UpCloud Managed Database
Managed PG/MySQL with properties tuning, users, and logical DBs.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o upcloud-managed-database-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/upcloud-managed-database/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle upcloud-managed-database-1.0.0.sigstore.json \
upcloud-managed-database-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "7265c0e46ed183582fc58ebafe5793f7e3d38bbd6eba42022f13be37188d1df9 upcloud-managed-database-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "managed_database" {
source = "www.iac-bazaar.com/iac-bazaar/upcloud-managed-database/upcloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/upcloud-managed-database?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, static-verified on IaC Bazaar: [UpCloud Managed Database](https://www.iac-bazaar.com/catalog/upcloud-managed-database?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "managed_database" {
source = "www.iac-bazaar.com/iac-bazaar/upcloud-managed-database/upcloud"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
upcloud-managed-database
A hardened UpCloud Managed PostgreSQL service: private-by-default endpoint
with a deny-all IP filter, managed encrypted storage, termination
protection, a daily backup window, common tuning properties, and
declaratively-managed additional users and logical databases. Works with
Terraform and OpenTofu (>= 1.6), UpCloud provider >= 5.0, < 6.0.
EU/Nordic-sovereign infrastructure, MIT-licensed provider.
Status: static-validated, live-test pending. Validated with
tofu validate+tflint+checkovagainst theUpCloudLtd/upcloudprovider. Not yet applied against a live UpCloud account (no cloud sandbox yet; a managed service takes several minutes to provision), so it ships under live-test quarantine.
Design & secure defaults
- Not publicly exposed.
public_access = falseby default. The inboundip_filterdefaults to empty = deny all external sources; connect over the SDN private network or the utility-network allow list. A precondition refusespublic_access = trueunless you also supply anip_filter, so you can never open the database to all of the internet by accident. - Encryption + TLS are intrinsic to UpCloud Managed Databases (storage
encrypted at rest; connections require TLS — see the
sslmodeoutput). - Termination protection on by default — destroying the service is blocked until you flip the flag.
- Daily managed backups at a configurable UTC
backup_hour/backup_minute. - Per-engine resource model. This module uses the engine-specific
upcloud_managed_database_postgresql(not a generic resource), plusupcloud_managed_database_userandupcloud_managed_database_logical_database. - Secret hygiene. Users are keyed by username (non-sensitive
for_each); optional explicit passwords come from a separatesensitivemap, never used as a key. Generated passwords and the connection URI are exported as sensitive outputs.
Requirements
| Requirement | Version |
|---|---|
| Terraform / OpenTofu | >= 1.6 |
UpCloudLtd/upcloud | >= 5.0, < 6.0 |
License
Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
upcloud-valkey
An UpCloud Managed Valkey service attached to your SDN private network with public access off (on by name) and an IP filter of the ranges that may connect, TLS on, RDB persistence with a nightly backup, an eviction policy set, service logs on, a maintenance window you chose, and termination protection (off by name). The password is generated and the URI is a sensitive output.
civo-database
firewall_id is optional and a database without one answers to every address that can reach its endpoint; nodes = 1 is one node whose failure is downtime; and backups are the platform's, not configurable here. Firewall and network required, two nodes (one by name), the password as a sensitive output, and an output that says no backup schedule can be set.
vultr-database
A managed database gets a public hostname and trusted_ips is optional: left empty, any address on the internet may try the password; the backup hour is picked for you; and a plan with no replicas is one node whose failure is downtime. Trusted ranges required (a /0 refused unless accepted), a VPC attachment, one standby by default, both windows set, and the password as a sensitive output.
azure-sql-managed-instance
The public data endpoint turns a private database into one listening on the internet on port 3342; SQL logins put an administrator password in state when Entra-only authentication would remove them entirely; and zone redundancy is off by default. Private, Entra-only with SQL authentication accepted by name, Business Critical across zones, TLS 1.2, and geo-zone-redundant backups.
oci-postgresql
password_type PLAIN_TEXT writes the admin password into the Terraform state and every plan that shows it; storage that is not regionally durable dies with its availability domain; and a DB system created without a management policy takes no backups. Vault secret reference, regionally durable storage, daily backups optionally copied to another region, a read replica, and an NSG on port 5432.
gcp-alloydb
AlloyDB cluster with primary + read-pool instances, PSC connectivity, automated backups and columnar/vector engine flags.