Skip to content

A

Architecture

The content of one stage in a Form, including its Representations, architectural facts, closures, and evidence.

C

Carried

An instance retained in Planned because the plan neither changes nor deletes it. The plan did not evaluate it, so missing evidence from a carried instance cannot establish a Policy pass or violation. See partial knowledge.

Closure

A Rule's record of fact resolution for one instance. Each declaration of a Context, Relation, or Contribution has its own closure:

OutcomeMeaning
resolvedAll relevant evidence is settled and the fact set is nonempty.
absentAll relevant evidence is settled and the fact set is empty.
indeterminateEvidence leaves part of the answer unsettled. Established facts may still be present.

Comparison

An architectural comparison between selected stages. One plan can show Planned changes, Reported drift, and Net change; two separate inputs produce Differences.

Composition

A Rule-defined group of implementation members under one root instance. Members keep their own Representations and do not inherit the root's Concept.

Concept

An architectural classification assigned by a Rule, such as subnet or managed database. An instance can be represented without a Concept.

Context

A fact that places an instance in an architectural frame, such as a subnet in a virtual network. Network placement alone does not establish runtime reachability.

Contribution

A directed fact stating that one Representation contributes to another. Contributor and target remain distinct.

Current context

The location open in the Explorer, whose direct contents appear on the canvas. This navigation label identifies the current scene; Context names an architectural placement fact.

D

Deferred

An instance whose action the plan leaves for later. Its population remains unverified, and a Policy evaluation that needs evidence from it stays indeterminate. See incomplete plans and deferred actions.

Dialect

A named, versioned unit of interpretation whose Rules match Terraform or OpenTofu instances and establish architectural meaning. Changing the active Dialects can change the interpretation of the same input.

Differences

The comparison between two separate inputs, using one selected stage from each. It shows how their architectures differ without establishing what drifted between the exports.

Drift report

The plan's reported drift records and their architectural consequences. It is separate from the Reported drift comparison; an empty report does not prove that live infrastructure is unchanged.

E

Embedded

Content that ships inside the Rootform binary. The official Dialects and RF Vocabulary are embedded and available without installation.

Enrichment

Additional configuration evidence read from a paired saved plan. It can identify a direct reference when the planned value is unknown until apply.

Evidence

The information available to establish architecture: plan or state instances, evaluated values, sensitivity masks, and supported references. A paired saved plan adds configuration traversals; Evidence in the Inspector shows the basis and limits of an instance's interpretation.

External endpoint

A target outside the input's represented inventory that a Dialect explicitly permits a fact to reference. Its recorded identity follows the Dialect's disclosure limits and does not verify a remote object's existence or health.

F

Form

The complete portable architectural result compiled from plan or state evidence. It contains supported stages, comparisons, reported drift, evidence, and the interpretation used; a saved Form reopens without the original input or installed Dialects.

I

Indeterminate

Evidence cannot settle a fact, change, or Policy assertion. An indeterminate result establishes neither absence nor no change, and it cannot count as a Policy pass.

Installed

Verified OCI content stored in the Rootform home on one machine. Installation makes a Dialect or Policy Pack available; project selection determines whether it is used.

Instance

One managed or data resource instance in Terraform or OpenTofu evidence, identified by its instance address. Indexed instances, such as aws_subnet.application[0] and aws_subnet.application[1], are distinct.

N

Net change

The plan comparison from Recorded to Planned. Drift that the plan proposes to reverse cancels out of this comparison.

P

Pairing

The checks that allow a saved plan to enrich a plan JSON export: matching recorded tool version, timestamp, and configuration shape. A verified pair permits traversal evidence but does not prove one planning operation.

Plan JSON

The completed plan export produced by terraform show -json plan.tfplan or the corresponding tofu command. Rootform reads this export as input; the event stream from plan -json has a different format and is refused.

Planned

The stage describing what a plan proposes. Values unknown until apply remain unknown, although paired saved-plan evidence can establish some references.

Planned changes

The plan comparison from Refreshed to Planned, showing the proposed architectural changes from the plan's starting state.

Policy

A named, authored assertion over one architecture stage within a Form. rootform check evaluates selected Policies; analysis with rootform run does not evaluate them.

Policy Pack

A unit that owns and selects related Policies. Projects select Policy Packs separately from Dialects.

Policy result

The separate artifact produced by a Policy check, recording selection, targets, outcomes, and diagnostics. It identifies the Form evaluated and does not change that Form.

Provenance

The recorded justification for an architectural fact: its Rule, declaration, closure, and evidence kind. Evidence kinds distinguish evaluated values, verified saved-plan traversals, and agreement between both.

R

Recorded

The stage describing recorded state. For state JSON, it reflects the export; in a plan, Rootform reconstructs it from drift records, and that reconstruction may be partial.

Refreshed

The stage describing the state a plan starts from. The plan does not establish whether or how far refresh ran.

Relation

A directed architectural connection whose meaning a Dialect declares. Terraform references and dependencies alone do not establish Relations.

Representation

An entry in a stage's architecture for a managed instance, data instance, or permitted external endpoint. A resource remains represented without a matching Rule. The Explorer can reveal secondary resources on demand.

Resolution

The evidence detail for a fact in the Explorer, showing the Rule and source evidence that established its endpoint. The closure records whether the relevant fact set is complete.

RF Vocabulary

The shared architectural definitions in the reserved rf namespace, including common Concepts and Contexts. It has no provider binding or Rules and is always embedded.

Rootform language

The language used to author Dialects and Policies, written in .rf.hcl or .rf.json files. Its declarations describe architectural interpretation and assertions.

rootform.lock

The project selection file, recording exact external Dialects and Policy Pack sources, plus exclusions and replacements of embedded Dialects. Embedded versions come from the binary, and Terraform or OpenTofu provider versions belong to their own lock.

Rule

A Dialect declaration that matches eligible instances and can assign a Concept, establish facts, or define composition members. Matching a Rule does not settle every fact; each declared fact still needs evidence.

S

Saved plan

The binary plan file written by terraform plan -out=plan.tfplan or the corresponding tofu command. Export its plan JSON for analysis and optionally pass the same saved plan with --plan-file for enrichment.

Selected

External content whose exact identity and source are recorded in the project's lock. The selected bytes must be available from their recorded source or vendored copy before analysis.

Stage

The role of one architecture within a Form: Recorded, Refreshed, or Planned. A stage the input does not support is unavailable; it must not be read as empty architecture.

State JSON

The state export produced by terraform show -json or the corresponding tofu command. It supplies one Recorded stage with evaluated values and sensitivity masks; raw terraform.tfstate is a different format and is refused.

V

Vendored

Selected external content copied into the project's .rootform/ directory. For a vendored family, Rootform reads only that copy and rejects missing, extra, or changed content.