CNI, AAD integration, virtual node pools.

cosign signed · 0 CVEsuse module
terraform-google-gke
v31.0.0
741k

Hardened GKE cluster, Workload Identity, private nodes.

cosign signed · 0 CVEsuse module
terraform-vault-policies
v3.2.1
320k

Reusable Vault policies, AppRole, JWT auth — drop-in for new orgs.

cosign signed · 0 CVEsuse module
terraform-kubernetes-helm
v2.4.0
610k

Opinionated Helm release wrapper with versioning and hooks.

cosign signed · 0 CVEsuse module

Production-grade IaC

Everything a Terraform platform should ship with

Locked, encrypted state

Backend choice of S3 / GCS / Azure Blob / Postgres / Vault / Consul — encryption + locking on by default.

Vault dynamic secrets

Provider creds, DB users, PKI certs minted per apply with short TTLs. Nothing long-lived in CI.

Policy as code (OPA / Sentinel)

Block bad plans before they reach apply: tag policies, blast-radius limits, regional pinning, cost caps.

PR plan diffs

Plan output rendered as a readable diff in your PR — added, changed, destroyed, with cost delta.

Drift detection

Scheduled drift checks per workspace; paged when reality diverges from state. One-click reconcile.

Time-travel state

Versioned state on the backend. Roll back to any prior version with audit trail and approval gate.

100+ providers

Every major cloud, plus Kubernetes, Vault, Consul, Cloudflare, Datadog, Snowflake, Stripe, Slack — wired.

Pipeline export

Generate GitHub Actions / GitLab CI / Jenkinsfile that runs the same plan, with the same policies.

Audited state ops

state mv, state rm, state import, lock release — every command logged with actor and reason.

Real workloads, measured

Numbers from production Terraform — not dev demos

30 days of customer applies across S3, GCS, Azure Blob, Postgres, and Vault backends. Median for resource counts between 50 and 800.

State lock acquired in < 250 ms p95
Vault dynamic creds revoked on every successful apply
State lock acquire p5084ms
Plan time p50 (200 res.)18s
Apply time p50184s
Policy gate latency240ms
Drift detection coverage100%

Where this earns its keep

From single-account startups to multi-org platform teams

Greenfield platform setup

Bootstrap VPC, K8s cluster, RDS, Vault, ingress, observability — one workspace, one apply, signed modules.

Lift-and-shift to multi-cloud

Move from one cloud to two without rewriting modules. Same HCL, swap provider blocks, roll workspace by workspace.

Sovereign / regulated estates

Vault state backend, policy gates, signed modules, scoped audit logs — meets SOC 2, PCI, HIPAA scopes.

Internal developer platform

Wrap Terraform in self-service templates: app teams pick a stack, fill 3 vars, get a production environment.

GPU + AI infra at scale

Spin up GPU node pools, autoscalers, model registries, and Vault-backed AI provider creds — all from HCL.

FinOps + drift control

Cost-aware policy: block plans that exceed budget. Schedule drift detection so reality matches HCL.

Connect a backend · ship an apply · all in under 10 minutes.

Terraform with state, secrets, and policy already wired up.

Open a workspace, point it at S3 (or any backend), connect Vault, and run your firstvxcli terraform applywith audit, locking, and dynamic secrets on by default.