Oracle CloudPlan-validated

OCI IAM Foundation (compartments + policies)

Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.

terraformOracle Cloudoci

Compare Identity & Access across clouds →

Part of: OCI Production Landing Zone

oci-iam-foundationvizier v1.2.0

Verification

Plan-validated

Passed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o oci-iam-foundation-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/oci-iam-foundation/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle oci-iam-foundation-1.0.0.sigstore.json \
  oci-iam-foundation-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "6d5036e3a620c49941013db6c307b84ffb18fd1bbdaf51fe2a1a57f97fd6538e  oci-iam-foundation-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "iam_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-iam-foundation/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: plan-validated](https://www.iac-bazaar.com/api/artifacts/oci-iam-foundation/badge)](https://www.iac-bazaar.com/catalog/oci-iam-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, plan-validated on IaC Bazaar: [OCI IAM Foundation (compartments + policies)](https://www.iac-bazaar.com/catalog/oci-iam-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "iam_foundation" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-iam-foundation/oci"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: plan-validated

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-iam-foundation

Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map. Works with Terraform and OpenTofu (>= 1.6), OCI provider >= 8.0, < 9.0.

Secure defaults:

  • Compartments are delete-protected (enable_delete = false) unless opted in
  • Policies are explicit statement lists — nothing is granted implicitly
  • Policies attach at the narrowest scope you name (a created compartment), falling back to the tenancy root only when no compartment_key is given
  • Dynamic groups require a non-empty matching rule (validated)

Requirements

  • Terraform or OpenTofu >= 1.6
  • Provider oracle/oci >= 8.0, < 9.0

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs
  • Notes

Related modules

Static validatedLive test pending

oci-budget

The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.

View module
Static validatedLive test pending

oci-tag-namespace

A tag default with is_required = false applies a value silently and lets anyone overwrite or blank it; required is the only enforcement OCI tagging has, and a required free-text tag enforces presence and nothing about meaning. Every default is required and validated against an allowed list unless accepted otherwise; the ten cost-tracking slots are counted; retirement is the only delete that works.

View module
Static validatedLive test pending

tencent-cam-role

A CAM role assumable by the services or root accounts you name and nothing else (a wildcard principal is refused), console login off because a role is for workloads, a custom policy written from your statements, the preset policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

View module
Static validatedLive test pending

ovh-iam-policy

An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.

View module
Static validatedLive test pending

alicloud-ram-role

A RAM role assumable by the services or accounts you name and nothing else (a wildcard principal is refused), with a custom policy written from your statements, the system policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.

View module
Static validatedLive test pending

ibm-trusted-profile

An IAM trusted profile, which is identity without an API key: policies that grant roles on one service and resource group each (Administrator by name), and links to the virtual servers or Kubernetes service accounts that may assume it through the metadata service, since a profile with no link is assumed by nobody (accepted by name).

View module