compliance.tf

What are control overrides?

Control overrides are module-scoped adjustments to the compliance controls enforced by a compliance.tf module, declared by appending enable or disable query parameters to an HTTPS module source URL.

Why they exist

No framework ships a control set that suits every resource. Take Object Lock retention for data already stored in a bucket: it must run against every existing object version, which is seldom worth the effort in a development account. With an override, a team can turn one control off for a single module, or turn on a control the framework omits, while still using the registry.

How it works

Use the HTTPS URL form of the module source for overrides; the registry address form carries no query string.

module "s3_bucket" {
  source = "https://soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws?version=5.0.0&disable=s3_bucket_object_lock_enabled"

  bucket = "my-app-data-dev"
}
source = "https://soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws?version=5.0.0&enable=s3_bucket_default_encryption_enabled_kms"

On the canonical endpoint, registry.compliance.tf, no controls are enforced; there, enable is the mechanism for selecting controls individually.

Where overrides are not accepted

  • Organization endpoints (<alias>.compliance.tf) reject enable and disable with an HTTP 400 error. On those endpoints the control set comes from the organization's published config snapshot; edit the config and promote a fresh snapshot instead.
  • The free plan cannot turn controls outside CIS v6.0 on or off. See Plans and entitlements.

Overrides and audits

Because an override lives in the module source, it remains visible in Git history and in .terraform/modules/modules.json. Handle it as an exception: write down the reason, any compensating control, and the approver. ctfkit, the compliance.tf CI checker, flags a disabled control as a finding, so the exception appears in CI too.

Sources

On this page

Ask AI about this

Help improve this page