Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "security_lake" {
source = "www.iac-bazaar.com/iac-bazaar/aws-security-lake/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-security-lake
Security Lake: organization security logs normalised to OCSF and landed in S3
as Parquet, with lifecycle transitions, optional replication and subscribers.
Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0.
Defaults worth knowing:
- The lifecycle transitions are the important input. The point of a security lake is holding logs long enough to investigate something discovered months later; the cost of one is holding logs. The default keeps 30 days hot, moves to infrequent access, then to Glacier - and does not expire, because an audit lake that deletes its own evidence is not one
- Log sources are named, not defaulted on. Their volumes differ by orders of magnitude: VPC flow logs from a busy estate dwarf CloudTrail management events, and Route 53 resolver logs can dwarf both
external_idon a subscriber is validated to at least 8 characters. It is the confused-deputy guard on the role the subscriber assumes, and a shared or guessable value defeats it
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-cloudtrail
Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.
aws-cloudwatch
A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.