Reference
aws Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/aws:= 6.62.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
aws.concept.ai-inference-endpointSource-
A managed endpoint that serves model inference requests.
-
No Rule in this Dialect uses this definition.
aws.concept.api-componentSource-
A route, stage, integration, or model contributing to an AWS API boundary.
aws.concept.appsync-componentSource-
An AWS AppSync data source, function, or resolver contributing to an API.
-
Used by
appsync-datasource,appsync-function,appsync-resolver. aws.concept.backup-planSource-
A managed policy scheduling and retaining backups.
-
No Rule in this Dialect uses this definition.
aws.concept.backup-vaultSource-
A managed vault storing protected recovery data.
-
No Rule in this Dialect uses this definition.
aws.concept.bedrock-agent-componentSource-
Configuration contributing to an Amazon Bedrock agent.
-
Used by
bedrockagent-agent-action-group. aws.concept.bedrockagent-agentSource-
Amazon Bedrock agent as a durable AWS architecture entity.
-
Used by
bedrockagent-agent,bedrockagent-agent-action-group. aws.concept.block-storage-volumeSource-
A durable block-storage volume attachable to compute workloads.
-
No Rule in this Dialect uses this definition.
aws.concept.cognito-componentSource-
Configuration contributing to an Amazon Cognito user pool.
-
Used by
cognito-user-group,cognito-user-pool-domain. aws.concept.cognito-user-poolSource-
Amazon Cognito user pool as a durable AWS architecture scope.
-
Used by
cognito-user-group,cognito-user-pool,cognito-user-pool-domain. aws.concept.compute-instanceSource-
A provisioned compute instance running a workload.
-
Used by
instance. aws.concept.connect-componentSource-
Routing or contact configuration contributing to an Amazon Connect instance.
aws.concept.container-repositorySource-
An Amazon ECR repository storing container images.
-
Used by
ecr-lifecycle-policy,ecr-repository. aws.concept.db-proxySource-
Amazon RDS DB proxy as a durable AWS architecture entity.
-
Used by
db-proxy,db-proxy-default-target-group,db-proxy-endpoint. aws.concept.db-proxy-componentSource-
An endpoint or target group contributing to an Amazon RDS Proxy.
aws.concept.dedicated-interconnectSource-
A dedicated private connection between an external network and a cloud provider.
-
No Rule in this Dialect uses this definition.
aws.concept.dns-zoneSource-
A managed DNS namespace containing resource records.
-
No Rule in this Dialect uses this definition.
aws.concept.dynamodb-componentSource-
An index contributing to an Amazon DynamoDB table.
-
Used by
dynamodb-global-secondary-index. aws.concept.dynamodb-tableSource-
An Amazon DynamoDB table, distinct from a managed database service instance.
aws.concept.ecs-clusterSource-
An Amazon ECS cluster providing container scheduling capacity.
-
Used by
ecs-cluster,ecs-service. aws.concept.ecs-serviceSource-
An Amazon ECS service maintaining a container workload.
-
Used by
ecs-service. aws.concept.eks-compute-profileSource-
An Amazon EKS Fargate profile contributing serverless pod capacity.
-
Used by
eks-fargate-profile. aws.concept.emr-clusterSource-
AWS EMR cluster as a durable AWS architecture entity.
-
Used by
emr-cluster,emr-instance-fleet,emr-instance-group. aws.concept.emr-cluster-componentSource-
Capacity contributing to an Amazon EMR cluster.
-
Used by
emr-instance-fleet,emr-instance-group. aws.concept.event-busSource-
An Amazon EventBridge event bus.
-
Used by
cloudwatch-event-bus,cloudwatch-event-rule. aws.concept.event-componentSource-
An Amazon EventBridge rule or target contributing to an event bus.
-
Used by
cloudwatch-event-rule,cloudwatch-event-target. aws.concept.global-accelerator-componentSource-
A listener or endpoint group contributing to an AWS Global Accelerator.
aws.concept.iam-roleSource-
An AWS IAM role, distinct from an explicitly non-human service principal.
-
Used by
iam-instance-profile,iam-role,iam-role-policy-attachment. aws.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by
iam-group,identitystore-group. aws.concept.instance-profileSource-
An AWS IAM instance profile associating an IAM role with compute.
-
Used by
iam-instance-profile. aws.concept.internet-gatewaySource-
Amazon VPC internet gateway as a durable AWS architecture entity.
-
Used by
internet-gateway. aws.concept.kubernetes-node-poolSource-
A node pool contributing compute capacity to a Kubernetes cluster.
-
Used by
eks-node-group. aws.concept.load-balancerSource-
A load-balancing service composed from routing infrastructure.
-
Used by 4 Rules
aws.concept.load-balancer-componentSource-
A listener or target group contributing to an AWS load balancer.
-
Used by
alb-target-group,lb-listener,lb-target-group. aws.concept.managed-database-componentSource-
Capacity or an endpoint contributing to a managed database.
aws.concept.managed-secretSource-
A managed secret identity whose sensitive value stays outside architecture output.
-
No Rule in this Dialect uses this definition.
aws.concept.message-queueSource-
A managed queue buffering work or messages for asynchronous consumers.
-
No Rule in this Dialect uses this definition.
aws.concept.message-subscriptionSource-
A durable subscription consuming messages from a topic.
-
Used by
sns-topic-subscription. aws.concept.message-topicSource-
A messaging topic receiving messages from publishers.
-
Used by
sns-topic,sns-topic-subscription. aws.concept.network-aclSource-
Amazon VPC network ACL as a durable AWS architecture entity.
-
Used by
network-acl. aws.concept.network-peeringSource-
A direct private connectivity agreement between virtual networks.
-
No Rule in this Dialect uses this definition.
aws.concept.pinpoint-componentSource-
A channel or event stream contributing to an AWS End User Messaging application.
aws.concept.private-endpointSource-
A private endpoint exposing a service inside a virtual network.
-
Used by
vpc-endpoint. aws.concept.repository-configurationSource-
Configuration contributing to an AWS artifact repository.
-
Used by
ecr-lifecycle-policy. aws.concept.route-tableSource-
Amazon VPC route table as a durable AWS architecture entity.
-
Used by
route-table. aws.concept.security-groupSource-
Amazon VPC security group as a durable AWS architecture entity.
-
Used by
security-group. aws.concept.serverless-functionSource-
A managed event-driven function runtime.
-
No Rule in this Dialect uses this definition.
aws.concept.service-identity-bindingSource-
An access-control binding that contributes to a service identity.
-
Used by
iam-role-policy-attachment. aws.concept.storage-configurationSource-
Configuration contributing to an AWS storage container.
-
Used by
s3-bucket-server-side-encryption-configuration,s3-bucket-versioning. aws.concept.transit-gatewaySource-
An AWS Transit Gateway connecting multiple networks.
-
Used by
ec2-transit-gateway,ec2-transit-gateway-vpc-attachment,vpn-connection. aws.concept.transit-gateway-attachmentSource-
A network attachment contributing to an AWS Transit Gateway.
-
Used by
ec2-transit-gateway-vpc-attachment. aws.concept.vpn-connectionSource-
A virtual private network connection between network endpoints.
-
Used by
vpn-connection. aws.concept.vpn-gatewaySource-
A managed gateway terminating virtual private network connections.
-
Used by
vpn-connection,vpn-gateway. aws.concept.workflowSource-
A managed workflow coordinating steps and service calls.
-
No Rule in this Dialect uses this definition.
aws.relation.subscribes-toSource-
Introduced by a labeled emission. Used by
sns-topic-subscription.
rf.concept.kubernetes-clusterrf.concept.managed-databaserf.concept.object-storage-containerrf.concept.subnetrf.concept.virtual-networkrf.context.networkrf.context.runtime
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
aws.rule.alb-target-group Source
Matches resource instances of aws_alb_target_group.
Classification: aws.concept.load-balancer-component.
aws.rule.alb Source
Matches resource instances of aws_alb.
Classification: aws.concept.load-balancer.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.api-gateway-integration Source
Matches resource instances of aws_api_gateway_integration.
Classification: aws.concept.api-component.
Contributions
- targets
aws.concept.api-gatewaythroughsource.rest_api_id.
Conditions, identity and resolution
Contribution through source.rest_api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.api-gateway-model Source
Matches resource instances of aws_api_gateway_model.
Classification: aws.concept.api-component.
Contributions
- targets
aws.concept.api-gatewaythroughsource.rest_api_id.
Conditions, identity and resolution
Contribution through source.rest_api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.api-gateway-resource Source
Matches resource instances of aws_api_gateway_resource.
Classification: aws.concept.api-component.
Contributions
- targets
aws.concept.api-gatewaythroughsource.rest_api_id.
Conditions, identity and resolution
Contribution through source.rest_api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.api-gateway-rest-api Source
Matches resource instances of aws_api_gateway_rest_api.
Classification: aws.concept.api-gateway.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.api-gateway-stage Source
Matches resource instances of aws_api_gateway_stage.
Classification: aws.concept.api-component.
Contributions
- targets
aws.concept.api-gatewaythroughsource.rest_api_id.
Conditions, identity and resolution
Contribution through source.rest_api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.apigatewayv2-api Source
Matches resource instances of aws_apigatewayv2_api.
Classification: aws.concept.api-gateway.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.apigatewayv2-model Source
Matches resource instances of aws_apigatewayv2_model.
Classification: aws.concept.api-component.
Contributions
- targets
aws.concept.api-gatewaythroughsource.api_id.
Conditions, identity and resolution
Contribution through source.api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.appsync-datasource Source
Matches resource instances of aws_appsync_datasource.
Classification: aws.concept.appsync-component.
Contributions
- targets
aws.concept.appsync-apithroughsource.api_id.
Conditions, identity and resolution
Contribution through source.api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.appsync-function Source
Matches resource instances of aws_appsync_function.
Classification: aws.concept.appsync-component.
Contributions
- targets
aws.concept.appsync-apithroughsource.api_id.
Conditions, identity and resolution
Contribution through source.api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.appsync-graphql-api Source
Matches resource instances of aws_appsync_graphql_api.
Classification: aws.concept.appsync-api.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.appsync-resolver Source
Matches resource instances of aws_appsync_resolver.
Classification: aws.concept.appsync-component.
Contributions
- targets
aws.concept.appsync-apithroughsource.api_id.
Conditions, identity and resolution
Contribution through source.api_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.bedrockagent-agent-action-group Source
Matches resource instances of aws_bedrockagent_agent_action_group.
Classification: aws.concept.bedrock-agent-component.
Contributions
- targets
aws.concept.bedrockagent-agentthroughsource.agent_id.
Conditions, identity and resolution
Contribution through source.agent_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.bedrockagent-agent Source
Matches resource instances of aws_bedrockagent_agent.
Classification: aws.concept.bedrockagent-agent.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.cloudwatch-event-bus Source
Matches resource instances of aws_cloudwatch_event_bus.
Classification: aws.concept.event-bus.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.cloudwatch-event-rule Source
Matches resource instances of aws_cloudwatch_event_rule.
Classification: aws.concept.event-component.
Contributions
- targets
aws.concept.event-busthroughsource.event_bus_name.
Conditions, identity and resolution
Contribution through source.event_bus_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.cloudwatch-event-target Source
Matches resource instances of aws_cloudwatch_event_target.
Classification: aws.concept.event-component.
aws.rule.cognito-user-group Source
Matches resource instances of aws_cognito_user_group.
Classification: aws.concept.cognito-component.
Contributions
- targets
aws.concept.cognito-user-poolthroughsource.user_pool_id.
Conditions, identity and resolution
Contribution through source.user_pool_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.cognito-user-pool-domain Source
Matches resource instances of aws_cognito_user_pool_domain.
Classification: aws.concept.cognito-component.
Contributions
- targets
aws.concept.cognito-user-poolthroughsource.user_pool_id.
Conditions, identity and resolution
Contribution through source.user_pool_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.cognito-user-pool Source
Matches resource instances of aws_cognito_user_pool.
Classification: aws.concept.cognito-user-pool.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.connect-contact-flow Source
Matches resource instances of aws_connect_contact_flow.
Classification: aws.concept.connect-component.
Contributions
- targets
aws.concept.connect-instancethroughsource.instance_id.
Conditions, identity and resolution
Contribution through source.instance_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.connect-instance Source
Matches resource instances of aws_connect_instance.
Classification: aws.concept.connect-instance.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.connect-queue Source
Matches resource instances of aws_connect_queue.
Classification: aws.concept.connect-component.
Contributions
- targets
aws.concept.connect-instancethroughsource.instance_id.
Conditions, identity and resolution
Contribution through source.instance_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.connect-routing-profile Source
Matches resource instances of aws_connect_routing_profile.
Classification: aws.concept.connect-component.
Contributions
- targets
aws.concept.connect-instancethroughsource.instance_id.
Conditions, identity and resolution
Contribution through source.instance_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.connect-security-profile Source
Matches resource instances of aws_connect_security_profile.
Classification: aws.concept.connect-component.
Contributions
- targets
aws.concept.connect-instancethroughsource.instance_id.
Conditions, identity and resolution
Contribution through source.instance_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.connect-user-hierarchy-group Source
Matches resource instances of aws_connect_user_hierarchy_group.
Classification: aws.concept.connect-component.
Contributions
- targets
aws.concept.connect-instancethroughsource.instance_id.
Conditions, identity and resolution
Contribution through source.instance_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.dax-cluster Source
Matches resource instances of aws_dax_cluster.
Classification: aws.concept.managed-cache.
aws.rule.db-instance Source
Matches resource instances of aws_db_instance.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["arn", "identifier"]scope:"provider"
Endpoint
attributes:["arn", "id", "identifier"]
aws.rule.db-proxy-default-target-group Source
Matches resource instances of aws_db_proxy_default_target_group.
Classification: aws.concept.db-proxy-component.
Contributions
- targets
aws.concept.db-proxythroughsource.db_proxy_name.
Conditions, identity and resolution
Contribution through source.db_proxy_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.db-proxy-endpoint Source
Matches resource instances of aws_db_proxy_endpoint.
Classification: aws.concept.db-proxy-component.
Contributions
- targets
aws.concept.db-proxythroughsource.db_proxy_name.
Conditions, identity and resolution
Contribution through source.db_proxy_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.db-proxy Source
Matches resource instances of aws_db_proxy.
Classification: aws.concept.db-proxy.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.docdb-cluster-instance Source
Matches resource instances of aws_docdb_cluster_instance.
Classification: aws.concept.managed-database-component.
Contributions
- targets
aws.rule.docdb-clusterthroughsource.cluster_identifier.
Conditions, identity and resolution
Contribution through source.cluster_identifier
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.cluster_identifiermatch.strategy:"exact"
aws.rule.docdb-cluster Source
Matches resource instances of aws_docdb_cluster.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["arn", "cluster_identifier"]scope:"provider"
Endpoint
attributes:["arn", "id", "cluster_identifier"]
aws.rule.dsql-cluster Source
Matches resource instances of aws_dsql_cluster.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["arn", "identifier"]scope:"provider"
Endpoint
attributes:["arn", "identifier"]
aws.rule.dynamodb-global-secondary-index Source
Matches resource instances of aws_dynamodb_global_secondary_index.
Classification: aws.concept.dynamodb-component.
Contributions
- targets
aws.concept.dynamodb-tablethroughsource.table_name.
Conditions, identity and resolution
Contribution through source.table_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.dynamodb-table Source
Matches resource instances of aws_dynamodb_table.
Classification: aws.concept.dynamodb-table.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.ec2-transit-gateway-vpc-attachment Source
Matches resource instances of aws_ec2_transit_gateway_vpc_attachment.
Classification: aws.concept.transit-gateway-attachment.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Contributions
- targets
aws.concept.transit-gatewaythroughsource.transit_gateway_id.
Conditions, identity and resolution
Contribution through source.transit_gateway_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.ec2-transit-gateway Source
Matches resource instances of aws_ec2_transit_gateway.
Classification: aws.concept.transit-gateway.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.ecr-lifecycle-policy Source
Matches resource instances of aws_ecr_lifecycle_policy.
Classification: aws.concept.repository-configuration.
Contributions
- targets
aws.concept.container-repositorythroughsource.repository.
Conditions, identity and resolution
Contribution through source.repository
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.ecr-repository Source
Matches resource instances of aws_ecr_repository.
Classification: aws.concept.container-repository.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.ecs-cluster Source
Matches resource instances of aws_ecs_cluster.
Classification: aws.concept.ecs-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.ecs-service Source
Matches resource instances of aws_ecs_service.
Classification: aws.concept.ecs-service.
Contexts
rf.context.runtime: targetsaws.concept.ecs-clusterthroughsource.cluster.
Conditions, identity and resolution
Context through source.cluster
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
aws.rule.efs-file-system Source
Matches resource instances of aws_efs_file_system.
Classification: aws.concept.managed-file-storage.
aws.rule.eks-cluster Source
Matches resource instances of aws_eks_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name", "endpoint"]
aws.rule.eks-fargate-profile Source
Matches resource instances of aws_eks_fargate_profile.
Classification: aws.concept.eks-compute-profile.
Contributions
- targets
rf.concept.kubernetes-clusterthroughsource.cluster_name.
Conditions, identity and resolution
Contribution through source.cluster_name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
aws.rule.eks-node-group Source
Matches resource instances of aws_eks_node_group.
Classification: aws.concept.kubernetes-node-pool.
Contributions
- targets
rf.concept.kubernetes-clusterthroughsource.cluster_name.
Conditions, identity and resolution
Contribution through source.cluster_name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
aws.rule.elasticache-cluster Source
Matches resource instances of aws_elasticache_cluster.
Classification: aws.concept.managed-cache.
aws.rule.elasticache-replication-group Source
Matches resource instances of aws_elasticache_replication_group.
Classification: aws.concept.managed-cache.
aws.rule.elb Source
Matches resource instances of aws_elb.
Classification: aws.concept.load-balancer.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.emr-cluster Source
Matches resource instances of aws_emr_cluster.
Classification: aws.concept.emr-cluster.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.emr-instance-fleet Source
Matches resource instances of aws_emr_instance_fleet.
Classification: aws.concept.emr-cluster-component.
Contributions
- targets
aws.concept.emr-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Contribution through source.cluster_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.emr-instance-group Source
Matches resource instances of aws_emr_instance_group.
Classification: aws.concept.emr-cluster-component.
Contributions
- targets
aws.concept.emr-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Contribution through source.cluster_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.fsx-lustre-file-system Source
Matches resource instances of aws_fsx_lustre_file_system.
Classification: aws.concept.managed-file-storage.
aws.rule.fsx-ontap-file-system Source
Matches resource instances of aws_fsx_ontap_file_system.
Classification: aws.concept.managed-file-storage.
aws.rule.fsx-openzfs-file-system Source
Matches resource instances of aws_fsx_openzfs_file_system.
Classification: aws.concept.managed-file-storage.
aws.rule.fsx-windows-file-system Source
Matches resource instances of aws_fsx_windows_file_system.
Classification: aws.concept.managed-file-storage.
aws.rule.globalaccelerator-accelerator Source
Matches resource instances of aws_globalaccelerator_accelerator.
Classification: aws.concept.global-accelerator.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.globalaccelerator-custom-routing-accelerator Source
Matches resource instances of aws_globalaccelerator_custom_routing_accelerator.
Classification: aws.concept.global-accelerator.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.globalaccelerator-custom-routing-endpoint-group Source
Matches resource instances of aws_globalaccelerator_custom_routing_endpoint_group.
Classification: aws.concept.global-accelerator-component.
aws.rule.globalaccelerator-custom-routing-listener Source
Matches resource instances of aws_globalaccelerator_custom_routing_listener.
Classification: aws.concept.global-accelerator-component.
Contributions
- targets
aws.concept.global-acceleratorthroughsource.accelerator_arn.
Conditions, identity and resolution
Contribution through source.accelerator_arn
on_null:"absent"on_empty:"absent"match.by:target.arnmatch.strategy:"exact"
aws.rule.globalaccelerator-endpoint-group Source
Matches resource instances of aws_globalaccelerator_endpoint_group.
Classification: aws.concept.global-accelerator-component.
aws.rule.globalaccelerator-listener Source
Matches resource instances of aws_globalaccelerator_listener.
Classification: aws.concept.global-accelerator-component.
Contributions
- targets
aws.concept.global-acceleratorthroughsource.accelerator_arn.
Conditions, identity and resolution
Contribution through source.accelerator_arn
on_null:"absent"on_empty:"absent"match.by:target.arnmatch.strategy:"exact"
aws.rule.iam-group Source
Matches resource instances of aws_iam_group.
Classification: aws.concept.identity-group.
aws.rule.iam-instance-profile Source
Matches resource instances of aws_iam_instance_profile.
Classification: aws.concept.instance-profile.
Contributions
- targets
aws.concept.iam-rolethroughsource.role.
Conditions, identity and resolution
Contribution through source.role
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
aws.rule.iam-role-policy-attachment Source
Matches resource instances of aws_iam_role_policy_attachment.
Classification: aws.concept.service-identity-binding.
Contributions
- targets
aws.concept.iam-rolethroughsource.role.
Conditions, identity and resolution
Contribution through source.role
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
aws.rule.iam-role Source
Matches resource instances of aws_iam_role.
Classification: aws.concept.iam-role.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
aws.rule.identitystore-group Source
Matches resource instances of aws_identitystore_group.
Classification: aws.concept.identity-group.
aws.rule.instance Source
Matches resource instances of aws_instance.
Classification: aws.concept.compute-instance.
Contexts
rf.context.network: targetsrf.concept.subnetthroughsource.subnet_id.
Conditions, identity and resolution
Context through source.subnet_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.internet-gateway Source
Matches resource instances of aws_internet_gateway.
Classification: aws.concept.internet-gateway.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.kms-alias Source
Matches resource instances of aws_kms_alias.
Classification: aws.concept.key-alias.
Contributions
- targets
aws.concept.encryption-keythroughsource.target_key_id.
Conditions, identity and resolution
Contribution through source.target_key_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.kms-key Source
Matches resource instances of aws_kms_key.
Classification: aws.concept.encryption-key.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
aws.rule.lb-listener Source
Matches resource instances of aws_lb_listener.
Classification: aws.concept.load-balancer-component.
Contributions
- targets
aws.concept.load-balancerthroughsource.load_balancer_arn.
Conditions, identity and resolution
Contribution through source.load_balancer_arn
on_null:"absent"on_empty:"absent"match.by:target.arnmatch.strategy:"exact"
aws.rule.lb-target-group Source
Matches resource instances of aws_lb_target_group.
Classification: aws.concept.load-balancer-component.
aws.rule.lb Source
Matches resource instances of aws_lb.
Classification: aws.concept.load-balancer.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.memorydb-cluster Source
Matches resource instances of aws_memorydb_cluster.
Classification: aws.concept.managed-cache.
aws.rule.nat-gateway Source
Matches resource instances of aws_nat_gateway.
Classification: aws.concept.managed-nat.
Contexts
rf.context.network: targetsrf.concept.subnetthroughsource.subnet_id.
Conditions, identity and resolution
Context through source.subnet_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.neptune-cluster-instance Source
Matches resource instances of aws_neptune_cluster_instance.
Classification: aws.concept.managed-database-component.
Contributions
- targets
aws.rule.neptune-clusterthroughsource.cluster_identifier.
Conditions, identity and resolution
Contribution through source.cluster_identifier
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.cluster_identifiermatch.strategy:"exact"
aws.rule.neptune-cluster Source
Matches resource instances of aws_neptune_cluster.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["arn", "cluster_identifier"]scope:"provider"
Endpoint
attributes:["arn", "id", "cluster_identifier"]
aws.rule.network-acl Source
Matches resource instances of aws_network_acl.
Classification: aws.concept.network-acl.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-adm-channel Source
Matches resource instances of aws_pinpoint_adm_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-apns-channel Source
Matches resource instances of aws_pinpoint_apns_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-apns-sandbox-channel Source
Matches resource instances of aws_pinpoint_apns_sandbox_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-apns-voip-channel Source
Matches resource instances of aws_pinpoint_apns_voip_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-apns-voip-sandbox-channel Source
Matches resource instances of aws_pinpoint_apns_voip_sandbox_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-app Source
Matches resource instances of aws_pinpoint_app.
Classification: aws.concept.pinpoint-app.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id", "application_id"]
aws.rule.pinpoint-baidu-channel Source
Matches resource instances of aws_pinpoint_baidu_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-email-channel Source
Matches resource instances of aws_pinpoint_email_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-event-stream Source
Matches resource instances of aws_pinpoint_event_stream.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-gcm-channel Source
Matches resource instances of aws_pinpoint_gcm_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.pinpoint-sms-channel Source
Matches resource instances of aws_pinpoint_sms_channel.
Classification: aws.concept.pinpoint-component.
Contributions
- targets
aws.concept.pinpoint-appthroughsource.application_id.
Conditions, identity and resolution
Contribution through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.rds-cluster-activity-stream Source
Matches resource instances of aws_rds_cluster_activity_stream.
Classification: aws.concept.managed-database-component.
Contributions
- targets
rf.concept.managed-databasethroughsource.resource_arn.
Conditions, identity and resolution
Contribution through source.resource_arn
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.arnmatch.strategy:"exact"
aws.rule.rds-cluster-endpoint Source
Matches resource instances of aws_rds_cluster_endpoint.
Classification: aws.concept.managed-database-component.
Contributions
- targets
aws.rule.rds-clusterthroughsource.cluster_identifier.
Conditions, identity and resolution
Contribution through source.cluster_identifier
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.cluster_identifiermatch.strategy:"exact"
aws.rule.rds-cluster-instance Source
Matches resource instances of aws_rds_cluster_instance.
Classification: aws.concept.managed-database-component.
Contributions
- targets
aws.rule.rds-clusterthroughsource.cluster_identifier.
Conditions, identity and resolution
Contribution through source.cluster_identifier
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.cluster_identifiermatch.strategy:"exact"
aws.rule.rds-cluster Source
Matches resource instances of aws_rds_cluster.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["arn", "cluster_identifier"]scope:"provider"
Endpoint
attributes:["arn", "id", "cluster_identifier"]
aws.rule.route-table Source
Matches resource instances of aws_route_table.
Classification: aws.concept.route-table.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.s3-bucket-server-side-encryption-configuration Source
Matches resource instances of aws_s3_bucket_server_side_encryption_configuration.
Classification: aws.concept.storage-configuration.
Contributions
- targets
rf.concept.object-storage-containerthroughsource.bucket.
Conditions, identity and resolution
Contribution through source.bucket
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.bucketmatch.strategy:"exact"
aws.rule.s3-bucket-versioning Source
Matches resource instances of aws_s3_bucket_versioning.
Classification: aws.concept.storage-configuration.
Contributions
- targets
rf.concept.object-storage-containerthroughsource.bucket.
Conditions, identity and resolution
Contribution through source.bucket
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.bucketmatch.strategy:"exact"
aws.rule.s3-bucket Source
Matches resource instances of aws_s3_bucket.
Classification: rf.concept.object-storage-container.
Conditions, identity and resolution
Identity
attributes:["bucket"]scope:"provider"
Endpoint
attributes:["id", "bucket", "arn"]
aws.rule.s3-directory-bucket Source
Matches resource instances of aws_s3_directory_bucket.
Classification: rf.concept.object-storage-container.
Conditions, identity and resolution
Identity
attributes:["bucket"]scope:"provider"
Endpoint
attributes:["id", "bucket", "arn"]
aws.rule.security-group Source
Matches resource instances of aws_security_group.
Classification: aws.concept.security-group.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.sns-topic-subscription Source
Matches resource instances of aws_sns_topic_subscription.
Classification: aws.concept.message-subscription.
Relations
aws.relation.subscribes-to: targetsaws.concept.message-topicthroughsource.topic_arn.
Conditions, identity and resolution
Relation through source.topic_arn
on_null:"absent"on_empty:"absent"match.by:target.arnmatch.strategy:"exact"
aws.rule.sns-topic Source
Matches resource instances of aws_sns_topic.
Classification: aws.concept.message-topic.
Conditions, identity and resolution
Identity
attributes:["arn"]scope:"global"
Endpoint
attributes:["arn", "id"]
aws.rule.subnet Source
Matches resource instances of aws_subnet.
Classification: rf.concept.subnet.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.vpc-endpoint Source
Matches resource instances of aws_vpc_endpoint.
Classification: aws.concept.private-endpoint.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
aws.rule.vpc Source
Matches resource instances of aws_vpc.
Classification: rf.concept.virtual-network.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id", "cidr_block"]
aws.rule.vpn-connection Source
Matches resource instances of aws_vpn_connection.
Classification: aws.concept.vpn-connection.
Contexts
rf.context.network: targetsaws.concept.vpn-gatewaythroughsource.vpn_gateway_id.rf.context.network: targetsaws.concept.transit-gatewaythroughsource.transit_gateway_id.
Conditions, identity and resolution
Context through source.vpn_gateway_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Context through source.transit_gateway_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
aws.rule.vpn-gateway Source
Matches resource instances of aws_vpn_gateway.
Classification: aws.concept.vpn-gateway.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.vpc_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"