Oracle CloudStatic-verified

Repositories that Are Declared, Private and Immutable

The registry creates a repository for any push to an unknown name by default - private, and unmanaged - and a tag can be overwritten unless the repository is immutable, so a deployment pinned to v1.4.2 runs whatever last claimed it. Manages the tenancy-wide create-on-push switch off, creates repositories immutable and private, and lists any that are public or mutable when that is accepted.

terraformOracle Cloudoci

Compare Container Registry across clouds →

oci-container-registryvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "container_registry" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-container-registry/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-container-registry

Container repositories that are declared, private, and immutable. Works with Terraform and OpenTofu (>= 1.6), oci provider >= 8.0, < 9.0.

is_repository_created_on_first_push is on by default. Any principal with push rights creates a repository by pushing to a name that does not exist - private, and unmanaged: no immutability, no owner, and a typo in an image name is a new repository billed for its layers. This module can manage the tenancy-wide setting (from one place, since it is a singleton) and turns it off; leaving it on needs accept_create_on_first_push.

A mutable tag is a name for whatever was pushed last. is_immutable defaults to false. Immutable here; mutable needs accept_mutable_tags.

is_public means anyone on the internet can pull. Refused without accept_public_repositories, and every public repository is listed.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules