Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • azure/azapi: = 2.12.0.
  • hashicorp/azuread: = 3.9.0.
  • hashicorp/azurerm: = 5.3.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
azapi_resourceresourceazure-enclave
managed-database
sre-agent
azure-enclave (conditional)
horizondb-cluster (conditional)
sre-agent (conditional)
azuread_access_package_assignment_policyresourceidentity-governance-detailentra-access-package-assignment-policy
azuread_app_role_assignmentresourceidentity-governance-detailentra-app-role-assignment
azuread_application_federated_identity_credentialresourceidentity-governance-detailentra-application-federated-identity
azuread_application_registrationresourceentra-applicationentra-application-registration
azuread_applicationresourceentra-applicationentra-application
azuread_authentication_strength_policyresourceidentity-governance-detailentra-authentication-strength-policy
azuread_group_without_membersresourceidentity-groupentra-group-without-members
azuread_groupresourceidentity-groupentra-group
azuread_named_locationresourceidentity-governance-detailentra-named-location
azuread_service_principalresourceservice-identityentra-service-principal
azurerm_aadb2c_directoryresourceentra-directoryentra-external-id-directory
azurerm_active_directory_domain_service_replica_setresourceidentity-governance-detailentra-domain-services-replica-set
azurerm_active_directory_domain_service_trustresourceidentity-governance-detailentra-domain-services-trust
azurerm_active_directory_domain_serviceresourceentra-domain-serviceentra-domain-services
azurerm_advanced_threat_protectionresourcesecurity-detailadvanced-threat-protection
azurerm_ai_foundry_projectresourceai-foundryai-foundry-project
azurerm_ai_foundryresourceai-foundryai-foundry
azurerm_analysis_services_serverresourceanalytics-clusteranalysis-services-server
azurerm_api_connectionresourceintegration-connectionapi-connection
azurerm_api_management_apiresourceapi-management-detailapi-management-api
azurerm_api_management_backendresourceapi-management-detailapi-management-backend
azurerm_api_management_gatewayresourceapi-management-detailapi-management-gateway
azurerm_api_management_policyresourceapi-management-detailapi-management-policy
azurerm_api_management_productresourceapi-management-detailapi-management-product
azurerm_api_management_standalone_gatewayresourceapi-gatewayapi-management-standalone-gateway
azurerm_api_management_workspaceresourceapi-management-detailapi-management-workspace
azurerm_api_managementresourceapi-gatewayapi-management
azurerm_app_configurationresourceapp-configurationapp-configuration
azurerm_app_service_connectionresourceintegration-connectionapp-service-connection
azurerm_app_service_environment_v3resourceapp-service-environmentapp-service-environment
azurerm_application_gatewayresourceload-balancerapplication-gateway
azurerm_application_insights_standard_web_testresourceoperations-detailapplication-insights-web-test
azurerm_application_insightsresourceapplication-insightsapplication-insights
azurerm_application_load_balancer_frontendresourceload-balancer-componentapplication-load-balancer-frontend
azurerm_application_load_balancerresourceload-balancerapplication-load-balancer
azurerm_application_security_groupresourcenetwork-policy-detailapplication-security-group
azurerm_arc_kubernetes_clusterresourcekubernetes-clusterarc-kubernetes-cluster
azurerm_arc_kubernetes_provisioned_clusterresourcekubernetes-clusterarc-provisioned-kubernetes-cluster
azurerm_arc_machineresourcearc-enabled-serverarc-enabled-server
azurerm_arc_private_link_scoperesourceprivate-link-scopearc-private-link-scope
azurerm_arc_resource_bridge_applianceresourcearc-resource-bridgearc-resource-bridge
azurerm_attestation_providerresourceattestation-providerattestation-provider
azurerm_automation_accountresourceautomation-accountautomation-account
azurerm_automation_runbookresourceworkflowautomation-runbook
azurerm_automation_scheduleresourceoperations-detailautomation-schedule
azurerm_availability_setresourcecompute-placementavailability-set
azurerm_backup_policy_file_shareresourcebackup-planfile-share-backup-policy
azurerm_backup_policy_vmresourcebackup-planvirtual-machine-backup-policy
azurerm_backup_protected_vmresourcesite-recovery-detailbackup-protected-vm
azurerm_bastion_hostresourcebastion-hostbastion-host
azurerm_batch_accountresourcebatch-accountbatch-account
azurerm_batch_applicationresourcebatch-poolbatch-application
azurerm_batch_poolresourcebatch-poolbatch-pool
azurerm_bot_channels_registrationresourcebot-servicebot-channels-registration
azurerm_bot_service_azure_botresourcebot-serviceazure-bot
azurerm_bot_web_appresourcebot-servicebot-web-app
azurerm_capacity_reservation_groupresourcecompute-placementcapacity-reservation-group
azurerm_capacity_reservationresourcecompute-placementcapacity-reservation
azurerm_cdn_endpointresourcecontent-delivery-profilecdn-endpoint
azurerm_cdn_frontdoor_endpointresourceload-balancer-componentfront-door-endpoint
azurerm_cdn_frontdoor_origin_groupresourceload-balancer-componentfront-door-origin-group
azurerm_cdn_frontdoor_originresourceload-balancer-componentfront-door-origin
azurerm_cdn_frontdoor_profileresourcefront-door-profilefront-door-profile
azurerm_cdn_frontdoor_routeresourceload-balancer-componentfront-door-route
azurerm_cdn_profileresourcecontent-delivery-profilecdn-profile
azurerm_chaos_studio_experimentresourcechaos-experimentchaos-studio-experiment
azurerm_cognitive_account_projectresourceai-foundryai-services-project
azurerm_cognitive_accountresourceai-service-accountai-services-account
azurerm_cognitive_deploymentresourceai-inference-endpointai-model-deployment
azurerm_communication_serviceresourcecommunication-servicecommunication-service
azurerm_confidential_ledgerresourceconfidential-ledgerconfidential-ledger
azurerm_container_app_environmentresourcecontainer-app-environmentcontainer-app-environment
azurerm_container_app_jobresourcecontainer-app-jobcontainer-app-job
azurerm_container_appresourcecontainer-appcontainer-app
azurerm_container_connected_registryresourcecontainer-registryconnected-container-registry
azurerm_container_groupresourcecontainer-instance-groupcontainer-instance-group
azurerm_container_registryresourcecontainer-registrycontainer-registry
azurerm_cosmosdb_accountresourcecosmos-accountcosmos-account
azurerm_cosmosdb_cassandra_clusterresourcemanaged-databasecosmos-cassandra-cluster
azurerm_cosmosdb_cassandra_keyspaceresourcelogical-databasecosmos-cassandra-keyspace
azurerm_cosmosdb_cassandra_tableresourcedatabase-componentcosmos-cassandra-table
azurerm_cosmosdb_gremlin_databaseresourcelogical-databasecosmos-gremlin-database
azurerm_cosmosdb_gremlin_graphresourcedatabase-componentcosmos-gremlin-graph
azurerm_cosmosdb_mongo_collectionresourcedatabase-componentcosmos-mongo-collection
azurerm_cosmosdb_mongo_databaseresourcelogical-databasecosmos-mongo-database
azurerm_cosmosdb_postgresql_clusterresourcemanaged-databasecosmos-postgresql-cluster
azurerm_cosmosdb_sql_containerresourcedatabase-componentcosmos-sql-container
azurerm_cosmosdb_sql_databaseresourcelogical-databasecosmos-sql-database
azurerm_cosmosdb_sql_dedicated_gatewayresourcedatabase-componentcosmos-dedicated-gateway
azurerm_custom_ip_prefixresourcepublic-addresscustom-ip-prefix
azurerm_dashboard_grafanaresourcemanaged-grafanamanaged-grafana
azurerm_data_factory_data_flowresourcedata-integration-detaildata-factory-data-flow
azurerm_data_factory_dataset_azure_blobresourcedata-integration-detaildata-factory-blob-dataset
azurerm_data_factory_dataset_azure_sql_tableresourcedata-integration-detaildata-factory-sql-dataset
azurerm_data_factory_integration_runtime_azureresourcedata-integration-runtimedata-factory-azure-integration-runtime
azurerm_data_factory_integration_runtime_self_hostedresourcedata-integration-runtimedata-factory-self-hosted-integration-runtime
azurerm_data_factory_linked_service_azure_blob_storageresourcedata-integration-detaildata-factory-blob-linked-service
azurerm_data_factory_linked_service_azure_sql_databaseresourcedata-integration-detaildata-factory-sql-linked-service
azurerm_data_factory_managed_private_endpointresourcedata-integration-detaildata-factory-managed-private-endpoint
azurerm_data_factory_pipelineresourceworkflowdata-factory-pipeline
azurerm_data_factory_trigger_scheduleresourcedata-integration-detaildata-factory-schedule-trigger
azurerm_data_factoryresourcedata-factorydata-factory
azurerm_data_protection_backup_policy_blob_storageresourcebackup-plandata-protection-blob-backup-policy
azurerm_data_protection_backup_policy_diskresourcebackup-plandata-protection-disk-backup-policy
azurerm_data_protection_backup_vaultresourcebackup-vaultdata-protection-backup-vault
azurerm_data_share_accountresourcedata-share-accountdata-share-account
azurerm_database_migration_projectresourcemigration-servicedatabase-migration-project
azurerm_database_migration_serviceresourcemigration-servicedatabase-migration-service
azurerm_databox_edge_deviceresourcemigration-servicedata-box-edge-device
azurerm_databricks_virtual_network_peeringresourcenetwork-peeringdatabricks-virtual-network-peering
azurerm_databricks_workspaceresourcedatabricks-workspacedatabricks-workspace
azurerm_datadog_monitorresourcethird-party-monitordatadog-monitor
azurerm_dedicated_hardware_security_moduleresourcemanaged-hsmdedicated-hardware-security-module
azurerm_dedicated_host_groupresourcededicated-host-groupdedicated-host-group
azurerm_dev_center_dev_box_definitionresourcedeveloper-environmentdev-box-definition
azurerm_dev_center_projectresourcedev-center-projectdev-center-project
azurerm_dev_centerresourcedev-centerdev-center
azurerm_dev_test_labresourcedeveloper-environmentdev-test-lab
azurerm_dev_test_linux_virtual_machineresourcecompute-instancedev-test-linux-virtual-machine
azurerm_dev_test_windows_virtual_machineresourcecompute-instancedev-test-windows-virtual-machine
azurerm_digital_twins_endpoint_eventgridresourceiot-detaildigital-twins-event-grid-endpoint
azurerm_digital_twins_instanceresourcedigital-twins-instancedigital-twins-instance
azurerm_dns_a_recordresourcedns-recorddns-a-record
azurerm_dns_aaaa_recordresourcedns-recorddns-aaaa-record
azurerm_dns_cname_recordresourcedns-recorddns-cname-record
azurerm_dns_mx_recordresourcedns-recorddns-mx-record
azurerm_dns_ns_recordresourcedns-recorddns-ns-record
azurerm_dns_ptr_recordresourcedns-recorddns-ptr-record
azurerm_dns_srv_recordresourcedns-recorddns-srv-record
azurerm_dns_txt_recordresourcedns-recorddns-txt-record
azurerm_dns_zoneresourcedns-zonedns-zone
azurerm_dynatrace_monitorresourcethird-party-monitordynatrace-monitor
azurerm_elastic_cloud_elasticsearchresourcethird-party-monitorelastic-cloud
azurerm_elastic_san_volume_groupresourceelastic-sanelastic-san-volume-group
azurerm_elastic_san_volumeresourceblock-storage-volumeelastic-san-volume
azurerm_elastic_sanresourceelastic-sanelastic-san
azurerm_email_communication_serviceresourceemail-communication-serviceemail-communication-service
azurerm_eventgrid_domain_topicresourceevent-grid-topicevent-grid-domain-topic
azurerm_eventgrid_domainresourceevent-grid-domainevent-grid-domain
azurerm_eventgrid_event_subscriptionresourcemessage-subscriptionevent-grid-event-subscription
azurerm_eventgrid_namespace_topicresourcemessage-topicevent-grid-namespace-topic
azurerm_eventgrid_namespaceresourceevent-grid-domainevent-grid-namespace
azurerm_eventgrid_partner_namespaceresourceevent-grid-domainevent-grid-partner-namespace
azurerm_eventgrid_system_topic_event_subscriptionresourcemessage-subscriptionevent-grid-system-topic-subscription
azurerm_eventgrid_system_topicresourceevent-grid-topicevent-grid-system-topic
azurerm_eventgrid_topicresourceevent-grid-topicevent-grid-topic
azurerm_eventhub_clusterresourceevent-streamevent-hubs-cluster
azurerm_eventhub_consumer_groupresourcemessaging-detailevent-hubs-consumer-group
azurerm_eventhub_namespace_schema_groupresourcemessaging-detailevent-hubs-schema-group
azurerm_eventhub_namespaceresourcemessaging-namespaceevent-hubs-namespace
azurerm_eventhubresourceevent-streamevent-hub
azurerm_express_route_circuitresourcededicated-interconnectexpressroute-circuit
azurerm_express_route_gatewayresourceexpressroute-gatewayexpressroute-gateway
azurerm_express_route_portresourcededicated-interconnectexpressroute-port
azurerm_extended_location_custom_locationresourcecustom-locationarc-custom-location
azurerm_fabric_capacityresourceanalytics-clusterfabric-capacity
azurerm_firewall_policy_rule_collection_groupresourcefirewall-policyazure-firewall-policy-rule-collection-group
azurerm_firewall_policyresourcefirewall-policyazure-firewall-policy
azurerm_firewallresourceazure-firewallazure-firewall
azurerm_fluid_relay_serverresourcerealtime-communication-servicefluid-relay
azurerm_frontdoorresourcefront-door-profileclassic-front-door
azurerm_function_app_flex_consumptionresourceserverless-functionflex-consumption-function-app
azurerm_function_app_functionresourceserverless-functionfunction-app-function
azurerm_graph_services_accountresourcegraph-data-connect-accountgraph-data-connect-account
azurerm_hdinsight_hadoop_clusterresourceanalytics-clusterhdinsight-hadoop-cluster
azurerm_hdinsight_hbase_clusterresourceanalytics-clusterhdinsight-hbase-cluster
azurerm_hdinsight_interactive_query_clusterresourceanalytics-clusterhdinsight-interactive-query-cluster
azurerm_hdinsight_kafka_clusterresourceanalytics-clusterhdinsight-kafka-cluster
azurerm_hdinsight_spark_clusterresourceanalytics-clusterhdinsight-spark-cluster
azurerm_healthbotresourcebot-servicehealth-bot
azurerm_healthcare_dicom_serviceresourcehealth-data-servicehealth-data-dicom-service
azurerm_healthcare_fhir_serviceresourcehealth-data-servicehealth-data-fhir-service
azurerm_healthcare_medtech_serviceresourcehealth-data-servicehealth-data-medtech-service
azurerm_healthcare_serviceresourcehealth-data-servicehealthcare-service
azurerm_healthcare_workspaceresourcehealth-data-workspacehealth-data-services-workspace
azurerm_imageresourcecompute-imagecompute-image
azurerm_iotcentral_applicationresourceiot-central-applicationiot-central-application
azurerm_iothub_device_update_accountresourceiot-update-serviceiot-hub-device-update-account
azurerm_iothub_device_update_instanceresourceiot-detailiot-hub-device-update-instance
azurerm_iothub_dpsresourceiot-provisioning-serviceiot-hub-device-provisioning-service
azurerm_iothub_endpoint_eventhubresourceiot-detailiot-hub-event-hubs-endpoint
azurerm_iothub_endpoint_servicebus_queueresourceiot-detailiot-hub-service-bus-queue-endpoint
azurerm_iothub_endpoint_storage_containerresourceiot-detailiot-hub-storage-endpoint
azurerm_iothubresourceiot-hubiot-hub
azurerm_ip_groupresourcenetwork-policy-detailip-group
azurerm_key_vault_access_policyresourcesecurity-detailkey-vault-access-policy
azurerm_key_vault_certificateresourcesecurity-detailkey-vault-certificate
azurerm_key_vault_keyresourceencryption-keykey-vault-key
azurerm_key_vault_managed_hardware_security_module_keyresourceencryption-keymanaged-hsm-key
azurerm_key_vault_managed_hardware_security_moduleresourcemanaged-hsmmanaged-hsm
azurerm_key_vault_secretresourcemanaged-secretkey-vault-secret
azurerm_key_vaultresourcekey-vaultkey-vault
azurerm_kubernetes_automatic_clusterresourcekubernetes-clusterautomatic-kubernetes-cluster
azurerm_kubernetes_cluster_node_poolresourcekubernetes-node-poolaks-node-pool
azurerm_kubernetes_clusterresourcekubernetes-clusteraks-cluster
azurerm_kubernetes_fleet_managerresourcekubernetes-fleetkubernetes-fleet
azurerm_kusto_clusterresourcedata-explorer-clusterdata-explorer-cluster
azurerm_kusto_eventgrid_data_connectionresourcedatabase-componentdata-explorer-event-grid-connection
azurerm_kusto_eventhub_data_connectionresourcedatabase-componentdata-explorer-event-hubs-connection
azurerm_lb_backend_address_poolresourceload-balancer-componentload-balancer-backend-pool
azurerm_lb_nat_ruleresourceload-balancer-componentload-balancer-nat-rule
azurerm_lb_outbound_ruleresourceload-balancer-componentload-balancer-outbound-rule
azurerm_lb_proberesourceload-balancer-componentload-balancer-probe
azurerm_lb_ruleresourceload-balancer-componentload-balancer-rule
azurerm_lbresourceload-balancerload-balancer
azurerm_lighthouse_definitionresourcegovernance-detaillighthouse-definition
azurerm_linux_function_appresourceserverless-functionlinux-function-app
azurerm_linux_virtual_machine_scale_setresourcevirtual-machine-scale-setlinux-virtual-machine-scale-set
azurerm_linux_virtual_machineresourcecompute-instancelinux-virtual-machine
azurerm_linux_web_appresourceapp-servicelinux-web-app
azurerm_load_testresourceload-testload-test
azurerm_local_network_gatewayresourcelocal-network-gatewaylocal-network-gateway
azurerm_log_analytics_clusterresourcelog-analytics-workspacelog-analytics-cluster
azurerm_log_analytics_data_export_ruleresourceoperations-detaillog-analytics-data-export-rule
azurerm_log_analytics_saved_searchresourceoperations-detaillog-analytics-saved-search
azurerm_log_analytics_solutionresourceoperations-detaillog-analytics-solution
azurerm_log_analytics_workspace_tableresourceoperations-detaillog-analytics-workspace-table
azurerm_log_analytics_workspaceresourcelog-analytics-workspacelog-analytics-workspace
azurerm_logic_app_action_httpresourceapi-management-detaillogic-app-http-action
azurerm_logic_app_integration_accountresourceintegration-accountlogic-app-integration-account
azurerm_logic_app_standardresourceworkflowlogic-app-standard
azurerm_logic_app_trigger_recurrenceresourceapi-management-detaillogic-app-recurrence-trigger
azurerm_logic_app_workflowresourceworkflowlogic-app-workflow
azurerm_machine_learning_compute_clusterresourcemachine-learning-computemachine-learning-compute-cluster
azurerm_machine_learning_compute_instanceresourcemachine-learning-computemachine-learning-compute-instance
azurerm_machine_learning_inference_clusterresourceai-inference-endpointmachine-learning-inference-cluster
azurerm_machine_learning_workspaceresourcemachine-learning-workspacemachine-learning-workspace
azurerm_maintenance_configurationresourcemaintenance-configurationmaintenance-configuration
azurerm_managed_applicationresourcemanaged-applicationmanaged-application
azurerm_managed_devops_poolresourcedeveloper-environmentmanaged-devops-pool
azurerm_managed_diskresourceblock-storage-volumemanaged-disk
azurerm_managed_lustre_file_systemresourcemanaged-file-storagemanaged-lustre-file-system
azurerm_managed_redis_geo_replicationresourcedatabase-componentmanaged-redis-geo-replication
azurerm_managed_redisresourcemanaged-cacheazure-managed-redis
azurerm_maps_accountresourcemaps-accountmaps-account
azurerm_mongo_clusterresourcemanaged-databasemongo-cluster
azurerm_monitor_action_groupresourceoperations-detailmonitor-action-group
azurerm_monitor_data_collection_endpointresourceoperations-detailmonitor-data-collection-endpoint
azurerm_monitor_diagnostic_settingresourceoperations-detailmonitor-diagnostic-setting
azurerm_monitor_metric_alertresourceoperations-detailmonitor-metric-alert
azurerm_monitor_private_link_scoperesourceprivate-link-scopemonitor-private-link-scope
azurerm_monitor_scheduled_query_rules_alert_v2resourceoperations-detailmonitor-scheduled-query-alert
azurerm_monitor_workspaceresourcemonitor-workspacemonitor-workspace
azurerm_mssql_databaseresourcelogical-databasemssql-database
azurerm_mssql_elasticpoolresourcedatabase-componentsql-elastic-pool
azurerm_mssql_failover_groupresourcedatabase-componentsql-failover-group
azurerm_mssql_managed_databaseresourcelogical-databasesql-managed-database
azurerm_mssql_managed_instanceresourcemanaged-databasesql-managed-instance
azurerm_mssql_serverresourcesql-servermssql-server
azurerm_mysql_flexible_databaseresourcelogical-databasemysql-database
azurerm_mysql_flexible_serverresourcemanaged-databasemysql-flexible-server
azurerm_nat_gateway_public_ip_associationresourcenetwork-policy-detailnat-gateway-public-ip-association
azurerm_nat_gateway_public_ip_prefix_associationresourcenetwork-policy-detailnat-gateway-public-ip-prefix-association
azurerm_nat_gatewayresourcemanaged-natnat-gateway
azurerm_netapp_accountresourcenetapp-accountnetapp-account
azurerm_netapp_backup_policyresourcebackup-plannetapp-backup-policy
azurerm_netapp_backup_vaultresourcebackup-vaultnetapp-backup-vault
azurerm_netapp_poolresourcenetapp-capacity-poolnetapp-capacity-pool
azurerm_netapp_volumeresourcemanaged-file-storagenetapp-volume
azurerm_network_ddos_protection_planresourceddos-protection-planddos-protection-plan
azurerm_network_function_azure_traffic_collectorresourcenetwork-function-servicenetwork-function-traffic-collector
azurerm_network_manager_ipam_poolresourcenetwork-policy-detailnetwork-manager-ipam-pool
azurerm_network_managerresourcevirtual-network-managervirtual-network-manager
azurerm_network_security_groupresourcenetwork-security-groupnetwork-security-group
azurerm_network_security_perimeterresourcenetwork-security-perimeternetwork-security-perimeter
azurerm_network_security_ruleresourcenetwork-policy-detailnetwork-security-rule
azurerm_network_watcher_flow_logresourceoperations-detailnetwork-watcher-flow-log
azurerm_network_watcherresourcenetwork-watchernetwork-watcher
azurerm_new_relic_monitorresourcethird-party-monitornew-relic-monitor
azurerm_nginx_deploymentresourcehybrid-platformnginx-deployment
azurerm_notification_hub_namespaceresourcenotification-namespacenotification-hubs-namespace
azurerm_notification_hubresourcenotification-hubnotification-hub
azurerm_oracle_autonomous_databaseresourcemanaged-databaseoracle-autonomous-database
azurerm_oracle_cloud_vm_clusterresourcehybrid-platformoracle-cloud-vm-cluster
azurerm_oracle_exadata_infrastructureresourcehybrid-platformoracle-exadata-infrastructure
azurerm_oracle_resource_anchorresourcehybrid-platformoracle-resource-anchor
azurerm_orchestrated_virtual_machine_scale_setresourcevirtual-machine-scale-setorchestrated-virtual-machine-scale-set
azurerm_palo_alto_next_generation_firewall_virtual_network_local_rulestackresourcehybrid-platformpalo-alto-firewall
azurerm_playwright_workspaceresourcedeveloper-environmentplaywright-workspace
azurerm_point_to_site_vpn_gatewayresourcevpn-gatewaypoint-to-site-vpn-gateway
azurerm_policy_definitionresourcegovernance-detailpolicy-definition
azurerm_policy_set_definitionresourcegovernance-detailpolicy-set-definition
azurerm_portal_dashboardresourceoperations-detailportal-dashboard
azurerm_postgresql_flexible_server_backupresourcedatabase-componentpostgresql-backup
azurerm_postgresql_flexible_server_databaseresourcelogical-databasepostgresql-database
azurerm_postgresql_flexible_serverresourcemanaged-databasepostgresql-flexible-server
azurerm_powerbi_embeddedresourceanalytics-clusterpower-bi-embedded-capacity
azurerm_private_dns_a_recordresourcedns-recordprivate-dns-a-record
azurerm_private_dns_cname_recordresourcedns-recordprivate-dns-cname-record
azurerm_private_dns_resolver_dns_forwarding_rulesetresourceprivate-network-linkprivate-dns-forwarding-ruleset
azurerm_private_dns_resolver_inbound_endpointresourceprivate-network-linkprivate-dns-inbound-endpoint
azurerm_private_dns_resolver_outbound_endpointresourceprivate-network-linkprivate-dns-outbound-endpoint
azurerm_private_dns_resolverresourceprivate-dns-resolverprivate-dns-resolver
azurerm_private_dns_zone_virtual_network_linkresourceprivate-network-linkprivate-dns-zone-vnet-link
azurerm_private_dns_zoneresourcedns-zoneprivate-dns-zone
azurerm_private_endpointresourceprivate-endpointprivate-endpoint
azurerm_private_link_serviceresourceprivate-link-serviceprivate-link-service
azurerm_proximity_placement_groupresourcecompute-placementproximity-placement-group
azurerm_public_ip_prefixresourcepublic-addresspublic-ip-prefix
azurerm_public_ipresourcepublic-addresspublic-address
azurerm_purview_accountresourcepurview-accountpurview-account
azurerm_qumulo_file_systemresourcemanaged-file-storagequmulo-file-system
azurerm_recovery_services_vaultresourcebackup-vaultrecovery-services-vault
azurerm_redhat_openshift_clusterresourcekubernetes-clusterred-hat-openshift-cluster
azurerm_redis_cacheresourcemanaged-cacheazure-cache-for-redis
azurerm_relay_hybrid_connectionresourcerelay-connectionrelay-hybrid-connection
azurerm_relay_namespaceresourcerelay-namespacerelay-namespace
azurerm_resource_groupresourceresource-groupresource-group
azurerm_resource_policy_assignmentresourcegovernance-detailresource-policy-assignment
azurerm_role_assignmentresourcegovernance-detailrole-assignment
azurerm_role_definitionresourcegovernance-detailrole-definition
azurerm_route_serverresourceroute-tableroute-server
azurerm_route_tableresourceroute-tableroute-table
azurerm_routeresourcenetwork-policy-detailroute
azurerm_search_serviceresourceai-search-serviceai-search-service
azurerm_security_center_subscription_pricingresourcedefender-plandefender-subscription-plan
azurerm_security_center_workspaceresourcedefender-plandefender-workspace
azurerm_sentinel_alert_rule_nrtresourcesecurity-detailsentinel-nrt-alert-rule
azurerm_sentinel_alert_rule_scheduledresourcesecurity-detailsentinel-scheduled-alert-rule
azurerm_sentinel_automation_ruleresourcesecurity-detailsentinel-automation-rule
azurerm_sentinel_data_connector_aws_cloud_trailresourcesecurity-detailsentinel-aws-cloudtrail-connector
azurerm_sentinel_data_connector_azure_active_directoryresourcesecurity-detailsentinel-entra-connector
azurerm_service_fabric_clusterresourceservice-fabric-clusterservice-fabric-cluster
azurerm_service_fabric_managed_clusterresourceservice-fabric-clustermanaged-service-fabric-cluster
azurerm_service_planresourceapp-service-planapp-service-plan
azurerm_servicebus_namespaceresourcemessaging-namespaceservice-bus-namespace
azurerm_servicebus_queueresourcemessage-queueservice-bus-queue
azurerm_servicebus_subscription_ruleresourcemessaging-detailservice-bus-subscription-rule
azurerm_servicebus_subscriptionresourcemessage-subscriptionservice-bus-subscription
azurerm_servicebus_topicresourceservice-bus-topicservice-bus-topic
azurerm_shared_image_galleryresourceimage-gallerycompute-gallery
azurerm_shared_imageresourcecompute-imageshared-image
azurerm_signalr_serviceresourcerealtime-communication-servicesignalr-service
azurerm_site_recovery_fabricresourcesite-recovery-fabricsite-recovery-fabric
azurerm_site_recovery_protection_containerresourcesite-recovery-fabricsite-recovery-protection-container
azurerm_site_recovery_replicated_vmresourcesite-recovery-detailsite-recovery-replicated-vm
azurerm_site_recovery_replication_recovery_planresourcesite-recovery-detailsite-recovery-plan
azurerm_snapshotresourcedisk-snapshotdisk-snapshot
azurerm_spring_cloud_appresourcespring-appspring-app
azurerm_spring_cloud_gatewayresourcespring-appspring-apps-gateway
azurerm_spring_cloud_serviceresourcespring-apps-servicespring-apps-service
azurerm_stack_hci_clusterresourceazure-local-clusterazure-local-cluster
azurerm_stack_hci_virtual_hard_diskresourceblock-storage-volumestack-hci-virtual-hard-disk
azurerm_static_web_appresourcestatic-web-appstatic-web-app
azurerm_storage_accountresourcestorage-accountstorage-account
azurerm_storage_blobresourcestorage-object-detailstorage-blob
azurerm_storage_containerresourceobject-storage-containerblob-container
azurerm_storage_data_lake_gen2_filesystemresourceobject-storage-containerdata-lake-filesystem
azurerm_storage_data_lake_gen2_pathresourcestorage-object-detaildata-lake-path
azurerm_storage_encryption_scoperesourcestorage-object-detailstorage-encryption-scope
azurerm_storage_management_policyresourcestorage-object-detailstorage-management-policy
azurerm_storage_moverresourcemigration-servicestorage-mover
azurerm_storage_queueresourcemessage-queuequeue-storage-queue
azurerm_storage_share_directoryresourcestorage-object-detailstorage-share-directory
azurerm_storage_share_fileresourcestorage-object-detailstorage-share-file
azurerm_storage_shareresourcemanaged-file-storageazure-files-share
azurerm_storage_syncresourcestorage-sync-servicestorage-sync-service
azurerm_storage_table_entityresourcestorage-object-detailstorage-table-entity
azurerm_storage_tableresourcetable-storage-tabletable-storage-table
azurerm_stream_analytics_clusterresourceanalytics-clusterstream-analytics-cluster
azurerm_stream_analytics_jobresourcestream-analytics-jobstream-analytics-job
azurerm_stream_analytics_output_blobresourcedata-integration-detailstream-analytics-blob-output
azurerm_stream_analytics_stream_input_eventhub_v2resourcedata-integration-detailstream-analytics-event-hubs-input
azurerm_subnet_nat_gateway_associationresourcenetwork-policy-detailsubnet-nat-gateway-association
azurerm_subnet_network_security_group_associationresourcenetwork-policy-detailsubnet-network-security-group-association
azurerm_subnet_route_table_associationresourcenetwork-policy-detailsubnet-route-table-association
azurerm_subnetresourcesubnetsubnet
azurerm_synapse_private_link_hubresourceprivate-link-scopesynapse-private-link-hub
azurerm_synapse_spark_poolresourceanalytics-poolsynapse-spark-pool
azurerm_synapse_sql_poolresourceanalytics-poolsynapse-sql-pool
azurerm_synapse_workspaceresourcesynapse-workspacesynapse-workspace
azurerm_system_center_virtual_machine_manager_serverresourcehybrid-platformsystem-center-vmm-server
azurerm_system_center_virtual_machine_manager_virtual_machine_instanceresourcecompute-instancesystem-center-virtual-machine
azurerm_traffic_manager_azure_endpointresourceload-balancer-componenttraffic-manager-azure-endpoint
azurerm_traffic_manager_profileresourcetraffic-manager-profiletraffic-manager-profile
azurerm_trusted_signing_accountresourcetrusted-signing-accounttrusted-signing-account
azurerm_user_assigned_identityresourceservice-identityuser-assigned-managed-identity
azurerm_video_indexer_accountresourcevideo-indexer-accountvideo-indexer-account
azurerm_virtual_desktop_application_groupresourcevirtual-desktop-application-groupvirtual-desktop-application-group
azurerm_virtual_desktop_applicationresourcecompute-placementvirtual-desktop-application
azurerm_virtual_desktop_host_poolresourcevirtual-desktop-host-poolvirtual-desktop-host-pool
azurerm_virtual_desktop_scaling_planresourcecompute-placementvirtual-desktop-scaling-plan
azurerm_virtual_desktop_workspaceresourcevirtual-desktop-workspacevirtual-desktop-workspace
azurerm_virtual_hubresourcevirtual-hubvirtual-hub
azurerm_virtual_machine_restore_pointresourcedisk-snapshotvirtual-machine-restore-point
azurerm_virtual_machine_scale_setresourcevirtual-machine-scale-setvirtual-machine-scale-set
azurerm_virtual_machineresourcecompute-instancevirtual-machine
azurerm_virtual_network_gateway_connectionresourcevpn-connectionvirtual-network-gateway-connection
azurerm_virtual_network_gatewayresourcevpn-gatewayvirtual-network-gateway
azurerm_virtual_network_peeringresourcenetwork-peeringvirtual-network-peering
azurerm_virtual_networkresourcevirtual-networkvirtual-network
azurerm_virtual_wanresourcevirtual-wanvirtual-wan
azurerm_vmware_clusterresourcehybrid-platformvmware-cluster
azurerm_vmware_private_cloudresourcevmware-private-cloudvmware-private-cloud
azurerm_vpn_gateway_connectionresourcevpn-connectionvpn-gateway-connection
azurerm_vpn_gatewayresourcevpn-gatewayvpn-gateway
azurerm_vpn_siteresourcelocal-network-gatewayvpn-site
azurerm_web_application_firewall_policyresourceweb-application-firewall-policyweb-application-firewall-policy
azurerm_web_pubsubresourcerealtime-communication-serviceweb-pubsub
azurerm_windows_function_appresourceserverless-functionwindows-function-app
azurerm_windows_virtual_machine_scale_setresourcevirtual-machine-scale-setwindows-virtual-machine-scale-set
azurerm_windows_virtual_machineresourcecompute-instancewindows-virtual-machine
azurerm_windows_web_appresourceapp-servicewindows-web-app
azurerm_workloads_sap_discovery_virtual_instanceresourcehybrid-platformsap-discovery-virtual-instance
azurerm_workloads_sap_single_node_virtual_instanceresourcehybrid-platformsap-single-node-virtual-instance
azurerm_workloads_sap_three_tier_virtual_instanceresourcehybrid-platformsap-three-tier-virtual-instance

Local vocabulary

Concepts

azure.concept.ai-foundry Source

A Microsoft Foundry account or project boundary.

Used by ai-foundry, ai-foundry-project, ai-services-project.

azure.concept.ai-inference-endpoint Source

A managed endpoint that serves model inference requests.

Used by ai-model-deployment, machine-learning-inference-cluster.

azure.concept.ai-search-service Source

An Azure AI Search service.

Used by ai-search-service.

azure.concept.ai-service-account Source

An Azure AI services account exposing managed AI APIs.

Used by ai-services-account.

azure.concept.analytics-pool Source

A SQL or Apache Spark analytics pool.

Used by synapse-spark-pool, synapse-sql-pool.

azure.concept.api-gateway Source

A managed gateway that exposes and governs APIs.

Used by api-management, api-management-standalone-gateway.

azure.concept.api-management-detail Source

An API, product, backend, policy, workspace, or gateway configuration inside API Management.

Used by 8 Rules
azure.concept.app-configuration Source

An Azure App Configuration store.

Used by app-configuration.

azure.concept.app-service Source

An Azure App Service web application runtime.

Used by linux-web-app, windows-web-app.

azure.concept.app-service-environment Source

An isolated Azure App Service hosting environment.

Used by app-service-environment.

azure.concept.app-service-plan Source

An Azure App Service plan providing shared runtime capacity.

Used by 6 Rules
azure.concept.application-insights Source

An Azure Monitor Application Insights application resource.

Used by application-insights, linux-function-app, windows-function-app.

azure.concept.arc-enabled-server Source

A server connected to Azure through Azure Arc.

Used by arc-enabled-server.

azure.concept.arc-resource-bridge Source

An Azure Arc resource bridge connecting an external platform.

Used by arc-resource-bridge.

azure.concept.attestation-provider Source

A Microsoft Azure Attestation provider.

Used by attestation-provider.

azure.concept.automation-account Source

An Azure Automation account owning runbooks and schedules.

Used by automation-account.

azure.concept.azure-enclave Source

An Azure Enclave isolated workload and connectivity boundary.

Used by azure-enclave.

azure.concept.azure-firewall Source

An Azure Firewall managed network security service.

Used by azure-firewall.

azure.concept.azure-local-cluster Source

An Azure Local or Azure Stack HCI cluster.

Used by azure-local-cluster.

azure.concept.backup-plan Source

A managed policy scheduling and retaining backups.

Used by 5 Rules
azure.concept.backup-vault Source

A managed vault storing protected recovery data.

Used by data-protection-backup-vault, netapp-backup-vault, recovery-services-vault.

azure.concept.bastion-host Source

An Azure Bastion service providing managed private administration access.

Used by bastion-host.

azure.concept.batch-account Source

An Azure Batch account owning pools, jobs, and applications.

Used by batch-account.

azure.concept.batch-pool Source

A pool providing compute capacity to Azure Batch.

Used by batch-application, batch-pool.

azure.concept.block-storage-volume Source

A durable block-storage volume attachable to compute workloads.

Used by elastic-san-volume, managed-disk, stack-hci-virtual-hard-disk.

azure.concept.bot-service Source

An Azure Bot Service bot registration or application.

Used by 4 Rules
azure.concept.chaos-experiment Source

An Azure Chaos Studio experiment.

Used by chaos-studio-experiment.

azure.concept.communication-service Source

An Azure Communication Services resource.

Used by communication-service.

azure.concept.compute-image Source

A reusable Azure compute image or image definition.

Used by compute-image, shared-image.

azure.concept.compute-instance Source

A provisioned compute instance running a workload.

Used by 6 Rules
azure.concept.compute-placement Source

Availability, proximity, reservation, or host placement supporting Azure compute.

Used by 6 Rules
azure.concept.confidential-ledger Source

An Azure confidential ledger providing tamper-evident storage.

Used by confidential-ledger.

azure.concept.container-app Source

An Azure Container Apps service running container revisions.

Used by container-app.

azure.concept.container-app-environment Source

An Azure Container Apps environment sharing network and operational boundaries.

Used by container-app, container-app-environment, container-app-job.

azure.concept.container-app-job Source

An Azure Container Apps job running finite container work.

Used by container-app-job.

azure.concept.container-instance-group Source

An Azure Container Instances container group scheduled as one unit.

Used by container-instance-group.

azure.concept.container-registry Source

An Azure Container Registry storing and distributing OCI artifacts.

Used by connected-container-registry, container-registry.

azure.concept.content-delivery-profile Source

An Azure content delivery profile serving cached content globally.

Used by cdn-endpoint, cdn-profile.

azure.concept.cosmos-account Source

An Azure Cosmos DB account defining global distribution and API boundaries.

Used by 6 Rules
azure.concept.custom-location Source

An Azure Arc custom location extending Azure resource placement.

Used by arc-custom-location.

azure.concept.data-explorer-cluster Source

An Azure Data Explorer cluster serving real-time analytics.

Used by data-explorer-cluster.

azure.concept.data-factory Source

An Azure Data Factory integration and orchestration boundary.

Used by data-factory.

azure.concept.data-integration-runtime Source

A managed or self-hosted Azure data integration runtime.

Used by data-factory-azure-integration-runtime, data-factory-self-hosted-integration-runtime.

azure.concept.data-share-account Source

An Azure Data Share account.

Used by data-share-account.

azure.concept.databricks-workspace Source

An Azure Databricks workspace.

Used by databricks-workspace.

azure.concept.ddos-protection-plan Source

An Azure DDoS Protection plan protecting virtual networks.

Used by ddos-protection-plan.

azure.concept.dedicated-host-group Source

An Azure Dedicated Host placement group.

Used by dedicated-host-group.

azure.concept.dedicated-interconnect Source

A dedicated private connection between an external network and a cloud provider.

Used by expressroute-circuit, expressroute-port.

azure.concept.defender-plan Source

A Microsoft Defender for Cloud protection plan or workspace integration.

Used by defender-subscription-plan, defender-workspace.

azure.concept.dev-center Source

A Microsoft Dev Box and deployment-environment Dev Center.

Used by dev-center.

azure.concept.dev-center-project Source

A Dev Center project boundary.

Used by dev-center-project.

azure.concept.developer-environment Source

A developer workstation, environment, or testing workspace.

Used by 4 Rules
azure.concept.digital-twins-instance Source

An Azure Digital Twins service instance.

Used by digital-twins-instance.

azure.concept.disk-snapshot Source

A point-in-time snapshot of Azure disk storage.

Used by disk-snapshot, virtual-machine-restore-point.

azure.concept.elastic-san Source

An Azure Elastic SAN storage boundary.

Used by elastic-san, elastic-san-volume-group.

azure.concept.email-communication-service Source

An Azure Communication Services Email resource.

Used by email-communication-service.

azure.concept.encryption-key Source

A managed key used for cryptographic operations.

Used by key-vault-key, managed-hsm-key.

azure.concept.entra-application Source

A Microsoft Entra application identity definition.

Used by entra-application, entra-application-registration.

azure.concept.entra-directory Source

A Microsoft Entra External ID directory boundary.

Used by entra-external-id-directory.

azure.concept.entra-domain-service Source

A Microsoft Entra Domain Services managed domain.

Used by entra-domain-services.

azure.concept.event-grid-domain Source

An Azure Event Grid domain or namespace owning event topics.

Used by 5 Rules
azure.concept.event-grid-topic Source

An Azure Event Grid custom, domain, or system topic owning event subscriptions.

Used by 4 Rules
azure.concept.event-stream Source

An Azure Event Hubs append-only event stream.

Used by 5 Rules
azure.concept.expressroute-gateway Source

An Azure ExpressRoute gateway connecting a virtual network to private circuits.

Used by expressroute-gateway.

azure.concept.firewall-policy Source

An Azure Firewall or web application firewall policy.

Used by azure-firewall-policy, azure-firewall-policy-rule-collection-group.

azure.concept.front-door-profile Source

An Azure Front Door global application delivery profile.

Used by classic-front-door, front-door-profile.

azure.concept.governance-detail Source

An Azure policy, role, deployment, budget, or governance configuration.

Used by 6 Rules
azure.concept.graph-data-connect-account Source

A Microsoft Graph Data Connect service account.

Used by graph-data-connect-account.

azure.concept.health-data-service Source

A FHIR, DICOM, or MedTech service in Azure Health Data Services.

Used by 4 Rules
azure.concept.health-data-workspace Source

An Azure Health Data Services workspace owning healthcare data services.

Used by health-data-services-workspace.

azure.concept.identity-governance-detail Source

A location, assignment, federation, role, or policy supporting identity governance.

Used by 7 Rules
azure.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by entra-group, entra-group-without-members.

An Azure Compute Gallery owning image definitions and versions.

Used by compute-gallery.

azure.concept.integration-account Source

An Azure Logic Apps integration account.

Used by logic-app-integration-account.

azure.concept.integration-connection Source

An Azure API or App Service connection supporting integration.

Used by api-connection, app-service-connection.

azure.concept.iot-central-application Source

An Azure IoT Central application.

Used by iot-central-application.

azure.concept.iot-detail Source

A route, endpoint, consumer group, certificate, or organization supporting Azure IoT.

Used by 5 Rules
azure.concept.iot-hub Source

An Azure IoT Hub device messaging service.

Used by iot-hub.

azure.concept.iot-provisioning-service Source

An Azure IoT Hub Device Provisioning Service.

Used by iot-hub-device-provisioning-service.

azure.concept.iot-update-service Source

An Azure Device Update for IoT Hub account boundary.

Used by iot-hub-device-update-account.

azure.concept.key-vault Source

An Azure Key Vault security boundary for keys, secrets, and certificates.

Used by 5 Rules
azure.concept.kubernetes-fleet Source

An Azure Kubernetes Fleet Manager fleet coordinating Kubernetes clusters.

Used by kubernetes-fleet.

azure.concept.kubernetes-node-pool Source

A node pool contributing compute capacity to a Kubernetes cluster.

Used by aks-node-pool.

azure.concept.load-balancer Source

A load-balancing service composed from routing infrastructure.

Used by 5 Rules
azure.concept.load-test Source

An Azure Load Testing resource.

Used by load-test.

azure.concept.local-network-gateway Source

An Azure representation of an external VPN site gateway.

Used by local-network-gateway, vpn-site.

azure.concept.machine-learning-compute Source

Compute capacity attached to Azure Machine Learning.

Used by machine-learning-compute-cluster, machine-learning-compute-instance.

azure.concept.machine-learning-workspace Source

An Azure Machine Learning workspace.

Used by machine-learning-workspace.

azure.concept.maintenance-configuration Source

An Azure maintenance configuration defining update windows.

Used by maintenance-configuration.

azure.concept.managed-application Source

An Azure Managed Application deployment.

Used by managed-application.

azure.concept.managed-cache Source

A managed in-memory cache service.

Used by azure-cache-for-redis, azure-managed-redis.

azure.concept.managed-file-storage Source

A managed shared file-storage service.

Used by 4 Rules
azure.concept.managed-grafana Source

An Azure Managed Grafana workspace.

Used by managed-grafana.

azure.concept.managed-hsm Source

An Azure Key Vault Managed HSM security boundary.

Used by dedicated-hardware-security-module, managed-hsm, managed-hsm-key.

azure.concept.managed-nat Source

A managed network address translation service.

Used by 4 Rules
azure.concept.managed-secret Source

A managed secret identity whose sensitive value stays outside architecture output.

Used by key-vault-secret.

azure.concept.maps-account Source

An Azure Maps account exposing geospatial platform APIs.

Used by maps-account.

azure.concept.message-queue Source

A managed queue buffering work or messages for asynchronous consumers.

Used by 4 Rules
azure.concept.message-subscription Source

A durable subscription consuming messages from a topic.

Used by event-grid-event-subscription, event-grid-system-topic-subscription, service-bus-subscription.

azure.concept.message-topic Source

A messaging topic receiving messages from publishers.

Used by event-grid-namespace-topic.

azure.concept.messaging-detail Source

A consumer group, authorization rule, schema, route, or endpoint supporting messaging.

Used by event-hubs-consumer-group, event-hubs-schema-group, service-bus-subscription-rule.

azure.concept.messaging-namespace Source

An Azure messaging namespace owning queues, topics, or event streams.

Used by 6 Rules
azure.concept.migration-service Source

An Azure migration or movement service.

Used by 4 Rules
azure.concept.monitor-workspace Source

An Azure Monitor workspace.

Used by monitor-workspace.

azure.concept.netapp-account Source

An Azure NetApp Files account.

Used by netapp-account.

azure.concept.netapp-capacity-pool Source

An Azure NetApp Files capacity pool.

Used by netapp-capacity-pool.

azure.concept.network-function-service Source

An Azure managed network-function collection or control service.

Used by network-function-traffic-collector.

azure.concept.network-peering Source

A direct private connectivity agreement between virtual networks.

Used by databricks-virtual-network-peering, virtual-network-peering.

azure.concept.network-security-group Source

An Azure Network Security Group containing stateful traffic rules.

Used by network-security-group.

azure.concept.network-security-perimeter Source

An Azure Network Security Perimeter isolating platform services.

Used by network-security-perimeter.

azure.concept.network-watcher Source

An Azure Network Watcher regional network monitoring service.

Used by network-watcher.

azure.concept.notification-hub Source

An Azure Notification Hubs push-notification hub.

Used by notification-hub.

azure.concept.notification-namespace Source

An Azure Notification Hubs namespace.

Used by notification-hubs-namespace.

azure.concept.private-dns-resolver Source

An Azure DNS Private Resolver forwarding DNS between networks.

Used by private-dns-resolver.

azure.concept.private-endpoint Source

A private endpoint exposing a service inside a virtual network.

Used by private-endpoint.

An Azure private-link scope or hub grouping private service connectivity.

Used by arc-private-link-scope, monitor-private-link-scope, synapse-private-link-hub.

An Azure Private Link service publishing a private endpoint target.

Used by private-link-service.

An Azure Private DNS virtual network link.

Used by 4 Rules
azure.concept.public-address Source

A public Azure IP address exposed to network traffic.

Used by 5 Rules
azure.concept.purview-account Source

A Microsoft Purview data governance account.

Used by purview-account.

azure.concept.realtime-communication-service Source

An Azure managed real-time communication service.

Used by fluid-relay, signalr-service, web-pubsub.

azure.concept.relay-connection Source

An Azure Relay hybrid connection.

Used by relay-hybrid-connection.

azure.concept.relay-namespace Source

An Azure Relay namespace.

Used by relay-namespace.

azure.concept.resource-group Source

An Azure Resource Group lifecycle and access boundary.

Used by 224 Rules
azure.concept.route-table Source

An Azure route table controlling subnet traffic paths.

Used by route-server, route-table.

azure.concept.service-bus-topic Source

An Azure Service Bus topic owning durable subscriptions.

Used by 4 Rules
azure.concept.service-fabric-cluster Source

An Azure Service Fabric cluster running distributed applications.

Used by managed-service-fabric-cluster, service-fabric-cluster.

azure.concept.service-identity-binding Source

An access-control binding that contributes to a service identity.

No Rule in this Dialect uses this definition.

azure.concept.site-recovery-detail Source

A recovery plan, mapping, replicated machine, or protection configuration.

Used by backup-protected-vm, site-recovery-plan, site-recovery-replicated-vm.

azure.concept.site-recovery-fabric Source

An Azure Site Recovery source or target fabric.

Used by site-recovery-fabric, site-recovery-protection-container.

azure.concept.spring-app Source

An application deployed in Azure Spring Apps.

Used by spring-app, spring-apps-gateway.

azure.concept.spring-apps-service Source

An Azure Spring Apps service boundary.

Used by spring-apps-service.

azure.concept.sql-server Source

An Azure SQL logical server owning managed databases.

Used by mssql-database, mssql-server.

azure.concept.sre-agent Source

An Azure SRE Agent operating against explicitly assigned Azure resources.

Used by sre-agent.

azure.concept.static-web-app Source

An Azure Static Web Apps site with managed hosting and APIs.

Used by static-web-app.

azure.concept.storage-object-detail Source

An object, path, directory, table entity, or policy inside Azure Storage.

Used by 7 Rules
azure.concept.storage-sync-service Source

An Azure File Sync service synchronizing file servers and Azure Files.

Used by storage-sync-service.

azure.concept.stream-analytics-job Source

An Azure Stream Analytics streaming query job.

Used by stream-analytics-job.

azure.concept.synapse-workspace Source

An Azure Synapse Analytics workspace.

Used by synapse-workspace.

azure.concept.table-storage-table Source

An Azure Table Storage table.

Used by storage-table-entity, table-storage-table.

azure.concept.third-party-monitor Source

A third-party observability service managed through Azure.

Used by 4 Rules
azure.concept.traffic-manager-profile Source

An Azure Traffic Manager DNS traffic-routing profile.

Used by traffic-manager-profile.

azure.concept.trusted-signing-account Source

An Azure Artifact Signing account.

Used by trusted-signing-account.

azure.concept.video-indexer-account Source

An Azure AI Video Indexer account.

Used by video-indexer-account.

azure.concept.virtual-desktop-application-group Source

An Azure Virtual Desktop desktop or RemoteApp publication group.

Used by virtual-desktop-application-group.

azure.concept.virtual-desktop-host-pool Source

An Azure Virtual Desktop host pool providing session hosts.

Used by virtual-desktop-host-pool.

azure.concept.virtual-desktop-workspace Source

An Azure Virtual Desktop workspace publishing application groups.

Used by virtual-desktop-workspace.

azure.concept.virtual-hub Source

An Azure Virtual WAN regional transit hub.

Used by virtual-hub.

azure.concept.virtual-machine-scale-set Source

An Azure-managed group of virtual machines that scales as one compute workload.

Used by 4 Rules
azure.concept.virtual-network-manager Source

An Azure Virtual Network Manager control plane for network groups and policy.

Used by virtual-network-manager.

azure.concept.virtual-wan Source

An Azure Virtual WAN global transit network.

Used by virtual-wan.

azure.concept.vmware-private-cloud Source

An Azure VMware Solution private cloud.

Used by vmware-private-cloud.

azure.concept.vpn-connection Source

A virtual private network connection between network endpoints.

Used by virtual-network-gateway-connection, vpn-gateway-connection.

azure.concept.vpn-gateway Source

A managed gateway terminating virtual private network connections.

Used by point-to-site-vpn-gateway, virtual-network-gateway, vpn-gateway.

azure.concept.web-application-firewall-policy Source

A reusable Azure Web Application Firewall policy applied to Application Gateway traffic.

Used by application-gateway, web-application-firewall-policy.

azure.concept.workflow Source

A managed workflow coordinating steps and service calls.

Used by 4 Rules

Contexts

azure.context.ownership Source

Administrative or lifecycle ownership.

Used by 257 Rules

Relations

azure.relation.delivers-to Source

Introduced by a labeled emission. Used by event-grid-event-subscription, event-grid-system-topic-subscription.

azure.relation.observed-by Source

Introduced by a labeled emission.

Used by 5 Rules
azure.relation.peers-with Source

Introduced by a labeled emission. Used by virtual-network-peering.

azure.relation.private-name-resolution Source

Introduced by a labeled emission. Used by postgresql-flexible-server.

azure.relation.subscribes-to Source

Introduced by a labeled emission. Used by event-grid-event-subscription, event-grid-system-topic-subscription, service-bus-subscription.

azure.relation.uses-waf-policy Source

Introduced by a labeled emission. Used by application-gateway.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

azure.rule.azure-enclave Source

Matches resource instances of azapi_resource.

Classification: azure.concept.azure-enclave.

Conditions, identity and resolution

Condition

RF
source.type == "Microsoft.Mission/virtualEnclaves@2026-03-01-preview"
azure.rule.horizondb-cluster Source

Matches resource instances of azapi_resource.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Condition

RF
source.type == "Microsoft.HorizonDb/clusters@2026-01-20-preview"
azure.rule.sre-agent Source

Matches resource instances of azapi_resource.

Classification: azure.concept.sre-agent.

Conditions, identity and resolution

Condition

RF
source.type == "Microsoft.App/agents@2026-01-01"
azure.rule.entra-access-package-assignment-policy Source

Matches resource instances of azuread_access_package_assignment_policy.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-app-role-assignment Source

Matches resource instances of azuread_app_role_assignment.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-application-federated-identity Source

Matches resource instances of azuread_application_federated_identity_credential.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-application-registration Source

Matches resource instances of azuread_application_registration.

Classification: azure.concept.entra-application.

azure.rule.entra-application Source

Matches resource instances of azuread_application.

Classification: azure.concept.entra-application.

azure.rule.entra-authentication-strength-policy Source

Matches resource instances of azuread_authentication_strength_policy.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-group-without-members Source

Matches resource instances of azuread_group_without_members.

Classification: azure.concept.identity-group.

azure.rule.entra-group Source

Matches resource instances of azuread_group.

Classification: azure.concept.identity-group.

azure.rule.entra-named-location Source

Matches resource instances of azuread_named_location.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-service-principal Source

Matches resource instances of azuread_service_principal.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["client_id"]
  • scope: "provider"

Endpoint

  • attributes: ["client_id"]
azure.rule.entra-external-id-directory Source

Matches resource instances of azurerm_aadb2c_directory.

Classification: azure.concept.entra-directory.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.entra-domain-services-replica-set Source

Matches resource instances of azurerm_active_directory_domain_service_replica_set.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-domain-services-trust Source

Matches resource instances of azurerm_active_directory_domain_service_trust.

Classification: azure.concept.identity-governance-detail.

azure.rule.entra-domain-services Source

Matches resource instances of azurerm_active_directory_domain_service.

Classification: azure.concept.entra-domain-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.advanced-threat-protection Source

Matches resource instances of azurerm_advanced_threat_protection.

Classification: azure.concept.security-detail.

azure.rule.ai-foundry-project Source

Matches resource instances of azurerm_ai_foundry_project.

Classification: azure.concept.ai-foundry.

azure.rule.ai-foundry Source

Matches resource instances of azurerm_ai_foundry.

Classification: azure.concept.ai-foundry.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.analysis-services-server Source

Matches resource instances of azurerm_analysis_services_server.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.api-connection Source

Matches resource instances of azurerm_api_connection.

Classification: azure.concept.integration-connection.

azure.rule.api-management-api Source

Matches resource instances of azurerm_api_management_api.

Classification: azure.concept.api-management-detail.

azure.rule.api-management-backend Source

Matches resource instances of azurerm_api_management_backend.

Classification: azure.concept.api-management-detail.

azure.rule.api-management-gateway Source

Matches resource instances of azurerm_api_management_gateway.

Classification: azure.concept.api-management-detail.

azure.rule.api-management-policy Source

Matches resource instances of azurerm_api_management_policy.

Classification: azure.concept.api-management-detail.

azure.rule.api-management-product Source

Matches resource instances of azurerm_api_management_product.

Classification: azure.concept.api-management-detail.

azure.rule.api-management-standalone-gateway Source

Matches resource instances of azurerm_api_management_standalone_gateway.

Classification: azure.concept.api-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.api-management-workspace Source

Matches resource instances of azurerm_api_management_workspace.

Classification: azure.concept.api-management-detail.

azure.rule.api-management Source

Matches resource instances of azurerm_api_management.

Classification: azure.concept.api-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.app-configuration Source

Matches resource instances of azurerm_app_configuration.

Classification: azure.concept.app-configuration.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.app-service-connection Source

Matches resource instances of azurerm_app_service_connection.

Classification: azure.concept.integration-connection.

azure.rule.app-service-environment Source

Matches resource instances of azurerm_app_service_environment_v3.

Classification: azure.concept.app-service-environment.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.application-gateway Source

Matches resource instances of azurerm_application_gateway.

Classification: azure.concept.load-balancer.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.gateway_ip_configuration[0].subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.firewall_policy_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.application-insights-web-test Source

Matches resource instances of azurerm_application_insights_standard_web_test.

Classification: azure.concept.operations-detail.

azure.rule.application-insights Source

Matches resource instances of azurerm_application_insights.

Classification: azure.concept.application-insights.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "connection_string"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "connection_string", "instrumentation_key"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.application-load-balancer-frontend Source

Matches resource instances of azurerm_application_load_balancer_frontend.

Classification: azure.concept.load-balancer-component.

azure.rule.application-load-balancer Source

Matches resource instances of azurerm_application_load_balancer.

Classification: azure.concept.load-balancer.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.application-security-group Source

Matches resource instances of azurerm_application_security_group.

Classification: azure.concept.network-policy-detail.

azure.rule.arc-kubernetes-cluster Source

Matches resource instances of azurerm_arc_kubernetes_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.arc-provisioned-kubernetes-cluster Source

Matches resource instances of azurerm_arc_kubernetes_provisioned_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.arc-enabled-server Source

Matches resource instances of azurerm_arc_machine.

Classification: azure.concept.arc-enabled-server.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.arc-private-link-scope Source

Matches resource instances of azurerm_arc_private_link_scope.

Classification: azure.concept.private-link-scope.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.arc-resource-bridge Source

Matches resource instances of azurerm_arc_resource_bridge_appliance.

Classification: azure.concept.arc-resource-bridge.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.attestation-provider Source

Matches resource instances of azurerm_attestation_provider.

Classification: azure.concept.attestation-provider.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.automation-account Source

Matches resource instances of azurerm_automation_account.

Classification: azure.concept.automation-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.automation-runbook Source

Matches resource instances of azurerm_automation_runbook.

Classification: azure.concept.workflow.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.automation-schedule Source

Matches resource instances of azurerm_automation_schedule.

Classification: azure.concept.operations-detail.

azure.rule.availability-set Source

Matches resource instances of azurerm_availability_set.

Classification: azure.concept.compute-placement.

azure.rule.file-share-backup-policy Source

Matches resource instances of azurerm_backup_policy_file_share.

Classification: azure.concept.backup-plan.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-machine-backup-policy Source

Matches resource instances of azurerm_backup_policy_vm.

Classification: azure.concept.backup-plan.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.backup-protected-vm Source

Matches resource instances of azurerm_backup_protected_vm.

Classification: azure.concept.site-recovery-detail.

azure.rule.bastion-host Source

Matches resource instances of azurerm_bastion_host.

Classification: azure.concept.bastion-host.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.batch-account Source

Matches resource instances of azurerm_batch_account.

Classification: azure.concept.batch-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.batch-application Source

Matches resource instances of azurerm_batch_application.

Classification: azure.concept.batch-pool.

azure.rule.batch-pool Source

Matches resource instances of azurerm_batch_pool.

Classification: azure.concept.batch-pool.

azure.rule.bot-channels-registration Source

Matches resource instances of azurerm_bot_channels_registration.

Classification: azure.concept.bot-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.azure-bot Source

Matches resource instances of azurerm_bot_service_azure_bot.

Classification: azure.concept.bot-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.bot-web-app Source

Matches resource instances of azurerm_bot_web_app.

Classification: azure.concept.bot-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.capacity-reservation-group Source

Matches resource instances of azurerm_capacity_reservation_group.

Classification: azure.concept.compute-placement.

azure.rule.capacity-reservation Source

Matches resource instances of azurerm_capacity_reservation.

Classification: azure.concept.compute-placement.

azure.rule.cdn-endpoint Source

Matches resource instances of azurerm_cdn_endpoint.

Classification: azure.concept.content-delivery-profile.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.front-door-endpoint Source

Matches resource instances of azurerm_cdn_frontdoor_endpoint.

Classification: azure.concept.load-balancer-component.

azure.rule.front-door-origin-group Source

Matches resource instances of azurerm_cdn_frontdoor_origin_group.

Classification: azure.concept.load-balancer-component.

azure.rule.front-door-origin Source

Matches resource instances of azurerm_cdn_frontdoor_origin.

Classification: azure.concept.load-balancer-component.

azure.rule.front-door-profile Source

Matches resource instances of azurerm_cdn_frontdoor_profile.

Classification: azure.concept.front-door-profile.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.front-door-route Source

Matches resource instances of azurerm_cdn_frontdoor_route.

Classification: azure.concept.load-balancer-component.

azure.rule.cdn-profile Source

Matches resource instances of azurerm_cdn_profile.

Classification: azure.concept.content-delivery-profile.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.chaos-studio-experiment Source

Matches resource instances of azurerm_chaos_studio_experiment.

Classification: azure.concept.chaos-experiment.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.ai-services-project Source

Matches resource instances of azurerm_cognitive_account_project.

Classification: azure.concept.ai-foundry.

azure.rule.ai-services-account Source

Matches resource instances of azurerm_cognitive_account.

Classification: azure.concept.ai-service-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.ai-model-deployment Source

Matches resource instances of azurerm_cognitive_deployment.

Classification: azure.concept.ai-inference-endpoint.

azure.rule.communication-service Source

Matches resource instances of azurerm_communication_service.

Classification: azure.concept.communication-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.confidential-ledger Source

Matches resource instances of azurerm_confidential_ledger.

Classification: azure.concept.confidential-ledger.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.container-app-environment Source

Matches resource instances of azurerm_container_app_environment.

Classification: azure.concept.container-app-environment.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.infrastructure_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.log_analytics_workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.container-app-job Source

Matches resource instances of azurerm_container_app_job.

Classification: azure.concept.container-app-job.

Contexts

Conditions, identity and resolution

Context through source.container_app_environment_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.container-app Source

Matches resource instances of azurerm_container_app.

Classification: azure.concept.container-app.

Contexts

Conditions, identity and resolution

Context through source.container_app_environment_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.connected-container-registry Source

Matches resource instances of azurerm_container_connected_registry.

Classification: azure.concept.container-registry.

azure.rule.container-instance-group Source

Matches resource instances of azurerm_container_group.

Classification: azure.concept.container-instance-group.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.container-registry Source

Matches resource instances of azurerm_container_registry.

Classification: azure.concept.container-registry.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-account Source

Matches resource instances of azurerm_cosmosdb_account.

Classification: azure.concept.cosmos-account.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-cassandra-cluster Source

Matches resource instances of azurerm_cosmosdb_cassandra_cluster.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-cassandra-keyspace Source

Matches resource instances of azurerm_cosmosdb_cassandra_keyspace.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.account_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-cassandra-table Source

Matches resource instances of azurerm_cosmosdb_cassandra_table.

Classification: azure.concept.database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cassandra_keyspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.cosmos-gremlin-database Source

Matches resource instances of azurerm_cosmosdb_gremlin_database.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.account_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-gremlin-graph Source

Matches resource instances of azurerm_cosmosdb_gremlin_graph.

Classification: azure.concept.database-component.

Contributions

Conditions, identity and resolution

Contribution through source.database_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-mongo-collection Source

Matches resource instances of azurerm_cosmosdb_mongo_collection.

Classification: azure.concept.database-component.

Contributions

Conditions, identity and resolution

Contribution through source.database_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-mongo-database Source

Matches resource instances of azurerm_cosmosdb_mongo_database.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.account_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-postgresql-cluster Source

Matches resource instances of azurerm_cosmosdb_postgresql_cluster.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-sql-container Source

Matches resource instances of azurerm_cosmosdb_sql_container.

Classification: azure.concept.database-component.

Contexts

Contributions

Conditions, identity and resolution

Context through source.database_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.database_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-sql-database Source

Matches resource instances of azurerm_cosmosdb_sql_database.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.account_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.cosmos-dedicated-gateway Source

Matches resource instances of azurerm_cosmosdb_sql_dedicated_gateway.

Classification: azure.concept.database-component.

Contributions

Conditions, identity and resolution

Contribution through source.cosmosdb_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.custom-ip-prefix Source

Matches resource instances of azurerm_custom_ip_prefix.

Classification: azure.concept.public-address.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-grafana Source

Matches resource instances of azurerm_dashboard_grafana.

Classification: azure.concept.managed-grafana.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-factory-data-flow Source

Matches resource instances of azurerm_data_factory_data_flow.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-blob-dataset Source

Matches resource instances of azurerm_data_factory_dataset_azure_blob.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-sql-dataset Source

Matches resource instances of azurerm_data_factory_dataset_azure_sql_table.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-azure-integration-runtime Source

Matches resource instances of azurerm_data_factory_integration_runtime_azure.

Classification: azure.concept.data-integration-runtime.

azure.rule.data-factory-self-hosted-integration-runtime Source

Matches resource instances of azurerm_data_factory_integration_runtime_self_hosted.

Classification: azure.concept.data-integration-runtime.

azure.rule.data-factory-blob-linked-service Source

Matches resource instances of azurerm_data_factory_linked_service_azure_blob_storage.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-sql-linked-service Source

Matches resource instances of azurerm_data_factory_linked_service_azure_sql_database.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-managed-private-endpoint Source

Matches resource instances of azurerm_data_factory_managed_private_endpoint.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory-pipeline Source

Matches resource instances of azurerm_data_factory_pipeline.

Classification: azure.concept.workflow.

azure.rule.data-factory-schedule-trigger Source

Matches resource instances of azurerm_data_factory_trigger_schedule.

Classification: azure.concept.data-integration-detail.

azure.rule.data-factory Source

Matches resource instances of azurerm_data_factory.

Classification: azure.concept.data-factory.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-protection-blob-backup-policy Source

Matches resource instances of azurerm_data_protection_backup_policy_blob_storage.

Classification: azure.concept.backup-plan.

azure.rule.data-protection-disk-backup-policy Source

Matches resource instances of azurerm_data_protection_backup_policy_disk.

Classification: azure.concept.backup-plan.

azure.rule.data-protection-backup-vault Source

Matches resource instances of azurerm_data_protection_backup_vault.

Classification: azure.concept.backup-vault.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-share-account Source

Matches resource instances of azurerm_data_share_account.

Classification: azure.concept.data-share-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.database-migration-project Source

Matches resource instances of azurerm_database_migration_project.

Classification: azure.concept.migration-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.database-migration-service Source

Matches resource instances of azurerm_database_migration_service.

Classification: azure.concept.migration-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-box-edge-device Source

Matches resource instances of azurerm_databox_edge_device.

Classification: azure.concept.migration-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.databricks-virtual-network-peering Source

Matches resource instances of azurerm_databricks_virtual_network_peering.

Classification: azure.concept.network-peering.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.databricks-workspace Source

Matches resource instances of azurerm_databricks_workspace.

Classification: azure.concept.databricks-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.datadog-monitor Source

Matches resource instances of azurerm_datadog_monitor.

Classification: azure.concept.third-party-monitor.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dedicated-hardware-security-module Source

Matches resource instances of azurerm_dedicated_hardware_security_module.

Classification: azure.concept.managed-hsm.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dedicated-host-group Source

Matches resource instances of azurerm_dedicated_host_group.

Classification: azure.concept.dedicated-host-group.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dev-box-definition Source

Matches resource instances of azurerm_dev_center_dev_box_definition.

Classification: azure.concept.developer-environment.

azure.rule.dev-center-project Source

Matches resource instances of azurerm_dev_center_project.

Classification: azure.concept.dev-center-project.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dev-center Source

Matches resource instances of azurerm_dev_center.

Classification: azure.concept.dev-center.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dev-test-lab Source

Matches resource instances of azurerm_dev_test_lab.

Classification: azure.concept.developer-environment.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dev-test-linux-virtual-machine Source

Matches resource instances of azurerm_dev_test_linux_virtual_machine.

Classification: azure.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dev-test-windows-virtual-machine Source

Matches resource instances of azurerm_dev_test_windows_virtual_machine.

Classification: azure.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.digital-twins-event-grid-endpoint Source

Matches resource instances of azurerm_digital_twins_endpoint_eventgrid.

Classification: azure.concept.iot-detail.

azure.rule.digital-twins-instance Source

Matches resource instances of azurerm_digital_twins_instance.

Classification: azure.concept.digital-twins-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-a-record Source

Matches resource instances of azurerm_dns_a_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-aaaa-record Source

Matches resource instances of azurerm_dns_aaaa_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-cname-record Source

Matches resource instances of azurerm_dns_cname_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-mx-record Source

Matches resource instances of azurerm_dns_mx_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-ns-record Source

Matches resource instances of azurerm_dns_ns_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-ptr-record Source

Matches resource instances of azurerm_dns_ptr_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-srv-record Source

Matches resource instances of azurerm_dns_srv_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-txt-record Source

Matches resource instances of azurerm_dns_txt_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.zone_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dns-zone Source

Matches resource instances of azurerm_dns_zone.

Classification: azure.concept.dns-zone.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.dynatrace-monitor Source

Matches resource instances of azurerm_dynatrace_monitor.

Classification: azure.concept.third-party-monitor.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.elastic-cloud Source

Matches resource instances of azurerm_elastic_cloud_elasticsearch.

Classification: azure.concept.third-party-monitor.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.elastic-san-volume-group Source

Matches resource instances of azurerm_elastic_san_volume_group.

Classification: azure.concept.elastic-san.

azure.rule.elastic-san-volume Source

Matches resource instances of azurerm_elastic_san_volume.

Classification: azure.concept.block-storage-volume.

azure.rule.elastic-san Source

Matches resource instances of azurerm_elastic_san.

Classification: azure.concept.elastic-san.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.email-communication-service Source

Matches resource instances of azurerm_email_communication_service.

Classification: azure.concept.email-communication-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-domain-topic Source

Matches resource instances of azurerm_eventgrid_domain_topic.

Classification: azure.concept.event-grid-topic.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.domain_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-domain Source

Matches resource instances of azurerm_eventgrid_domain.

Classification: azure.concept.event-grid-domain.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-event-subscription Source

Matches resource instances of azurerm_eventgrid_event_subscription.

Classification: azure.concept.message-subscription.

Contexts

Relations

Conditions, identity and resolution

Context through source.scope

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.scope

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.eventhub_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.service_bus_queue_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.service_bus_topic_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.azure_function_endpoint[0].function_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.storage_queue_endpoint[0].storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.event-grid-namespace-topic Source

Matches resource instances of azurerm_eventgrid_namespace_topic.

Classification: azure.concept.message-topic.

Contexts

Conditions, identity and resolution

Context through source.eventgrid_namespace_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.event-grid-namespace Source

Matches resource instances of azurerm_eventgrid_namespace.

Classification: azure.concept.event-grid-domain.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-partner-namespace Source

Matches resource instances of azurerm_eventgrid_partner_namespace.

Classification: azure.concept.event-grid-domain.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-system-topic-subscription Source

Matches resource instances of azurerm_eventgrid_system_topic_event_subscription.

Classification: azure.concept.message-subscription.

Contexts

Relations

Conditions, identity and resolution

Context through source.system_topic

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.system_topic

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.eventhub_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.service_bus_queue_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.service_bus_topic_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.azure_function_endpoint[0].function_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.storage_queue_endpoint[0].storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.event-grid-system-topic Source

Matches resource instances of azurerm_eventgrid_system_topic.

Classification: azure.concept.event-grid-topic.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-grid-topic Source

Matches resource instances of azurerm_eventgrid_topic.

Classification: azure.concept.event-grid-topic.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-hubs-cluster Source

Matches resource instances of azurerm_eventhub_cluster.

Classification: azure.concept.event-stream.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-hubs-consumer-group Source

Matches resource instances of azurerm_eventhub_consumer_group.

Classification: azure.concept.messaging-detail.

Contexts

Contributions

Conditions, identity and resolution

Context through source.eventhub_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.eventhub_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-hubs-schema-group Source

Matches resource instances of azurerm_eventhub_namespace_schema_group.

Classification: azure.concept.messaging-detail.

Contributions

Conditions, identity and resolution

Contribution through source.namespace_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.event-hubs-namespace Source

Matches resource instances of azurerm_eventhub_namespace.

Classification: azure.concept.messaging-namespace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.event-hub Source

Matches resource instances of azurerm_eventhub.

Classification: azure.concept.event-stream.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.expressroute-circuit Source

Matches resource instances of azurerm_express_route_circuit.

Classification: azure.concept.dedicated-interconnect.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.expressroute-gateway Source

Matches resource instances of azurerm_express_route_gateway.

Classification: azure.concept.expressroute-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.expressroute-port Source

Matches resource instances of azurerm_express_route_port.

Classification: azure.concept.dedicated-interconnect.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.arc-custom-location Source

Matches resource instances of azurerm_extended_location_custom_location.

Classification: azure.concept.custom-location.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.fabric-capacity Source

Matches resource instances of azurerm_fabric_capacity.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.azure-firewall-policy-rule-collection-group Source

Matches resource instances of azurerm_firewall_policy_rule_collection_group.

Classification: azure.concept.firewall-policy.

azure.rule.azure-firewall-policy Source

Matches resource instances of azurerm_firewall_policy.

Classification: azure.concept.firewall-policy.

azure.rule.azure-firewall Source

Matches resource instances of azurerm_firewall.

Classification: azure.concept.azure-firewall.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.fluid-relay Source

Matches resource instances of azurerm_fluid_relay_server.

Classification: azure.concept.realtime-communication-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.classic-front-door Source

Matches resource instances of azurerm_frontdoor.

Classification: azure.concept.front-door-profile.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.flex-consumption-function-app Source

Matches resource instances of azurerm_function_app_flex_consumption.

Classification: azure.concept.serverless-function.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.service_plan_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.function-app-function Source

Matches resource instances of azurerm_function_app_function.

Classification: azure.concept.serverless-function.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
azure.rule.graph-data-connect-account Source

Matches resource instances of azurerm_graph_services_account.

Classification: azure.concept.graph-data-connect-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.hdinsight-hadoop-cluster Source

Matches resource instances of azurerm_hdinsight_hadoop_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.hdinsight-hbase-cluster Source

Matches resource instances of azurerm_hdinsight_hbase_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.hdinsight-interactive-query-cluster Source

Matches resource instances of azurerm_hdinsight_interactive_query_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.hdinsight-kafka-cluster Source

Matches resource instances of azurerm_hdinsight_kafka_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.hdinsight-spark-cluster Source

Matches resource instances of azurerm_hdinsight_spark_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.health-bot Source

Matches resource instances of azurerm_healthbot.

Classification: azure.concept.bot-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.health-data-dicom-service Source

Matches resource instances of azurerm_healthcare_dicom_service.

Classification: azure.concept.health-data-service.

azure.rule.health-data-fhir-service Source

Matches resource instances of azurerm_healthcare_fhir_service.

Classification: azure.concept.health-data-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.health-data-medtech-service Source

Matches resource instances of azurerm_healthcare_medtech_service.

Classification: azure.concept.health-data-service.

azure.rule.healthcare-service Source

Matches resource instances of azurerm_healthcare_service.

Classification: azure.concept.health-data-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.health-data-services-workspace Source

Matches resource instances of azurerm_healthcare_workspace.

Classification: azure.concept.health-data-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.compute-image Source

Matches resource instances of azurerm_image.

Classification: azure.concept.compute-image.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.iot-central-application Source

Matches resource instances of azurerm_iotcentral_application.

Classification: azure.concept.iot-central-application.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.iot-hub-device-update-account Source

Matches resource instances of azurerm_iothub_device_update_account.

Classification: azure.concept.iot-update-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.iot-hub-device-update-instance Source

Matches resource instances of azurerm_iothub_device_update_instance.

Classification: azure.concept.iot-detail.

azure.rule.iot-hub-device-provisioning-service Source

Matches resource instances of azurerm_iothub_dps.

Classification: azure.concept.iot-provisioning-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.iot-hub-event-hubs-endpoint Source

Matches resource instances of azurerm_iothub_endpoint_eventhub.

Classification: azure.concept.iot-detail.

azure.rule.iot-hub-service-bus-queue-endpoint Source

Matches resource instances of azurerm_iothub_endpoint_servicebus_queue.

Classification: azure.concept.iot-detail.

azure.rule.iot-hub-storage-endpoint Source

Matches resource instances of azurerm_iothub_endpoint_storage_container.

Classification: azure.concept.iot-detail.

azure.rule.iot-hub Source

Matches resource instances of azurerm_iothub.

Classification: azure.concept.iot-hub.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.ip-group Source

Matches resource instances of azurerm_ip_group.

Classification: azure.concept.network-policy-detail.

azure.rule.key-vault-access-policy Source

Matches resource instances of azurerm_key_vault_access_policy.

Classification: azure.concept.security-detail.

Contributions

Conditions, identity and resolution

Contribution through source.key_vault_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.key-vault-certificate Source

Matches resource instances of azurerm_key_vault_certificate.

Classification: azure.concept.security-detail.

Contributions

Conditions, identity and resolution

Contribution through source.key_vault_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.key-vault-key Source

Matches resource instances of azurerm_key_vault_key.

Classification: azure.concept.encryption-key.

Contexts

Conditions, identity and resolution

Context through source.key_vault_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.managed-hsm-key Source

Matches resource instances of azurerm_key_vault_managed_hardware_security_module_key.

Classification: azure.concept.encryption-key.

Contexts

Conditions, identity and resolution

Context through source.managed_hsm_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.managed-hsm Source

Matches resource instances of azurerm_key_vault_managed_hardware_security_module.

Classification: azure.concept.managed-hsm.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.key-vault-secret Source

Matches resource instances of azurerm_key_vault_secret.

Classification: azure.concept.managed-secret.

Contexts

Conditions, identity and resolution

Context through source.key_vault_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.key-vault Source

Matches resource instances of azurerm_key_vault.

Classification: azure.concept.key-vault.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.automatic-kubernetes-cluster Source

Matches resource instances of azurerm_kubernetes_automatic_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.aks-node-pool Source

Matches resource instances of azurerm_kubernetes_cluster_node_pool.

Classification: azure.concept.kubernetes-node-pool.

Contexts

Contributions

Conditions, identity and resolution

Context through source.vnet_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.kubernetes_cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.aks-cluster Source

Matches resource instances of azurerm_kubernetes_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "kube_config[0].host", "kube_admin_config[0].host"]

Context through source.default_node_pool[0].vnet_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.oms_agent[0].log_analytics_workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.kubernetes-fleet Source

Matches resource instances of azurerm_kubernetes_fleet_manager.

Classification: azure.concept.kubernetes-fleet.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-explorer-cluster Source

Matches resource instances of azurerm_kusto_cluster.

Classification: azure.concept.data-explorer-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.data-explorer-event-grid-connection Source

Matches resource instances of azurerm_kusto_eventgrid_data_connection.

Classification: azure.concept.database-component.

azure.rule.data-explorer-event-hubs-connection Source

Matches resource instances of azurerm_kusto_eventhub_data_connection.

Classification: azure.concept.database-component.

azure.rule.load-balancer-backend-pool Source

Matches resource instances of azurerm_lb_backend_address_pool.

Classification: azure.concept.load-balancer-component.

Contributions

Conditions, identity and resolution

Contribution through source.loadbalancer_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.load-balancer-nat-rule Source

Matches resource instances of azurerm_lb_nat_rule.

Classification: azure.concept.load-balancer-component.

azure.rule.load-balancer-outbound-rule Source

Matches resource instances of azurerm_lb_outbound_rule.

Classification: azure.concept.load-balancer-component.

azure.rule.load-balancer-probe Source

Matches resource instances of azurerm_lb_probe.

Classification: azure.concept.load-balancer-component.

azure.rule.load-balancer-rule Source

Matches resource instances of azurerm_lb_rule.

Classification: azure.concept.load-balancer-component.

Contributions

Conditions, identity and resolution

Contribution through source.loadbalancer_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.load-balancer Source

Matches resource instances of azurerm_lb.

Classification: azure.concept.load-balancer.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.lighthouse-definition Source

Matches resource instances of azurerm_lighthouse_definition.

Classification: azure.concept.governance-detail.

azure.rule.linux-function-app Source

Matches resource instances of azurerm_linux_function_app.

Classification: azure.concept.serverless-function.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.service_plan_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.site_config[0].application_insights_connection_string

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.connection_string
  • match.strategy: "exact"
azure.rule.linux-virtual-machine-scale-set Source

Matches resource instances of azurerm_linux_virtual_machine_scale_set.

Classification: azure.concept.virtual-machine-scale-set.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.linux-virtual-machine Source

Matches resource instances of azurerm_linux_virtual_machine.

Classification: azure.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.linux-web-app Source

Matches resource instances of azurerm_linux_web_app.

Classification: azure.concept.app-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.service_plan_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.load-test Source

Matches resource instances of azurerm_load_test.

Classification: azure.concept.load-test.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.local-network-gateway Source

Matches resource instances of azurerm_local_network_gateway.

Classification: azure.concept.local-network-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.log-analytics-cluster Source

Matches resource instances of azurerm_log_analytics_cluster.

Classification: azure.concept.log-analytics-workspace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.log-analytics-data-export-rule Source

Matches resource instances of azurerm_log_analytics_data_export_rule.

Classification: azure.concept.operations-detail.

Contributions

Conditions, identity and resolution

Contribution through source.workspace_resource_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.log-analytics-saved-search Source

Matches resource instances of azurerm_log_analytics_saved_search.

Classification: azure.concept.operations-detail.

Contributions

Conditions, identity and resolution

Contribution through source.log_analytics_workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.log-analytics-solution Source

Matches resource instances of azurerm_log_analytics_solution.

Classification: azure.concept.operations-detail.

Contexts

Contributions

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.workspace_resource_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.log-analytics-workspace-table Source

Matches resource instances of azurerm_log_analytics_workspace_table.

Classification: azure.concept.operations-detail.

Contributions

Conditions, identity and resolution

Contribution through source.workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.log-analytics-workspace Source

Matches resource instances of azurerm_log_analytics_workspace.

Classification: azure.concept.log-analytics-workspace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.logic-app-http-action Source

Matches resource instances of azurerm_logic_app_action_http.

Classification: azure.concept.api-management-detail.

azure.rule.logic-app-integration-account Source

Matches resource instances of azurerm_logic_app_integration_account.

Classification: azure.concept.integration-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.logic-app-standard Source

Matches resource instances of azurerm_logic_app_standard.

Classification: azure.concept.workflow.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.logic-app-recurrence-trigger Source

Matches resource instances of azurerm_logic_app_trigger_recurrence.

Classification: azure.concept.api-management-detail.

azure.rule.logic-app-workflow Source

Matches resource instances of azurerm_logic_app_workflow.

Classification: azure.concept.workflow.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.machine-learning-compute-cluster Source

Matches resource instances of azurerm_machine_learning_compute_cluster.

Classification: azure.concept.machine-learning-compute.

azure.rule.machine-learning-compute-instance Source

Matches resource instances of azurerm_machine_learning_compute_instance.

Classification: azure.concept.machine-learning-compute.

azure.rule.machine-learning-inference-cluster Source

Matches resource instances of azurerm_machine_learning_inference_cluster.

Classification: azure.concept.ai-inference-endpoint.

azure.rule.machine-learning-workspace Source

Matches resource instances of azurerm_machine_learning_workspace.

Classification: azure.concept.machine-learning-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.maintenance-configuration Source

Matches resource instances of azurerm_maintenance_configuration.

Classification: azure.concept.maintenance-configuration.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-application Source

Matches resource instances of azurerm_managed_application.

Classification: azure.concept.managed-application.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-devops-pool Source

Matches resource instances of azurerm_managed_devops_pool.

Classification: azure.concept.developer-environment.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-disk Source

Matches resource instances of azurerm_managed_disk.

Classification: azure.concept.block-storage-volume.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-lustre-file-system Source

Matches resource instances of azurerm_managed_lustre_file_system.

Classification: azure.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-redis-geo-replication Source

Matches resource instances of azurerm_managed_redis_geo_replication.

Classification: azure.concept.database-component.

azure.rule.azure-managed-redis Source

Matches resource instances of azurerm_managed_redis.

Classification: azure.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.maps-account Source

Matches resource instances of azurerm_maps_account.

Classification: azure.concept.maps-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.mongo-cluster Source

Matches resource instances of azurerm_mongo_cluster.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.monitor-action-group Source

Matches resource instances of azurerm_monitor_action_group.

Classification: azure.concept.operations-detail.

azure.rule.monitor-data-collection-endpoint Source

Matches resource instances of azurerm_monitor_data_collection_endpoint.

Classification: azure.concept.operations-detail.

azure.rule.monitor-diagnostic-setting Source

Matches resource instances of azurerm_monitor_diagnostic_setting.

Classification: azure.concept.operations-detail.

azure.rule.monitor-metric-alert Source

Matches resource instances of azurerm_monitor_metric_alert.

Classification: azure.concept.operations-detail.

azure.rule.monitor-private-link-scope Source

Matches resource instances of azurerm_monitor_private_link_scope.

Classification: azure.concept.private-link-scope.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.monitor-scheduled-query-alert Source

Matches resource instances of azurerm_monitor_scheduled_query_rules_alert_v2.

Classification: azure.concept.operations-detail.

azure.rule.monitor-workspace Source

Matches resource instances of azurerm_monitor_workspace.

Classification: azure.concept.monitor-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.mssql-database Source

Matches resource instances of azurerm_mssql_database.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.server_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.sql-elastic-pool Source

Matches resource instances of azurerm_mssql_elasticpool.

Classification: azure.concept.database-component.

azure.rule.sql-failover-group Source

Matches resource instances of azurerm_mssql_failover_group.

Classification: azure.concept.database-component.

azure.rule.sql-managed-database Source

Matches resource instances of azurerm_mssql_managed_database.

Classification: azure.concept.logical-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
azure.rule.sql-managed-instance Source

Matches resource instances of azurerm_mssql_managed_instance.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.mssql-server Source

Matches resource instances of azurerm_mssql_server.

Classification: azure.concept.sql-server.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.mysql-database Source

Matches resource instances of azurerm_mysql_flexible_database.

Classification: azure.concept.logical-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.mysql-flexible-server Source

Matches resource instances of azurerm_mysql_flexible_server.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.nat-gateway-public-ip-association Source

Matches resource instances of azurerm_nat_gateway_public_ip_association.

Classification: azure.concept.network-policy-detail.

Contributions

Conditions, identity and resolution

Contribution through source.nat_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.public_ip_address_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.nat-gateway-public-ip-prefix-association Source

Matches resource instances of azurerm_nat_gateway_public_ip_prefix_association.

Classification: azure.concept.network-policy-detail.

Contributions

Conditions, identity and resolution

Contribution through source.nat_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.public_ip_prefix_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.nat-gateway Source

Matches resource instances of azurerm_nat_gateway.

Classification: azure.concept.managed-nat.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.netapp-account Source

Matches resource instances of azurerm_netapp_account.

Classification: azure.concept.netapp-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.netapp-backup-policy Source

Matches resource instances of azurerm_netapp_backup_policy.

Classification: azure.concept.backup-plan.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.netapp-backup-vault Source

Matches resource instances of azurerm_netapp_backup_vault.

Classification: azure.concept.backup-vault.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.netapp-capacity-pool Source

Matches resource instances of azurerm_netapp_pool.

Classification: azure.concept.netapp-capacity-pool.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.netapp-volume Source

Matches resource instances of azurerm_netapp_volume.

Classification: azure.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.ddos-protection-plan Source

Matches resource instances of azurerm_network_ddos_protection_plan.

Classification: azure.concept.ddos-protection-plan.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.network-function-traffic-collector Source

Matches resource instances of azurerm_network_function_azure_traffic_collector.

Classification: azure.concept.network-function-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.network-manager-ipam-pool Source

Matches resource instances of azurerm_network_manager_ipam_pool.

Classification: azure.concept.network-policy-detail.

azure.rule.virtual-network-manager Source

Matches resource instances of azurerm_network_manager.

Classification: azure.concept.virtual-network-manager.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.network-security-group Source

Matches resource instances of azurerm_network_security_group.

Classification: azure.concept.network-security-group.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.network-security-perimeter Source

Matches resource instances of azurerm_network_security_perimeter.

Classification: azure.concept.network-security-perimeter.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.network-security-rule Source

Matches resource instances of azurerm_network_security_rule.

Classification: azure.concept.network-policy-detail.

azure.rule.network-watcher-flow-log Source

Matches resource instances of azurerm_network_watcher_flow_log.

Classification: azure.concept.operations-detail.

azure.rule.network-watcher Source

Matches resource instances of azurerm_network_watcher.

Classification: azure.concept.network-watcher.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.new-relic-monitor Source

Matches resource instances of azurerm_new_relic_monitor.

Classification: azure.concept.third-party-monitor.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.nginx-deployment Source

Matches resource instances of azurerm_nginx_deployment.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.notification-hubs-namespace Source

Matches resource instances of azurerm_notification_hub_namespace.

Classification: azure.concept.notification-namespace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.notification-hub Source

Matches resource instances of azurerm_notification_hub.

Classification: azure.concept.notification-hub.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.oracle-autonomous-database Source

Matches resource instances of azurerm_oracle_autonomous_database.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.oracle-cloud-vm-cluster Source

Matches resource instances of azurerm_oracle_cloud_vm_cluster.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.oracle-exadata-infrastructure Source

Matches resource instances of azurerm_oracle_exadata_infrastructure.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.oracle-resource-anchor Source

Matches resource instances of azurerm_oracle_resource_anchor.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.orchestrated-virtual-machine-scale-set Source

Matches resource instances of azurerm_orchestrated_virtual_machine_scale_set.

Classification: azure.concept.virtual-machine-scale-set.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.palo-alto-firewall Source

Matches resource instances of azurerm_palo_alto_next_generation_firewall_virtual_network_local_rulestack.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.playwright-workspace Source

Matches resource instances of azurerm_playwright_workspace.

Classification: azure.concept.developer-environment.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.point-to-site-vpn-gateway Source

Matches resource instances of azurerm_point_to_site_vpn_gateway.

Classification: azure.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.policy-definition Source

Matches resource instances of azurerm_policy_definition.

Classification: azure.concept.governance-detail.

azure.rule.policy-set-definition Source

Matches resource instances of azurerm_policy_set_definition.

Classification: azure.concept.governance-detail.

azure.rule.portal-dashboard Source

Matches resource instances of azurerm_portal_dashboard.

Classification: azure.concept.operations-detail.

azure.rule.postgresql-backup Source

Matches resource instances of azurerm_postgresql_flexible_server_backup.

Classification: azure.concept.database-component.

azure.rule.postgresql-database Source

Matches resource instances of azurerm_postgresql_flexible_server_database.

Classification: azure.concept.logical-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
azure.rule.postgresql-flexible-server Source

Matches resource instances of azurerm_postgresql_flexible_server.

Classification: rf.concept.managed-database.

Contexts

Relations

Conditions, identity and resolution

Context through source.delegated_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.power-bi-embedded-capacity Source

Matches resource instances of azurerm_powerbi_embedded.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.private-dns-a-record Source

Matches resource instances of azurerm_private_dns_a_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.private-dns-cname-record Source

Matches resource instances of azurerm_private_dns_cname_record.

Classification: azure.concept.dns-record.

Contexts

Contributions

Conditions, identity and resolution

Context through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.private-dns-forwarding-ruleset Source

Matches resource instances of azurerm_private_dns_resolver_dns_forwarding_ruleset.

Classification: azure.concept.private-network-link.

azure.rule.private-dns-inbound-endpoint Source

Matches resource instances of azurerm_private_dns_resolver_inbound_endpoint.

Classification: azure.concept.private-network-link.

azure.rule.private-dns-outbound-endpoint Source

Matches resource instances of azurerm_private_dns_resolver_outbound_endpoint.

Classification: azure.concept.private-network-link.

azure.rule.private-dns-resolver Source

Matches resource instances of azurerm_private_dns_resolver.

Classification: azure.concept.private-dns-resolver.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.private-dns-zone-vnet-link Source

Matches resource instances of azurerm_private_dns_zone_virtual_network_link.

Classification: azure.concept.private-network-link.

Contexts

Contributions

Conditions, identity and resolution

Context through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.private_dns_zone_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.virtual_network_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.private-dns-zone Source

Matches resource instances of azurerm_private_dns_zone.

Classification: azure.concept.dns-zone.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.private-endpoint Source

Matches resource instances of azurerm_private_endpoint.

Classification: azure.concept.private-endpoint.

Contexts

Conditions, identity and resolution

Context through source.subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.private-link-service Source

Matches resource instances of azurerm_private_link_service.

Classification: azure.concept.private-link-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.proximity-placement-group Source

Matches resource instances of azurerm_proximity_placement_group.

Classification: azure.concept.compute-placement.

azure.rule.public-ip-prefix Source

Matches resource instances of azurerm_public_ip_prefix.

Classification: azure.concept.public-address.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.public-address Source

Matches resource instances of azurerm_public_ip.

Classification: azure.concept.public-address.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.purview-account Source

Matches resource instances of azurerm_purview_account.

Classification: azure.concept.purview-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.qumulo-file-system Source

Matches resource instances of azurerm_qumulo_file_system.

Classification: azure.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.recovery-services-vault Source

Matches resource instances of azurerm_recovery_services_vault.

Classification: azure.concept.backup-vault.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.red-hat-openshift-cluster Source

Matches resource instances of azurerm_redhat_openshift_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.azure-cache-for-redis Source

Matches resource instances of azurerm_redis_cache.

Classification: azure.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.relay-hybrid-connection Source

Matches resource instances of azurerm_relay_hybrid_connection.

Classification: azure.concept.relay-connection.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.relay-namespace Source

Matches resource instances of azurerm_relay_namespace.

Classification: azure.concept.relay-namespace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.resource-group Source

Matches resource instances of azurerm_resource_group.

Classification: azure.concept.resource-group.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
azure.rule.resource-policy-assignment Source

Matches resource instances of azurerm_resource_policy_assignment.

Classification: azure.concept.governance-detail.

azure.rule.role-assignment Source

Matches resource instances of azurerm_role_assignment.

Classification: azure.concept.governance-detail.

azure.rule.role-definition Source

Matches resource instances of azurerm_role_definition.

Classification: azure.concept.governance-detail.

azure.rule.route-server Source

Matches resource instances of azurerm_route_server.

Classification: azure.concept.route-table.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.route-table Source

Matches resource instances of azurerm_route_table.

Classification: azure.concept.route-table.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.route Source

Matches resource instances of azurerm_route.

Classification: azure.concept.network-policy-detail.

azure.rule.ai-search-service Source

Matches resource instances of azurerm_search_service.

Classification: azure.concept.ai-search-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.defender-subscription-plan Source

Matches resource instances of azurerm_security_center_subscription_pricing.

Classification: azure.concept.defender-plan.

azure.rule.defender-workspace Source

Matches resource instances of azurerm_security_center_workspace.

Classification: azure.concept.defender-plan.

azure.rule.sentinel-nrt-alert-rule Source

Matches resource instances of azurerm_sentinel_alert_rule_nrt.

Classification: azure.concept.security-detail.

azure.rule.sentinel-scheduled-alert-rule Source

Matches resource instances of azurerm_sentinel_alert_rule_scheduled.

Classification: azure.concept.security-detail.

azure.rule.sentinel-automation-rule Source

Matches resource instances of azurerm_sentinel_automation_rule.

Classification: azure.concept.security-detail.

azure.rule.sentinel-aws-cloudtrail-connector Source

Matches resource instances of azurerm_sentinel_data_connector_aws_cloud_trail.

Classification: azure.concept.security-detail.

azure.rule.sentinel-entra-connector Source

Matches resource instances of azurerm_sentinel_data_connector_azure_active_directory.

Classification: azure.concept.security-detail.

azure.rule.service-fabric-cluster Source

Matches resource instances of azurerm_service_fabric_cluster.

Classification: azure.concept.service-fabric-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.managed-service-fabric-cluster Source

Matches resource instances of azurerm_service_fabric_managed_cluster.

Classification: azure.concept.service-fabric-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.app-service-plan Source

Matches resource instances of azurerm_service_plan.

Classification: azure.concept.app-service-plan.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.service-bus-namespace Source

Matches resource instances of azurerm_servicebus_namespace.

Classification: azure.concept.messaging-namespace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.service-bus-queue Source

Matches resource instances of azurerm_servicebus_queue.

Classification: azure.concept.message-queue.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.namespace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.service-bus-subscription-rule Source

Matches resource instances of azurerm_servicebus_subscription_rule.

Classification: azure.concept.messaging-detail.

azure.rule.service-bus-subscription Source

Matches resource instances of azurerm_servicebus_subscription.

Classification: azure.concept.message-subscription.

Contexts

Relations

Conditions, identity and resolution

Context through source.topic_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.topic_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.service-bus-topic Source

Matches resource instances of azurerm_servicebus_topic.

Classification: azure.concept.service-bus-topic.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.namespace_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.compute-gallery Source

Matches resource instances of azurerm_shared_image_gallery.

Classification: azure.concept.image-gallery.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.shared-image Source

Matches resource instances of azurerm_shared_image.

Classification: azure.concept.compute-image.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.signalr-service Source

Matches resource instances of azurerm_signalr_service.

Classification: azure.concept.realtime-communication-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.site-recovery-fabric Source

Matches resource instances of azurerm_site_recovery_fabric.

Classification: azure.concept.site-recovery-fabric.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.site-recovery-protection-container Source

Matches resource instances of azurerm_site_recovery_protection_container.

Classification: azure.concept.site-recovery-fabric.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.site-recovery-replicated-vm Source

Matches resource instances of azurerm_site_recovery_replicated_vm.

Classification: azure.concept.site-recovery-detail.

azure.rule.site-recovery-plan Source

Matches resource instances of azurerm_site_recovery_replication_recovery_plan.

Classification: azure.concept.site-recovery-detail.

azure.rule.disk-snapshot Source

Matches resource instances of azurerm_snapshot.

Classification: azure.concept.disk-snapshot.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.spring-app Source

Matches resource instances of azurerm_spring_cloud_app.

Classification: azure.concept.spring-app.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.spring-apps-gateway Source

Matches resource instances of azurerm_spring_cloud_gateway.

Classification: azure.concept.spring-app.

azure.rule.spring-apps-service Source

Matches resource instances of azurerm_spring_cloud_service.

Classification: azure.concept.spring-apps-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.azure-local-cluster Source

Matches resource instances of azurerm_stack_hci_cluster.

Classification: azure.concept.azure-local-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.stack-hci-virtual-hard-disk Source

Matches resource instances of azurerm_stack_hci_virtual_hard_disk.

Classification: azure.concept.block-storage-volume.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.static-web-app Source

Matches resource instances of azurerm_static_web_app.

Classification: azure.concept.static-web-app.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.storage-account Source

Matches resource instances of azurerm_storage_account.

Classification: azure.concept.storage-account.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.storage-blob Source

Matches resource instances of azurerm_storage_blob.

Classification: azure.concept.storage-object-detail.

Contributions

Conditions, identity and resolution

Contribution through source.storage_container_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.blob-container Source

Matches resource instances of azurerm_storage_container.

Classification: rf.concept.object-storage-container.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.data-lake-filesystem Source

Matches resource instances of azurerm_storage_data_lake_gen2_filesystem.

Classification: rf.concept.object-storage-container.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.data-lake-path Source

Matches resource instances of azurerm_storage_data_lake_gen2_path.

Classification: azure.concept.storage-object-detail.

azure.rule.storage-encryption-scope Source

Matches resource instances of azurerm_storage_encryption_scope.

Classification: azure.concept.storage-object-detail.

Contributions

Conditions, identity and resolution

Contribution through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.storage-management-policy Source

Matches resource instances of azurerm_storage_management_policy.

Classification: azure.concept.storage-object-detail.

Contributions

Conditions, identity and resolution

Contribution through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.storage-mover Source

Matches resource instances of azurerm_storage_mover.

Classification: azure.concept.migration-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.queue-storage-queue Source

Matches resource instances of azurerm_storage_queue.

Classification: azure.concept.message-queue.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.storage-share-directory Source

Matches resource instances of azurerm_storage_share_directory.

Classification: azure.concept.storage-object-detail.

azure.rule.storage-share-file Source

Matches resource instances of azurerm_storage_share_file.

Classification: azure.concept.storage-object-detail.

azure.rule.azure-files-share Source

Matches resource instances of azurerm_storage_share.

Classification: azure.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.storage-sync-service Source

Matches resource instances of azurerm_storage_sync.

Classification: azure.concept.storage-sync-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.storage-table-entity Source

Matches resource instances of azurerm_storage_table_entity.

Classification: azure.concept.storage-object-detail.

Contributions

Conditions, identity and resolution

Contribution through source.storage_table_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.table-storage-table Source

Matches resource instances of azurerm_storage_table.

Classification: azure.concept.table-storage-table.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.storage_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.stream-analytics-cluster Source

Matches resource instances of azurerm_stream_analytics_cluster.

Classification: azure.concept.analytics-cluster.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.stream-analytics-job Source

Matches resource instances of azurerm_stream_analytics_job.

Classification: azure.concept.stream-analytics-job.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.stream-analytics-blob-output Source

Matches resource instances of azurerm_stream_analytics_output_blob.

Classification: azure.concept.data-integration-detail.

azure.rule.stream-analytics-event-hubs-input Source

Matches resource instances of azurerm_stream_analytics_stream_input_eventhub_v2.

Classification: azure.concept.data-integration-detail.

azure.rule.subnet-nat-gateway-association Source

Matches resource instances of azurerm_subnet_nat_gateway_association.

Classification: azure.concept.network-policy-detail.

Contributions

Conditions, identity and resolution

Contribution through source.subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.nat_gateway_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.subnet-network-security-group-association Source

Matches resource instances of azurerm_subnet_network_security_group_association.

Classification: azure.concept.network-policy-detail.

azure.rule.subnet-route-table-association Source

Matches resource instances of azurerm_subnet_route_table_association.

Classification: azure.concept.network-policy-detail.

azure.rule.subnet Source

Matches resource instances of azurerm_subnet.

Classification: rf.concept.subnet.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.virtual_network_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.synapse-private-link-hub Source

Matches resource instances of azurerm_synapse_private_link_hub.

Classification: azure.concept.private-link-scope.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.synapse-spark-pool Source

Matches resource instances of azurerm_synapse_spark_pool.

Classification: azure.concept.analytics-pool.

azure.rule.synapse-sql-pool Source

Matches resource instances of azurerm_synapse_sql_pool.

Classification: azure.concept.analytics-pool.

azure.rule.synapse-workspace Source

Matches resource instances of azurerm_synapse_workspace.

Classification: azure.concept.synapse-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.system-center-vmm-server Source

Matches resource instances of azurerm_system_center_virtual_machine_manager_server.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.system-center-virtual-machine Source

Matches resource instances of azurerm_system_center_virtual_machine_manager_virtual_machine_instance.

Classification: azure.concept.compute-instance.

azure.rule.traffic-manager-azure-endpoint Source

Matches resource instances of azurerm_traffic_manager_azure_endpoint.

Classification: azure.concept.load-balancer-component.

azure.rule.traffic-manager-profile Source

Matches resource instances of azurerm_traffic_manager_profile.

Classification: azure.concept.traffic-manager-profile.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.trusted-signing-account Source

Matches resource instances of azurerm_trusted_signing_account.

Classification: azure.concept.trusted-signing-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.user-assigned-managed-identity Source

Matches resource instances of azurerm_user_assigned_identity.

Classification: rf.concept.service-identity.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "principal_id", "client_id"]
  • scope: "global"

Endpoint

  • attributes: ["id", "principal_id", "client_id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.video-indexer-account Source

Matches resource instances of azurerm_video_indexer_account.

Classification: azure.concept.video-indexer-account.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-desktop-application-group Source

Matches resource instances of azurerm_virtual_desktop_application_group.

Classification: azure.concept.virtual-desktop-application-group.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-desktop-application Source

Matches resource instances of azurerm_virtual_desktop_application.

Classification: azure.concept.compute-placement.

azure.rule.virtual-desktop-host-pool Source

Matches resource instances of azurerm_virtual_desktop_host_pool.

Classification: azure.concept.virtual-desktop-host-pool.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-desktop-scaling-plan Source

Matches resource instances of azurerm_virtual_desktop_scaling_plan.

Classification: azure.concept.compute-placement.

azure.rule.virtual-desktop-workspace Source

Matches resource instances of azurerm_virtual_desktop_workspace.

Classification: azure.concept.virtual-desktop-workspace.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-hub Source

Matches resource instances of azurerm_virtual_hub.

Classification: azure.concept.virtual-hub.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-machine-restore-point Source

Matches resource instances of azurerm_virtual_machine_restore_point.

Classification: azure.concept.disk-snapshot.

azure.rule.virtual-machine-scale-set Source

Matches resource instances of azurerm_virtual_machine_scale_set.

Classification: azure.concept.virtual-machine-scale-set.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-machine Source

Matches resource instances of azurerm_virtual_machine.

Classification: azure.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-network-gateway-connection Source

Matches resource instances of azurerm_virtual_network_gateway_connection.

Classification: azure.concept.vpn-connection.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-network-gateway Source

Matches resource instances of azurerm_virtual_network_gateway.

Classification: azure.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-network-peering Source

Matches resource instances of azurerm_virtual_network_peering.

Classification: azure.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.remote_virtual_network_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.virtual-network Source

Matches resource instances of azurerm_virtual_network.

Classification: rf.concept.virtual-network.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.virtual-wan Source

Matches resource instances of azurerm_virtual_wan.

Classification: azure.concept.virtual-wan.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.vmware-cluster Source

Matches resource instances of azurerm_vmware_cluster.

Classification: azure.concept.hybrid-platform.

azure.rule.vmware-private-cloud Source

Matches resource instances of azurerm_vmware_private_cloud.

Classification: azure.concept.vmware-private-cloud.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.vpn-gateway-connection Source

Matches resource instances of azurerm_vpn_gateway_connection.

Classification: azure.concept.vpn-connection.

azure.rule.vpn-gateway Source

Matches resource instances of azurerm_vpn_gateway.

Classification: azure.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.vpn-site Source

Matches resource instances of azurerm_vpn_site.

Classification: azure.concept.local-network-gateway.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.web-application-firewall-policy Source

Matches resource instances of azurerm_web_application_firewall_policy.

Classification: azure.concept.web-application-firewall-policy.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.web-pubsub Source

Matches resource instances of azurerm_web_pubsub.

Classification: azure.concept.realtime-communication-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.windows-function-app Source

Matches resource instances of azurerm_windows_function_app.

Classification: azure.concept.serverless-function.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.service_plan_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.site_config[0].application_insights_connection_string

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.connection_string
  • match.strategy: "exact"
azure.rule.windows-virtual-machine-scale-set Source

Matches resource instances of azurerm_windows_virtual_machine_scale_set.

Classification: azure.concept.virtual-machine-scale-set.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.windows-virtual-machine Source

Matches resource instances of azurerm_windows_virtual_machine.

Classification: azure.concept.compute-instance.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.windows-web-app Source

Matches resource instances of azurerm_windows_web_app.

Classification: azure.concept.app-service.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.virtual_network_subnet_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Context through source.service_plan_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
azure.rule.sap-discovery-virtual-instance Source

Matches resource instances of azurerm_workloads_sap_discovery_virtual_instance.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.sap-single-node-virtual-instance Source

Matches resource instances of azurerm_workloads_sap_single_node_virtual_instance.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
azure.rule.sap-three-tier-virtual-instance Source

Matches resource instances of azurerm_workloads_sap_three_tier_virtual_instance.

Classification: azure.concept.hybrid-platform.

Contexts

Conditions, identity and resolution

Context through source.resource_group_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"