AWSStatic-verified

Backup Vault, Plans and Vault Lock

A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.

terraformAWSaws
aws-backupvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan pending (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "backup" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-backup/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-backup

An AWS Backup vault, the plans that write into it, the selections that decide what is protected, and the service role that can both back up and restore. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Vault Lock is the part worth understanding. A backup you can delete is not a defence against the thing most likely to destroy your data, which is somebody holding your credentials.

  • GOVERNANCE can be removed by a principal with backup:DisableBackupVaultLock. Useful; not that defence
  • COMPLIANCE cannot be removed by anybody once changeable_for_days has elapsed - not you, not the root user, not AWS Support. Recovery points survive until their retention expires

That is the point, and it is irreversible, so this module makes you state it rather than inheriting it. The validation refuses a COMPLIANCE lock with a window under three days, because that window is the only chance to undo it.

Other defaults:

  • force_destroy off: that is how a vault of recovery points disappears by accident
  • The service role gets the restore policy as well as the backup one. A role with only the backup half takes backups nobody can restore through AWS Backup
  • Notifications carry failures and modifications, not successes - a plan that silently stops running is otherwise first noticed when a restore is needed
  • delete_after_days is validated to be at least 90 days after cold_storage_after_days, which AWS requires and reports late
  • Selections prefer select_by_tag: it picks up a resource created next month without anybody editing this file

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules