A Policy Pack is an independent source unit. It owns a name, version, and Policies. This guide uses the public baseline Pack with the Azure commerce plan, which contains a Kubernetes cluster and a managed database. A Policy observes architectural facts; it never creates them. Exact RF Vocabulary and Dialect identities are derived when the Pack is linked.
baseline/├── pack.rf.hcl├── policies/│ ├── cluster-network-context.rf.hcl│ └── managed-database-network-context.rf.hcl├── LICENSE└── NOTICERootform discovers .rf.hcl and .rf.json recursively. Exactly one
policy_pack declaration owns every top-level policy below this root.
policy_pack "baseline" { version = "0.1.0"}policy "cluster-network-context" { target { concept = rf.concept.kubernetes-cluster }
assert = ( exists(contexts(rf.context.network, rf.concept.virtual-network)) || exists(contexts(rf.context.network, rf.concept.subnet)) )
message = "Kubernetes clusters must belong to a network context."}policy "managed-database-network-context" { target { concept = rf.concept.managed-database }
assert = ( exists(contexts(rf.context.network, rf.concept.virtual-network)) || exists(contexts(rf.context.network, rf.concept.subnet)) )
message = "Managed databases must belong to a network context."}These two Policy blocks reproduce the baseline source.
For the evidence model behind an assertion, read Policies over facts.
-
policy_pack "baseline"establishes source identity. Policy IDs use owner-first syntax, for examplebaseline.policy.cluster-network-context. Names use lowercase kebab case. Version is exactMAJOR.MINOR.PATCH.No
requiresblock exists. Policies use qualified references only. Linking resolves each referenced owner and symbol against the Form, then records exact versions and digests in the compiled Pack. -
Each Policy has one target block. The baseline targets shared Concepts, so they can select matching Rules from different provider Dialects. The commerce walkthrough uses Azure. The target below is an AWS-only variant of the cluster Policy; keep its provider filters separate from the baseline used in this walkthrough.
AWS-only target variant RFtarget {concept = rf.concept.kubernetes-clusterrules = [aws.rule.eks-cluster]dialects = ["aws"]}At least
conceptorrulesis required. Values within each list are OR; present dimensions combine with AND.dialectsfilters owner of applied Rule. One selected Representation is evaluated once. Base Representation without matching Concept or applied Rule is not selected. -
From the Rootform repository root, run the Azure commerce plan against the baseline Pack. Its saved plan pairs with the plan JSON and supplies the traversals needed to decide these network contexts. Plan inputs shows how to export both files from your own project with
terraformortofu. Saved plans and plan JSON can contain secrets in clear text; keep yours out of Git and public artifacts. Rootform reads them locally and keeps sensitive values out of its outputs.Shellrootform run examples/playground/commerce-platform/head/plan.json \--plan-file examples/playground/commerce-platform/head/plan.tfplan \--no-serve -o analysis.jsonrootform check analysis.json --policy-pack ./policy-packs/baseline --color alwaysrootform list policies --policy-pack ./policy-packs/baselinerootform show policy baseline.policy.cluster-network-context \--policy-pack ./policy-packs/baselinePassing result, excerpt OUTPUTPolicy check completedPolicies 2 selectedEvaluations 2Passed 2Verdict PASSEDThe check summary reports both selected targets passing and exits
0. A violation exits1; indeterminate evidence or no selected decision exits3. The latter two are not passes.listnames both qualified Policies, whileshowprints the target and assertion without evaluating it. If a context is indeterminate, inspect the instance closure and confirm that the saved plan matches the JSON. The local override lasts one command and leavesrootform.lockunchanged.The check walkthrough shows violations, indeterminate closures, and no-target results on small plans.
Save the linked Pack against the Form when replay must use that exact semantic selection.
analysis.jsoncame from the preceding run:Shellrootform compile policy-pack ./policy-packs/baseline --semantics analysis.json \--output baseline.compiled.jsonrootform check analysis.json --policy-pack baseline.compiled.json --color alwaysThe compile command prints the Pack, semantic-pin count and destination. The check loads the Form without recompiling the plan and reports Policy outcomes with the check exit status. The compiled artifact records the authored content digest, linked digest, language version, and exact semantic identities. A mismatch fails closed. When the project should retain the source Pack, use
rootform add policy-packs ./policy-packs/baselinefrom that project root and commit the Pack source withrootform.lock. -
Packaging is local and offline:
Shellrootform package policy-packs ./policy-packs/baseline \--to ./artifacts/policies \--source-url https://example.com/team/policies \--documentation-url https://example.com/team/policies/docs \--licenses Apache-2.0The result names the Pack and local destination. Record the reviewed source revision with
--revisionwhen your publication process requires that provenance. Packaging itself sends nothing to a registry. Publication is separate and generic:Shellrootform publish policy-packs ./artifacts/policies \--to registry.example.com/team/policy-packsV0 has no mutable Policy Pack index. Existing version tag with different digest is rejected.
-
From the project root, add the published reference, then prepare its exact selection:
Shellcd ./infrarootform add policy-packs \registry.example.com/team/policy-packs:policy-pack-baseline-0.1.0rootform init . --locked --no-inputAfter exporting a plan for this project, evaluate the selected Pack with
rootform check plan.json --locked.The registry reference is illustrative; replace it with the published one you reviewed.
addrecords digests without hand editing the lock. SetDOCKER_CONFIGbefore acquisition if the registry needs credentials. See External content storage for paths.
See Policy Pack reference,
evaluation, and
compiled-policy-pack.schema.json.