Linode Block Storage Volume
Attachable, resizable NVMe block volume with safe attach/detach lifecycle handling.
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o linode-volume-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/linode-volume/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle linode-volume-1.0.0.sigstore.json \
linode-volume-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "0b65d99dd6fa5a6144734219bfcd095bd30f080712294dc2b653ecdf2071899e linode-volume-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "volume" {
source = "www.iac-bazaar.com/iac-bazaar/linode-volume/linode"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/linode-volume?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, plan-validated on IaC Bazaar: [Linode Block Storage Volume](https://www.iac-bazaar.com/catalog/linode-volume?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "volume" {
source = "www.iac-bazaar.com/iac-bazaar/linode-volume/linode"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
linode-volume
Status: static-validated, live-test pending. Ships under live-test quarantine — no Linode cloud sandbox is wired into the gate yet. Static validation (fmt, validate, tflint) is green.
Attachable, resizable Linode Block Storage NVMe volume with Block Storage
Disk Encryption on by default and safe attach/detach lifecycle handling.
Optionally clones from an existing volume. Pairs with the linode-instance
module. Works with Terraform and OpenTofu (>= 1.6), Linode provider
>= 3.14, < 4.0.
Secure defaults
- Encryption at rest enabled by default (
encryption = true). The region must support Block Storage Disk Encryption. - Detached by default. With no
linode_id, the volume is created unattached; setlinode_idto attach it to an instance (in the same region). - Grow-only guardrail. A plan-time precondition rejects sizes below the 10 GB floor; volumes can only be resized larger, never smaller, so a shrink is caught before the API rejects it.
- Clone-aware region handling. When
source_volume_idis set the clone inherits the source region andregionis ignored; a precondition requires aregiononly when not cloning.
Requirements
- Terraform or OpenTofu
>= 1.6 linode/linodeprovider>= 3.14, < 4.0- A Linode personal access token with Volumes write scope (
LINODE_TOKENor the providertoken). encryption = truerequires a region with Block Storage Disk Encryption support.
License
Commercial — LicenseRef-IaCBazaar-Commercial. IaC Bazaar EULA. © IaC Bazaar.
Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
linode-object-storage
S3-compatible bucket with scoped access keys, versioning, lifecycle rules, and optional static-site hosting.
exoscale-block-storage
Snapshots exist as a resource you take and nothing on the platform schedules one; a volume attaches from the instance side, one instance at a time, in its zone; and a volume made from a snapshot is the restore path. A baseline snapshot when asked, restore from a snapshot when given, and an output that says no schedule exists.
ibm-block-volume
VPC backup policies match volumes by user tag, so a volume created without the tag sits silently outside the policy; encryption is provider-managed unless a root key CRN is given; and an attachment can delete the volume with the instance. The policy created with its plan and the volume tagged with the tag it matches (none by name), your key when given, the volume kept on instance deletion.
oci-block-volume
Every tenancy ships Bronze, Silver and Gold policies and a volume follows one only through a separate assignment - the page reads Backup policy: none for the many never assigned. Assigns a policy to the volume it creates and refuses one without. Custom schedules add destination_region and retention lock, which Oracle policies lack: same-region backups are a copy of the failure.
do-volume
Droplet backups copy the boot disk and nothing attached to it, so a database whose data lives on a volume is an empty server to the backup; there is no snapshot schedule for volumes either. A formatted, attached, regional volume with two outputs that say exactly that, so whatever consumes the module cannot assume a copy exists.
scaleway-block-volume
iops is required, is the price per GB, and cannot change after creation; snapshots exist as a resource you take and nothing on the platform schedules one; the volume is zonal and attaches from the server side. The tier validated to the two that exist, a baseline snapshot when asked, and an output that says no schedule exists.