OVHcloud Managed Kubernetes
MKS cluster with node pools and private-network (vRack) attachment.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o ovh-managed-k8s-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/ovh-managed-k8s/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle ovh-managed-k8s-1.0.0.sigstore.json \
ovh-managed-k8s-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "de5fe46537e1ed967a579eefcf2013bbc9dbc66f74a7eb40fc4a7a14190a16b2 ovh-managed-k8s-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "managed_k8s" {
source = "www.iac-bazaar.com/iac-bazaar/ovh-managed-k8s/ovh"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Premium, so its contract unlocks when you buy it.
Documentation
ovh-managed-k8s
An OVHcloud Managed Kubernetes (MKS) cluster: private-network-attached (vRack), with one or more node pools that autoscale by default, a hardened API server, and a free control plane (you pay only for worker nodes).
Status: static-validated, live-test pending. Validated with
tofu validate+tflint+checkovagainst theovh/ovhprovider. Not yet applied against a live OVHcloud project, so it ships under live-test quarantine (no cloud sandbox account yet).
Design & secure defaults
- Private network by default. The module creates a dedicated vRack private
network and a subnet for the workers, attaches the cluster to it via the
per-region OpenStack network id, so the node/kubelet network is not on the
public interface. Node egress defaults to the public interface
(
private_network_routing_as_default = false) so the cluster has working outbound internet out of the box; set it totrueonly after adding a vRack gateway. Pass an existing network withcreate_private_network = false+private_network_id(the OpenStack network id) +nodes_subnet_id. - API-server hardening. The
NodeRestrictionadmission plugin is enabled by default; add/remove plugins viaapiserver_admission_plugins_*. - Controlled upgrades.
update_policy = "MINIMAL_DOWNTIME"keeps the control plane patched without a full-cluster outage (useNEVER_UPDATEto pin). - Autoscaling node pools. Each pool autoscales between
min_nodesandmax_nodes; a precondition enforcesmin_nodes <= max_nodes. Pool names may not contain underscores (an OVH constraint).anti_affinityspreads nodes across hypervisors for resilience. - No hardcoded secrets. Credentials come from the provider block /
environment; the generated
kubeconfigoutput is markedsensitive.
Provider
ovh/ovh >= 2.0, < 3.0. Requires Terraform/OpenTofu >= 1.6.
License
Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Key inputs
- Outputs
Related modules
Alibaba Cloud ACK Cluster
Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.
Azure Kubernetes Service Cluster
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
Civo Kubernetes Cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
DigitalOcean DOKS Cluster
Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.
EKS Cluster with Managed Node Groups
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
Exoscale SKS Cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.