Skip to content

Rootform language is a closed, statically validated language for two jobs:

  • Dialects interpret managed and data resource instances from plan JSON or state JSON.
  • Policy Packs evaluate the resulting architecture without reading raw infrastructure values.

HCL supplies lexical syntax for .rf.hcl and .rf.json. Rootform defines the accepted blocks, attributes, expressions, references, types, defaults, and runtime meaning. General HCL or Terraform expressions are not implicitly part of RF.

This reference documents Rootform language version 0.1.0 and is normative. For motivation and worked examples, start with the learning path.

How to use this reference

Source units

PageContract covered
Syntax and filesSource discovery, native and JSON syntax, structural grammar, names, versions, and source-unit boundaries
Symbols and referencesCanonical IDs, local and qualified references, resolution, and duplicate rules
RF VocabularyComplete embedded rf.* vocabulary and exact meanings

Dialects

PageContract covered
Dialect declarationsdialect, provider, concept, context, and relation
Rules and matchingrule, match, managed and data instance kinds, predicates, and selection
Fact emissionscontext, relation, contribution, explicit attribute matching, and omissions
CompositionOrdered members, per-instance resolution, and unresolved-member reasons

Expression language

PageContract covered
ExpressionsLiteral types, expression grammars, operators, precedence, and rejected syntax
Traversals and scopesource, provider, target, member, path steps, and position rules
Built-insComplete signatures and parameters for exists, length, and architecture queries

Policies

PageContract covered
Policy Packspolicy_pack, policy, target, linking, messages, and target intersections
EvaluationRule precedence, three-valued evidence, query completeness, outcomes, and exit status

Diagnostics and limits: Stable codes, severity, source ranges, and all author-facing bounds

Construct index

Cardinality applies across one source root unless a placement says otherwise.

ConstructSource unitPlacementCardinalityLabelDetail
dialectDialectTop levelExactly 1RequiredDialect declarations
providerDialectInside dialect0 or more; at least 1 when unit has a RuleRequiredProvider block
conceptDialectTop level0 or moreRequiredSemantic definitions
context definitionDialectTop level0 or moreRequiredSemantic definitions
relation definitionDialectTop level0 or moreRequiredSemantic definitions
ruleDialectTop level0 or moreRequiredRules
identityDialectInside rule0 or 1ForbiddenIdentity and endpoint declarations
endpointDialectInside rule0 or 1ForbiddenIdentity and endpoint declarations
Rule matchDialectInside ruleExactly 1ForbiddenMatching
context emissionDialectInside rule0 or moreOptional, exclusive with asContext emission
relation emissionDialectInside rule0 or moreOptional, exclusive with asRelation emission
contribution emissionDialectInside rule0 or moreForbiddenContribution emission
Fact matchDialectInside an emission0 or 1ForbiddenExplicit attribute match
compositionDialectInside rule0 or 1ForbiddenComposition
memberDialectInside composition1 or moreRequiredMember
Member matchDialectInside memberExactly 1ForbiddenMember matching
policy_packPolicy PackTop levelExactly 1RequiredPolicy Pack manifest
policyPolicy PackTop level0 or moreRequiredPolicy
targetPolicy PackInside policyExactly 1ForbiddenTarget

Closed expression surface

AreaAccepted values
Literal valuesString, Boolean, non-negative number literal with exact signed 64-bit integer value
Unary operators!
Binary operators&&, ||, ==, !=, <, <=, >, >=
Traversal rootssource, provider, target, member.<name>, each restricted by position
Policy wrappersexists(query), length(query)
Policy queriescontexts(...), relations(...), contributions(...)

where and assert do not accept collections, object values, null, floating-point values, arithmetic, conditionals, comprehensions, splats, dynamic indexes, or arbitrary function calls. Static string fields use result-based constant HCL evaluation, and dedicated Policy target fields accept closed list syntax.

Reference conventions

Parameter tables use these meanings:

TermMeaning
RequiredAuthor must provide value or block.
OptionalAuthor may omit value or block.
DefaultValue compiler uses when optional attribute is absent.
StaticValue must evaluate in empty HCL context; variables and runtime data are unavailable.

Unknown attributes, blocks, functions, and expression shapes fail closed with a diagnostic. They are never preserved for later evaluation.