Linode Object Storage Bucket
S3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o linode-object-storage-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/linode-object-storage/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle linode-object-storage-1.0.0.sigstore.json \
linode-object-storage-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "26a5b3a2c728ef4c3ca6d8c7bbd32336268c00281b4843a28c45d39bdbf286e0 linode-object-storage-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "object_storage" {
source = "www.iac-bazaar.com/iac-bazaar/linode-object-storage/linode"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/linode-object-storage?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, plan-validated on IaC Bazaar: [Linode Object Storage Bucket](https://www.iac-bazaar.com/catalog/linode-object-storage?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "object_storage" {
source = "www.iac-bazaar.com/iac-bazaar/linode-object-storage/linode"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
linode-object-storage
S3-compatible Linode Object Storage bucket — private and versioned by
default — with optional lifecycle rules, custom-domain TLS, and a
least-privilege access key scoped to just this bucket. Works with Terraform
and OpenTofu (>= 1.6), Linode provider >= 3.14, < 4.0.
Status: static-validated, live-test pending. This module ships under live-test quarantine: it has passed
tofu fmt,tofu validate, andtflint, but the real apply → verify → destroy gate is pending a Linode Object Storage sandbox (the service is a flat $5/mo while enabled). Treat the secure defaults below as the contract.
Design & secure defaults
- Private by default.
acl = "private"— no anonymous access. Thepublic-read-writecanned ACL (anonymous write to anyone) is rejected by variable validation outright. - Versioning on by default for data protection, paired with an optional
noncurrent_version_expiration_dayslifecycle rule so old versions don't accumulate cost unbounded. - Least-privilege key. The generated
linode_object_storage_keyis scoped with abucket_accessblock to this bucket only — not an account-wide key. Permission defaults toread_write; setread_onlyfor consumers. Thesecret_keyoutput issensitiveand is only returned at create time. - CORS off unless you opt in (
cors_enabled = true), and even then prefer a narrow per-origin policy via the S3 API for production browser apps. - Custom-domain TLS via the optional
certblock (PEM cert + key, keptsensitive) so a public bucket can be served over HTTPS on your domain.
Requirements
- Terraform or OpenTofu
>= 1.6 linode/linodeprovider>= 3.14, < 4.0- Object Storage must be enabled on the account (a flat $5/mo while active).
- The provider's
acl/versioning/lifecycle_rulefeatures use the S3 API under the hood and require object-storage-scoped credentials (the provider token, oraccess_key/secret_keyon the provider). - Destroy must empty the bucket first — Linode does not force-delete a
non-empty bucket, and the provider has no
force_destroyflag. Empty the bucket (e.g. vias3tooling) beforedestroy. - "Static-site hosting" is the standard S3 convention (upload an
index.html/error.htmland serve from the bucket's public endpoint); it is not a separate Terraform argument on this resource.
License
Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work
(not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
linode-volume
Attachable, resizable NVMe block volume with safe attach/detach lifecycle handling.
scaleway-object-bucket
Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.
tencent-cos-bucket
A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.
ibm-cos-bucket
Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.
do-spaces-bucket
A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.