Glossary
This glossary defines the vocabulary that appears throughout the compliance.tf documentation and states what each term implies for a Terraform or OpenTofu codebase. Every entry starts with a single-paragraph meaning, then explains how compliance.tf uses the concept and the point where its coverage ends.
Foundations
- Compliance-as-code - requirements encoded as code, with automated checks performed by tooling.
- Policy-as-code - Rego or Sentinel rules that a policy engine applies to a plan.
- Preventive vs detective controls - blocking a bad change before it is applied, versus detecting it afterward.
- Terraform module registry - the service and protocol behind versioned module distribution, including private registries.
Migration and compatibility
- Brownfield Terraform migration - shifting already managed infrastructure onto new modules while avoiding recreation.
- terraform-aws-modules compatibility - matching the upstream module's inputs and outputs.
- Module version pinning - setting the exact module version that each
terraform initretrieves. - OpenTofu compatibility - modules and registries that operate with OpenTofu in addition to Terraform.
Evidence and scope
- Terraform audit evidence - records demonstrating that a control was present.
- Control mapping - connecting a technical control with requirement IDs from a framework.
- Compliance scope boundary - the line between what a tool covers and the responsibilities left with you.
- IaC compliance scanning - checking HCL or plan JSON for rule violations ahead of deployment.
- SARIF - the standard JSON representation for static analysis results.
Governance and change control
- Operational Rules - Terraform standards set for the whole organization and applied during module download.
- Terraform lifecycle rules -
prevent_destroy,ignore_changesandcreate_before_destroy. - Control overrides - turning individual controls on or off for each module.
- Config snapshot - a published copy of a compliance configuration that cannot be changed.
- Promotion gate - the check a change must clear before reaching the next environment.