IBM Cloud VPC Landing Zone (Lite)
VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o ibm-vpc-landing-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/ibm-vpc-landing/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle ibm-vpc-landing-1.0.0.sigstore.json \
ibm-vpc-landing-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "d974e9e3bad423a9079d281e345fa346bfb58ee0031e3e8ddc6a7a316a5c461b ibm-vpc-landing-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "vpc_landing" {
source = "www.iac-bazaar.com/iac-bazaar/ibm-vpc-landing/ibmcloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ibm-vpc-landing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, plan-validated on IaC Bazaar: [IBM Cloud VPC Landing Zone (Lite)](https://www.iac-bazaar.com/catalog/ibm-vpc-landing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "vpc_landing" {
source = "www.iac-bazaar.com/iac-bazaar/ibm-vpc-landing/ibmcloud"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
ibm-vpc-landing
IBM Cloud VPC Landing Zone (Lite) — a VPC with subnets, public gateways,
ACLs, and security groups following IBM Secure Landing Zone patterns. Works
with Terraform and OpenTofu (>= 1.6), IBM Cloud provider >= 2.0, < 3.0.
Secure defaults:
- Manual address-prefix management — only the ranges you declare exist
- A deny-by-default network ACL attached to every subnet (only VPC-internal traffic inbound and all traffic outbound; the internet-wide stateless ephemeral inbound allowance is off by default and must be opted into)
- Public gateways created only for zones whose subnets opt in
- A workload security group with zero inbound exposure until you declare
tcp_ingress_rules(intra-group traffic optional, outbound open)
Requirements
- Terraform or OpenTofu
>= 1.6 IBM-Cloud/ibmprovider>= 2.0, < 3.0- An IBM Cloud API key with VPC Infrastructure Services access
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
- Notes
Related modules
ibm-direct-link
A Direct Link gateway with both default route filters set to deny, because permit accepts every prefix the other side advertises including a default route that would pull the VPC's whole egress across the circuit. The BGP session is authenticated, BFD is on, global routing and metered billing are required inputs, and a virtual connection per VPC is what makes the circuit reach anything.
ibm-transit-gateway
An IBM Cloud Transit Gateway local to one region (global by name) with a connection per VPC you name, each denying every prefix by default and permitting the prefix rules you write, since a transit gateway has no route tables and every connection advertises everything otherwise; a connection that permits all has to say so.
ibm-vpn-gateway
An IBM Cloud VPC VPN gateway in policy mode with one connection to your on-premises gateway on IKEv2, with its own IKE and IPsec policies (AES-256, SHA-256, DH group 14) so IBM's auto-negotiation list never admits SHA-1 or a small group, the weak options refused by validation, IKEv1 by name, and dead peer detection that restarts the connection.
ibm-vpe-gateway
An IBM Cloud VPC virtual private endpoint gateway to a cloud service, with a reserved IP in each subnet you name (one zone has to be accepted by name), behind the security groups you name (the VPC default group by name), and DNS resolution binding enabled so the VPC resolves the service to the gateway.
ibm-public-gateway
IBM Cloud VPC public gateways, one per zone you list because a gateway serves its own zone only, with the subnets in the map attached to the gateway of their zone (a gateway with no subnet forwards nothing) and a reserved floating IP per zone when you pass one so the egress address survives recreation. gateway_count says what bills by the hour.
huawei-vpc
A Huawei Cloud VPC whose range is checked against RFC 1918 (a public range by name), with subnets placed in the zones you name, each with its gateway at the first address and DHCP handing out Huawei's resolvers so the platform's service names resolve. Nothing egresses: a NAT gateway (huawei-nat-gateway) or an EIP is a separate decision.