Oracle CloudStatic-verified

Event Rules that Match Something Specific and Act

An empty condition is legal and matches the completion of every API call on every resource type in the compartment, flooding the target; a rule can be created disabled, and so can each action inside an enabled rule, which then matches events and does nothing while showing Active. Every rule names its event types, both levels are enabled unless accepted, and the IAM the service needs is exported.

terraformOracle Cloudoci

Compare Messaging & Pub/Sub across clouds →

oci-events-rulevizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "events_rule" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-events-rule/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-events-rule

Event rules that match something specific, are enabled, and act. Works with Terraform and OpenTofu (>= 1.6), oci provider >= 8.0, < 9.0.

An empty condition matches every event in the compartment and floods the target. Each rule names its event types; matching everything needs accept_match_everything.

A rule can be created disabled, and so can each action inside an enabled rule. An enabled rule whose only action is disabled matches events and does nothing, and shows as Active. Both are enabled unless accept_disabled_rules.

The action needs permission. The Events service delivers as itself and needs an IAM policy for the target kind; policy_required lists the statements.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules

Static validatedLive test pending

oci-queue

dead_letter_queue_delivery_count defaults to zero, which is no dead-letter queue: a message a consumer cannot process is redelivered after every visibility timeout until retention expires, a poison message that holds a consumer for a day. Five deliveries then the dead-letter queue, seven days of retention instead of one, and a vault key instead of an Oracle-managed one.

View module
Static validatedLive test pending

oci-streaming

A public stream pool is an FQDN reachable from anywhere with a valid token; auto_create_topics lets any producer create a stream by writing to a new name; retention defaults to 24 hours, so a consumer a day behind loses data with no error on the producer side. Private endpoint behind NSGs, declared streams, seven days of retention, and the stream that loses data soonest reported as an output.

View module
Static validatedLive test pending

oci-email-delivery

A domain without DKIM sends mail that looks forged and lands in spam; without a custom return path, bounces go to Oracle's domain and DMARC alignment fails; and a From address that is not an approved sender is refused by the API. DKIM key created, return path created, senders listed and checked against the domain, and every DNS record to publish exported in one output.

View module
Static validatedLive test pending

aws-mq

deployment_mode defaults to SINGLE_INSTANCE, and Amazon MQ reboots the instance to patch it - so a single broker has planned downtime on AWS's schedule. Active/standby across two AZs, both log streams on, and passwords in a separate variable from users, because a sensitive value cannot be a for_each argument at all.

View module
Static validatedLive test pending

aws-kinesis-firehose

Without error_output_prefix, records Firehose could not process are written into the same prefix as the ones it could, wrapped in an error envelope that whatever reads the prefix treats as data. Nothing reports it.

View module
Live-tested

gcp-cloud-tasks

A Cloud Tasks queue with capped dispatch rate and concurrency, a bounded exponential-backoff retry policy, and full Stackdriver logging so failed dispatches are observable rather than silent.

View module