An OBS Bucket that Is Private on Both Switches, Versioned and Encrypted
Public access is two switches: a private ACL still leaves a bucket policy free to grant anonymous reads, and only Block Public Access refuses both; versioning and encryption are both off by default; abandoned uploads bill until a rule aborts them. Private ACL plus BPA with public by name, versioning on, encrypted with the region's key or yours, incomplete uploads freed after a week.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "obs_bucket" {
source = "www.iac-bazaar.com/iac-bazaar/huawei-obs-bucket/huaweicloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
huawei-obs-bucket
An OBS bucket that is private on both switches, versioned, encrypted, and
cleans up after itself. Works with Terraform and OpenTofu (>= 1.6),
huaweicloud provider >= 1.60, < 2.0.
Public access is two switches. Private ACL and Block Public Access;
public needs accept_public_read.
Versioning and encryption are both off by default. Both on here;
kms_key_id optional.
Abandoned multipart uploads are aborted after seven days.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
huawei-evs-disk
A backup on Huawei Cloud is a vault, a policy and a resource list that exist separately, so the common state is a policy with no vault or a vault with no disks; and a disk is encrypted only when a KMS key is given. The vault created with the policy applied and the disk as its resource (none by name), a key expected (none by name), attached to the instance you give.
scaleway-object-bucket
Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.
tencent-cos-bucket
A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.
ibm-cos-bucket
Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.
do-spaces-bucket
A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.