A Resource Directory Where Policy Can Attach and Accounts Can Be Deleted
A Resource Directory with its folders and member accounts. Two switches decide whether it works: control policies are off until the directory enables them, so a policy written elsewhere attaches to nothing; and member deletion is off by default, which makes every account this creates permanent and terraform destroy fail on it. Both are on here.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-15 · how we verify
Use it from the registry
terraform · opentofumodule "landing_zone" {
source = "www.iac-bazaar.com/iac-bazaar/alicloud-landing-zone/alicloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
alicloud-landing-zone
A Resource Directory with folders and member accounts on Alibaba Cloud Resource Management. Works with Terraform and OpenTofu
(>= 1.6), alicloud provider >= 1.0, < 2.0.
The account that runs this becomes the management account, permanently. Enabling a resource directory is done once and for whoever called it.
Control policies are off until the directory turns them on. While the SCP status is Disabled, alicloud-org-policy can create a policy that attaches to nothing, and the failure arrives at apply with a clean plan behind it. control_policies_can_attach is an output for exactly that reason.
member_deletion_status is Disabled by default, which makes every member account this module creates permanent: terraform destroy fails on it and the cleanup is a console job. Enabled here, because a factory that cannot unmake an account is a ratchet.
Folders are where policy attaches and the root includes the management account. An account left at the root inherits whatever is attached there, so putting one there has to be said out loud.
The tree is one level deep per call, because a folder naming another folder in the same resource block is a dependency cycle in Terraform. Nest by calling the module again with parent_folder_id from the first call.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
alicloud-org-policy
A Resource Management control policy and the folders or accounts it attaches to, which are separate resources: an unattached policy appears in the console list with a name and a document and constrains nobody. A control policy is a ceiling, so the module counts Deny statements and asks about Allow ones, which grant nothing. Attaching to the root reaches the management account.
aws-control-tower
A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.
tencent-landing-zone
Tencent organization nodes and members. policy_type takes one value and it is Financial: what a membership grants is numbered billing permissions, not a governance boundary, and is_a_policy_boundary says false. The permissions are taken as words and written as the integers Tencent wants, and the one that moves money is asked about.
huawei-landing-zone
An organization, its units and its accounts. enabled_policy_types is what makes a service control policy attachable at all: without it a policy is created and fails to attach, at apply, behind a clean plan, and neither console connects the two. The account email and phone are the recovery path, so an account with none is listed as an output.
azure-landing-zone-core
Management-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.
gcp-project-factory
Opinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.