A DevOps Project whose Pushes Build, on Your Network
The project, repository and pipeline are separate resources and none reacts to a commit until a trigger ties a push to the pipeline; builds run as the DevOps service and fail on the first step without a dynamic group and policy; and the runner is on Oracle's network unless given a subnet. Trigger created, runner attached to your subnet, and the IAM rule and statements exported.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "devops" {
source = "www.iac-bazaar.com/iac-bazaar/oci-devops/oci"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
oci-devops
A DevOps project with a repository, a build pipeline, and the trigger that
makes a push build. Works with Terraform and OpenTofu (>= 1.6), oci
provider >= 8.0, < 9.0.
A pipeline with no trigger builds when somebody clicks Run. The trigger
is created here; a pipeline without one needs accept_manual_builds.
The build runner needs a dynamic group and a policy. policy_required
exports the rule and statements; without them the first run fails on the
first step.
The runner has public network access unless told otherwise. A runner
that must reach a private registry or database needs runner_subnet_id;
none needs accept_public_runner.
Notifications are required by the API: every project event goes to an ONS topic.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage