What are Operational Rules?
Operational Rules are organization-wide Terraform standards, such as lifecycle settings, allowed regions or deletion protection, that compliance.tf applies to modules as they are downloaded from its registry, apart from compliance controls.
The problem they solve
Some standards cannot be expressed through a module's inputs. Terraform accepts only literal values for prevent_destroy, ignore_changes and create_before_destroy, which means a reusable module cannot expose a switch that lets callers set prevent_destroy. OpenTofu 1.12 and later permits an expression in prevent_destroy alone, and only a module written to use that expression benefits. A wrapper module also cannot attach lifecycle settings to resources inside the module it calls; teams that need those settings fork the module and then carry the fork. Operational Rules instead put the standard into the module code at download time, with no fork and no wrapper module.
Rules compared with controls
| Compliance controls | Operational Rules | |
|---|---|---|
| Purpose | Serve a framework requirement | Impose an organization's operating standard |
| Chosen by | The framework endpoint | The organization |
| Order | Run first | Run second |
| Audit use | Point to framework requirement IDs | Not regulatory controls |
What the catalog covers
The rule catalog lists rules that:
- Block destruction of data stores and encryption resources.
- Ignore out-of-Terraform changes to tags, AMIs, autoscaled capacity, deployed artifacts and rotated secrets.
- Apply
create_before_destroyto security groups and certificates. - Strip provisioner blocks.
- Limit instance types and regions.
- Enable deletion protection.
- Require S3 lifecycle rules that abort multipart uploads left incomplete.
For the lifecycle settings, see Terraform lifecycle rules.
Baseline and rulesets
An organization's Baseline is the rule collection applied to each module that organization pulls down. A named ruleset is an additional bundle that a module call picks by name. A rules state toggle gates them through the Disabled, Preview and Enforced positions; only Enforced applies them. With Disabled or Preview, the Baseline and rulesets stay saved and visible in the dashboard, but downloads do not get them. A rule change reaches a workspace when that workspace next performs a fresh download, so run terraform init -upgrade where the module is already cached.
Rules behave the same with Terraform and OpenTofu. Custom rules are not offered yet.