weave
Modules

Integrations

Each module is a thin wrapper around a real system. We curate the catalog from the same systems IT teams already control with Terraform — minus the cloud-infrastructure providers, since that's not what weave does. If you'd build it in Terraform to manage configuration drift, weave helps you manage what's actually running.

87
Supported integrations

Identity & SSO

Who is this human, and what can they touch?
Identity & SSO hashicorp/ad
Active Directory

Users, groups, OUs, enable/disable/reset.

Identity & SSO
adobe

Adobe Admin Console control plane via the User Management API (UMAPI) — users, user groups, group membership, identity types, and full snapshot/diff/apply round-trip for the resources most worth versioning.

Identity & SSO auth0/auth0
Auth0

CIAM users, tenants, rules, log streams.

Identity & SSO aws (IAM subset)
AWS IAM (live ops)

Users, roles, keys, sessions — live, not Terraform-managed.

Identity & SSO Duo Admin API
Duo Security

MFA tokens, bypass codes, device trust events.

Identity & SSO freeipa-community/freeipa
FreeIPA

Users, groups, hosts, HBAC/sudo rules.

Identity & SSO Admin SDK
Google Workspace

Users, groups, OUs, suspend/unsuspend/sign-out everywhere.

Identity & SSO JumpCloud API
JumpCloud

Directory + device-bound identity for SMB IT.

Identity & SSO keycloak/keycloak
Keycloak

Self-hosted OIDC/SAML realm + user ops.

Identity & SSO KnowBe4 REST API
KnowBe4

Security awareness users, groups, phishing and training campaigns.

Identity & SSO RFC 4511
LDAP

Generic LDAP search and group membership lookups.

Identity & SSO hashicorp/azuread
Microsoft Entra ID

Azure AD users, groups, sign-ins, enable/disable, revoke sessions.

Identity & SSO okta/okta
Okta

find/list users + groups, suspend / unsuspend, reset MFA, reset password.

Identity & SSO onelogin/onelogin
OneLogin

Users, apps, MFA, role management.

Identity & SSO pingidentity/pingone
PingOne

Ping Identity users, environments, apps, MFA.

Endpoints & MDM

Mostly absent from Terraform. Huge for IT.

Networking

What's plugged in and reachable, right now?
Networking aruba/aoscx
Aruba AOS-CX

Switches, VLANs, interfaces, LAGs.

Networking aws (Route 53 subset)
AWS Route 53

Hosted zones + records as the API sees them right now.

Networking CheckPointSW/checkpoint
Check Point

Gateways, access rules, NAT, session publish.

Networking CiscoDevNet/iosxe
Cisco IOS XE

Interfaces, VLANs, routes, ACLs via RESTCONF.

Networking CiscoDevNet/nxos
Cisco NX-OS

Interfaces, VLANs, VRFs, BGP peers via NX-API.

Networking Cisco Umbrella API
Cisco Umbrella

DNS policies, destinations, identities, domain intelligence.

Networking cloudflare/cloudflare
Cloudflare

Zones, DNS records — search and dump as the API sees them.

Networking Extreme Networks API
Extreme Networks

EXOS/Switch Engine ports, VLANs, stacks.

Networking F5Networks/bigip
F5 BIG-IP

Virtual servers, pools, nodes, iRules.

Networking fortinetdev/fortios
Fortinet FortiGate

Policies, address objects, live sessions.

Networking jeremmfr/junos
Juniper Junos

Interfaces, routes, security policies, commit/rollback.

Networking cisco-open/meraki
Meraki

Live MAC/IP lookup, switch port VLAN moves, network/device search.

Networking terraform-routeros/routeros
MikroTik RouterOS

Interfaces, firewall rules, DHCP leases, wireless.

Networking e-breuninger/netbox
NetBox

DCIM/IPAM source of truth — sites, racks, IPs, devices.

Networking PaloAltoNetworks/panos
Palo Alto NGFW

PAN-OS policies, address objects, commits.

Networking bpg/proxmox
Proxmox VE

Nodes, QEMU VMs, LXC containers, lifecycle ops.

Networking tailscale/tailscale
Tailscale

Tailnet devices + keys; delete, expire-key, retag in one shot.

Networking twingate/twingate
Twingate

Zero-trust resources + groups; modern VPN replacement.

Networking ubiquiti-community/unifi
Ubiquiti UniFi

Comprehensive control plane: networks, WLANs, firewall, port-forwards, devices, clients — 13 state kinds.

Networking vmware/vsphere
VMware vSphere

Hosts, VMs, datastores, snapshots, power ops.

Networking Zscaler ZIA API
Zscaler ZIA

URL policies, firewall rules, users — Zscaler Internet Access.

Comms & Incident

Where humans coordinate when things break.

Code & DevOps

Source of truth for everything that ships.

Observability

What's healthy, what's screaming.

Secrets & Config

The keys to the kingdom — audited live.

SaaS / Business

Tools the whole company touches.

Don't see your system?

Each module is ~200 lines of Python plus a manifest. Adding a new one is a single PR. Open an issue with the system you want, or send a PR — the contributor guide is in the repo.