Cloud CDN in Front of a Bucket, with the Certificate, the Cache and the Redirect
enable_cdn defaults to false, so a backend bucket behind a global load balancer is served from the bucket on every request; a backend bucket is read as allUsers, which is to say public; the managed certificate stays PROVISIONING until DNS points at the address; and port 80 forwards unless a URL map redirects it. CDN on with negative caching, the bucket named as public, TLS 1.2, a 301 on 80.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "cloud_cdn" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-cloud-cdn/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-cloud-cdn
Cloud CDN in front of a Cloud Storage bucket: a global HTTPS front end
with a managed certificate, caching on, and HTTP redirected. Works with
Terraform and OpenTofu (>= 1.6), google provider >= 6.0, < 7.0.
enable_cdn defaults to false. On here, with negative caching.
A backend bucket is public. The module grants allUsers
objectViewer, because that is what the CDN reads as; for a private
origin use gcp-http-load-balancer with a backend service.
The managed certificate issues only after DNS points at the address;
ip_address is the output to use first.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
akamai-property-ion
End-to-end Ion CDN property: origin, edge hostname, caching/performance rule tree, CP code, and staging/production activation.
azure-front-door
Global entry point: Front Door profile, endpoints, origin groups, custom domains with managed TLS and WAF policy.
aws-cloudfront-site
Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.