{"id":19978379,"url":"https://github.com/geekcell/terraform-aws-backup","last_synced_at":"2026-05-13T09:36:35.095Z","repository":{"id":65738051,"uuid":"564347172","full_name":"geekcell/terraform-aws-backup","owner":"geekcell","description":"Terraform module to provision an AWS Backup.","archived":false,"fork":false,"pushed_at":"2023-11-06T10:59:09.000Z","size":40,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-03-01T18:48:51.915Z","etag":null,"topics":["aws","backup","terraform","terraform-module"],"latest_commit_sha":null,"homepage":"https://www.geekcell.io","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/geekcell.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-11-10T14:22:04.000Z","updated_at":"2023-05-11T12:56:54.000Z","dependencies_parsed_at":"2023-11-06T11:33:27.451Z","dependency_job_id":null,"html_url":"https://github.com/geekcell/terraform-aws-backup","commit_stats":null,"previous_names":[],"tags_count":11,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-backup","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-backup/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-backup/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-backup/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/geekcell","download_url":"https://codeload.github.com/geekcell/terraform-aws-backup/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":241411541,"owners_count":19958753,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","backup","terraform","terraform-module"],"created_at":"2024-11-13T03:33:14.116Z","updated_at":"2026-05-13T09:36:35.061Z","avatar_url":"https://github.com/geekcell.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- BEGIN_TF_DOCS --\u003e\n[![Geek Cell GmbH](https://raw.githubusercontent.com/geekcell/.github/main/geekcell-github-banner.png)](https://www.geekcell.io/)\n\n### Code Quality\n[![License](https://img.shields.io/github/license/geekcell/terraform-aws-backup)](https://github.com/geekcell/terraform-aws-backup/blob/master/LICENSE)\n[![GitHub release (latest tag)](https://img.shields.io/github/v/release/geekcell/terraform-aws-backup?logo=github\u0026sort=semver)](https://github.com/geekcell/terraform-aws-backup/releases)\n[![Release](https://github.com/geekcell/terraform-aws-backup/actions/workflows/release.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-backup/actions/workflows/release.yaml)\n[![Validate](https://github.com/geekcell/terraform-aws-backup/actions/workflows/validate.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-backup/actions/workflows/validate.yaml)\n[![Lint](https://github.com/geekcell/terraform-aws-backup/actions/workflows/linter.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-backup/actions/workflows/linter.yaml)\n[![Test](https://github.com/geekcell/terraform-aws-backup/actions/workflows/test.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-backup/actions/workflows/test.yaml)\n\n### Security\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/general)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=INFRASTRUCTURE+SECURITY)\n\n#### Cloud\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_aws)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+AWS+V1.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_aws_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+AWS+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_azure)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+AZURE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_azure_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+AZURE+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_gcp)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+GCP+V1.1)\n\n##### Container\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_kubernetes_16)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+KUBERNETES+V1.6)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_eks_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+EKS+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_gke_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+GKE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/cis_kubernetes)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=CIS+KUBERNETES+V1.5)\n\n#### Data protection\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/soc2)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=SOC2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/pci)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=PCI-DSS+V3.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/pci_dss_v321)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=PCI-DSS+V3.2.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/iso)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=ISO27001)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/nist)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=NIST-800-53)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/hipaa)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=HIPAA)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-backup/fedramp_moderate)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-backup\u0026benchmark=FEDRAMP+%28MODERATE%29)\n\n# Terraform AWS Backup\n\nThis Terraform module provides a preconfigured solution for setting up\nAWS Backup in your AWS account. With this module, you can easily and\nefficiently create and manage backups for your AWS resources. Our\nteam has extensive experience working with AWS Backup and has optimized\nthis module to provide the best possible experience for users.\n\nUsing this Terraform module, you can save time and effort in setting up\nand managing your backup policies, as well as avoid common mistakes and\npitfalls. The module encapsulates all necessary configurations, making\nit easy to use and integrate into your existing AWS environment. Whether\nyou are looking to add backup protection for your critical resources or\nstreamline your existing backup processes, this Terraform module is a\ngreat choice.\n\n## Inputs\n\n| Name | Description | Type | Default | Required |\n|------|-------------|------|---------|:--------:|\n| \u003ca name=\"input_changeable_for_days\"\u003e\u003c/a\u003e [changeable\\_for\\_days](#input\\_changeable\\_for\\_days) | The number of days before the lock date. If omitted creates a vault lock in governance mode, otherwise it will create\u003cbr\u003e  a vault lock in compliance mode. When you apply this setting:\u003cbr\u003e\u003cbr\u003e  The vault will become immutable in 3 days after applying. You have 3 days of grace time to manage or delete the vault\u003cbr\u003e  lock before it becomes immutable. During this time, only those users with specific IAM permissions can make changes.\u003cbr\u003e\u003cbr\u003e  Once the vault is locked in compliance mode, it cannot be managed or deleted by anyone, even the root user or AWS.\u003cbr\u003e  The only way to deactivate the lock is to terminate the account, which will delete all the backups.\u003cbr\u003e\u003cbr\u003e  Since you cannot delete the Vault, it will be charged for backups until that date. Be careful! | `number` | `null` | no |\n| \u003ca name=\"input_create_backup_vault\"\u003e\u003c/a\u003e [create\\_backup\\_vault](#input\\_create\\_backup\\_vault) | Whether to create a backup vault or use a pre-existing one. | `bool` | `true` | no |\n| \u003ca name=\"input_custom_rules\"\u003e\u003c/a\u003e [custom\\_rules](#input\\_custom\\_rules) | Backup rules to add to the AWS Backup Vault. See examples for usage. | \u003cpre\u003elist(object({\u003cbr\u003e    name     = string\u003cbr\u003e    schedule = optional(string)\u003cbr\u003e\u003cbr\u003e    start_window      = optional(number)\u003cbr\u003e    completion_window = optional(number)\u003cbr\u003e\u003cbr\u003e    enable_continuous_backup = optional(bool)\u003cbr\u003e    recovery_point_tags      = optional(map(string), {})\u003cbr\u003e\u003cbr\u003e    lifecycle = optional(object({\u003cbr\u003e      cold_storage_after = optional(number)\u003cbr\u003e      delete_after       = optional(number)\u003cbr\u003e    }))\u003cbr\u003e\u003cbr\u003e    copy_action = optional(object({\u003cbr\u003e      destination_vault_arn = optional(string)\u003cbr\u003e      lifecycle = optional(object({\u003cbr\u003e        cold_storage_after = optional(number)\u003cbr\u003e        delete_after       = optional(number)\u003cbr\u003e      }))\u003cbr\u003e    }))\u003cbr\u003e  }))\u003c/pre\u003e | `[]` | no |\n| \u003ca name=\"input_enable_customer_managed_kms\"\u003e\u003c/a\u003e [enable\\_customer\\_managed\\_kms](#input\\_enable\\_customer\\_managed\\_kms) | Whether to enable customer managed KMS encryption for the backup vault. | `bool` | `false` | no |\n| \u003ca name=\"input_enable_vault_lock\"\u003e\u003c/a\u003e [enable\\_vault\\_lock](#input\\_enable\\_vault\\_lock) | Whether to enable Vault Lock for the backup vault. | `bool` | `false` | no |\n| \u003ca name=\"input_enable_windows_vss_backup\"\u003e\u003c/a\u003e [enable\\_windows\\_vss\\_backup](#input\\_enable\\_windows\\_vss\\_backup) | Whether to enable Windows VSS backup for the backup plan. | `bool` | `false` | no |\n| \u003ca name=\"input_kms_key_id\"\u003e\u003c/a\u003e [kms\\_key\\_id](#input\\_kms\\_key\\_id) | The ARN of the KMS Key to use to encrypt your backups. If left empty, the default AWS KMS will be used. | `string` | `null` | no |\n| \u003ca name=\"input_max_retention_days\"\u003e\u003c/a\u003e [max\\_retention\\_days](#input\\_max\\_retention\\_days) | The maximum retention period that the vault retains its recovery points. | `number` | `365` | no |\n| \u003ca name=\"input_min_retention_days\"\u003e\u003c/a\u003e [min\\_retention\\_days](#input\\_min\\_retention\\_days) | The minimum retention period that the vault retains its recovery points. | `number` | `7` | no |\n| \u003ca name=\"input_plan_name\"\u003e\u003c/a\u003e [plan\\_name](#input\\_plan\\_name) | The display name of the backup plan. | `string` | n/a | yes |\n| \u003ca name=\"input_predefined_rules\"\u003e\u003c/a\u003e [predefined\\_rules](#input\\_predefined\\_rules) | A list of predefined backup rules to add to the AWS Backup Plan. See examples for usage. | `list(string)` | `[]` | no |\n| \u003ca name=\"input_role_arn\"\u003e\u003c/a\u003e [role\\_arn](#input\\_role\\_arn) | The ARN of the IAM role that AWS Backup uses to authenticate when restoring or backing up the target resources. If left empty, a default role will be created. | `string` | `null` | no |\n| \u003ca name=\"input_selections\"\u003e\u003c/a\u003e [selections](#input\\_selections) | An array of strings that either contain Amazon Resource Names (ARNs) or match patterns of resources to assign to a backup plan. | \u003cpre\u003elist(object({\u003cbr\u003e    name     = string\u003cbr\u003e    role_arn = optional(string)\u003cbr\u003e\u003cbr\u003e    arns = optional(list(string))\u003cbr\u003e    tag = optional(object({\u003cbr\u003e      type  = string\u003cbr\u003e      key   = string\u003cbr\u003e      value = string\u003cbr\u003e    }))\u003cbr\u003e  }))\u003c/pre\u003e | `[]` | no |\n| \u003ca name=\"input_tags\"\u003e\u003c/a\u003e [tags](#input\\_tags) | Tags to add to the AWS Backup. | `map(any)` | `{}` | no |\n| \u003ca name=\"input_vault_force_destroy\"\u003e\u003c/a\u003e [vault\\_force\\_destroy](#input\\_vault\\_force\\_destroy) | Whether to allow the backup vault to be destroyed even if it contains recovery points. | `string` | `false` | no |\n| \u003ca name=\"input_vault_name\"\u003e\u003c/a\u003e [vault\\_name](#input\\_vault\\_name) | Name of the backup vault to create or use and existing one. | `string` | n/a | yes |\n\n## Outputs\n\n| Name | Description |\n|------|-------------|\n| \u003ca name=\"output_backup_plan_arn\"\u003e\u003c/a\u003e [backup\\_plan\\_arn](#output\\_backup\\_plan\\_arn) | The ARN of the backup plan. |\n| \u003ca name=\"output_backup_plan_id\"\u003e\u003c/a\u003e [backup\\_plan\\_id](#output\\_backup\\_plan\\_id) | The ID of the backup plan. |\n| \u003ca name=\"output_backup_vault_arn\"\u003e\u003c/a\u003e [backup\\_vault\\_arn](#output\\_backup\\_vault\\_arn) | The ARN of the backup vault. |\n| \u003ca name=\"output_backup_vault_id\"\u003e\u003c/a\u003e [backup\\_vault\\_id](#output\\_backup\\_vault\\_id) | The ID of the backup vault. |\n\n## Providers\n\n| Name | Version |\n|------|---------|\n| \u003ca name=\"provider_aws\"\u003e\u003c/a\u003e [aws](#provider\\_aws) | \u003e= 4.36 |\n\n## Resources\n\n- resource.aws_backup_plan.main (main.tf#53)\n- resource.aws_backup_selection.main (main.tf#113)\n- resource.aws_backup_vault.main (main.tf#33)\n- resource.aws_backup_vault_lock_configuration.main (main.tf#43)\n- data source.aws_backup_vault.main (main.tf#27)\n\n# Examples\n### Basic Example\n```hcl\nmodule \"basic-example\" {\n  source = \"../../\"\n\n  vault_name = \"my-project\"\n  plan_name  = \"customer-data\"\n\n  selections = [\n    {\n      name = \"s3-buckets\"\n      arns = [\"arn:aws:s3:::my-bucket\", \"arn:aws:s3:::my-other-bucket\"]\n    },\n    {\n      name = \"db-snaps\"\n      arns = [\"arn:aws:rds:us-east-2:123456789012:db:my-mysql-instance\"]\n    }\n  ]\n}\n```\n\n### With Rules\n```hcl\nmodule \"with-rules\" {\n  source = \"../../\"\n\n  vault_name = \"my-project\"\n  plan_name  = \"customer-data\"\n\n  predefined_rules = [\"daily-snapshot\", \"monthly-snapshot\"]\n  custom_rules = [\n    {\n      name                     = \"my-custom-rule\"\n      schedule                 = \"cron(0 3 ? * 2,3,4,5,6,7,1 *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = false\n\n      lifecycle = {\n        cold_storage_after = 1\n        delete_after       = 180 # half a year\n      }\n    }\n  ]\n\n  selections = [\n    {\n      name = \"s3-buckets\"\n      arns = [\"arn:aws:s3:::my-bucket\", \"arn:aws:s3:::my-other-bucket\"]\n    },\n    {\n      name = \"db-snaps\"\n      arns = [\"arn:aws:rds:us-east-2:123456789012:db:my-mysql-instance\"]\n    }\n  ]\n}\n```\n\n# Predefined Rules\n```hcl\nlocals {\n  predefined_rules = [\n    # At 03:00 AM UTC, daily\n    {\n      name                     = \"daily-snapshot\"\n      schedule                 = \"cron(0 3 ? * * *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = true\n      recovery_point_tags      = {}\n\n      lifecycle = {\n        cold_storage_after = null\n        delete_after       = 35 # 5 weeks\n      }\n\n      copy_action = null\n    },\n\n    # At 03:00 AM UTC, every Sunday\n    {\n      name                     = \"weekly-snapshot\"\n      schedule                 = \"cron(0 3 ? * SUN *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = true\n      recovery_point_tags      = {}\n\n      lifecycle = {\n        cold_storage_after = null\n        delete_after       = 183 # 6 months\n      }\n\n      copy_action = null\n    },\n\n    # At 03:00 AM UTC, on day 1 of the month\n    {\n      name                     = \"monthly-snapshot\"\n      schedule                 = \"cron(0 3 1 * ? *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = false\n      recovery_point_tags      = {}\n\n      lifecycle = {\n        cold_storage_after = 1   # day\n        delete_after       = 365 # 1 year\n      }\n\n      copy_action = null\n    },\n\n    # At 03:00 AM UTC, on day 1 of the month, only in January, April, July, and October\n    {\n      name                     = \"quarterly-snapshot\"\n      schedule                 = \"cron(0 3 1 1,4,7,10 ? *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = false\n      recovery_point_tags      = {}\n\n      lifecycle = {\n        cold_storage_after = 1   # day\n        delete_after       = 730 # 2 years\n      }\n\n      copy_action = null\n    },\n\n    # At 03:00 AM UTC, on day 1 of the month, only in January\n    {\n      name                     = \"yearly-snapshot\"\n      schedule                 = \"cron(0 3 1 1 ? *)\"\n      start_window             = 60\n      completion_window        = 240\n      enable_continuous_backup = false\n      recovery_point_tags      = {}\n\n      lifecycle = {\n        cold_storage_after = 1    # day\n        delete_after       = 3650 # 10 years\n      }\n\n      copy_action = null\n    }\n  ]\n}\n```\n\u003c!-- END_TF_DOCS --\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-backup","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgeekcell%2Fterraform-aws-backup","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-backup/lists"}