An Origin CA Certificate Whose Private Key Never Enters the Terraform State
A certificate for the hop between Cloudflare and your origin. It is trusted by Cloudflare and by nothing else, so it is right only when the origin accepts Cloudflare alone. A CSR is required precisely so the key stays where it was generated, and the validity is one year rather than the fifteen the API offers, since that is how long a leaked key stays usable.
This is the operations reference: version drift, dependants and neighbours. For what the module provisions, its inputs and outputs, and how to buy it, see the catalogue entry.
Provider drift
This artifact declares no Terraform provider requirements, so there is nothing to drift. Provider freshness applies to Terraform and OpenTofu modules.
What depends on this
No reference architecture names this module, so changing it affects only configurations that reference it directly.
Nearest alternatives
Nothing else in the catalogue covers secrets & kms on Cloudflare. If this module is not the right shape, the closest options are on other clouds.
The same job on other clouds
Managed TLS Certificates on other providers. Useful when the cloud is still open, or when you are pricing a second one. How far a comparison like that can be trusted is covered in comparing clouds.
Installing it
module "cloudflare_origin_ca_certificate" {
source = "www.iac-bazaar.com/iac-bazaar/cloudflare-origin-ca-certificate/cloudflare"
version = "1.0.0"
}A registry token is required for the download itself. Installing through the registry protocol has the two credential steps.