compliance.tf

What is compliance-as-code?

Compliance-as-code means writing regulatory and security requirements as code kept under version control, which automated tooling then evaluates so that infrastructure gets checked against those requirements prior to or during deployment.

How it works

Take a requirement like "data at rest must be encrypted". It begins as prose inside a framework such as SOC 2, PCI DSS or HIPAA, and compliance-as-code converts it into a technical check. That check sits in a repository alongside the infrastructure code and executes on every change. It can live in three common places:

ApproachWhere the check runsWhat happens on a violation
Policy-as-codeA policy engine evaluates the Terraform planThe plan gets rejected
IaC compliance scanningA scanner inspects HCL or plan JSON in CIA finding is raised
Controls built into modulesThe module itself, during terraform planThe plan fails with a validation error

Since the checks themselves are code, they are reviewed, versioned and reproducible. An auditor can then see a record of which rule applied to which change, rather than a policy document that might not reflect what was actually deployed.

How compliance.tf applies it

compliance.tf places the controls directly inside the Terraform module. Every module served from a framework endpoint works as a drop-in replacement for the matching terraform-aws-modules module, and it carries that framework's controls as built-in module defaults together with input validation. When a value violates a control, terraform plan fails, and the error identifies the control along with the frameworks that require it.

module "logs" {
  source  = "soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws"
  version = "~> 5.0"

  bucket = "example-logs"
}

With a framework endpoint, the controls are versioned together with the module, so pinning an exact module version pins the controls enforced by that version as well.

Limits

Technical configuration is the scope of compliance-as-code. Organizational, HR, physical, incident-response and access-management controls still demand their own evidence, and compliance.tf enforces controls only on resources created through its modules. See compliance scope boundary.

Sources

On this page

Ask AI about this

Help improve this page