Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "signer" {
source = "www.iac-bazaar.com/iac-bazaar/aws-signer/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-signer
AWS Signer profiles for Lambda packages and container images, who may sign with
them, and the Lambda code signing configuration that makes a signature mean
something. Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0.
The point is validation, not the signature. Signing a Lambda package proves
who built it and changes nothing on its own. Nothing rejects an unsigned or
tampered package until a function references a code signing config - and that
config's own default policy is Warn, which logs the problem and deploys the
package anyway.
This module defaults untrusted_artifact_on_deployment to Enforce,
because a warning nobody reads is indistinguishable from no check at all.
Other defaults:
- A config with no profiles is refused at plan: it would trust nobody and block everything
validity_periodbounds how long a signature is accepted. A signature that never expires cannot be retired without revoking the whole profile
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-cognito
A secure-by-default Cognito user pool and app client with optional hosted-UI domain - strong password policy, TOTP MFA, account-enumeration protection, SRP-only flows, and refresh-token revocation.
aws-detective
Builds an investigable graph from CloudTrail, VPC flow logs and GuardDuty findings, with member accounts and organization delegation. It detects nothing itself - it makes an existing finding into a timeline.
aws-firewall-manager
WAF, security group and Network Firewall policy applied across an organization. Remediation is off by default so the first apply is a report rather than an edit to resources in every member account.
aws-guardduty
Threat detection with each protection plan - S3, EKS, RDS, Lambda, malware, runtime - a separate decision with its billing dimension stated, plus organization delegation and findings filtered by severity into EventBridge.
aws-iam-access-analyzer
Finds what a principal outside your zone of trust could actually reach, which is the question policy reviews get wrong by reading JSON. External analysis is free; unused-access analysis is a separate, billed analyzer.
aws-iam-roles
Least-privilege IAM roles, managed policies, and GitHub/EKS OIDC federation in one composable module.