Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o linode-volume-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/linode-volume/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle linode-volume-1.0.0.sigstore.json \
linode-volume-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "0b65d99dd6fa5a6144734219bfcd095bd30f080712294dc2b653ecdf2071899e linode-volume-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "volume" {
source = "www.iac-bazaar.com/iac-bazaar/linode-volume/linode"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Basic, so its contract unlocks when you buy it.
Documentation
linode-volume
Status: static-validated, live-test pending. Ships under live-test quarantine — no Linode cloud sandbox is wired into the gate yet. Static validation (fmt, validate, tflint) is green.
Attachable, resizable Linode Block Storage NVMe volume with Block Storage
Disk Encryption on by default and safe attach/detach lifecycle handling.
Optionally clones from an existing volume. Pairs with the linode-instance
module. Works with Terraform and OpenTofu (>= 1.6), Linode provider
>= 3.14, < 4.0.
Secure defaults
- Encryption at rest enabled by default (
encryption = true). The region must support Block Storage Disk Encryption. - Detached by default. With no
linode_id, the volume is created unattached; setlinode_idto attach it to an instance (in the same region). - Grow-only guardrail. A plan-time precondition rejects sizes below the 10 GB floor; volumes can only be resized larger, never smaller, so a shrink is caught before the API rejects it.
- Clone-aware region handling. When
source_volume_idis set the clone inherits the source region andregionis ignored; a precondition requires aregiononly when not cloning.
Requirements
- Terraform or OpenTofu
>= 1.6 linode/linodeprovider>= 3.14, < 4.0- A Linode personal access token with Volumes write scope (
LINODE_TOKENor the providertoken). encryption = truerequires a region with Block Storage Disk Encryption support.
License
Commercial — LicenseRef-IaCBazaar-Commercial. IaC Bazaar EULA. © IaC Bazaar.
Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs