OCI IAM Foundation (compartments + policies)
Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups, policy statements and tag namespaces from a single map.
Compare Identity & Access across clouds →
Part of: OCI Production Landing Zone
Verification
Plan-validatedPassed: module logic verified on a mocked plan - inputs, validation rules, conditional creation and outputs resolve (no real provider, no cloud).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o oci-iam-foundation-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/oci-iam-foundation/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle oci-iam-foundation-1.0.0.sigstore.json \
oci-iam-foundation-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "6d5036e3a620c49941013db6c307b84ffb18fd1bbdaf51fe2a1a57f97fd6538e oci-iam-foundation-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "iam_foundation" {
source = "www.iac-bazaar.com/iac-bazaar/oci-iam-foundation/oci"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads plan-validated because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/oci-iam-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, plan-validated on IaC Bazaar: [OCI IAM Foundation (compartments + policies)](https://www.iac-bazaar.com/catalog/oci-iam-foundation?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "iam_foundation" {
source = "www.iac-bazaar.com/iac-bazaar/oci-iam-foundation/oci"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
oci-iam-foundation
Tenancy landing-zone core: compartment hierarchy, groups, dynamic groups,
policy statements and tag namespaces from a single map. Works with
Terraform and OpenTofu (>= 1.6), OCI provider >= 8.0, < 9.0.
Secure defaults:
- Compartments are delete-protected (
enable_delete = false) unless opted in - Policies are explicit statement lists — nothing is granted implicitly
- Policies attach at the narrowest scope you name (a created compartment),
falling back to the tenancy root only when no
compartment_keyis given - Dynamic groups require a non-empty matching rule (validated)
Requirements
- Terraform or OpenTofu
>= 1.6 - Provider
oracle/oci>= 8.0, < 9.0
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
- Notes
Related modules
oci-budget
The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.
oci-tag-namespace
A tag default with is_required = false applies a value silently and lets anyone overwrite or blank it; required is the only enforcement OCI tagging has, and a required free-text tag enforces presence and nothing about meaning. Every default is required and validated against an allowed list unless accepted otherwise; the ten cost-tracking slots are counted; retirement is the only delete that works.
tencent-cam-role
A CAM role assumable by the services or root accounts you name and nothing else (a wildcard principal is refused), console login off because a role is for workloads, a custom policy written from your statements, the preset policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.
ovh-iam-policy
An OVHcloud IAM policy over named identities and resources. A policy with neither allow nor deny appears in the list with a description somebody wrote and does nothing at all, which is refused here. except is a hole in allow rather than a deny, and expired_at is reported as an output because a policy that expires fails like a broken credential.
alicloud-ram-role
A RAM role assumable by the services or accounts you name and nothing else (a wildcard principal is refused), with a custom policy written from your statements, the system policies you name attached (AdministratorAccess and any *FullAccess policy by name), and a session ceiling of an hour.
ibm-trusted-profile
An IAM trusted profile, which is identity without an API key: policies that grant roles on one service and resource group each (Administrator by name), and links to the virtual servers or Kubernetes service accounts that may assume it through the metadata service, since a profile with no link is assumed by nobody (accepted by name).