Linode Object Storage Bucket
S3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o linode-object-storage-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/linode-object-storage/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle linode-object-storage-1.0.0.sigstore.json \
linode-object-storage-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "26a5b3a2c728ef4c3ca6d8c7bbd32336268c00281b4843a28c45d39bdbf286e0 linode-object-storage-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "object_storage" {
source = "www.iac-bazaar.com/iac-bazaar/linode-object-storage/linode"
version = "1.0.0"
}Free module — Terraform/OpenTofu downloads it with no token or setup. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
This module is in the Free band, and a free account sees the contract of every Free module — no subscription needed.
Documentation
linode-object-storage
S3-compatible Linode Object Storage bucket — private and versioned by
default — with optional lifecycle rules, custom-domain TLS, and a
least-privilege access key scoped to just this bucket. Works with Terraform
and OpenTofu (>= 1.6), Linode provider >= 3.14, < 4.0.
Status: static-validated, live-test pending. This module ships under live-test quarantine: it has passed
tofu fmt,tofu validate, andtflint, but the real apply → verify → destroy gate is pending a Linode Object Storage sandbox (the service is a flat $5/mo while enabled). Treat the secure defaults below as the contract.
Design & secure defaults
- Private by default.
acl = "private"— no anonymous access. Thepublic-read-writecanned ACL (anonymous write to anyone) is rejected by variable validation outright. - Versioning on by default for data protection, paired with an optional
noncurrent_version_expiration_dayslifecycle rule so old versions don't accumulate cost unbounded. - Least-privilege key. The generated
linode_object_storage_keyis scoped with abucket_accessblock to this bucket only — not an account-wide key. Permission defaults toread_write; setread_onlyfor consumers. Thesecret_keyoutput issensitiveand is only returned at create time. - CORS off unless you opt in (
cors_enabled = true), and even then prefer a narrow per-origin policy via the S3 API for production browser apps. - Custom-domain TLS via the optional
certblock (PEM cert + key, keptsensitive) so a public bucket can be served over HTTPS on your domain.
Requirements
- Terraform or OpenTofu
>= 1.6 linode/linodeprovider>= 3.14, < 4.0- Object Storage must be enabled on the account (a flat $5/mo while active).
- The provider's
acl/versioning/lifecycle_rulefeatures use the S3 API under the hood and require object-storage-scoped credentials (the provider token, oraccess_key/secret_keyon the provider). - Destroy must empty the bucket first — Linode does not force-delete a
non-empty bucket, and the provider has no
force_destroyflag. Empty the bucket (e.g. vias3tooling) beforedestroy. - "Static-site hosting" is the standard S3 convention (upload an
index.html/error.htmland serve from the bucket's public endpoint); it is not a separate Terraform argument on this resource.
License
Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work
(not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
Related modules
Linode Block Storage Volume
Attachable, resizable NVMe block volume with safe attach/detach lifecycle handling.
AWS S3 Bucket (hardened)
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.
Azure Storage Account (secure-by-default)
Storage account with containers/file shares, lifecycle rules, network rules, CMK encryption and private endpoint options - Azure's most-deployed resource done right.
Cloud Storage Bucket
Hardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.
Object Storage Bucket
Bucket with versioning, lifecycle/auto-tiering, retention rules, replication and pre-authenticated request support.