What is a Terraform module registry?
A Terraform module registry is a service that stores versioned Terraform modules and delivers them to Terraform or OpenTofu via the module registry protocol, letting a source address plus a version constraint point to a module that can be downloaded.
How it works
Terraform reads every module source while installing modules, which happens during terraform init or terraform get. If the source points at a registry, Terraform performs service discovery on the hostname to locate the registry API, enumerates the published versions, selects the newest release satisfying the version constraint, and fetches it. Once a module is installed, Terraform retains it as long as the source stays the same and the version still fits the constraint; running terraform init -upgrade or terraform get -update looks for a newer match. The public registry lives at registry.terraform.io. Private registries speak the same protocol under their own hostname and typically ask for a token.
There are two ways to reference a module:
| Form | Example | Authentication | Version selection |
|---|---|---|---|
| Registry address | soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws | Token from terraform login, or a TF_TOKEN_* variable (Terraform 1.2 or newer, or OpenTofu) | Set with the version argument; constraints like ~> 5.0 |
| HTTPS URL | https://soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws?version=5.0.0 | .netrc | Passed as the ?version= query parameter |
Terraform talks to the registry only during module installation. Later commands such as plan and apply work from the downloaded copy.
How compliance.tf applies it
compliance.tf runs as a private Terraform registry that publishes hardened builds of the open-source terraform-aws-modules. Which controls apply depends on the hostname: soc2.compliance.tf returns modules carrying SOC 2 controls, while hipaa.compliance.tf returns them with HIPAA controls. An organization endpoint, <alias>.compliance.tf, serves that organization's own published configuration.
terraform login soc2.compliance.tf # or: tofu login soc2.compliance.tfFor CI pipelines, place a long-lived token in TF_TOKEN_soc2_compliance_tf rather than running terraform login. This variable requires Terraform 1.2 or later; with older releases, add the token to the CLI configuration file instead.
When a requested terraform-aws-modules/* module is missing from the compliance.tf catalog, the request falls back to registry.terraform.io. Modules served through fallback receive no compliance controls by default. Any request for another namespace returns 404.