A subnet belongs to a VPC. This tour teaches how a Rule turns that reference into network Context, then how a Policy checks the established fact.
Start with the two-resource VPC and subnet plan from
Trace a placement. Keep its plan.json
and matching plan.tfplan in your working directory. The subnet's vpc_id is
unknown before apply, but its configuration directly references aws_vpc.main.id.
The plan-input guide gives export commands for both producers.
-
Save these files beneath
./aws. This example uses the embedded AWS owner for a command-local source override; a distributable Dialect uses your own owner.aws/dialect.rf.hcl RFdialect "aws" {version = "0.1.0"provider "hashicorp/aws" {version = "= 6.62.0"}}The source root supplies identity and a provider binding. Files do not create imports or matching priority. The
rfowner names the embedded RF Vocabulary. - aws/network/vpc.rf.hcl RFrule "vpc" {match {kind = "resource"type = "aws_vpc"}as = rf.concept.virtual-networkidentity {attributes = ["id"]}endpoint {attributes = ["id"]}}rule "subnet" {match {kind = "resource"type = "aws_subnet"}as = rf.concept.subnetcontext {as = rf.context.networkto = rf.concept.virtual-networkvia = source.vpc_idon_null = "absent"on_empty = "absent"match {by = target.idstrategy = "exact"}}}
Every instance already has a Representation.
asclassifies the VPC and subnet. The VPC'sidentitymakes its knownidavailable for value matching;endpointallows a verified reference to that ID to name the instance before the value is known. The subnet's Context readssource.vpc_idand requires a virtual-network target. Its nestedmatchsupplies the value-comparison route. - Shellrootform validate dialects ./awsrootform run plan.json --plan-file plan.tfplan --dialect ./aws \--no-serve -o analysis.json
In
analysis.json, the Planned stage contains both Representations, a network Context fromaws_subnet.applicationtoaws_vpc.main, and aresolvedclosure. Its fact provenance recordstraversal: the saved plan identifies the endpoint without requiring the unknown ID. The Form records the evidence behind that claim. No live cloud connection was tested. - Shellrootform run plan.json --dialect ./aws --no-serve -o values-only.json
The two instances retain their classification. The unknown
vpc_idcannot establish the Context alone, so its closure isindeterminate(unknown_until_apply). A known ID could resolve by value matching when target identity and provider compatibility are established. The saved plan is optional enrichment, not an architectural input requirement. -
Save the manifest and Policy beneath
./policies:policies/pack.rf.hcl RFpolicy_pack "tutorial" {version = "0.1.0"}policies/subnet-network-context.rf.hcl RFpolicy "subnet-network-context" {target {concept = rf.concept.subnet}assert = exists(contexts(rf.context.network, rf.concept.virtual-network))message = "Subnets must have an established virtual network context."}Shellrootform check analysis.json --policy-pack ./policiesThe subnet has one confirmed network Context, so this Policy passes with exit
0. The check reads the saved Form; it does not rebuild the architecture.Shellrootform check values-only.json --policy-pack ./policiesThis check is indeterminate and exits
3. Zero confirmed facts under an indeterminate closure do not prove that the subnet lacks a VPC. To prove absence, the Rule would need known evidence under its declared null/empty policy and a complete relevant population.
Read a Rule explains the complete official version. Evidence and target resolution covers known values, state evidence, ambiguity and external endpoints. Then follow Write a Dialect or Write a Policy Pack to author your own source.