IBM Cloud VPC Landing Zone (Lite)
VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o ibm-vpc-landing-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/ibm-vpc-landing/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle ibm-vpc-landing-1.0.0.sigstore.json \
ibm-vpc-landing-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "d974e9e3bad423a9079d281e345fa346bfb58ee0031e3e8ddc6a7a316a5c461b ibm-vpc-landing-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "vpc_landing" {
source = "www.iac-bazaar.com/iac-bazaar/ibm-vpc-landing/ibmcloud"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Professional, so its contract unlocks when you buy it.
Documentation
ibm-vpc-landing
IBM Cloud VPC Landing Zone (Lite) — a VPC with subnets, public gateways,
ACLs, and security groups following IBM Secure Landing Zone patterns. Works
with Terraform and OpenTofu (>= 1.6), IBM Cloud provider >= 2.0, < 3.0.
Secure defaults:
- Manual address-prefix management — only the ranges you declare exist
- A deny-by-default network ACL attached to every subnet (only VPC-internal traffic inbound and all traffic outbound; the internet-wide stateless ephemeral inbound allowance is off by default and must be opted into)
- Public gateways created only for zones whose subnets opt in
- A workload security group with zero inbound exposure until you declare
tcp_ingress_rules(intra-group traffic optional, outbound open)
Requirements
- Terraform or OpenTofu
>= 1.6 IBM-Cloud/ibmprovider>= 2.0, < 3.0- An IBM Cloud API key with VPC Infrastructure Services access
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
- Notes
Related modules
Alibaba Cloud VPC Foundation
Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.
Azure Virtual Network (hub-ready)
Production VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.
GCP VPC Network Foundation
Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.
Hetzner Private Network + NAT
Private network with subnets, routes, and a NAT gateway server for egress-only fleets.
Linode VPC with Subnets
Isolated VPC network with labeled subnets ready for instances, LKE, and NodeBalancer backends.
OCI VCN (hub-ready network foundation)
Production VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.