Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/aws: = 6.62.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
aws_alb_target_groupresourceload-balancer-componentalb-target-group
aws_albresourceload-balanceralb
aws_api_gateway_integrationresourceapi-componentapi-gateway-integration
aws_api_gateway_modelresourceapi-componentapi-gateway-model
aws_api_gateway_resourceresourceapi-componentapi-gateway-resource
aws_api_gateway_rest_apiresourceapi-gatewayapi-gateway-rest-api
aws_api_gateway_stageresourceapi-componentapi-gateway-stage
aws_apigatewayv2_apiresourceapi-gatewayapigatewayv2-api
aws_apigatewayv2_modelresourceapi-componentapigatewayv2-model
aws_appsync_datasourceresourceappsync-componentappsync-datasource
aws_appsync_functionresourceappsync-componentappsync-function
aws_appsync_graphql_apiresourceappsync-apiappsync-graphql-api
aws_appsync_resolverresourceappsync-componentappsync-resolver
aws_bedrockagent_agent_action_groupresourcebedrock-agent-componentbedrockagent-agent-action-group
aws_bedrockagent_agentresourcebedrockagent-agentbedrockagent-agent
aws_cloudwatch_event_busresourceevent-buscloudwatch-event-bus
aws_cloudwatch_event_ruleresourceevent-componentcloudwatch-event-rule
aws_cloudwatch_event_targetresourceevent-componentcloudwatch-event-target
aws_cognito_user_groupresourcecognito-componentcognito-user-group
aws_cognito_user_pool_domainresourcecognito-componentcognito-user-pool-domain
aws_cognito_user_poolresourcecognito-user-poolcognito-user-pool
aws_connect_contact_flowresourceconnect-componentconnect-contact-flow
aws_connect_instanceresourceconnect-instanceconnect-instance
aws_connect_queueresourceconnect-componentconnect-queue
aws_connect_routing_profileresourceconnect-componentconnect-routing-profile
aws_connect_security_profileresourceconnect-componentconnect-security-profile
aws_connect_user_hierarchy_groupresourceconnect-componentconnect-user-hierarchy-group
aws_dax_clusterresourcemanaged-cachedax-cluster
aws_db_instanceresourcemanaged-databasedb-instance
aws_db_proxy_default_target_groupresourcedb-proxy-componentdb-proxy-default-target-group
aws_db_proxy_endpointresourcedb-proxy-componentdb-proxy-endpoint
aws_db_proxyresourcedb-proxydb-proxy
aws_docdb_cluster_instanceresourcemanaged-database-componentdocdb-cluster-instance
aws_docdb_clusterresourcemanaged-databasedocdb-cluster
aws_dsql_clusterresourcemanaged-databasedsql-cluster
aws_dynamodb_global_secondary_indexresourcedynamodb-componentdynamodb-global-secondary-index
aws_dynamodb_tableresourcedynamodb-tabledynamodb-table
aws_ec2_transit_gateway_vpc_attachmentresourcetransit-gateway-attachmentec2-transit-gateway-vpc-attachment
aws_ec2_transit_gatewayresourcetransit-gatewayec2-transit-gateway
aws_ecr_lifecycle_policyresourcerepository-configurationecr-lifecycle-policy
aws_ecr_repositoryresourcecontainer-repositoryecr-repository
aws_ecs_clusterresourceecs-clusterecs-cluster
aws_ecs_serviceresourceecs-serviceecs-service
aws_efs_file_systemresourcemanaged-file-storageefs-file-system
aws_eks_clusterresourcekubernetes-clustereks-cluster
aws_eks_fargate_profileresourceeks-compute-profileeks-fargate-profile
aws_eks_node_groupresourcekubernetes-node-pooleks-node-group
aws_elasticache_clusterresourcemanaged-cacheelasticache-cluster
aws_elasticache_replication_groupresourcemanaged-cacheelasticache-replication-group
aws_elbresourceload-balancerelb
aws_emr_clusterresourceemr-clusteremr-cluster
aws_emr_instance_fleetresourceemr-cluster-componentemr-instance-fleet
aws_emr_instance_groupresourceemr-cluster-componentemr-instance-group
aws_fsx_lustre_file_systemresourcemanaged-file-storagefsx-lustre-file-system
aws_fsx_ontap_file_systemresourcemanaged-file-storagefsx-ontap-file-system
aws_fsx_openzfs_file_systemresourcemanaged-file-storagefsx-openzfs-file-system
aws_fsx_windows_file_systemresourcemanaged-file-storagefsx-windows-file-system
aws_globalaccelerator_acceleratorresourceglobal-acceleratorglobalaccelerator-accelerator
aws_globalaccelerator_custom_routing_acceleratorresourceglobal-acceleratorglobalaccelerator-custom-routing-accelerator
aws_globalaccelerator_custom_routing_endpoint_groupresourceglobal-accelerator-componentglobalaccelerator-custom-routing-endpoint-group
aws_globalaccelerator_custom_routing_listenerresourceglobal-accelerator-componentglobalaccelerator-custom-routing-listener
aws_globalaccelerator_endpoint_groupresourceglobal-accelerator-componentglobalaccelerator-endpoint-group
aws_globalaccelerator_listenerresourceglobal-accelerator-componentglobalaccelerator-listener
aws_iam_groupresourceidentity-groupiam-group
aws_iam_instance_profileresourceinstance-profileiam-instance-profile
aws_iam_role_policy_attachmentresourceservice-identity-bindingiam-role-policy-attachment
aws_iam_roleresourceiam-roleiam-role
aws_identitystore_groupresourceidentity-groupidentitystore-group
aws_instanceresourcecompute-instanceinstance
aws_internet_gatewayresourceinternet-gatewayinternet-gateway
aws_kms_aliasresourcekey-aliaskms-alias
aws_kms_keyresourceencryption-keykms-key
aws_lb_listenerresourceload-balancer-componentlb-listener
aws_lb_target_groupresourceload-balancer-componentlb-target-group
aws_lbresourceload-balancerlb
aws_memorydb_clusterresourcemanaged-cachememorydb-cluster
aws_nat_gatewayresourcemanaged-natnat-gateway
aws_neptune_cluster_instanceresourcemanaged-database-componentneptune-cluster-instance
aws_neptune_clusterresourcemanaged-databaseneptune-cluster
aws_network_aclresourcenetwork-aclnetwork-acl
aws_pinpoint_adm_channelresourcepinpoint-componentpinpoint-adm-channel
aws_pinpoint_apns_channelresourcepinpoint-componentpinpoint-apns-channel
aws_pinpoint_apns_sandbox_channelresourcepinpoint-componentpinpoint-apns-sandbox-channel
aws_pinpoint_apns_voip_channelresourcepinpoint-componentpinpoint-apns-voip-channel
aws_pinpoint_apns_voip_sandbox_channelresourcepinpoint-componentpinpoint-apns-voip-sandbox-channel
aws_pinpoint_appresourcepinpoint-apppinpoint-app
aws_pinpoint_baidu_channelresourcepinpoint-componentpinpoint-baidu-channel
aws_pinpoint_email_channelresourcepinpoint-componentpinpoint-email-channel
aws_pinpoint_event_streamresourcepinpoint-componentpinpoint-event-stream
aws_pinpoint_gcm_channelresourcepinpoint-componentpinpoint-gcm-channel
aws_pinpoint_sms_channelresourcepinpoint-componentpinpoint-sms-channel
aws_rds_cluster_activity_streamresourcemanaged-database-componentrds-cluster-activity-stream
aws_rds_cluster_endpointresourcemanaged-database-componentrds-cluster-endpoint
aws_rds_cluster_instanceresourcemanaged-database-componentrds-cluster-instance
aws_rds_clusterresourcemanaged-databaserds-cluster
aws_route_tableresourceroute-tableroute-table
aws_s3_bucket_server_side_encryption_configurationresourcestorage-configurations3-bucket-server-side-encryption-configuration
aws_s3_bucket_versioningresourcestorage-configurations3-bucket-versioning
aws_s3_bucketresourceobject-storage-containers3-bucket
aws_s3_directory_bucketresourceobject-storage-containers3-directory-bucket
aws_security_groupresourcesecurity-groupsecurity-group
aws_sns_topic_subscriptionresourcemessage-subscriptionsns-topic-subscription
aws_sns_topicresourcemessage-topicsns-topic
aws_subnetresourcesubnetsubnet
aws_vpc_endpointresourceprivate-endpointvpc-endpoint
aws_vpcresourcevirtual-networkvpc
aws_vpn_connectionresourcevpn-connectionvpn-connection
aws_vpn_gatewayresourcevpn-gatewayvpn-gateway

Local vocabulary

Concepts

aws.concept.ai-inference-endpoint Source

A managed endpoint that serves model inference requests.

No Rule in this Dialect uses this definition.

aws.concept.api-component Source

A route, stage, integration, or model contributing to an AWS API boundary.

Used by 5 Rules
aws.concept.api-gateway Source

A managed gateway that exposes and governs APIs.

Used by 7 Rules
aws.concept.appsync-api Source

An AWS AppSync GraphQL API boundary.

Used by 4 Rules
aws.concept.appsync-component Source

An AWS AppSync data source, function, or resolver contributing to an API.

Used by appsync-datasource, appsync-function, appsync-resolver.

aws.concept.backup-plan Source

A managed policy scheduling and retaining backups.

No Rule in this Dialect uses this definition.

aws.concept.backup-vault Source

A managed vault storing protected recovery data.

No Rule in this Dialect uses this definition.

aws.concept.bedrock-agent-component Source

Configuration contributing to an Amazon Bedrock agent.

Used by bedrockagent-agent-action-group.

aws.concept.bedrockagent-agent Source

Amazon Bedrock agent as a durable AWS architecture entity.

Used by bedrockagent-agent, bedrockagent-agent-action-group.

aws.concept.block-storage-volume Source

A durable block-storage volume attachable to compute workloads.

No Rule in this Dialect uses this definition.

aws.concept.cognito-component Source

Configuration contributing to an Amazon Cognito user pool.

Used by cognito-user-group, cognito-user-pool-domain.

aws.concept.cognito-user-pool Source

Amazon Cognito user pool as a durable AWS architecture scope.

Used by cognito-user-group, cognito-user-pool, cognito-user-pool-domain.

aws.concept.compute-instance Source

A provisioned compute instance running a workload.

Used by instance.

aws.concept.connect-component Source

Routing or contact configuration contributing to an Amazon Connect instance.

Used by 5 Rules
aws.concept.connect-instance Source

Amazon Connect instance as a durable AWS architecture entity.

Used by 6 Rules
aws.concept.container-repository Source

An Amazon ECR repository storing container images.

Used by ecr-lifecycle-policy, ecr-repository.

aws.concept.db-proxy Source

Amazon RDS DB proxy as a durable AWS architecture entity.

Used by db-proxy, db-proxy-default-target-group, db-proxy-endpoint.

aws.concept.db-proxy-component Source

An endpoint or target group contributing to an Amazon RDS Proxy.

Used by db-proxy-default-target-group, db-proxy-endpoint.

aws.concept.dedicated-interconnect Source

A dedicated private connection between an external network and a cloud provider.

No Rule in this Dialect uses this definition.

aws.concept.dns-zone Source

A managed DNS namespace containing resource records.

No Rule in this Dialect uses this definition.

aws.concept.dynamodb-component Source

An index contributing to an Amazon DynamoDB table.

Used by dynamodb-global-secondary-index.

aws.concept.dynamodb-table Source

An Amazon DynamoDB table, distinct from a managed database service instance.

Used by dynamodb-global-secondary-index, dynamodb-table.

aws.concept.ecs-cluster Source

An Amazon ECS cluster providing container scheduling capacity.

Used by ecs-cluster, ecs-service.

aws.concept.ecs-service Source

An Amazon ECS service maintaining a container workload.

Used by ecs-service.

aws.concept.eks-compute-profile Source

An Amazon EKS Fargate profile contributing serverless pod capacity.

Used by eks-fargate-profile.

aws.concept.emr-cluster Source

AWS EMR cluster as a durable AWS architecture entity.

Used by emr-cluster, emr-instance-fleet, emr-instance-group.

aws.concept.emr-cluster-component Source

Capacity contributing to an Amazon EMR cluster.

Used by emr-instance-fleet, emr-instance-group.

aws.concept.encryption-key Source

A managed key used for cryptographic operations.

Used by kms-alias, kms-key.

aws.concept.event-bus Source

An Amazon EventBridge event bus.

Used by cloudwatch-event-bus, cloudwatch-event-rule.

aws.concept.event-component Source

An Amazon EventBridge rule or target contributing to an event bus.

Used by cloudwatch-event-rule, cloudwatch-event-target.

aws.concept.global-accelerator Source

An AWS Global Accelerator traffic entry point.

Used by 4 Rules
aws.concept.global-accelerator-component Source

A listener or endpoint group contributing to an AWS Global Accelerator.

Used by 4 Rules
aws.concept.iam-role Source

An AWS IAM role, distinct from an explicitly non-human service principal.

Used by iam-instance-profile, iam-role, iam-role-policy-attachment.

aws.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by iam-group, identitystore-group.

aws.concept.instance-profile Source

An AWS IAM instance profile associating an IAM role with compute.

Used by iam-instance-profile.

aws.concept.internet-gateway Source

Amazon VPC internet gateway as a durable AWS architecture entity.

Used by internet-gateway.

aws.concept.key-alias Source

An AWS KMS alias contributing to an encryption key.

Used by kms-alias.

aws.concept.kubernetes-node-pool Source

A node pool contributing compute capacity to a Kubernetes cluster.

Used by eks-node-group.

aws.concept.load-balancer Source

A load-balancing service composed from routing infrastructure.

Used by 4 Rules
aws.concept.load-balancer-component Source

A listener or target group contributing to an AWS load balancer.

Used by alb-target-group, lb-listener, lb-target-group.

aws.concept.managed-cache Source

A managed in-memory cache service.

Used by 4 Rules
aws.concept.managed-database-component Source

Capacity or an endpoint contributing to a managed database.

Used by 5 Rules
aws.concept.managed-file-storage Source

A managed shared file-storage service.

Used by 5 Rules
aws.concept.managed-nat Source

A managed network address translation service.

Used by nat-gateway.

aws.concept.managed-secret Source

A managed secret identity whose sensitive value stays outside architecture output.

No Rule in this Dialect uses this definition.

aws.concept.message-queue Source

A managed queue buffering work or messages for asynchronous consumers.

No Rule in this Dialect uses this definition.

aws.concept.message-subscription Source

A durable subscription consuming messages from a topic.

Used by sns-topic-subscription.

aws.concept.message-topic Source

A messaging topic receiving messages from publishers.

Used by sns-topic, sns-topic-subscription.

aws.concept.network-acl Source

Amazon VPC network ACL as a durable AWS architecture entity.

Used by network-acl.

aws.concept.network-peering Source

A direct private connectivity agreement between virtual networks.

No Rule in this Dialect uses this definition.

aws.concept.private-endpoint Source

A private endpoint exposing a service inside a virtual network.

Used by vpc-endpoint.

aws.concept.repository-configuration Source

Configuration contributing to an AWS artifact repository.

Used by ecr-lifecycle-policy.

aws.concept.route-table Source

Amazon VPC route table as a durable AWS architecture entity.

Used by route-table.

aws.concept.security-group Source

Amazon VPC security group as a durable AWS architecture entity.

Used by security-group.

aws.concept.serverless-function Source

A managed event-driven function runtime.

No Rule in this Dialect uses this definition.

aws.concept.service-identity-binding Source

An access-control binding that contributes to a service identity.

Used by iam-role-policy-attachment.

aws.concept.storage-configuration Source

Configuration contributing to an AWS storage container.

Used by s3-bucket-server-side-encryption-configuration, s3-bucket-versioning.

aws.concept.transit-gateway Source

An AWS Transit Gateway connecting multiple networks.

Used by ec2-transit-gateway, ec2-transit-gateway-vpc-attachment, vpn-connection.

aws.concept.transit-gateway-attachment Source

A network attachment contributing to an AWS Transit Gateway.

Used by ec2-transit-gateway-vpc-attachment.

aws.concept.vpn-connection Source

A virtual private network connection between network endpoints.

Used by vpn-connection.

aws.concept.vpn-gateway Source

A managed gateway terminating virtual private network connections.

Used by vpn-connection, vpn-gateway.

aws.concept.workflow Source

A managed workflow coordinating steps and service calls.

No Rule in this Dialect uses this definition.

Relations

aws.relation.subscribes-to Source

Introduced by a labeled emission. Used by sns-topic-subscription.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

aws.rule.alb-target-group Source

Matches resource instances of aws_alb_target_group.

Classification: aws.concept.load-balancer-component.

aws.rule.alb Source

Matches resource instances of aws_alb.

Classification: aws.concept.load-balancer.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.api-gateway-integration Source

Matches resource instances of aws_api_gateway_integration.

Classification: aws.concept.api-component.

Contributions

Conditions, identity and resolution

Contribution through source.rest_api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.api-gateway-model Source

Matches resource instances of aws_api_gateway_model.

Classification: aws.concept.api-component.

Contributions

Conditions, identity and resolution

Contribution through source.rest_api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.api-gateway-resource Source

Matches resource instances of aws_api_gateway_resource.

Classification: aws.concept.api-component.

Contributions

Conditions, identity and resolution

Contribution through source.rest_api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.api-gateway-rest-api Source

Matches resource instances of aws_api_gateway_rest_api.

Classification: aws.concept.api-gateway.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.api-gateway-stage Source

Matches resource instances of aws_api_gateway_stage.

Classification: aws.concept.api-component.

Contributions

Conditions, identity and resolution

Contribution through source.rest_api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.apigatewayv2-api Source

Matches resource instances of aws_apigatewayv2_api.

Classification: aws.concept.api-gateway.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.apigatewayv2-model Source

Matches resource instances of aws_apigatewayv2_model.

Classification: aws.concept.api-component.

Contributions

Conditions, identity and resolution

Contribution through source.api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.appsync-datasource Source

Matches resource instances of aws_appsync_datasource.

Classification: aws.concept.appsync-component.

Contributions

Conditions, identity and resolution

Contribution through source.api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.appsync-function Source

Matches resource instances of aws_appsync_function.

Classification: aws.concept.appsync-component.

Contributions

Conditions, identity and resolution

Contribution through source.api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.appsync-graphql-api Source

Matches resource instances of aws_appsync_graphql_api.

Classification: aws.concept.appsync-api.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.appsync-resolver Source

Matches resource instances of aws_appsync_resolver.

Classification: aws.concept.appsync-component.

Contributions

Conditions, identity and resolution

Contribution through source.api_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.bedrockagent-agent-action-group Source

Matches resource instances of aws_bedrockagent_agent_action_group.

Classification: aws.concept.bedrock-agent-component.

Contributions

Conditions, identity and resolution

Contribution through source.agent_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.bedrockagent-agent Source

Matches resource instances of aws_bedrockagent_agent.

Classification: aws.concept.bedrockagent-agent.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.cloudwatch-event-bus Source

Matches resource instances of aws_cloudwatch_event_bus.

Classification: aws.concept.event-bus.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.cloudwatch-event-rule Source

Matches resource instances of aws_cloudwatch_event_rule.

Classification: aws.concept.event-component.

Contributions

Conditions, identity and resolution

Contribution through source.event_bus_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.cloudwatch-event-target Source

Matches resource instances of aws_cloudwatch_event_target.

Classification: aws.concept.event-component.

aws.rule.cognito-user-group Source

Matches resource instances of aws_cognito_user_group.

Classification: aws.concept.cognito-component.

Contributions

Conditions, identity and resolution

Contribution through source.user_pool_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.cognito-user-pool-domain Source

Matches resource instances of aws_cognito_user_pool_domain.

Classification: aws.concept.cognito-component.

Contributions

Conditions, identity and resolution

Contribution through source.user_pool_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.cognito-user-pool Source

Matches resource instances of aws_cognito_user_pool.

Classification: aws.concept.cognito-user-pool.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.connect-contact-flow Source

Matches resource instances of aws_connect_contact_flow.

Classification: aws.concept.connect-component.

Contributions

Conditions, identity and resolution

Contribution through source.instance_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.connect-instance Source

Matches resource instances of aws_connect_instance.

Classification: aws.concept.connect-instance.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.connect-queue Source

Matches resource instances of aws_connect_queue.

Classification: aws.concept.connect-component.

Contributions

Conditions, identity and resolution

Contribution through source.instance_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.connect-routing-profile Source

Matches resource instances of aws_connect_routing_profile.

Classification: aws.concept.connect-component.

Contributions

Conditions, identity and resolution

Contribution through source.instance_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.connect-security-profile Source

Matches resource instances of aws_connect_security_profile.

Classification: aws.concept.connect-component.

Contributions

Conditions, identity and resolution

Contribution through source.instance_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.connect-user-hierarchy-group Source

Matches resource instances of aws_connect_user_hierarchy_group.

Classification: aws.concept.connect-component.

Contributions

Conditions, identity and resolution

Contribution through source.instance_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.dax-cluster Source

Matches resource instances of aws_dax_cluster.

Classification: aws.concept.managed-cache.

aws.rule.db-instance Source

Matches resource instances of aws_db_instance.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["arn", "identifier"]
  • scope: "provider"

Endpoint

  • attributes: ["arn", "id", "identifier"]
aws.rule.db-proxy-default-target-group Source

Matches resource instances of aws_db_proxy_default_target_group.

Classification: aws.concept.db-proxy-component.

Contributions

Conditions, identity and resolution

Contribution through source.db_proxy_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.db-proxy-endpoint Source

Matches resource instances of aws_db_proxy_endpoint.

Classification: aws.concept.db-proxy-component.

Contributions

Conditions, identity and resolution

Contribution through source.db_proxy_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.db-proxy Source

Matches resource instances of aws_db_proxy.

Classification: aws.concept.db-proxy.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.docdb-cluster-instance Source

Matches resource instances of aws_docdb_cluster_instance.

Classification: aws.concept.managed-database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_identifier

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.cluster_identifier
  • match.strategy: "exact"
aws.rule.docdb-cluster Source

Matches resource instances of aws_docdb_cluster.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["arn", "cluster_identifier"]
  • scope: "provider"

Endpoint

  • attributes: ["arn", "id", "cluster_identifier"]
aws.rule.dsql-cluster Source

Matches resource instances of aws_dsql_cluster.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["arn", "identifier"]
  • scope: "provider"

Endpoint

  • attributes: ["arn", "identifier"]
aws.rule.dynamodb-global-secondary-index Source

Matches resource instances of aws_dynamodb_global_secondary_index.

Classification: aws.concept.dynamodb-component.

Contributions

Conditions, identity and resolution

Contribution through source.table_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.dynamodb-table Source

Matches resource instances of aws_dynamodb_table.

Classification: aws.concept.dynamodb-table.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.ec2-transit-gateway-vpc-attachment Source

Matches resource instances of aws_ec2_transit_gateway_vpc_attachment.

Classification: aws.concept.transit-gateway-attachment.

Contexts

Contributions

Conditions, identity and resolution

Contribution through source.transit_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.ec2-transit-gateway Source

Matches resource instances of aws_ec2_transit_gateway.

Classification: aws.concept.transit-gateway.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.ecr-lifecycle-policy Source

Matches resource instances of aws_ecr_lifecycle_policy.

Classification: aws.concept.repository-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.repository

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.ecr-repository Source

Matches resource instances of aws_ecr_repository.

Classification: aws.concept.container-repository.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.ecs-cluster Source

Matches resource instances of aws_ecs_cluster.

Classification: aws.concept.ecs-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.ecs-service Source

Matches resource instances of aws_ecs_service.

Classification: aws.concept.ecs-service.

Contexts

Conditions, identity and resolution

Context through source.cluster

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.efs-file-system Source

Matches resource instances of aws_efs_file_system.

Classification: aws.concept.managed-file-storage.

aws.rule.eks-cluster Source

Matches resource instances of aws_eks_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name", "endpoint"]
aws.rule.eks-fargate-profile Source

Matches resource instances of aws_eks_fargate_profile.

Classification: aws.concept.eks-compute-profile.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.eks-node-group Source

Matches resource instances of aws_eks_node_group.

Classification: aws.concept.kubernetes-node-pool.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.elasticache-cluster Source

Matches resource instances of aws_elasticache_cluster.

Classification: aws.concept.managed-cache.

aws.rule.elasticache-replication-group Source

Matches resource instances of aws_elasticache_replication_group.

Classification: aws.concept.managed-cache.

aws.rule.elb Source

Matches resource instances of aws_elb.

Classification: aws.concept.load-balancer.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.emr-cluster Source

Matches resource instances of aws_emr_cluster.

Classification: aws.concept.emr-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.emr-instance-fleet Source

Matches resource instances of aws_emr_instance_fleet.

Classification: aws.concept.emr-cluster-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.emr-instance-group Source

Matches resource instances of aws_emr_instance_group.

Classification: aws.concept.emr-cluster-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.fsx-lustre-file-system Source

Matches resource instances of aws_fsx_lustre_file_system.

Classification: aws.concept.managed-file-storage.

aws.rule.fsx-ontap-file-system Source

Matches resource instances of aws_fsx_ontap_file_system.

Classification: aws.concept.managed-file-storage.

aws.rule.fsx-openzfs-file-system Source

Matches resource instances of aws_fsx_openzfs_file_system.

Classification: aws.concept.managed-file-storage.

aws.rule.fsx-windows-file-system Source

Matches resource instances of aws_fsx_windows_file_system.

Classification: aws.concept.managed-file-storage.

aws.rule.globalaccelerator-accelerator Source

Matches resource instances of aws_globalaccelerator_accelerator.

Classification: aws.concept.global-accelerator.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.globalaccelerator-custom-routing-accelerator Source

Matches resource instances of aws_globalaccelerator_custom_routing_accelerator.

Classification: aws.concept.global-accelerator.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.globalaccelerator-custom-routing-endpoint-group Source

Matches resource instances of aws_globalaccelerator_custom_routing_endpoint_group.

Classification: aws.concept.global-accelerator-component.

aws.rule.globalaccelerator-custom-routing-listener Source

Matches resource instances of aws_globalaccelerator_custom_routing_listener.

Classification: aws.concept.global-accelerator-component.

Contributions

Conditions, identity and resolution

Contribution through source.accelerator_arn

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.arn
  • match.strategy: "exact"
aws.rule.globalaccelerator-endpoint-group Source

Matches resource instances of aws_globalaccelerator_endpoint_group.

Classification: aws.concept.global-accelerator-component.

aws.rule.globalaccelerator-listener Source

Matches resource instances of aws_globalaccelerator_listener.

Classification: aws.concept.global-accelerator-component.

Contributions

Conditions, identity and resolution

Contribution through source.accelerator_arn

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.arn
  • match.strategy: "exact"
aws.rule.iam-group Source

Matches resource instances of aws_iam_group.

Classification: aws.concept.identity-group.

aws.rule.iam-instance-profile Source

Matches resource instances of aws_iam_instance_profile.

Classification: aws.concept.instance-profile.

Contributions

Conditions, identity and resolution

Contribution through source.role

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.iam-role-policy-attachment Source

Matches resource instances of aws_iam_role_policy_attachment.

Classification: aws.concept.service-identity-binding.

Contributions

Conditions, identity and resolution

Contribution through source.role

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
aws.rule.iam-role Source

Matches resource instances of aws_iam_role.

Classification: aws.concept.iam-role.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
aws.rule.identitystore-group Source

Matches resource instances of aws_identitystore_group.

Classification: aws.concept.identity-group.

aws.rule.instance Source

Matches resource instances of aws_instance.

Classification: aws.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.internet-gateway Source

Matches resource instances of aws_internet_gateway.

Classification: aws.concept.internet-gateway.

Contexts

Conditions, identity and resolution

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.kms-alias Source

Matches resource instances of aws_kms_alias.

Classification: aws.concept.key-alias.

Contributions

Conditions, identity and resolution

Contribution through source.target_key_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.kms-key Source

Matches resource instances of aws_kms_key.

Classification: aws.concept.encryption-key.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
aws.rule.lb-listener Source

Matches resource instances of aws_lb_listener.

Classification: aws.concept.load-balancer-component.

Contributions

Conditions, identity and resolution

Contribution through source.load_balancer_arn

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.arn
  • match.strategy: "exact"
aws.rule.lb-target-group Source

Matches resource instances of aws_lb_target_group.

Classification: aws.concept.load-balancer-component.

aws.rule.lb Source

Matches resource instances of aws_lb.

Classification: aws.concept.load-balancer.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.memorydb-cluster Source

Matches resource instances of aws_memorydb_cluster.

Classification: aws.concept.managed-cache.

aws.rule.nat-gateway Source

Matches resource instances of aws_nat_gateway.

Classification: aws.concept.managed-nat.

Contexts

Conditions, identity and resolution

Context through source.subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.neptune-cluster-instance Source

Matches resource instances of aws_neptune_cluster_instance.

Classification: aws.concept.managed-database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_identifier

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.cluster_identifier
  • match.strategy: "exact"
aws.rule.neptune-cluster Source

Matches resource instances of aws_neptune_cluster.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["arn", "cluster_identifier"]
  • scope: "provider"

Endpoint

  • attributes: ["arn", "id", "cluster_identifier"]
aws.rule.network-acl Source

Matches resource instances of aws_network_acl.

Classification: aws.concept.network-acl.

Contexts

Conditions, identity and resolution

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-adm-channel Source

Matches resource instances of aws_pinpoint_adm_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-apns-channel Source

Matches resource instances of aws_pinpoint_apns_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-apns-sandbox-channel Source

Matches resource instances of aws_pinpoint_apns_sandbox_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-apns-voip-channel Source

Matches resource instances of aws_pinpoint_apns_voip_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-apns-voip-sandbox-channel Source

Matches resource instances of aws_pinpoint_apns_voip_sandbox_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-app Source

Matches resource instances of aws_pinpoint_app.

Classification: aws.concept.pinpoint-app.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "application_id"]
aws.rule.pinpoint-baidu-channel Source

Matches resource instances of aws_pinpoint_baidu_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-email-channel Source

Matches resource instances of aws_pinpoint_email_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-event-stream Source

Matches resource instances of aws_pinpoint_event_stream.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-gcm-channel Source

Matches resource instances of aws_pinpoint_gcm_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.pinpoint-sms-channel Source

Matches resource instances of aws_pinpoint_sms_channel.

Classification: aws.concept.pinpoint-component.

Contributions

Conditions, identity and resolution

Contribution through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.rds-cluster-activity-stream Source

Matches resource instances of aws_rds_cluster_activity_stream.

Classification: aws.concept.managed-database-component.

Contributions

Conditions, identity and resolution

Contribution through source.resource_arn

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.arn
  • match.strategy: "exact"
aws.rule.rds-cluster-endpoint Source

Matches resource instances of aws_rds_cluster_endpoint.

Classification: aws.concept.managed-database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_identifier

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.cluster_identifier
  • match.strategy: "exact"
aws.rule.rds-cluster-instance Source

Matches resource instances of aws_rds_cluster_instance.

Classification: aws.concept.managed-database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_identifier

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.cluster_identifier
  • match.strategy: "exact"
aws.rule.rds-cluster Source

Matches resource instances of aws_rds_cluster.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["arn", "cluster_identifier"]
  • scope: "provider"

Endpoint

  • attributes: ["arn", "id", "cluster_identifier"]
aws.rule.route-table Source

Matches resource instances of aws_route_table.

Classification: aws.concept.route-table.

Contexts

Conditions, identity and resolution

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.s3-bucket-server-side-encryption-configuration Source

Matches resource instances of aws_s3_bucket_server_side_encryption_configuration.

Classification: aws.concept.storage-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.bucket

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.bucket
  • match.strategy: "exact"
aws.rule.s3-bucket-versioning Source

Matches resource instances of aws_s3_bucket_versioning.

Classification: aws.concept.storage-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.bucket

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.bucket
  • match.strategy: "exact"
aws.rule.s3-bucket Source

Matches resource instances of aws_s3_bucket.

Classification: rf.concept.object-storage-container.

Conditions, identity and resolution

Identity

  • attributes: ["bucket"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "bucket", "arn"]
aws.rule.s3-directory-bucket Source

Matches resource instances of aws_s3_directory_bucket.

Classification: rf.concept.object-storage-container.

Conditions, identity and resolution

Identity

  • attributes: ["bucket"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "bucket", "arn"]
aws.rule.security-group Source

Matches resource instances of aws_security_group.

Classification: aws.concept.security-group.

Contexts

Conditions, identity and resolution

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.sns-topic-subscription Source

Matches resource instances of aws_sns_topic_subscription.

Classification: aws.concept.message-subscription.

Relations

Conditions, identity and resolution

Relation through source.topic_arn

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.arn
  • match.strategy: "exact"
aws.rule.sns-topic Source

Matches resource instances of aws_sns_topic.

Classification: aws.concept.message-topic.

Conditions, identity and resolution

Identity

  • attributes: ["arn"]
  • scope: "global"

Endpoint

  • attributes: ["arn", "id"]
aws.rule.subnet Source

Matches resource instances of aws_subnet.

Classification: rf.concept.subnet.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.vpc-endpoint Source

Matches resource instances of aws_vpc_endpoint.

Classification: aws.concept.private-endpoint.

Contexts

Conditions, identity and resolution

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.vpc Source

Matches resource instances of aws_vpc.

Classification: rf.concept.virtual-network.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "cidr_block"]
aws.rule.vpn-connection Source

Matches resource instances of aws_vpn_connection.

Classification: aws.concept.vpn-connection.

Contexts

Conditions, identity and resolution

Context through source.vpn_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.transit_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
aws.rule.vpn-gateway Source

Matches resource instances of aws_vpn_gateway.

Classification: aws.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"