Object Storage Reachable from Where You Say with a User, Policy and Key of Its Own
A service answers on the networks attached to it, and a public network makes the S3 endpoint an internet endpoint; a user has no access until a policy is attached and no key until one is created; and the service has no versioning and no lifecycle. Private by default with public by name, buckets, a user with the policy you name and one key, and outputs that say what is not available.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "object_storage" {
source = "www.iac-bazaar.com/iac-bazaar/upcloud-object-storage/upcloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
upcloud-object-storage
An UpCloud Managed Object Storage service with a bucket, a user of its
own, a scoped policy and a key, reachable from where you say. Works with
Terraform and OpenTofu (>= 1.6), UpCloudLtd/upcloud provider
>= 5.0, < 6.0.
A service is reachable from where its networks say. Private by
default; public_endpoint needs accept_public_endpoint.
A user has no access until a policy is attached; user, policy and key are created together.
No versioning, no lifecycle; the outputs say so.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
upcloud-storage
encrypt defaults to false and cannot change after creation; and the backup rule is the rare schedule that lives on the device itself, so it cannot be forgotten separately but can still be left out. Encryption on, a daily backup at 02:00 UTC kept 30 days unless told otherwise (none by name), filesystem resize opt-in, and the device attached from the server side in its zone.
scaleway-object-bucket
Versioning is off by default and one-way; object lock can only be decided at creation; the bucket's own ACL attribute is deprecated, so a private ACL is written separately or never set; and abandoned uploads bill until a rule aborts them. Versioning on and off by name, lock with a default retention when asked, the private ACL explicit, incomplete uploads freed after a week, old versions expiring.
tencent-cos-bucket
A COS bucket name carries the account's APPID; versioning is off by default and once on can only be suspended; encryption at rest is off until an algorithm is named; and abandoned multipart uploads bill until a rule aborts them. The two name halves joined, private with public by name, versioning on, AES256 or your KMS key, object lock decided at creation, incomplete uploads freed after a week.
ibm-cos-bucket
Versioning is off by default; encryption is IBM-managed unless a Key Protect root key is given; allowed_ip is an allow list nobody sets, so any address that authenticates reaches the bucket; and a WORM retention rule cannot be removed once set. Versioning on with off by name, your root key when given, allowed ranges taken, retention optional, incomplete uploads freed after a week.
do-spaces-bucket
A public-read ACL is a bucket listing on the internet, versioning is off by default, and an abandoned multipart upload bills until a lifecycle rule aborts it. Private with a policy that denies anonymous and non-TLS access, versioning on with superseded versions expiring so the bill stops growing, incomplete uploads freed after a week, and public read or no versioning accepted by name.
aws-s3-bucket
Private S3 bucket with encryption, versioning, public-access block, and TLS-only policy.