Terraform errors and module diffs you can reproduce
Terraform will not accept lifecycle on a module call. It also rejects
prevent_destroy = var.prevent_destroy inside a resource. Start with those two
errors, then read the literal lifecycle block inserted into the module's HCL.
These walkthroughs give you the output before the setup. The captured preview demos run without an account or AWS credentials; authenticated results awaiting capture are labeled where they would appear.
| Start with your question | Walkthrough | Evidence available |
|---|---|---|
Why can I not pass prevent_destroy into a module? | Terraform rejects both attempts | Terraform errors and rule-preview diffs |
| What would the registry change in my module? | Read the diff before changing your source | S3 lifecycle diff, scope and API refusals |
| Where should I enforce access logging? | Find missing S3 logging, then test a source change | Checkov finding and source configuration; authenticated plans await capture |
Run the captured examples first
git clone https://github.com/antonbabenko/compliance.tf-demo
cd compliance.tf-demo
make demo-03
make demo-02
make -C scenarios/02-free-preview refusalsAfter cloning, the replay commands need make, bash and jq, and make no
network requests.
Scenario 03's make problem reproduces the errors using your Terraform;
scenario 02's make live makes a fresh public API request.
A source diff answers a specific question
Operational rules change module code at download time, for example by adding
lifecycle settings to resources. The public preview shows those code changes.
It does not download an installable module, run a plan or touch AWS.
Framework controls address requirements such as logging and encryption. Testing an authenticated framework module is a separate step. Neither a code diff nor a successful plan establishes that an account passes an audit.
The repository also contains a three-framework comparison setup. It holds the caller inputs and version constant, but its served-module captures are still missing. Read it as a procedure to run, not a comparison result.