Backup Vault, Plans and Vault Lock
A vault, its plans and what they protect, with the service role that can restore as well as back up. Vault Lock is stated rather than defaulted: COMPLIANCE mode cannot be removed by anybody once its window elapses, which is the point and is irreversible.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "backup" {
source = "www.iac-bazaar.com/iac-bazaar/aws-backup/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-backup
An AWS Backup vault, the plans that write into it, the selections that decide
what is protected, and the service role that can both back up and restore.
Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0.
Vault Lock is the part worth understanding. A backup you can delete is not a defence against the thing most likely to destroy your data, which is somebody holding your credentials.
- GOVERNANCE can be removed by a principal with
backup:DisableBackupVaultLock. Useful; not that defence - COMPLIANCE cannot be removed by anybody once
changeable_for_dayshas elapsed - not you, not the root user, not AWS Support. Recovery points survive until their retention expires
That is the point, and it is irreversible, so this module makes you state it rather than inheriting it. The validation refuses a COMPLIANCE lock with a window under three days, because that window is the only chance to undo it.
Other defaults:
force_destroyoff: that is how a vault of recovery points disappears by accident- The service role gets the restore policy as well as the backup one. A role with only the backup half takes backups nobody can restore through AWS Backup
- Notifications carry failures and modifications, not successes - a plan that silently stops running is otherwise first noticed when a restore is needed
delete_after_daysis validated to be at least 90 days aftercold_storage_after_days, which AWS requires and reports late- Selections prefer
select_by_tag: it picks up a resource created next month without anybody editing this file
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
aws-efs
An EFS file system with mount targets, a least-privilege NFS security group, lifecycle tiering, automatic backups, and a resource policy that enforces encryption in transit.
aws-ebs-volume
Volumes that are always encrypted, optional attachment, and a DLM snapshot schedule in the same module - because a volume with no schedule is one copy of your data on hardware that can fail, and leaving snapshots to somebody else usually means nobody.
aws-fsx-lustre
A Lustre file system with the S3 link, root squash and compression set deliberately. SCRATCH deployments are not replicated - a lost file server loses the data - so this defaults to PERSISTENT_2 and refuses the combinations FSx accepts quietly.