Oracle CloudStatic-verified

A Connector that Is Active and Archives What Logging Forgets

OCI Logging keeps a log for at most six months; a service connector from a log group to Object Storage is the archive, and it can be created INACTIVE, which is how one that was set up has moved nothing since. Created active, reads a whole log group so new logs are included, writes to a bucket, stream, function, topic, metric or Log Analytics, and exports the IAM statement the hub needs.

terraformOracle Cloudoci
oci-service-connectorvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "service_connector" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-service-connector/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-service-connector

A Service Connector that is active, reads something, and writes somewhere that keeps it. Works with Terraform and OpenTofu (>= 1.6), oci provider >= 8.0, < 9.0.

A connector can be created inactive. ACTIVE here; INACTIVE needs accept_inactive.

The connector is how logs outlive 180 days. OCI Logging keeps a log for at most six months. A connector from a log group to an Object Storage bucket is the archive; it is also how logs reach a SIEM (streaming target), a function, a topic, or Monitoring as a metric.

A log source with no log id reads the whole group. Group-level by default, so a log added next month is archived automatically.

The connector must be allowed to write. It runs as the Service Connector Hub service and needs an IAM policy on the target; without one it is ACTIVE and every batch fails. policy_required is the statement to add.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules