Plan it. Lock it. Apply it.
Multi-cloud Terraform with the boring-but-critical parts done for you: S3 + DynamoDB lock state with KMS-CMK encryption, Vault dynamic secrets resolved per apply, OPA / Sentinel policy gates, drift detection, and audited state ops — driven from the dashboard orvxcli terraform.
One workflow · the providers and backends you already trust
State management · pick your backend
State on S3, GCS, Azure Blob, Postgres, Vault, or Consul
Encrypted at rest with your CMK, locked by default, audited on every read and write. Click a backend to see the exact config and what you get for free.
terraform {
backend "s3" {
bucket = "tf-state-prod"
key = "api/terraform.tfstate"
region = "us-east-1"
encrypt = true
kms_key_id = "alias/tf-state-cmk"
dynamodb_table = "tf-state-locks"
workspace_key_prefix = "ws"
}
}- Versioning + lifecycle for time-travel rollbacks
- KMS-CMK encryption at rest, TLS 1.3 in transit
- DynamoDB table for state locking — no concurrent applies
- IAM-scoped access per workspace and per environment
Vault · zero long-lived secrets
Dynamic credentials, resolved per apply, revoked on completion
No more AWS_ACCESS_KEY in CI variables. No more shared Postgres passwords in terraform.tfvars. Vault mints fresh credentials for each apply, leases them for an hour or four, and revokes them when the run ends — even if it crashes.
- AWS / Azure / GCP IAM creds with provider-scoped roles
- Postgres / MySQL / Mongo dynamic users with deterministic privileges
- PKI certificates auto-renewed before expiry — no cert outages
- KV v2 fallback for static secrets that must rotate on schedule
Sample code · copy-paste ready
The four files every production Terraform repo needs
A real multi-cloud apply has a main.tf, a hardenedbackend.tf, a Vault-driven vault.tf, and a vxcli wrapper that ties it together with policy and audit. Tabs below show all four — pulled from real production templates.
- OPA / Sentinel policies enforced before plan reaches apply
- State diffs rendered in PR comments — readable, not raw HCL
- Drift detection on a schedule per workspace, paged on regression
- Pipeline export to GitHub Actions, GitLab, Jenkins — same plan
1# Multi-provider Terraform — same workflow, every cloud.2terraform {3 required_version = ">= 1.7"4 required_providers {5 aws = { source = "hashicorp/aws", version = "~> 5.0" }6 azurerm = { source = "hashicorp/azurerm", version = "~> 3.0" }7 google = { source = "hashicorp/google", version = "~> 5.0" }8 kubernetes = { source = "hashicorp/kubernetes", version = "~> 2.0" }9 vault = { source = "hashicorp/vault", version = "~> 4.0" }10 vxcloud = { source = "prodxcloud/vxcloud", version = "~> 1.0" }11 }12}13 14# Pull AWS creds dynamically from Vault (1h lease, auto-revoked).15data "vault_aws_access_credentials" "deploy" {16 backend = "aws"17 role = "tf-deploy"18 type = "iam_user"19}20 21provider "aws" {22 region = "us-east-1"23 access_key = data.vault_aws_access_credentials.deploy.access_key24 secret_key = data.vault_aws_access_credentials.deploy.secret_key25}26 27# A real workload across two clouds.28module "vpc" {29 source = "terraform-aws-modules/vpc/aws"30 version = "~> 5.5"31 name = "studio-prod-vpc"32 cidr = "10.0.0.0/16"33}34 35resource "vxcloud_vm" "api" {36 name = "studio-api"37 cloud = "aws"38 region = "us-east-1"39 type = "g3.medium"40 count = 341 vpc_id = module.vpc.vpc_id42}Generate Terraform from a goal
vxcli terraform new "EKS cluster + RDS Postgres in 2 AZs" — emits main.tf, backend.tf, vault.tf wired to your defaults.
Module registry
Battle-tested modules, mirrored and signed
The most-pulled community modules, mirrored into your workspace registry with cosign signatures and CVE scans. Plus your private modules, same UX.
Production-grade VPC with public/private subnets, NAT, flow logs.
Managed EKS cluster with autoscaling node groups and IRSA roles.
AKS with Azure CNI, AAD integration, virtual node pools.
Hardened GKE cluster, Workload Identity, private nodes.
Reusable Vault policies, AppRole, JWT auth — drop-in for new orgs.
Opinionated Helm release wrapper with versioning and hooks.
Production-grade IaC
Everything a Terraform platform should ship with
Locked, encrypted state
Backend choice of S3 / GCS / Azure Blob / Postgres / Vault / Consul — encryption + locking on by default.
Vault dynamic secrets
Provider creds, DB users, PKI certs minted per apply with short TTLs. Nothing long-lived in CI.
Policy as code (OPA / Sentinel)
Block bad plans before they reach apply: tag policies, blast-radius limits, regional pinning, cost caps.
PR plan diffs
Plan output rendered as a readable diff in your PR — added, changed, destroyed, with cost delta.
Drift detection
Scheduled drift checks per workspace; paged when reality diverges from state. One-click reconcile.
Time-travel state
Versioned state on the backend. Roll back to any prior version with audit trail and approval gate.
100+ providers
Every major cloud, plus Kubernetes, Vault, Consul, Cloudflare, Datadog, Snowflake, Stripe, Slack — wired.
Pipeline export
Generate GitHub Actions / GitLab CI / Jenkinsfile that runs the same plan, with the same policies.
Audited state ops
state mv, state rm, state import, lock release — every command logged with actor and reason.
Real workloads, measured
Numbers from production Terraform — not dev demos
30 days of customer applies across S3, GCS, Azure Blob, Postgres, and Vault backends. Median for resource counts between 50 and 800.
Where this earns its keep
From single-account startups to multi-org platform teams
Greenfield platform setup
Bootstrap VPC, K8s cluster, RDS, Vault, ingress, observability — one workspace, one apply, signed modules.
Lift-and-shift to multi-cloud
Move from one cloud to two without rewriting modules. Same HCL, swap provider blocks, roll workspace by workspace.
Sovereign / regulated estates
Vault state backend, policy gates, signed modules, scoped audit logs — meets SOC 2, PCI, HIPAA scopes.
Internal developer platform
Wrap Terraform in self-service templates: app teams pick a stack, fill 3 vars, get a production environment.
GPU + AI infra at scale
Spin up GPU node pools, autoscalers, model registries, and Vault-backed AI provider creds — all from HCL.
FinOps + drift control
Cost-aware policy: block plans that exceed budget. Schedule drift detection so reality matches HCL.
Terraform with state, secrets, and policy already wired up.
Open a workspace, point it at S3 (or any backend), connect Vault, and run your firstvxcli terraform applywith audit, locking, and dynamic secrets on by default.