IBM CloudPlan-validated

IBM Cloud VPC Landing Zone (Lite)

VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.

terraformAlt & Specialty Cloudsibmcloud

Compare Virtual Private Cloud (VPC) across clouds →

ibm-vpc-landingvizier v1.2.0

Verification

Plan-validated

Passed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o ibm-vpc-landing-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/ibm-vpc-landing/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle ibm-vpc-landing-1.0.0.sigstore.json \
  ibm-vpc-landing-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "d974e9e3bad423a9079d281e345fa346bfb58ee0031e3e8ddc6a7a316a5c461b  ibm-vpc-landing-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "vpc_landing" {
  source  = "www.iac-bazaar.com/iac-bazaar/ibm-vpc-landing/ibmcloud"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: plan-validated](https://www.iac-bazaar.com/api/artifacts/ibm-vpc-landing/badge)](https://www.iac-bazaar.com/catalog/ibm-vpc-landing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, plan-validated on IaC Bazaar: [IBM Cloud VPC Landing Zone (Lite)](https://www.iac-bazaar.com/catalog/ibm-vpc-landing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "vpc_landing" {
  source  = "www.iac-bazaar.com/iac-bazaar/ibm-vpc-landing/ibmcloud"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: plan-validated

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

ibm-vpc-landing

IBM Cloud VPC Landing Zone (Lite) — a VPC with subnets, public gateways, ACLs, and security groups following IBM Secure Landing Zone patterns. Works with Terraform and OpenTofu (>= 1.6), IBM Cloud provider >= 2.0, < 3.0.

Secure defaults:

  • Manual address-prefix management — only the ranges you declare exist
  • A deny-by-default network ACL attached to every subnet (only VPC-internal traffic inbound and all traffic outbound; the internet-wide stateless ephemeral inbound allowance is off by default and must be opted into)
  • Public gateways created only for zones whose subnets opt in
  • A workload security group with zero inbound exposure until you declare tcp_ingress_rules (intra-group traffic optional, outbound open)

Requirements

  • Terraform or OpenTofu >= 1.6
  • IBM-Cloud/ibm provider >= 2.0, < 3.0
  • An IBM Cloud API key with VPC Infrastructure Services access

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs
  • Notes

Related modules

Static validatedLive test pending

ibm-direct-link

A Direct Link gateway with both default route filters set to deny, because permit accepts every prefix the other side advertises including a default route that would pull the VPC's whole egress across the circuit. The BGP session is authenticated, BFD is on, global routing and metered billing are required inputs, and a virtual connection per VPC is what makes the circuit reach anything.

View module
Static validatedLive test pending

ibm-transit-gateway

An IBM Cloud Transit Gateway local to one region (global by name) with a connection per VPC you name, each denying every prefix by default and permitting the prefix rules you write, since a transit gateway has no route tables and every connection advertises everything otherwise; a connection that permits all has to say so.

View module
Static validatedLive test pending

ibm-vpn-gateway

An IBM Cloud VPC VPN gateway in policy mode with one connection to your on-premises gateway on IKEv2, with its own IKE and IPsec policies (AES-256, SHA-256, DH group 14) so IBM's auto-negotiation list never admits SHA-1 or a small group, the weak options refused by validation, IKEv1 by name, and dead peer detection that restarts the connection.

View module
Static validatedLive test pending

ibm-vpe-gateway

An IBM Cloud VPC virtual private endpoint gateway to a cloud service, with a reserved IP in each subnet you name (one zone has to be accepted by name), behind the security groups you name (the VPC default group by name), and DNS resolution binding enabled so the VPC resolves the service to the gateway.

View module
Static validatedLive test pending

ibm-public-gateway

IBM Cloud VPC public gateways, one per zone you list because a gateway serves its own zone only, with the subnets in the map attached to the gateway of their zone (a gateway with no subnet forwards nothing) and a reserved floating IP per zone when you pass one so the egress address survives recreation. gateway_count says what bills by the hour.

View module
Static validatedLive test pending

huawei-vpc

A Huawei Cloud VPC whose range is checked against RFC 1918 (a public range by name), with subnets placed in the zones you name, each with its gateway at the first address and DHCP handing out Huawei's resolvers so the platform's service names resolve. Nothing egresses: a NAT gateway (huawei-nat-gateway) or an EIP is a separate decision.

View module