What is terraform-aws-modules compatibility?
terraform-aws-modules compatibility means a module accepts the same input variables and returns the same outputs as the matching entry in the open-source terraform-aws-modules collection, so it can replace that module with a change to the source line only.
Why it matters
terraform-aws-modules ranks among the most widely used Terraform module collections. For a team already calling those modules, their interfaces are baked into variables, .tfvars files, outputs and downstream references. A compatible replacement keeps all of that working, so adoption starts as a one-line change per module and then turns to any control failures reported by the plan.
What stays the same and what can change
| Stays the same | Can change |
|---|---|
| Names and types of input variables | A value that violates a control now fails during terraform plan |
| Output names and returned values | Secure defaults apply when no value was set |
| Resource layout and Terraform state | Available versions (see below) |
| AWS provider requirements |
The interface remains fixed. Behavior shifts where a control requires that shift, and a few controls can make Terraform recreate a resource; see brownfield Terraform migration.
How compliance.tf applies it
Every module in the compliance.tf catalog is interface-compatible with the matching upstream terraform-aws-modules module and requires no provider changes. Each module is built against specific upstream major versions; find them on the version compatibility page. If your deployment uses an older upstream major version, upgrade the upstream module first and migrate to compliance.tf as a separate change. New upstream versions reach compliance.tf the same day.
A module outside the catalog is proxied from registry.terraform.io and has no controls. Confirm coverage in the module catalog before counting on a control.