Description
A Terraform module fetched through a git::https://... source without a ?ref= revision uses the remote repository’s default branch. Installing or updating the module can fetch different code as that branch changes.
Selecting a reviewed module version makes changes easier to control. Branches and tags can move to other commits; use a reviewed full commit hash when the same code must be reproducible.
Potential impact
- Unexpected module changes can alter infrastructure behavior.
- It can become harder to distinguish module changes from changes to your own code when investigating a failed deployment.
- Unreviewed changes can reach production.
Remediation
Specify a reviewed revision with ?ref= in the Git module source. Use a full commit hash when an immutable reference is required, and review and test module upgrades before applying them.
Examples
These excerpts compare Git module references. Replace the example.com address with the actual module repository.
Before
module "network" {
source = "git::https://example.com/terraform-modules/network.git"
}
After
module "network" {
source = "git::https://example.com/terraform-modules/network.git?ref=v1.4.2"
}
The after-example selects the v1.4.2 tag. If the tag moves, the fetched code can change, so this setting alone does not make the reference immutable.