AzureStatic-verified

Golden Images that Boot Trusted, Stay Private and Expire

Community sharing publishes every image version to every Azure customer, unauthenticated, with your publisher email attached; trusted launch supported means a VM may boot without Secure Boot, and an image with no end-of-life date is a 2021 build still being deployed. Private by default, trusted launch required on every definition, an end-of-life date on each, and Hyper-V generation 2 throughout.

terraformAzureazure
azure-image-galleryvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • No applicable security policies for this provider
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "image_gallery" {
  source  = "www.iac-bazaar.com/iac-bazaar/azure-image-gallery/azure"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

azure-image-gallery

An Azure Compute Gallery whose image definitions require trusted launch, are shared with named subscriptions only, and carry an end of life. Works with Terraform and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0.

sharing.permission = "Community" publishes to every Azure customer, unauthenticated, with your publisher email attached. Refused without accept_community_sharing.

trusted_launch_supported is "may"; trusted_launch_enabled is "must". Every definition here requires trusted launch, so a VM from it boots with Secure Boot and vTPM or not at all; an OS that cannot needs accept_untrusted_launch.

An image with no end of life is a golden image from 2021 still being deployed. Each definition carries a date; none needs accept_no_end_of_life.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules