Skip to content

RF Vocabulary is Rootform's embedded cross-Dialect vocabulary. Its owner is rf; its version is 0.1.0.

It is not an installable Dialect, local extension, or Policy Pack. Authors do not declare or download it. Compiler records exact vocabulary dependency when a Dialect or Policy Pack references an rf.* symbol.

Concepts

IDExact contract
rf.concept.kubernetes-clusterA declared Kubernetes cluster, excluding namespaces, node pools, and workload groups.
rf.concept.managed-databaseA managed database service or instance, excluding logical tables and databases.
rf.concept.object-storage-containerAn object storage container, excluding multi-service storage accounts.
rf.concept.service-identityA principal explicitly intended for a non-human service or workload, excluding generic roles, permissions, bindings, and credentials.
rf.concept.subnetA declared native subnet, not a CIDR literal.
rf.concept.virtual-networkAn explicitly declared virtual network.

These boundaries are normative. For example, a logical database inside a managed service is not rf.concept.managed-database, and a role is not rf.concept.service-identity.

Contexts

IDExact contract
rf.context.networkA declared network attachment without a connectivity guarantee.
rf.context.runtimeA declared execution environment or target without proof of effective execution.

A network Context records declared attachment. It does not prove routing, reachability, firewall allowance, or runtime traffic. A runtime Context records declared execution placement. It does not prove that execution happened.

Unsupported kinds

RF Vocabulary 0.1.0 defines:

  • six Concepts;
  • two Contexts;
  • no Relations;
  • no Rules.

Therefore rf.relation.* and rf.rule.* are invalid references.

Using RF Vocabulary in a Dialect

subnet.rf.hcl RF
rule "subnet" {
match {
type = "example_subnet"
}
as = rf.concept.subnet
context {
as = rf.context.network
to = rf.concept.virtual-network
via = source.network_id
on_null = "absent"
on_empty = "absent"
}
}

Use an RF symbol only when provider-specific meaning satisfies its complete contract. Frequency or a similar name is insufficient.

Using RF Vocabulary in a Policy Pack

network policy RF
policy "subnet-has-network-context" {
target {
concept = rf.concept.subnet
}
assert = exists(
contexts(rf.context.network, rf.concept.virtual-network)
)
message = "Each subnet must declare its virtual network."
}

Policy references are always owner-qualified, so rf. prefix is required. Linking verifies exact vocabulary version and semantic digest against the Form.