The content of one stage in a Form, including its Representations, architectural facts, closures, and evidence.
An instance retained in Planned because the plan neither changes nor deletes it. The plan did not evaluate it, so missing evidence from a carried instance cannot establish a Policy pass or violation. See partial knowledge.
A Rule's record of fact resolution for one instance. Each declaration of a Context, Relation, or Contribution has its own closure:
An architectural comparison between selected stages. One plan can show Planned changes, Reported drift, and Net change; two separate inputs produce Differences.
A Rule-defined group of implementation members under one root instance. Members keep their own Representations and do not inherit the root's Concept.
An architectural classification assigned by a Rule, such as subnet or managed database. An instance can be represented without a Concept.
A fact that places an instance in an architectural frame, such as a subnet in a virtual network. Network placement alone does not establish runtime reachability.
A directed fact stating that one Representation contributes to another. Contributor and target remain distinct.
The location open in the Explorer, whose direct contents appear on the canvas. This navigation label identifies the current scene; Context names an architectural placement fact.
An instance whose action the plan leaves for later. Its population remains unverified, and a Policy evaluation that needs evidence from it stays indeterminate. See incomplete plans and deferred actions.
A named, versioned unit of interpretation whose Rules match Terraform or OpenTofu instances and establish architectural meaning. Changing the active Dialects can change the interpretation of the same input.
The comparison between two separate inputs, using one selected stage from each. It shows how their architectures differ without establishing what drifted between the exports.
The plan's reported drift records and their architectural consequences. It is separate from the Reported drift comparison; an empty report does not prove that live infrastructure is unchanged.
Content that ships inside the Rootform binary. The official Dialects and RF Vocabulary are embedded and available without installation.
Additional configuration evidence read from a paired saved plan. It can identify a direct reference when the planned value is unknown until apply.
The information available to establish architecture: plan or state instances, evaluated values, sensitivity masks, and supported references. A paired saved plan adds configuration traversals; Evidence in the Inspector shows the basis and limits of an instance's interpretation.
A target outside the input's represented inventory that a Dialect explicitly permits a fact to reference. Its recorded identity follows the Dialect's disclosure limits and does not verify a remote object's existence or health.
The complete portable architectural result compiled from plan or state evidence. It contains supported stages, comparisons, reported drift, evidence, and the interpretation used; a saved Form reopens without the original input or installed Dialects.
Evidence cannot settle a fact, change, or Policy assertion. An indeterminate result establishes neither absence nor no change, and it cannot count as a Policy pass.
Verified OCI content stored in the Rootform home on one machine. Installation makes a Dialect or Policy Pack available; project selection determines whether it is used.
One managed or data resource instance in Terraform or OpenTofu evidence,
identified by its instance address.
Indexed instances, such as aws_subnet.application[0] and
aws_subnet.application[1], are distinct.
The plan comparison from Recorded to Planned. Drift that the plan proposes to reverse cancels out of this comparison.
The checks that allow a saved plan to enrich a plan JSON export: matching recorded tool version, timestamp, and configuration shape. A verified pair permits traversal evidence but does not prove one planning operation.
The completed plan export
produced by terraform show -json plan.tfplan or the corresponding tofu
command. Rootform reads this export as input; the event stream from
plan -json has a different format and is refused.
The stage describing what a plan proposes. Values unknown until apply remain unknown, although paired saved-plan evidence can establish some references.
The plan comparison from Refreshed to Planned, showing the proposed architectural changes from the plan's starting state.
A named, authored assertion over one architecture stage
within a Form. rootform check evaluates selected Policies; analysis with
rootform run does not evaluate them.
A unit that owns and selects related Policies. Projects select Policy Packs separately from Dialects.
The separate artifact produced by a Policy check, recording selection, targets, outcomes, and diagnostics. It identifies the Form evaluated and does not change that Form.
The recorded justification for an architectural fact: its Rule, declaration, closure, and evidence kind. Evidence kinds distinguish evaluated values, verified saved-plan traversals, and agreement between both.
The stage describing recorded state. For state JSON, it reflects the export; in a plan, Rootform reconstructs it from drift records, and that reconstruction may be partial.
The stage describing the state a plan starts from. The plan does not establish whether or how far refresh ran.
A directed architectural connection whose meaning a Dialect declares. Terraform references and dependencies alone do not establish Relations.
An entry in a stage's architecture for a managed instance, data instance, or permitted external endpoint. A resource remains represented without a matching Rule. The Explorer can reveal secondary resources on demand.
The evidence detail for a fact in the Explorer, showing the Rule and source evidence that established its endpoint. The closure records whether the relevant fact set is complete.
The shared architectural definitions
in the reserved rf namespace, including common Concepts and Contexts. It
has no provider binding or Rules and is always embedded.
The language used to author Dialects and Policies,
written in .rf.hcl or .rf.json files. Its declarations describe
architectural interpretation and assertions.
The project selection file, recording exact external Dialects and Policy Pack sources, plus exclusions and replacements of embedded Dialects. Embedded versions come from the binary, and Terraform or OpenTofu provider versions belong to their own lock.
A Dialect declaration that matches eligible instances and can assign a Concept, establish facts, or define composition members. Matching a Rule does not settle every fact; each declared fact still needs evidence.
The binary plan file written
by terraform plan -out=plan.tfplan or the corresponding tofu command.
Export its plan JSON for analysis and optionally pass the same saved plan
with --plan-file for enrichment.
External content whose exact identity and source are recorded in the project's lock. The selected bytes must be available from their recorded source or vendored copy before analysis.
The role of one architecture within a Form: Recorded, Refreshed, or Planned. A stage the input does not support is unavailable; it must not be read as empty architecture.
The state export
produced by terraform show -json or the corresponding tofu command. It
supplies one Recorded stage with evaluated values and sensitivity masks;
raw terraform.tfstate is a different format and is refused.
Selected external content copied into the project's .rootform/ directory.
For a vendored family, Rootform reads only that copy and rejects missing,
extra, or changed content.