compliance.tf

What is a Terraform module registry?

A Terraform module registry is a service that stores versioned Terraform modules and delivers them to Terraform or OpenTofu via the module registry protocol, letting a source address plus a version constraint point to a module that can be downloaded.

How it works

Terraform reads every module source while installing modules, which happens during terraform init or terraform get. If the source points at a registry, Terraform performs service discovery on the hostname to locate the registry API, enumerates the published versions, selects the newest release satisfying the version constraint, and fetches it. Once a module is installed, Terraform retains it as long as the source stays the same and the version still fits the constraint; running terraform init -upgrade or terraform get -update looks for a newer match. The public registry lives at registry.terraform.io. Private registries speak the same protocol under their own hostname and typically ask for a token.

There are two ways to reference a module:

FormExampleAuthenticationVersion selection
Registry addresssoc2.compliance.tf/terraform-aws-modules/s3-bucket/awsToken from terraform login, or a TF_TOKEN_* variable (Terraform 1.2 or newer, or OpenTofu)Set with the version argument; constraints like ~> 5.0
HTTPS URLhttps://soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws?version=5.0.0.netrcPassed as the ?version= query parameter

Terraform talks to the registry only during module installation. Later commands such as plan and apply work from the downloaded copy.

How compliance.tf applies it

compliance.tf runs as a private Terraform registry that publishes hardened builds of the open-source terraform-aws-modules. Which controls apply depends on the hostname: soc2.compliance.tf returns modules carrying SOC 2 controls, while hipaa.compliance.tf returns them with HIPAA controls. An organization endpoint, <alias>.compliance.tf, serves that organization's own published configuration.

terraform login soc2.compliance.tf   # or: tofu login soc2.compliance.tf

For CI pipelines, place a long-lived token in TF_TOKEN_soc2_compliance_tf rather than running terraform login. This variable requires Terraform 1.2 or later; with older releases, add the token to the CLI configuration file instead.

When a requested terraform-aws-modules/* module is missing from the compliance.tf catalog, the request falls back to registry.terraform.io. Modules served through fallback receive no compliance controls by default. Any request for another namespace returns 404.

Sources

On this page

Ask AI about this

Help improve this page