OVHcloudStatic-verified

A Private Registry that Answers Only to the Ranges You Say

A registry's endpoint is public and every address may try a login until an IP restriction exists; the registry user is the credential and its password lands in state; and the plan is the storage ceiling. Allowed ranges expected with none accepted by name, one user created for the pipeline with its password as a sensitive output, and the plan looked up by name.

terraformAlt & Specialty Cloudsovh

Compare Container Registry across clouds →

ovh-container-registryvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • No applicable security policies for this provider
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "container_registry" {
  source  = "www.iac-bazaar.com/iac-bazaar/ovh-container-registry/ovh"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

ovh-container-registry

An OVHcloud Managed Private Registry with a user of its own and an IP restriction, so the registry answers only to the ranges you say. Works with Terraform and OpenTofu (>= 1.6), ovh provider >= 2.0, < 3.0.

A registry answers to the internet until restricted. allowed_cidrs expected; none needs accept_open_registry.

A user is the credential; one is created for the pipeline.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules

Static validatedLive test pending

do-container-registry

Docker credentials for the registry never expire unless told to, so the login a CI job wrote to disk two years ago still pushes today; there is one registry per account; and the tier is a storage ceiling that turns into a failed push far from the cause. The registry, read-only credentials that live a day and read-write ones that live an hour, both re-issued on the next apply after expiry.

View module
Static validatedLive test pending

scaleway-container-registry

is_public makes every image in the namespace pullable by anyone, and the key CI pushes with is usually a person's API key with every permission that person has and no expiry. Private unless public is accepted by name, and on request an IAM application whose only permission is registry access in one project, with an API key that expires on the date you set.

View module
Live-tested

gcp-artifact-registry

Docker/Maven/npm repos with cleanup policies, remote and virtual repositories, CMEK and reader/writer IAM.

View module
Live-tested

azure-acr

ACR with geo-replication, retention/trust policies, private endpoint and AcrPull role wiring for AKS/Container Apps.

View module
Live-tested

aws-ecr

ECR repo with lifecycle rules, scan-on-push, immutable tags, and cross-account/replication policies.

View module
Static validatedLive test pending

oci-container-registry

The registry creates a repository for any push to an unknown name by default - private, and unmanaged - and a tag can be overwritten unless the repository is immutable, so a deployment pinned to v1.4.2 runs whatever last claimed it. Manages the tenancy-wide create-on-push switch off, creates repositories immutable and private, and lists any that are public or mutable when that is accepted.

View module