Skip to content

Open Source Modules

Compliance-ready infrastructure blueprints for ISO 27001, NIS2, and KRITIS environments. Each module is tested, documented, and free - MIT licensed, no strings attached.

New to this stack? Start with the Hub & Spoke foundation - the Firewall and other modules are designed to drop into it.

Terraform Module Azure Terraform ISO 27001 NIS2 Private Link

Azure Acmebot - Zero-Trust Edition

Production-ready Let's Encrypt automation for hardened Azure environments. Full Private Link isolation, default-deny firewall rules, and Managed Identity - compliant with ISO 27001, NIS2, and KRITIS out of the box.

Free & Open Source
  • Default-deny network architecture (VNet Integration + Private Link)
  • Private DNS Zones - correct resolution out of the box
  • Entra ID & Managed Identity automation included
  • Full source code - no lock-in, no black box
Terraform Module Start here Azure Terraform Zero-Trust Networking Compliance

Hub & Spoke - Zero-Trust Edition

Zero-Trust NSGs, centralized Private DNS, DINE policy bypass - audit-ready on day one.

Free & Open Source
  • Zero-Trust NSG baseline bound to all Spoke subnets
  • Centralized Private DNS Zones (Blob, SQL, Key Vault, ACR)
  • DINE policy lifecycle bypass - no more broken pipelines
  • Environment-aware naming convention throughout
  • Full source code - no lock-in, no black box
Terraform Module Azure Terraform Firewall Networking Zero-Trust

Azure Firewall - Forced Tunneling Edition

Cycle-error-free Forced Tunneling with KMS & Azure AD bypasses, dynamic IP Groups, and FQDN baseline policies. Drops into any existing Hub & Spoke without breaking Windows VMs or Managed Identities.

Free & Open Source
  • Cycle-error-free resource ordering - deploys first time, every time
  • KMS & Azure AD bypass routes - no broken Windows VMs or auth failures
  • Dynamic for_each subnet binding - scales to any number of Spokes
  • IP Group-based firewall policies - no hardcoded IP addresses
  • FQDN baseline rules for Windows Updates and core Microsoft services
Terraform Module Azure Terraform AI Zero-Trust OpenAI

Azure OpenAI RAG - Zero-Trust Networking

A fully isolated, audit-ready AI infrastructure blueprint. Private Endpoints for both Azure OpenAI and AI Search, automated Private DNS, and RBAC Identity Chaining - no shared keys.

Free & Open Source
  • Private Endpoints for both services - public network access disabled
  • Identity Chaining via Managed Identity + RBAC, zero static keys
  • Automated Private DNS Zone linking for both services
  • ISO 27001 & NIS2 compliant architecture on day one

License

  • MIT licensed - full Terraform source code, no lock-in
  • Use it in your own infrastructure or for client work, freely
  • Questions? david@woitzik.dev

New modules & deep dives

Get notified when new modules drop. No spam, unsubscribe anytime.