# Module Sources and Versions — Terraform

Source: https://www.skillbyai.com/en/terraform/m-sources

> Registry, git and local paths.

## Pin what you reuse

Modules can come from a local path (`./modules/service`), the public or a private **registry** (`terraform-aws-modules/vpc/aws` with a `version` constraint), or a git repository pinned to a tag (`git::https://...?ref=v1.4.0`). Pin versions so upgrades are deliberate, read the module's inputs and what it creates, and review changelogs before upgrading; a popular module can still create resources you did not expect.

## Module source examples

Not run here; it needs a cloud account or a remote backend.

```hcl
module "vpc" {
  source  = "terraform-aws-modules/vpc/aws"     # public registry
  version = "~> 5.8"
  name    = "shop"
  cidr    = "10.0.0.0/16"
}

module "service" {
  source = "git::https://github.com/acme/tf-modules.git//service?ref=v1.4.0"   # pinned tag
}
```

## Run plan after module upgrades

Upgrade one module at a time and read the plan; module changes can rename or replace resources.

**Quiz:** Why pin module versions?

- [ ] Unpinned modules cannot be used
- [ ] Pinning makes modules free
- [x] So upgrades happen deliberately after review, not silently
- [ ] Versions are only for providers

*Answer:* So upgrades happen deliberately after review, not silently. Reproducible builds need pinned inputs.
