OCI VCN (hub-ready network foundation)
Production VCN with public/private subnets, internet/NAT/service gateways, route tables, NSGs and IPv6 - the module every OCI tenancy starts with.
Compare Virtual Private Cloud (VPC) across clouds →
Part of: OCI Production Landing Zone
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o oci-vcn-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/oci-vcn/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle oci-vcn-1.0.0.sigstore.json \
oci-vcn-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "73ccd9b5208bc91e457ec0876544a6797783ba9dbe969b0b81ad131e68bff918 oci-vcn-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "vcn" {
source = "www.iac-bazaar.com/iac-bazaar/oci-vcn/oci"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Professional, so its contract unlocks when you buy it.
Documentation
oci-vcn
Production VCN with public/private subnets, internet/NAT/service gateways,
route tables, NSGs and IPv6 — the module every OCI tenancy starts with. Works
with Terraform and OpenTofu (>= 1.6), OCI provider >= 8.0, < 9.0.
Secure defaults:
- Private subnets prohibit public IPs on VNICs and route via NAT/service gateway
- No security rules are opened implicitly — every rule is an explicit NSG entry
- Service-gateway route keeps Oracle Services Network traffic (Object Storage, OS updates) off the public internet
- IPv6 is opt-in (VCN-level
enable_ipv6+ per-subnetipv6_index/64 carve)
Requirements
- Terraform or OpenTofu
>= 1.6 - Provider
oracle/oci>= 8.0, < 9.0
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
- Notes
Related modules
DRG Hub & Spoke Connectivity
Dynamic Routing Gateway with VCN attachments, custom DRG route tables, remote peering and IPSec/FastConnect attach points.
Alibaba Cloud VPC Foundation
Multi-AZ VPC with vSwitches, NAT gateway, SNAT, security groups, and flow logs.
Azure Virtual Network (hub-ready)
Production VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.
GCP VPC Network Foundation
Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.
Hetzner Private Network + NAT
Private network with subnets, routes, and a NAT gateway server for egress-only fleets.
IBM Cloud VPC Landing Zone (Lite)
VPC with subnets, public gateways, ACLs, and security groups following IBM SLZ patterns.