# azure Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `azure/azapi`: `= 2.12.0`.
- `hashicorp/azuread`: `= 3.9.0`.
- `hashicorp/azurerm`: `= 5.3.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `azapi_resource` | `resource` | [`azure-enclave`](#azure-concept-azure-enclave)<br>[`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database)<br>[`sre-agent`](#azure-concept-sre-agent) | [`azure-enclave`](#rule-azure-enclave) (conditional)<br>[`horizondb-cluster`](#rule-horizondb-cluster) (conditional)<br>[`sre-agent`](#rule-sre-agent) (conditional) |
| `azuread_access_package_assignment_policy` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-access-package-assignment-policy`](#rule-entra-access-package-assignment-policy) |
| `azuread_app_role_assignment` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-app-role-assignment`](#rule-entra-app-role-assignment) |
| `azuread_application_federated_identity_credential` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-application-federated-identity`](#rule-entra-application-federated-identity) |
| `azuread_application_registration` | `resource` | [`entra-application`](#azure-concept-entra-application) | [`entra-application-registration`](#rule-entra-application-registration) |
| `azuread_application` | `resource` | [`entra-application`](#azure-concept-entra-application) | [`entra-application`](#rule-entra-application) |
| `azuread_authentication_strength_policy` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-authentication-strength-policy`](#rule-entra-authentication-strength-policy) |
| `azuread_group_without_members` | `resource` | [`identity-group`](#azure-concept-identity-group) | [`entra-group-without-members`](#rule-entra-group-without-members) |
| `azuread_group` | `resource` | [`identity-group`](#azure-concept-identity-group) | [`entra-group`](#rule-entra-group) |
| `azuread_named_location` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-named-location`](#rule-entra-named-location) |
| `azuread_service_principal` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`entra-service-principal`](#rule-entra-service-principal) |
| `azurerm_aadb2c_directory` | `resource` | [`entra-directory`](#azure-concept-entra-directory) | [`entra-external-id-directory`](#rule-entra-external-id-directory) |
| `azurerm_active_directory_domain_service_replica_set` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-domain-services-replica-set`](#rule-entra-domain-services-replica-set) |
| `azurerm_active_directory_domain_service_trust` | `resource` | [`identity-governance-detail`](#azure-concept-identity-governance-detail) | [`entra-domain-services-trust`](#rule-entra-domain-services-trust) |
| `azurerm_active_directory_domain_service` | `resource` | [`entra-domain-service`](#azure-concept-entra-domain-service) | [`entra-domain-services`](#rule-entra-domain-services) |
| `azurerm_advanced_threat_protection` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`advanced-threat-protection`](#rule-advanced-threat-protection) |
| `azurerm_ai_foundry_project` | `resource` | [`ai-foundry`](#azure-concept-ai-foundry) | [`ai-foundry-project`](#rule-ai-foundry-project) |
| `azurerm_ai_foundry` | `resource` | [`ai-foundry`](#azure-concept-ai-foundry) | [`ai-foundry`](#rule-ai-foundry) |
| `azurerm_analysis_services_server` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`analysis-services-server`](#rule-analysis-services-server) |
| `azurerm_api_connection` | `resource` | [`integration-connection`](#azure-concept-integration-connection) | [`api-connection`](#rule-api-connection) |
| `azurerm_api_management_api` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-api`](#rule-api-management-api) |
| `azurerm_api_management_backend` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-backend`](#rule-api-management-backend) |
| `azurerm_api_management_gateway` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-gateway`](#rule-api-management-gateway) |
| `azurerm_api_management_policy` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-policy`](#rule-api-management-policy) |
| `azurerm_api_management_product` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-product`](#rule-api-management-product) |
| `azurerm_api_management_standalone_gateway` | `resource` | [`api-gateway`](#azure-concept-api-gateway) | [`api-management-standalone-gateway`](#rule-api-management-standalone-gateway) |
| `azurerm_api_management_workspace` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`api-management-workspace`](#rule-api-management-workspace) |
| `azurerm_api_management` | `resource` | [`api-gateway`](#azure-concept-api-gateway) | [`api-management`](#rule-api-management) |
| `azurerm_app_configuration` | `resource` | [`app-configuration`](#azure-concept-app-configuration) | [`app-configuration`](#rule-app-configuration) |
| `azurerm_app_service_connection` | `resource` | [`integration-connection`](#azure-concept-integration-connection) | [`app-service-connection`](#rule-app-service-connection) |
| `azurerm_app_service_environment_v3` | `resource` | [`app-service-environment`](#azure-concept-app-service-environment) | [`app-service-environment`](#rule-app-service-environment) |
| `azurerm_application_gateway` | `resource` | [`load-balancer`](#azure-concept-load-balancer) | [`application-gateway`](#rule-application-gateway) |
| `azurerm_application_insights_standard_web_test` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`application-insights-web-test`](#rule-application-insights-web-test) |
| `azurerm_application_insights` | `resource` | [`application-insights`](#azure-concept-application-insights) | [`application-insights`](#rule-application-insights) |
| `azurerm_application_load_balancer_frontend` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`application-load-balancer-frontend`](#rule-application-load-balancer-frontend) |
| `azurerm_application_load_balancer` | `resource` | [`load-balancer`](#azure-concept-load-balancer) | [`application-load-balancer`](#rule-application-load-balancer) |
| `azurerm_application_security_group` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`application-security-group`](#rule-application-security-group) |
| `azurerm_arc_kubernetes_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`arc-kubernetes-cluster`](#rule-arc-kubernetes-cluster) |
| `azurerm_arc_kubernetes_provisioned_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`arc-provisioned-kubernetes-cluster`](#rule-arc-provisioned-kubernetes-cluster) |
| `azurerm_arc_machine` | `resource` | [`arc-enabled-server`](#azure-concept-arc-enabled-server) | [`arc-enabled-server`](#rule-arc-enabled-server) |
| `azurerm_arc_private_link_scope` | `resource` | [`private-link-scope`](#azure-concept-private-link-scope) | [`arc-private-link-scope`](#rule-arc-private-link-scope) |
| `azurerm_arc_resource_bridge_appliance` | `resource` | [`arc-resource-bridge`](#azure-concept-arc-resource-bridge) | [`arc-resource-bridge`](#rule-arc-resource-bridge) |
| `azurerm_attestation_provider` | `resource` | [`attestation-provider`](#azure-concept-attestation-provider) | [`attestation-provider`](#rule-attestation-provider) |
| `azurerm_automation_account` | `resource` | [`automation-account`](#azure-concept-automation-account) | [`automation-account`](#rule-automation-account) |
| `azurerm_automation_runbook` | `resource` | [`workflow`](#azure-concept-workflow) | [`automation-runbook`](#rule-automation-runbook) |
| `azurerm_automation_schedule` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`automation-schedule`](#rule-automation-schedule) |
| `azurerm_availability_set` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`availability-set`](#rule-availability-set) |
| `azurerm_backup_policy_file_share` | `resource` | [`backup-plan`](#azure-concept-backup-plan) | [`file-share-backup-policy`](#rule-file-share-backup-policy) |
| `azurerm_backup_policy_vm` | `resource` | [`backup-plan`](#azure-concept-backup-plan) | [`virtual-machine-backup-policy`](#rule-virtual-machine-backup-policy) |
| `azurerm_backup_protected_vm` | `resource` | [`site-recovery-detail`](#azure-concept-site-recovery-detail) | [`backup-protected-vm`](#rule-backup-protected-vm) |
| `azurerm_bastion_host` | `resource` | [`bastion-host`](#azure-concept-bastion-host) | [`bastion-host`](#rule-bastion-host) |
| `azurerm_batch_account` | `resource` | [`batch-account`](#azure-concept-batch-account) | [`batch-account`](#rule-batch-account) |
| `azurerm_batch_application` | `resource` | [`batch-pool`](#azure-concept-batch-pool) | [`batch-application`](#rule-batch-application) |
| `azurerm_batch_pool` | `resource` | [`batch-pool`](#azure-concept-batch-pool) | [`batch-pool`](#rule-batch-pool) |
| `azurerm_bot_channels_registration` | `resource` | [`bot-service`](#azure-concept-bot-service) | [`bot-channels-registration`](#rule-bot-channels-registration) |
| `azurerm_bot_service_azure_bot` | `resource` | [`bot-service`](#azure-concept-bot-service) | [`azure-bot`](#rule-azure-bot) |
| `azurerm_bot_web_app` | `resource` | [`bot-service`](#azure-concept-bot-service) | [`bot-web-app`](#rule-bot-web-app) |
| `azurerm_capacity_reservation_group` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`capacity-reservation-group`](#rule-capacity-reservation-group) |
| `azurerm_capacity_reservation` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`capacity-reservation`](#rule-capacity-reservation) |
| `azurerm_cdn_endpoint` | `resource` | [`content-delivery-profile`](#azure-concept-content-delivery-profile) | [`cdn-endpoint`](#rule-cdn-endpoint) |
| `azurerm_cdn_frontdoor_endpoint` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`front-door-endpoint`](#rule-front-door-endpoint) |
| `azurerm_cdn_frontdoor_origin_group` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`front-door-origin-group`](#rule-front-door-origin-group) |
| `azurerm_cdn_frontdoor_origin` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`front-door-origin`](#rule-front-door-origin) |
| `azurerm_cdn_frontdoor_profile` | `resource` | [`front-door-profile`](#azure-concept-front-door-profile) | [`front-door-profile`](#rule-front-door-profile) |
| `azurerm_cdn_frontdoor_route` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`front-door-route`](#rule-front-door-route) |
| `azurerm_cdn_profile` | `resource` | [`content-delivery-profile`](#azure-concept-content-delivery-profile) | [`cdn-profile`](#rule-cdn-profile) |
| `azurerm_chaos_studio_experiment` | `resource` | [`chaos-experiment`](#azure-concept-chaos-experiment) | [`chaos-studio-experiment`](#rule-chaos-studio-experiment) |
| `azurerm_cognitive_account_project` | `resource` | [`ai-foundry`](#azure-concept-ai-foundry) | [`ai-services-project`](#rule-ai-services-project) |
| `azurerm_cognitive_account` | `resource` | [`ai-service-account`](#azure-concept-ai-service-account) | [`ai-services-account`](#rule-ai-services-account) |
| `azurerm_cognitive_deployment` | `resource` | [`ai-inference-endpoint`](#azure-concept-ai-inference-endpoint) | [`ai-model-deployment`](#rule-ai-model-deployment) |
| `azurerm_communication_service` | `resource` | [`communication-service`](#azure-concept-communication-service) | [`communication-service`](#rule-communication-service) |
| `azurerm_confidential_ledger` | `resource` | [`confidential-ledger`](#azure-concept-confidential-ledger) | [`confidential-ledger`](#rule-confidential-ledger) |
| `azurerm_container_app_environment` | `resource` | [`container-app-environment`](#azure-concept-container-app-environment) | [`container-app-environment`](#rule-container-app-environment) |
| `azurerm_container_app_job` | `resource` | [`container-app-job`](#azure-concept-container-app-job) | [`container-app-job`](#rule-container-app-job) |
| `azurerm_container_app` | `resource` | [`container-app`](#azure-concept-container-app) | [`container-app`](#rule-container-app) |
| `azurerm_container_connected_registry` | `resource` | [`container-registry`](#azure-concept-container-registry) | [`connected-container-registry`](#rule-connected-container-registry) |
| `azurerm_container_group` | `resource` | [`container-instance-group`](#azure-concept-container-instance-group) | [`container-instance-group`](#rule-container-instance-group) |
| `azurerm_container_registry` | `resource` | [`container-registry`](#azure-concept-container-registry) | [`container-registry`](#rule-container-registry) |
| `azurerm_cosmosdb_account` | `resource` | [`cosmos-account`](#azure-concept-cosmos-account) | [`cosmos-account`](#rule-cosmos-account) |
| `azurerm_cosmosdb_cassandra_cluster` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`cosmos-cassandra-cluster`](#rule-cosmos-cassandra-cluster) |
| `azurerm_cosmosdb_cassandra_keyspace` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`cosmos-cassandra-keyspace`](#rule-cosmos-cassandra-keyspace) |
| `azurerm_cosmosdb_cassandra_table` | `resource` | [`database-component`](#azure-concept-database-component) | [`cosmos-cassandra-table`](#rule-cosmos-cassandra-table) |
| `azurerm_cosmosdb_gremlin_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`cosmos-gremlin-database`](#rule-cosmos-gremlin-database) |
| `azurerm_cosmosdb_gremlin_graph` | `resource` | [`database-component`](#azure-concept-database-component) | [`cosmos-gremlin-graph`](#rule-cosmos-gremlin-graph) |
| `azurerm_cosmosdb_mongo_collection` | `resource` | [`database-component`](#azure-concept-database-component) | [`cosmos-mongo-collection`](#rule-cosmos-mongo-collection) |
| `azurerm_cosmosdb_mongo_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`cosmos-mongo-database`](#rule-cosmos-mongo-database) |
| `azurerm_cosmosdb_postgresql_cluster` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`cosmos-postgresql-cluster`](#rule-cosmos-postgresql-cluster) |
| `azurerm_cosmosdb_sql_container` | `resource` | [`database-component`](#azure-concept-database-component) | [`cosmos-sql-container`](#rule-cosmos-sql-container) |
| `azurerm_cosmosdb_sql_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`cosmos-sql-database`](#rule-cosmos-sql-database) |
| `azurerm_cosmosdb_sql_dedicated_gateway` | `resource` | [`database-component`](#azure-concept-database-component) | [`cosmos-dedicated-gateway`](#rule-cosmos-dedicated-gateway) |
| `azurerm_custom_ip_prefix` | `resource` | [`public-address`](#azure-concept-public-address) | [`custom-ip-prefix`](#rule-custom-ip-prefix) |
| `azurerm_dashboard_grafana` | `resource` | [`managed-grafana`](#azure-concept-managed-grafana) | [`managed-grafana`](#rule-managed-grafana) |
| `azurerm_data_factory_data_flow` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-data-flow`](#rule-data-factory-data-flow) |
| `azurerm_data_factory_dataset_azure_blob` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-blob-dataset`](#rule-data-factory-blob-dataset) |
| `azurerm_data_factory_dataset_azure_sql_table` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-sql-dataset`](#rule-data-factory-sql-dataset) |
| `azurerm_data_factory_integration_runtime_azure` | `resource` | [`data-integration-runtime`](#azure-concept-data-integration-runtime) | [`data-factory-azure-integration-runtime`](#rule-data-factory-azure-integration-runtime) |
| `azurerm_data_factory_integration_runtime_self_hosted` | `resource` | [`data-integration-runtime`](#azure-concept-data-integration-runtime) | [`data-factory-self-hosted-integration-runtime`](#rule-data-factory-self-hosted-integration-runtime) |
| `azurerm_data_factory_linked_service_azure_blob_storage` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-blob-linked-service`](#rule-data-factory-blob-linked-service) |
| `azurerm_data_factory_linked_service_azure_sql_database` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-sql-linked-service`](#rule-data-factory-sql-linked-service) |
| `azurerm_data_factory_managed_private_endpoint` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-managed-private-endpoint`](#rule-data-factory-managed-private-endpoint) |
| `azurerm_data_factory_pipeline` | `resource` | [`workflow`](#azure-concept-workflow) | [`data-factory-pipeline`](#rule-data-factory-pipeline) |
| `azurerm_data_factory_trigger_schedule` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`data-factory-schedule-trigger`](#rule-data-factory-schedule-trigger) |
| `azurerm_data_factory` | `resource` | [`data-factory`](#azure-concept-data-factory) | [`data-factory`](#rule-data-factory) |
| `azurerm_data_protection_backup_policy_blob_storage` | `resource` | [`backup-plan`](#azure-concept-backup-plan) | [`data-protection-blob-backup-policy`](#rule-data-protection-blob-backup-policy) |
| `azurerm_data_protection_backup_policy_disk` | `resource` | [`backup-plan`](#azure-concept-backup-plan) | [`data-protection-disk-backup-policy`](#rule-data-protection-disk-backup-policy) |
| `azurerm_data_protection_backup_vault` | `resource` | [`backup-vault`](#azure-concept-backup-vault) | [`data-protection-backup-vault`](#rule-data-protection-backup-vault) |
| `azurerm_data_share_account` | `resource` | [`data-share-account`](#azure-concept-data-share-account) | [`data-share-account`](#rule-data-share-account) |
| `azurerm_database_migration_project` | `resource` | [`migration-service`](#azure-concept-migration-service) | [`database-migration-project`](#rule-database-migration-project) |
| `azurerm_database_migration_service` | `resource` | [`migration-service`](#azure-concept-migration-service) | [`database-migration-service`](#rule-database-migration-service) |
| `azurerm_databox_edge_device` | `resource` | [`migration-service`](#azure-concept-migration-service) | [`data-box-edge-device`](#rule-data-box-edge-device) |
| `azurerm_databricks_virtual_network_peering` | `resource` | [`network-peering`](#azure-concept-network-peering) | [`databricks-virtual-network-peering`](#rule-databricks-virtual-network-peering) |
| `azurerm_databricks_workspace` | `resource` | [`databricks-workspace`](#azure-concept-databricks-workspace) | [`databricks-workspace`](#rule-databricks-workspace) |
| `azurerm_datadog_monitor` | `resource` | [`third-party-monitor`](#azure-concept-third-party-monitor) | [`datadog-monitor`](#rule-datadog-monitor) |
| `azurerm_dedicated_hardware_security_module` | `resource` | [`managed-hsm`](#azure-concept-managed-hsm) | [`dedicated-hardware-security-module`](#rule-dedicated-hardware-security-module) |
| `azurerm_dedicated_host_group` | `resource` | [`dedicated-host-group`](#azure-concept-dedicated-host-group) | [`dedicated-host-group`](#rule-dedicated-host-group) |
| `azurerm_dev_center_dev_box_definition` | `resource` | [`developer-environment`](#azure-concept-developer-environment) | [`dev-box-definition`](#rule-dev-box-definition) |
| `azurerm_dev_center_project` | `resource` | [`dev-center-project`](#azure-concept-dev-center-project) | [`dev-center-project`](#rule-dev-center-project) |
| `azurerm_dev_center` | `resource` | [`dev-center`](#azure-concept-dev-center) | [`dev-center`](#rule-dev-center) |
| `azurerm_dev_test_lab` | `resource` | [`developer-environment`](#azure-concept-developer-environment) | [`dev-test-lab`](#rule-dev-test-lab) |
| `azurerm_dev_test_linux_virtual_machine` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`dev-test-linux-virtual-machine`](#rule-dev-test-linux-virtual-machine) |
| `azurerm_dev_test_windows_virtual_machine` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`dev-test-windows-virtual-machine`](#rule-dev-test-windows-virtual-machine) |
| `azurerm_digital_twins_endpoint_eventgrid` | `resource` | [`iot-detail`](#azure-concept-iot-detail) | [`digital-twins-event-grid-endpoint`](#rule-digital-twins-event-grid-endpoint) |
| `azurerm_digital_twins_instance` | `resource` | [`digital-twins-instance`](#azure-concept-digital-twins-instance) | [`digital-twins-instance`](#rule-digital-twins-instance) |
| `azurerm_dns_a_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-a-record`](#rule-dns-a-record) |
| `azurerm_dns_aaaa_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-aaaa-record`](#rule-dns-aaaa-record) |
| `azurerm_dns_cname_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-cname-record`](#rule-dns-cname-record) |
| `azurerm_dns_mx_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-mx-record`](#rule-dns-mx-record) |
| `azurerm_dns_ns_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-ns-record`](#rule-dns-ns-record) |
| `azurerm_dns_ptr_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-ptr-record`](#rule-dns-ptr-record) |
| `azurerm_dns_srv_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-srv-record`](#rule-dns-srv-record) |
| `azurerm_dns_txt_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`dns-txt-record`](#rule-dns-txt-record) |
| `azurerm_dns_zone` | `resource` | [`dns-zone`](#azure-concept-dns-zone) | [`dns-zone`](#rule-dns-zone) |
| `azurerm_dynatrace_monitor` | `resource` | [`third-party-monitor`](#azure-concept-third-party-monitor) | [`dynatrace-monitor`](#rule-dynatrace-monitor) |
| `azurerm_elastic_cloud_elasticsearch` | `resource` | [`third-party-monitor`](#azure-concept-third-party-monitor) | [`elastic-cloud`](#rule-elastic-cloud) |
| `azurerm_elastic_san_volume_group` | `resource` | [`elastic-san`](#azure-concept-elastic-san) | [`elastic-san-volume-group`](#rule-elastic-san-volume-group) |
| `azurerm_elastic_san_volume` | `resource` | [`block-storage-volume`](#azure-concept-block-storage-volume) | [`elastic-san-volume`](#rule-elastic-san-volume) |
| `azurerm_elastic_san` | `resource` | [`elastic-san`](#azure-concept-elastic-san) | [`elastic-san`](#rule-elastic-san) |
| `azurerm_email_communication_service` | `resource` | [`email-communication-service`](#azure-concept-email-communication-service) | [`email-communication-service`](#rule-email-communication-service) |
| `azurerm_eventgrid_domain_topic` | `resource` | [`event-grid-topic`](#azure-concept-event-grid-topic) | [`event-grid-domain-topic`](#rule-event-grid-domain-topic) |
| `azurerm_eventgrid_domain` | `resource` | [`event-grid-domain`](#azure-concept-event-grid-domain) | [`event-grid-domain`](#rule-event-grid-domain) |
| `azurerm_eventgrid_event_subscription` | `resource` | [`message-subscription`](#azure-concept-message-subscription) | [`event-grid-event-subscription`](#rule-event-grid-event-subscription) |
| `azurerm_eventgrid_namespace_topic` | `resource` | [`message-topic`](#azure-concept-message-topic) | [`event-grid-namespace-topic`](#rule-event-grid-namespace-topic) |
| `azurerm_eventgrid_namespace` | `resource` | [`event-grid-domain`](#azure-concept-event-grid-domain) | [`event-grid-namespace`](#rule-event-grid-namespace) |
| `azurerm_eventgrid_partner_namespace` | `resource` | [`event-grid-domain`](#azure-concept-event-grid-domain) | [`event-grid-partner-namespace`](#rule-event-grid-partner-namespace) |
| `azurerm_eventgrid_system_topic_event_subscription` | `resource` | [`message-subscription`](#azure-concept-message-subscription) | [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription) |
| `azurerm_eventgrid_system_topic` | `resource` | [`event-grid-topic`](#azure-concept-event-grid-topic) | [`event-grid-system-topic`](#rule-event-grid-system-topic) |
| `azurerm_eventgrid_topic` | `resource` | [`event-grid-topic`](#azure-concept-event-grid-topic) | [`event-grid-topic`](#rule-event-grid-topic) |
| `azurerm_eventhub_cluster` | `resource` | [`event-stream`](#azure-concept-event-stream) | [`event-hubs-cluster`](#rule-event-hubs-cluster) |
| `azurerm_eventhub_consumer_group` | `resource` | [`messaging-detail`](#azure-concept-messaging-detail) | [`event-hubs-consumer-group`](#rule-event-hubs-consumer-group) |
| `azurerm_eventhub_namespace_schema_group` | `resource` | [`messaging-detail`](#azure-concept-messaging-detail) | [`event-hubs-schema-group`](#rule-event-hubs-schema-group) |
| `azurerm_eventhub_namespace` | `resource` | [`messaging-namespace`](#azure-concept-messaging-namespace) | [`event-hubs-namespace`](#rule-event-hubs-namespace) |
| `azurerm_eventhub` | `resource` | [`event-stream`](#azure-concept-event-stream) | [`event-hub`](#rule-event-hub) |
| `azurerm_express_route_circuit` | `resource` | [`dedicated-interconnect`](#azure-concept-dedicated-interconnect) | [`expressroute-circuit`](#rule-expressroute-circuit) |
| `azurerm_express_route_gateway` | `resource` | [`expressroute-gateway`](#azure-concept-expressroute-gateway) | [`expressroute-gateway`](#rule-expressroute-gateway) |
| `azurerm_express_route_port` | `resource` | [`dedicated-interconnect`](#azure-concept-dedicated-interconnect) | [`expressroute-port`](#rule-expressroute-port) |
| `azurerm_extended_location_custom_location` | `resource` | [`custom-location`](#azure-concept-custom-location) | [`arc-custom-location`](#rule-arc-custom-location) |
| `azurerm_fabric_capacity` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`fabric-capacity`](#rule-fabric-capacity) |
| `azurerm_firewall_policy_rule_collection_group` | `resource` | [`firewall-policy`](#azure-concept-firewall-policy) | [`azure-firewall-policy-rule-collection-group`](#rule-azure-firewall-policy-rule-collection-group) |
| `azurerm_firewall_policy` | `resource` | [`firewall-policy`](#azure-concept-firewall-policy) | [`azure-firewall-policy`](#rule-azure-firewall-policy) |
| `azurerm_firewall` | `resource` | [`azure-firewall`](#azure-concept-azure-firewall) | [`azure-firewall`](#rule-azure-firewall) |
| `azurerm_fluid_relay_server` | `resource` | [`realtime-communication-service`](#azure-concept-realtime-communication-service) | [`fluid-relay`](#rule-fluid-relay) |
| `azurerm_frontdoor` | `resource` | [`front-door-profile`](#azure-concept-front-door-profile) | [`classic-front-door`](#rule-classic-front-door) |
| `azurerm_function_app_flex_consumption` | `resource` | [`serverless-function`](#azure-concept-serverless-function) | [`flex-consumption-function-app`](#rule-flex-consumption-function-app) |
| `azurerm_function_app_function` | `resource` | [`serverless-function`](#azure-concept-serverless-function) | [`function-app-function`](#rule-function-app-function) |
| `azurerm_graph_services_account` | `resource` | [`graph-data-connect-account`](#azure-concept-graph-data-connect-account) | [`graph-data-connect-account`](#rule-graph-data-connect-account) |
| `azurerm_hdinsight_hadoop_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`hdinsight-hadoop-cluster`](#rule-hdinsight-hadoop-cluster) |
| `azurerm_hdinsight_hbase_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`hdinsight-hbase-cluster`](#rule-hdinsight-hbase-cluster) |
| `azurerm_hdinsight_interactive_query_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`hdinsight-interactive-query-cluster`](#rule-hdinsight-interactive-query-cluster) |
| `azurerm_hdinsight_kafka_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`hdinsight-kafka-cluster`](#rule-hdinsight-kafka-cluster) |
| `azurerm_hdinsight_spark_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`hdinsight-spark-cluster`](#rule-hdinsight-spark-cluster) |
| `azurerm_healthbot` | `resource` | [`bot-service`](#azure-concept-bot-service) | [`health-bot`](#rule-health-bot) |
| `azurerm_healthcare_dicom_service` | `resource` | [`health-data-service`](#azure-concept-health-data-service) | [`health-data-dicom-service`](#rule-health-data-dicom-service) |
| `azurerm_healthcare_fhir_service` | `resource` | [`health-data-service`](#azure-concept-health-data-service) | [`health-data-fhir-service`](#rule-health-data-fhir-service) |
| `azurerm_healthcare_medtech_service` | `resource` | [`health-data-service`](#azure-concept-health-data-service) | [`health-data-medtech-service`](#rule-health-data-medtech-service) |
| `azurerm_healthcare_service` | `resource` | [`health-data-service`](#azure-concept-health-data-service) | [`healthcare-service`](#rule-healthcare-service) |
| `azurerm_healthcare_workspace` | `resource` | [`health-data-workspace`](#azure-concept-health-data-workspace) | [`health-data-services-workspace`](#rule-health-data-services-workspace) |
| `azurerm_image` | `resource` | [`compute-image`](#azure-concept-compute-image) | [`compute-image`](#rule-compute-image) |
| `azurerm_iotcentral_application` | `resource` | [`iot-central-application`](#azure-concept-iot-central-application) | [`iot-central-application`](#rule-iot-central-application) |
| `azurerm_iothub_device_update_account` | `resource` | [`iot-update-service`](#azure-concept-iot-update-service) | [`iot-hub-device-update-account`](#rule-iot-hub-device-update-account) |
| `azurerm_iothub_device_update_instance` | `resource` | [`iot-detail`](#azure-concept-iot-detail) | [`iot-hub-device-update-instance`](#rule-iot-hub-device-update-instance) |
| `azurerm_iothub_dps` | `resource` | [`iot-provisioning-service`](#azure-concept-iot-provisioning-service) | [`iot-hub-device-provisioning-service`](#rule-iot-hub-device-provisioning-service) |
| `azurerm_iothub_endpoint_eventhub` | `resource` | [`iot-detail`](#azure-concept-iot-detail) | [`iot-hub-event-hubs-endpoint`](#rule-iot-hub-event-hubs-endpoint) |
| `azurerm_iothub_endpoint_servicebus_queue` | `resource` | [`iot-detail`](#azure-concept-iot-detail) | [`iot-hub-service-bus-queue-endpoint`](#rule-iot-hub-service-bus-queue-endpoint) |
| `azurerm_iothub_endpoint_storage_container` | `resource` | [`iot-detail`](#azure-concept-iot-detail) | [`iot-hub-storage-endpoint`](#rule-iot-hub-storage-endpoint) |
| `azurerm_iothub` | `resource` | [`iot-hub`](#azure-concept-iot-hub) | [`iot-hub`](#rule-iot-hub) |
| `azurerm_ip_group` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`ip-group`](#rule-ip-group) |
| `azurerm_key_vault_access_policy` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`key-vault-access-policy`](#rule-key-vault-access-policy) |
| `azurerm_key_vault_certificate` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`key-vault-certificate`](#rule-key-vault-certificate) |
| `azurerm_key_vault_key` | `resource` | [`encryption-key`](#azure-concept-encryption-key) | [`key-vault-key`](#rule-key-vault-key) |
| `azurerm_key_vault_managed_hardware_security_module_key` | `resource` | [`encryption-key`](#azure-concept-encryption-key) | [`managed-hsm-key`](#rule-managed-hsm-key) |
| `azurerm_key_vault_managed_hardware_security_module` | `resource` | [`managed-hsm`](#azure-concept-managed-hsm) | [`managed-hsm`](#rule-managed-hsm) |
| `azurerm_key_vault_secret` | `resource` | [`managed-secret`](#azure-concept-managed-secret) | [`key-vault-secret`](#rule-key-vault-secret) |
| `azurerm_key_vault` | `resource` | [`key-vault`](#azure-concept-key-vault) | [`key-vault`](#rule-key-vault) |
| `azurerm_kubernetes_automatic_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`automatic-kubernetes-cluster`](#rule-automatic-kubernetes-cluster) |
| `azurerm_kubernetes_cluster_node_pool` | `resource` | [`kubernetes-node-pool`](#azure-concept-kubernetes-node-pool) | [`aks-node-pool`](#rule-aks-node-pool) |
| `azurerm_kubernetes_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`aks-cluster`](#rule-aks-cluster) |
| `azurerm_kubernetes_fleet_manager` | `resource` | [`kubernetes-fleet`](#azure-concept-kubernetes-fleet) | [`kubernetes-fleet`](#rule-kubernetes-fleet) |
| `azurerm_kusto_cluster` | `resource` | [`data-explorer-cluster`](#azure-concept-data-explorer-cluster) | [`data-explorer-cluster`](#rule-data-explorer-cluster) |
| `azurerm_kusto_eventgrid_data_connection` | `resource` | [`database-component`](#azure-concept-database-component) | [`data-explorer-event-grid-connection`](#rule-data-explorer-event-grid-connection) |
| `azurerm_kusto_eventhub_data_connection` | `resource` | [`database-component`](#azure-concept-database-component) | [`data-explorer-event-hubs-connection`](#rule-data-explorer-event-hubs-connection) |
| `azurerm_lb_backend_address_pool` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`load-balancer-backend-pool`](#rule-load-balancer-backend-pool) |
| `azurerm_lb_nat_rule` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`load-balancer-nat-rule`](#rule-load-balancer-nat-rule) |
| `azurerm_lb_outbound_rule` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`load-balancer-outbound-rule`](#rule-load-balancer-outbound-rule) |
| `azurerm_lb_probe` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`load-balancer-probe`](#rule-load-balancer-probe) |
| `azurerm_lb_rule` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`load-balancer-rule`](#rule-load-balancer-rule) |
| `azurerm_lb` | `resource` | [`load-balancer`](#azure-concept-load-balancer) | [`load-balancer`](#rule-load-balancer) |
| `azurerm_lighthouse_definition` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`lighthouse-definition`](#rule-lighthouse-definition) |
| `azurerm_linux_function_app` | `resource` | [`serverless-function`](#azure-concept-serverless-function) | [`linux-function-app`](#rule-linux-function-app) |
| `azurerm_linux_virtual_machine_scale_set` | `resource` | [`virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set) | [`linux-virtual-machine-scale-set`](#rule-linux-virtual-machine-scale-set) |
| `azurerm_linux_virtual_machine` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`linux-virtual-machine`](#rule-linux-virtual-machine) |
| `azurerm_linux_web_app` | `resource` | [`app-service`](#azure-concept-app-service) | [`linux-web-app`](#rule-linux-web-app) |
| `azurerm_load_test` | `resource` | [`load-test`](#azure-concept-load-test) | [`load-test`](#rule-load-test) |
| `azurerm_local_network_gateway` | `resource` | [`local-network-gateway`](#azure-concept-local-network-gateway) | [`local-network-gateway`](#rule-local-network-gateway) |
| `azurerm_log_analytics_cluster` | `resource` | [`log-analytics-workspace`](#azure-concept-log-analytics-workspace) | [`log-analytics-cluster`](#rule-log-analytics-cluster) |
| `azurerm_log_analytics_data_export_rule` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`log-analytics-data-export-rule`](#rule-log-analytics-data-export-rule) |
| `azurerm_log_analytics_saved_search` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`log-analytics-saved-search`](#rule-log-analytics-saved-search) |
| `azurerm_log_analytics_solution` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`log-analytics-solution`](#rule-log-analytics-solution) |
| `azurerm_log_analytics_workspace_table` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`log-analytics-workspace-table`](#rule-log-analytics-workspace-table) |
| `azurerm_log_analytics_workspace` | `resource` | [`log-analytics-workspace`](#azure-concept-log-analytics-workspace) | [`log-analytics-workspace`](#rule-log-analytics-workspace) |
| `azurerm_logic_app_action_http` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`logic-app-http-action`](#rule-logic-app-http-action) |
| `azurerm_logic_app_integration_account` | `resource` | [`integration-account`](#azure-concept-integration-account) | [`logic-app-integration-account`](#rule-logic-app-integration-account) |
| `azurerm_logic_app_standard` | `resource` | [`workflow`](#azure-concept-workflow) | [`logic-app-standard`](#rule-logic-app-standard) |
| `azurerm_logic_app_trigger_recurrence` | `resource` | [`api-management-detail`](#azure-concept-api-management-detail) | [`logic-app-recurrence-trigger`](#rule-logic-app-recurrence-trigger) |
| `azurerm_logic_app_workflow` | `resource` | [`workflow`](#azure-concept-workflow) | [`logic-app-workflow`](#rule-logic-app-workflow) |
| `azurerm_machine_learning_compute_cluster` | `resource` | [`machine-learning-compute`](#azure-concept-machine-learning-compute) | [`machine-learning-compute-cluster`](#rule-machine-learning-compute-cluster) |
| `azurerm_machine_learning_compute_instance` | `resource` | [`machine-learning-compute`](#azure-concept-machine-learning-compute) | [`machine-learning-compute-instance`](#rule-machine-learning-compute-instance) |
| `azurerm_machine_learning_inference_cluster` | `resource` | [`ai-inference-endpoint`](#azure-concept-ai-inference-endpoint) | [`machine-learning-inference-cluster`](#rule-machine-learning-inference-cluster) |
| `azurerm_machine_learning_workspace` | `resource` | [`machine-learning-workspace`](#azure-concept-machine-learning-workspace) | [`machine-learning-workspace`](#rule-machine-learning-workspace) |
| `azurerm_maintenance_configuration` | `resource` | [`maintenance-configuration`](#azure-concept-maintenance-configuration) | [`maintenance-configuration`](#rule-maintenance-configuration) |
| `azurerm_managed_application` | `resource` | [`managed-application`](#azure-concept-managed-application) | [`managed-application`](#rule-managed-application) |
| `azurerm_managed_devops_pool` | `resource` | [`developer-environment`](#azure-concept-developer-environment) | [`managed-devops-pool`](#rule-managed-devops-pool) |
| `azurerm_managed_disk` | `resource` | [`block-storage-volume`](#azure-concept-block-storage-volume) | [`managed-disk`](#rule-managed-disk) |
| `azurerm_managed_lustre_file_system` | `resource` | [`managed-file-storage`](#azure-concept-managed-file-storage) | [`managed-lustre-file-system`](#rule-managed-lustre-file-system) |
| `azurerm_managed_redis_geo_replication` | `resource` | [`database-component`](#azure-concept-database-component) | [`managed-redis-geo-replication`](#rule-managed-redis-geo-replication) |
| `azurerm_managed_redis` | `resource` | [`managed-cache`](#azure-concept-managed-cache) | [`azure-managed-redis`](#rule-azure-managed-redis) |
| `azurerm_maps_account` | `resource` | [`maps-account`](#azure-concept-maps-account) | [`maps-account`](#rule-maps-account) |
| `azurerm_mongo_cluster` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`mongo-cluster`](#rule-mongo-cluster) |
| `azurerm_monitor_action_group` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`monitor-action-group`](#rule-monitor-action-group) |
| `azurerm_monitor_data_collection_endpoint` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`monitor-data-collection-endpoint`](#rule-monitor-data-collection-endpoint) |
| `azurerm_monitor_diagnostic_setting` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`monitor-diagnostic-setting`](#rule-monitor-diagnostic-setting) |
| `azurerm_monitor_metric_alert` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`monitor-metric-alert`](#rule-monitor-metric-alert) |
| `azurerm_monitor_private_link_scope` | `resource` | [`private-link-scope`](#azure-concept-private-link-scope) | [`monitor-private-link-scope`](#rule-monitor-private-link-scope) |
| `azurerm_monitor_scheduled_query_rules_alert_v2` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`monitor-scheduled-query-alert`](#rule-monitor-scheduled-query-alert) |
| `azurerm_monitor_workspace` | `resource` | [`monitor-workspace`](#azure-concept-monitor-workspace) | [`monitor-workspace`](#rule-monitor-workspace) |
| `azurerm_mssql_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`mssql-database`](#rule-mssql-database) |
| `azurerm_mssql_elasticpool` | `resource` | [`database-component`](#azure-concept-database-component) | [`sql-elastic-pool`](#rule-sql-elastic-pool) |
| `azurerm_mssql_failover_group` | `resource` | [`database-component`](#azure-concept-database-component) | [`sql-failover-group`](#rule-sql-failover-group) |
| `azurerm_mssql_managed_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`sql-managed-database`](#rule-sql-managed-database) |
| `azurerm_mssql_managed_instance` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`sql-managed-instance`](#rule-sql-managed-instance) |
| `azurerm_mssql_server` | `resource` | [`sql-server`](#azure-concept-sql-server) | [`mssql-server`](#rule-mssql-server) |
| `azurerm_mysql_flexible_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`mysql-database`](#rule-mysql-database) |
| `azurerm_mysql_flexible_server` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`mysql-flexible-server`](#rule-mysql-flexible-server) |
| `azurerm_nat_gateway_public_ip_association` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`nat-gateway-public-ip-association`](#rule-nat-gateway-public-ip-association) |
| `azurerm_nat_gateway_public_ip_prefix_association` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`nat-gateway-public-ip-prefix-association`](#rule-nat-gateway-public-ip-prefix-association) |
| `azurerm_nat_gateway` | `resource` | [`managed-nat`](#azure-concept-managed-nat) | [`nat-gateway`](#rule-nat-gateway) |
| `azurerm_netapp_account` | `resource` | [`netapp-account`](#azure-concept-netapp-account) | [`netapp-account`](#rule-netapp-account) |
| `azurerm_netapp_backup_policy` | `resource` | [`backup-plan`](#azure-concept-backup-plan) | [`netapp-backup-policy`](#rule-netapp-backup-policy) |
| `azurerm_netapp_backup_vault` | `resource` | [`backup-vault`](#azure-concept-backup-vault) | [`netapp-backup-vault`](#rule-netapp-backup-vault) |
| `azurerm_netapp_pool` | `resource` | [`netapp-capacity-pool`](#azure-concept-netapp-capacity-pool) | [`netapp-capacity-pool`](#rule-netapp-capacity-pool) |
| `azurerm_netapp_volume` | `resource` | [`managed-file-storage`](#azure-concept-managed-file-storage) | [`netapp-volume`](#rule-netapp-volume) |
| `azurerm_network_ddos_protection_plan` | `resource` | [`ddos-protection-plan`](#azure-concept-ddos-protection-plan) | [`ddos-protection-plan`](#rule-ddos-protection-plan) |
| `azurerm_network_function_azure_traffic_collector` | `resource` | [`network-function-service`](#azure-concept-network-function-service) | [`network-function-traffic-collector`](#rule-network-function-traffic-collector) |
| `azurerm_network_manager_ipam_pool` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`network-manager-ipam-pool`](#rule-network-manager-ipam-pool) |
| `azurerm_network_manager` | `resource` | [`virtual-network-manager`](#azure-concept-virtual-network-manager) | [`virtual-network-manager`](#rule-virtual-network-manager) |
| `azurerm_network_security_group` | `resource` | [`network-security-group`](#azure-concept-network-security-group) | [`network-security-group`](#rule-network-security-group) |
| `azurerm_network_security_perimeter` | `resource` | [`network-security-perimeter`](#azure-concept-network-security-perimeter) | [`network-security-perimeter`](#rule-network-security-perimeter) |
| `azurerm_network_security_rule` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`network-security-rule`](#rule-network-security-rule) |
| `azurerm_network_watcher_flow_log` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`network-watcher-flow-log`](#rule-network-watcher-flow-log) |
| `azurerm_network_watcher` | `resource` | [`network-watcher`](#azure-concept-network-watcher) | [`network-watcher`](#rule-network-watcher) |
| `azurerm_new_relic_monitor` | `resource` | [`third-party-monitor`](#azure-concept-third-party-monitor) | [`new-relic-monitor`](#rule-new-relic-monitor) |
| `azurerm_nginx_deployment` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`nginx-deployment`](#rule-nginx-deployment) |
| `azurerm_notification_hub_namespace` | `resource` | [`notification-namespace`](#azure-concept-notification-namespace) | [`notification-hubs-namespace`](#rule-notification-hubs-namespace) |
| `azurerm_notification_hub` | `resource` | [`notification-hub`](#azure-concept-notification-hub) | [`notification-hub`](#rule-notification-hub) |
| `azurerm_oracle_autonomous_database` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`oracle-autonomous-database`](#rule-oracle-autonomous-database) |
| `azurerm_oracle_cloud_vm_cluster` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`oracle-cloud-vm-cluster`](#rule-oracle-cloud-vm-cluster) |
| `azurerm_oracle_exadata_infrastructure` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`oracle-exadata-infrastructure`](#rule-oracle-exadata-infrastructure) |
| `azurerm_oracle_resource_anchor` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`oracle-resource-anchor`](#rule-oracle-resource-anchor) |
| `azurerm_orchestrated_virtual_machine_scale_set` | `resource` | [`virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set) | [`orchestrated-virtual-machine-scale-set`](#rule-orchestrated-virtual-machine-scale-set) |
| `azurerm_palo_alto_next_generation_firewall_virtual_network_local_rulestack` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`palo-alto-firewall`](#rule-palo-alto-firewall) |
| `azurerm_playwright_workspace` | `resource` | [`developer-environment`](#azure-concept-developer-environment) | [`playwright-workspace`](#rule-playwright-workspace) |
| `azurerm_point_to_site_vpn_gateway` | `resource` | [`vpn-gateway`](#azure-concept-vpn-gateway) | [`point-to-site-vpn-gateway`](#rule-point-to-site-vpn-gateway) |
| `azurerm_policy_definition` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`policy-definition`](#rule-policy-definition) |
| `azurerm_policy_set_definition` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`policy-set-definition`](#rule-policy-set-definition) |
| `azurerm_portal_dashboard` | `resource` | [`operations-detail`](#azure-concept-operations-detail) | [`portal-dashboard`](#rule-portal-dashboard) |
| `azurerm_postgresql_flexible_server_backup` | `resource` | [`database-component`](#azure-concept-database-component) | [`postgresql-backup`](#rule-postgresql-backup) |
| `azurerm_postgresql_flexible_server_database` | `resource` | [`logical-database`](#azure-concept-logical-database) | [`postgresql-database`](#rule-postgresql-database) |
| `azurerm_postgresql_flexible_server` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`postgresql-flexible-server`](#rule-postgresql-flexible-server) |
| `azurerm_powerbi_embedded` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`power-bi-embedded-capacity`](#rule-power-bi-embedded-capacity) |
| `azurerm_private_dns_a_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`private-dns-a-record`](#rule-private-dns-a-record) |
| `azurerm_private_dns_cname_record` | `resource` | [`dns-record`](#azure-concept-dns-record) | [`private-dns-cname-record`](#rule-private-dns-cname-record) |
| `azurerm_private_dns_resolver_dns_forwarding_ruleset` | `resource` | [`private-network-link`](#azure-concept-private-network-link) | [`private-dns-forwarding-ruleset`](#rule-private-dns-forwarding-ruleset) |
| `azurerm_private_dns_resolver_inbound_endpoint` | `resource` | [`private-network-link`](#azure-concept-private-network-link) | [`private-dns-inbound-endpoint`](#rule-private-dns-inbound-endpoint) |
| `azurerm_private_dns_resolver_outbound_endpoint` | `resource` | [`private-network-link`](#azure-concept-private-network-link) | [`private-dns-outbound-endpoint`](#rule-private-dns-outbound-endpoint) |
| `azurerm_private_dns_resolver` | `resource` | [`private-dns-resolver`](#azure-concept-private-dns-resolver) | [`private-dns-resolver`](#rule-private-dns-resolver) |
| `azurerm_private_dns_zone_virtual_network_link` | `resource` | [`private-network-link`](#azure-concept-private-network-link) | [`private-dns-zone-vnet-link`](#rule-private-dns-zone-vnet-link) |
| `azurerm_private_dns_zone` | `resource` | [`dns-zone`](#azure-concept-dns-zone) | [`private-dns-zone`](#rule-private-dns-zone) |
| `azurerm_private_endpoint` | `resource` | [`private-endpoint`](#azure-concept-private-endpoint) | [`private-endpoint`](#rule-private-endpoint) |
| `azurerm_private_link_service` | `resource` | [`private-link-service`](#azure-concept-private-link-service) | [`private-link-service`](#rule-private-link-service) |
| `azurerm_proximity_placement_group` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`proximity-placement-group`](#rule-proximity-placement-group) |
| `azurerm_public_ip_prefix` | `resource` | [`public-address`](#azure-concept-public-address) | [`public-ip-prefix`](#rule-public-ip-prefix) |
| `azurerm_public_ip` | `resource` | [`public-address`](#azure-concept-public-address) | [`public-address`](#rule-public-address) |
| `azurerm_purview_account` | `resource` | [`purview-account`](#azure-concept-purview-account) | [`purview-account`](#rule-purview-account) |
| `azurerm_qumulo_file_system` | `resource` | [`managed-file-storage`](#azure-concept-managed-file-storage) | [`qumulo-file-system`](#rule-qumulo-file-system) |
| `azurerm_recovery_services_vault` | `resource` | [`backup-vault`](#azure-concept-backup-vault) | [`recovery-services-vault`](#rule-recovery-services-vault) |
| `azurerm_redhat_openshift_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`red-hat-openshift-cluster`](#rule-red-hat-openshift-cluster) |
| `azurerm_redis_cache` | `resource` | [`managed-cache`](#azure-concept-managed-cache) | [`azure-cache-for-redis`](#rule-azure-cache-for-redis) |
| `azurerm_relay_hybrid_connection` | `resource` | [`relay-connection`](#azure-concept-relay-connection) | [`relay-hybrid-connection`](#rule-relay-hybrid-connection) |
| `azurerm_relay_namespace` | `resource` | [`relay-namespace`](#azure-concept-relay-namespace) | [`relay-namespace`](#rule-relay-namespace) |
| `azurerm_resource_group` | `resource` | [`resource-group`](#azure-concept-resource-group) | [`resource-group`](#rule-resource-group) |
| `azurerm_resource_policy_assignment` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`resource-policy-assignment`](#rule-resource-policy-assignment) |
| `azurerm_role_assignment` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`role-assignment`](#rule-role-assignment) |
| `azurerm_role_definition` | `resource` | [`governance-detail`](#azure-concept-governance-detail) | [`role-definition`](#rule-role-definition) |
| `azurerm_route_server` | `resource` | [`route-table`](#azure-concept-route-table) | [`route-server`](#rule-route-server) |
| `azurerm_route_table` | `resource` | [`route-table`](#azure-concept-route-table) | [`route-table`](#rule-route-table) |
| `azurerm_route` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`route`](#rule-route) |
| `azurerm_search_service` | `resource` | [`ai-search-service`](#azure-concept-ai-search-service) | [`ai-search-service`](#rule-ai-search-service) |
| `azurerm_security_center_subscription_pricing` | `resource` | [`defender-plan`](#azure-concept-defender-plan) | [`defender-subscription-plan`](#rule-defender-subscription-plan) |
| `azurerm_security_center_workspace` | `resource` | [`defender-plan`](#azure-concept-defender-plan) | [`defender-workspace`](#rule-defender-workspace) |
| `azurerm_sentinel_alert_rule_nrt` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`sentinel-nrt-alert-rule`](#rule-sentinel-nrt-alert-rule) |
| `azurerm_sentinel_alert_rule_scheduled` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`sentinel-scheduled-alert-rule`](#rule-sentinel-scheduled-alert-rule) |
| `azurerm_sentinel_automation_rule` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`sentinel-automation-rule`](#rule-sentinel-automation-rule) |
| `azurerm_sentinel_data_connector_aws_cloud_trail` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`sentinel-aws-cloudtrail-connector`](#rule-sentinel-aws-cloudtrail-connector) |
| `azurerm_sentinel_data_connector_azure_active_directory` | `resource` | [`security-detail`](#azure-concept-security-detail) | [`sentinel-entra-connector`](#rule-sentinel-entra-connector) |
| `azurerm_service_fabric_cluster` | `resource` | [`service-fabric-cluster`](#azure-concept-service-fabric-cluster) | [`service-fabric-cluster`](#rule-service-fabric-cluster) |
| `azurerm_service_fabric_managed_cluster` | `resource` | [`service-fabric-cluster`](#azure-concept-service-fabric-cluster) | [`managed-service-fabric-cluster`](#rule-managed-service-fabric-cluster) |
| `azurerm_service_plan` | `resource` | [`app-service-plan`](#azure-concept-app-service-plan) | [`app-service-plan`](#rule-app-service-plan) |
| `azurerm_servicebus_namespace` | `resource` | [`messaging-namespace`](#azure-concept-messaging-namespace) | [`service-bus-namespace`](#rule-service-bus-namespace) |
| `azurerm_servicebus_queue` | `resource` | [`message-queue`](#azure-concept-message-queue) | [`service-bus-queue`](#rule-service-bus-queue) |
| `azurerm_servicebus_subscription_rule` | `resource` | [`messaging-detail`](#azure-concept-messaging-detail) | [`service-bus-subscription-rule`](#rule-service-bus-subscription-rule) |
| `azurerm_servicebus_subscription` | `resource` | [`message-subscription`](#azure-concept-message-subscription) | [`service-bus-subscription`](#rule-service-bus-subscription) |
| `azurerm_servicebus_topic` | `resource` | [`service-bus-topic`](#azure-concept-service-bus-topic) | [`service-bus-topic`](#rule-service-bus-topic) |
| `azurerm_shared_image_gallery` | `resource` | [`image-gallery`](#azure-concept-image-gallery) | [`compute-gallery`](#rule-compute-gallery) |
| `azurerm_shared_image` | `resource` | [`compute-image`](#azure-concept-compute-image) | [`shared-image`](#rule-shared-image) |
| `azurerm_signalr_service` | `resource` | [`realtime-communication-service`](#azure-concept-realtime-communication-service) | [`signalr-service`](#rule-signalr-service) |
| `azurerm_site_recovery_fabric` | `resource` | [`site-recovery-fabric`](#azure-concept-site-recovery-fabric) | [`site-recovery-fabric`](#rule-site-recovery-fabric) |
| `azurerm_site_recovery_protection_container` | `resource` | [`site-recovery-fabric`](#azure-concept-site-recovery-fabric) | [`site-recovery-protection-container`](#rule-site-recovery-protection-container) |
| `azurerm_site_recovery_replicated_vm` | `resource` | [`site-recovery-detail`](#azure-concept-site-recovery-detail) | [`site-recovery-replicated-vm`](#rule-site-recovery-replicated-vm) |
| `azurerm_site_recovery_replication_recovery_plan` | `resource` | [`site-recovery-detail`](#azure-concept-site-recovery-detail) | [`site-recovery-plan`](#rule-site-recovery-plan) |
| `azurerm_snapshot` | `resource` | [`disk-snapshot`](#azure-concept-disk-snapshot) | [`disk-snapshot`](#rule-disk-snapshot) |
| `azurerm_spring_cloud_app` | `resource` | [`spring-app`](#azure-concept-spring-app) | [`spring-app`](#rule-spring-app) |
| `azurerm_spring_cloud_gateway` | `resource` | [`spring-app`](#azure-concept-spring-app) | [`spring-apps-gateway`](#rule-spring-apps-gateway) |
| `azurerm_spring_cloud_service` | `resource` | [`spring-apps-service`](#azure-concept-spring-apps-service) | [`spring-apps-service`](#rule-spring-apps-service) |
| `azurerm_stack_hci_cluster` | `resource` | [`azure-local-cluster`](#azure-concept-azure-local-cluster) | [`azure-local-cluster`](#rule-azure-local-cluster) |
| `azurerm_stack_hci_virtual_hard_disk` | `resource` | [`block-storage-volume`](#azure-concept-block-storage-volume) | [`stack-hci-virtual-hard-disk`](#rule-stack-hci-virtual-hard-disk) |
| `azurerm_static_web_app` | `resource` | [`static-web-app`](#azure-concept-static-web-app) | [`static-web-app`](#rule-static-web-app) |
| `azurerm_storage_account` | `resource` | [`storage-account`](#azure-concept-storage-account) | [`storage-account`](#rule-storage-account) |
| `azurerm_storage_blob` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-blob`](#rule-storage-blob) |
| `azurerm_storage_container` | `resource` | [`object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) | [`blob-container`](#rule-blob-container) |
| `azurerm_storage_data_lake_gen2_filesystem` | `resource` | [`object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) | [`data-lake-filesystem`](#rule-data-lake-filesystem) |
| `azurerm_storage_data_lake_gen2_path` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`data-lake-path`](#rule-data-lake-path) |
| `azurerm_storage_encryption_scope` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-encryption-scope`](#rule-storage-encryption-scope) |
| `azurerm_storage_management_policy` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-management-policy`](#rule-storage-management-policy) |
| `azurerm_storage_mover` | `resource` | [`migration-service`](#azure-concept-migration-service) | [`storage-mover`](#rule-storage-mover) |
| `azurerm_storage_queue` | `resource` | [`message-queue`](#azure-concept-message-queue) | [`queue-storage-queue`](#rule-queue-storage-queue) |
| `azurerm_storage_share_directory` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-share-directory`](#rule-storage-share-directory) |
| `azurerm_storage_share_file` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-share-file`](#rule-storage-share-file) |
| `azurerm_storage_share` | `resource` | [`managed-file-storage`](#azure-concept-managed-file-storage) | [`azure-files-share`](#rule-azure-files-share) |
| `azurerm_storage_sync` | `resource` | [`storage-sync-service`](#azure-concept-storage-sync-service) | [`storage-sync-service`](#rule-storage-sync-service) |
| `azurerm_storage_table_entity` | `resource` | [`storage-object-detail`](#azure-concept-storage-object-detail) | [`storage-table-entity`](#rule-storage-table-entity) |
| `azurerm_storage_table` | `resource` | [`table-storage-table`](#azure-concept-table-storage-table) | [`table-storage-table`](#rule-table-storage-table) |
| `azurerm_stream_analytics_cluster` | `resource` | [`analytics-cluster`](#azure-concept-analytics-cluster) | [`stream-analytics-cluster`](#rule-stream-analytics-cluster) |
| `azurerm_stream_analytics_job` | `resource` | [`stream-analytics-job`](#azure-concept-stream-analytics-job) | [`stream-analytics-job`](#rule-stream-analytics-job) |
| `azurerm_stream_analytics_output_blob` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`stream-analytics-blob-output`](#rule-stream-analytics-blob-output) |
| `azurerm_stream_analytics_stream_input_eventhub_v2` | `resource` | [`data-integration-detail`](#azure-concept-data-integration-detail) | [`stream-analytics-event-hubs-input`](#rule-stream-analytics-event-hubs-input) |
| `azurerm_subnet_nat_gateway_association` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`subnet-nat-gateway-association`](#rule-subnet-nat-gateway-association) |
| `azurerm_subnet_network_security_group_association` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`subnet-network-security-group-association`](#rule-subnet-network-security-group-association) |
| `azurerm_subnet_route_table_association` | `resource` | [`network-policy-detail`](#azure-concept-network-policy-detail) | [`subnet-route-table-association`](#rule-subnet-route-table-association) |
| `azurerm_subnet` | `resource` | [`subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) | [`subnet`](#rule-subnet) |
| `azurerm_synapse_private_link_hub` | `resource` | [`private-link-scope`](#azure-concept-private-link-scope) | [`synapse-private-link-hub`](#rule-synapse-private-link-hub) |
| `azurerm_synapse_spark_pool` | `resource` | [`analytics-pool`](#azure-concept-analytics-pool) | [`synapse-spark-pool`](#rule-synapse-spark-pool) |
| `azurerm_synapse_sql_pool` | `resource` | [`analytics-pool`](#azure-concept-analytics-pool) | [`synapse-sql-pool`](#rule-synapse-sql-pool) |
| `azurerm_synapse_workspace` | `resource` | [`synapse-workspace`](#azure-concept-synapse-workspace) | [`synapse-workspace`](#rule-synapse-workspace) |
| `azurerm_system_center_virtual_machine_manager_server` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`system-center-vmm-server`](#rule-system-center-vmm-server) |
| `azurerm_system_center_virtual_machine_manager_virtual_machine_instance` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`system-center-virtual-machine`](#rule-system-center-virtual-machine) |
| `azurerm_traffic_manager_azure_endpoint` | `resource` | [`load-balancer-component`](#azure-concept-load-balancer-component) | [`traffic-manager-azure-endpoint`](#rule-traffic-manager-azure-endpoint) |
| `azurerm_traffic_manager_profile` | `resource` | [`traffic-manager-profile`](#azure-concept-traffic-manager-profile) | [`traffic-manager-profile`](#rule-traffic-manager-profile) |
| `azurerm_trusted_signing_account` | `resource` | [`trusted-signing-account`](#azure-concept-trusted-signing-account) | [`trusted-signing-account`](#rule-trusted-signing-account) |
| `azurerm_user_assigned_identity` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`user-assigned-managed-identity`](#rule-user-assigned-managed-identity) |
| `azurerm_video_indexer_account` | `resource` | [`video-indexer-account`](#azure-concept-video-indexer-account) | [`video-indexer-account`](#rule-video-indexer-account) |
| `azurerm_virtual_desktop_application_group` | `resource` | [`virtual-desktop-application-group`](#azure-concept-virtual-desktop-application-group) | [`virtual-desktop-application-group`](#rule-virtual-desktop-application-group) |
| `azurerm_virtual_desktop_application` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`virtual-desktop-application`](#rule-virtual-desktop-application) |
| `azurerm_virtual_desktop_host_pool` | `resource` | [`virtual-desktop-host-pool`](#azure-concept-virtual-desktop-host-pool) | [`virtual-desktop-host-pool`](#rule-virtual-desktop-host-pool) |
| `azurerm_virtual_desktop_scaling_plan` | `resource` | [`compute-placement`](#azure-concept-compute-placement) | [`virtual-desktop-scaling-plan`](#rule-virtual-desktop-scaling-plan) |
| `azurerm_virtual_desktop_workspace` | `resource` | [`virtual-desktop-workspace`](#azure-concept-virtual-desktop-workspace) | [`virtual-desktop-workspace`](#rule-virtual-desktop-workspace) |
| `azurerm_virtual_hub` | `resource` | [`virtual-hub`](#azure-concept-virtual-hub) | [`virtual-hub`](#rule-virtual-hub) |
| `azurerm_virtual_machine_restore_point` | `resource` | [`disk-snapshot`](#azure-concept-disk-snapshot) | [`virtual-machine-restore-point`](#rule-virtual-machine-restore-point) |
| `azurerm_virtual_machine_scale_set` | `resource` | [`virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set) | [`virtual-machine-scale-set`](#rule-virtual-machine-scale-set) |
| `azurerm_virtual_machine` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`virtual-machine`](#rule-virtual-machine) |
| `azurerm_virtual_network_gateway_connection` | `resource` | [`vpn-connection`](#azure-concept-vpn-connection) | [`virtual-network-gateway-connection`](#rule-virtual-network-gateway-connection) |
| `azurerm_virtual_network_gateway` | `resource` | [`vpn-gateway`](#azure-concept-vpn-gateway) | [`virtual-network-gateway`](#rule-virtual-network-gateway) |
| `azurerm_virtual_network_peering` | `resource` | [`network-peering`](#azure-concept-network-peering) | [`virtual-network-peering`](#rule-virtual-network-peering) |
| `azurerm_virtual_network` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`virtual-network`](#rule-virtual-network) |
| `azurerm_virtual_wan` | `resource` | [`virtual-wan`](#azure-concept-virtual-wan) | [`virtual-wan`](#rule-virtual-wan) |
| `azurerm_vmware_cluster` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`vmware-cluster`](#rule-vmware-cluster) |
| `azurerm_vmware_private_cloud` | `resource` | [`vmware-private-cloud`](#azure-concept-vmware-private-cloud) | [`vmware-private-cloud`](#rule-vmware-private-cloud) |
| `azurerm_vpn_gateway_connection` | `resource` | [`vpn-connection`](#azure-concept-vpn-connection) | [`vpn-gateway-connection`](#rule-vpn-gateway-connection) |
| `azurerm_vpn_gateway` | `resource` | [`vpn-gateway`](#azure-concept-vpn-gateway) | [`vpn-gateway`](#rule-vpn-gateway) |
| `azurerm_vpn_site` | `resource` | [`local-network-gateway`](#azure-concept-local-network-gateway) | [`vpn-site`](#rule-vpn-site) |
| `azurerm_web_application_firewall_policy` | `resource` | [`web-application-firewall-policy`](#azure-concept-web-application-firewall-policy) | [`web-application-firewall-policy`](#rule-web-application-firewall-policy) |
| `azurerm_web_pubsub` | `resource` | [`realtime-communication-service`](#azure-concept-realtime-communication-service) | [`web-pubsub`](#rule-web-pubsub) |
| `azurerm_windows_function_app` | `resource` | [`serverless-function`](#azure-concept-serverless-function) | [`windows-function-app`](#rule-windows-function-app) |
| `azurerm_windows_virtual_machine_scale_set` | `resource` | [`virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set) | [`windows-virtual-machine-scale-set`](#rule-windows-virtual-machine-scale-set) |
| `azurerm_windows_virtual_machine` | `resource` | [`compute-instance`](#azure-concept-compute-instance) | [`windows-virtual-machine`](#rule-windows-virtual-machine) |
| `azurerm_windows_web_app` | `resource` | [`app-service`](#azure-concept-app-service) | [`windows-web-app`](#rule-windows-web-app) |
| `azurerm_workloads_sap_discovery_virtual_instance` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`sap-discovery-virtual-instance`](#rule-sap-discovery-virtual-instance) |
| `azurerm_workloads_sap_single_node_virtual_instance` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`sap-single-node-virtual-instance`](#rule-sap-single-node-virtual-instance) |
| `azurerm_workloads_sap_three_tier_virtual_instance` | `resource` | [`hybrid-platform`](#azure-concept-hybrid-platform) | [`sap-three-tier-virtual-instance`](#rule-sap-three-tier-virtual-instance) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="azure-concept-ai-foundry"><code>azure.concept.ai-foundry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Foundry account or project boundary.

</dd>
<dd>

Used by [`ai-foundry`](#rule-ai-foundry), [`ai-foundry-project`](#rule-ai-foundry-project), [`ai-services-project`](#rule-ai-services-project).

</dd>
</div>

<div>
<dt id="azure-concept-ai-inference-endpoint"><code>azure.concept.ai-inference-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed endpoint that serves model inference requests.

</dd>
<dd>

Used by [`ai-model-deployment`](#rule-ai-model-deployment), [`machine-learning-inference-cluster`](#rule-machine-learning-inference-cluster).

</dd>
</div>

<div>
<dt id="azure-concept-ai-search-service"><code>azure.concept.ai-search-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-search.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure AI Search service.

</dd>
<dd>

Used by [`ai-search-service`](#rule-ai-search-service).

</dd>
</div>

<div>
<dt id="azure-concept-ai-service-account"><code>azure.concept.ai-service-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-services.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure AI services account exposing managed AI APIs.

</dd>
<dd>

Used by [`ai-services-account`](#rule-ai-services-account).

</dd>
</div>

<div>
<dt id="azure-concept-analytics-cluster"><code>azure.concept.analytics-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A managed Azure analytics cluster or server.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`analysis-services-server`](#rule-analysis-services-server)
- [`fabric-capacity`](#rule-fabric-capacity)
- [`hdinsight-hadoop-cluster`](#rule-hdinsight-hadoop-cluster)
- [`hdinsight-hbase-cluster`](#rule-hdinsight-hbase-cluster)
- [`hdinsight-interactive-query-cluster`](#rule-hdinsight-interactive-query-cluster)
- [`hdinsight-kafka-cluster`](#rule-hdinsight-kafka-cluster)
- [`hdinsight-spark-cluster`](#rule-hdinsight-spark-cluster)
- [`power-bi-embedded-capacity`](#rule-power-bi-embedded-capacity)
- [`stream-analytics-cluster`](#rule-stream-analytics-cluster)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-analytics-pool"><code>azure.concept.analytics-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/synapse.rf.hcl#L2-L4">Source</a></dt>
<dd>

A SQL or Apache Spark analytics pool.

</dd>
<dd>

Used by [`synapse-spark-pool`](#rule-synapse-spark-pool), [`synapse-sql-pool`](#rule-synapse-sql-pool).

</dd>
</div>

<div>
<dt id="azure-concept-api-gateway"><code>azure.concept.api-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed gateway that exposes and governs APIs.

</dd>
<dd>

Used by [`api-management`](#rule-api-management), [`api-management-standalone-gateway`](#rule-api-management-standalone-gateway).

</dd>
</div>

<div>
<dt id="azure-concept-api-management-detail"><code>azure.concept.api-management-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An API, product, backend, policy, workspace, or gateway configuration inside API Management.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`api-management-api`](#rule-api-management-api)
- [`api-management-backend`](#rule-api-management-backend)
- [`api-management-gateway`](#rule-api-management-gateway)
- [`api-management-policy`](#rule-api-management-policy)
- [`api-management-product`](#rule-api-management-product)
- [`api-management-workspace`](#rule-api-management-workspace)
- [`logic-app-http-action`](#rule-logic-app-http-action)
- [`logic-app-recurrence-trigger`](#rule-logic-app-recurrence-trigger)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-app-configuration"><code>azure.concept.app-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/app-configuration.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure App Configuration store.

</dd>
<dd>

Used by [`app-configuration`](#rule-app-configuration).

</dd>
</div>

<div>
<dt id="azure-concept-app-service"><code>azure.concept.app-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure App Service web application runtime.

</dd>
<dd>

Used by [`linux-web-app`](#rule-linux-web-app), [`windows-web-app`](#rule-windows-web-app).

</dd>
</div>

<div>
<dt id="azure-concept-app-service-environment"><code>azure.concept.app-service-environment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L6-L8">Source</a></dt>
<dd>

An isolated Azure App Service hosting environment.

</dd>
<dd>

Used by [`app-service-environment`](#rule-app-service-environment).

</dd>
</div>

<div>
<dt id="azure-concept-app-service-plan"><code>azure.concept.app-service-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure App Service plan providing shared runtime capacity.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`app-service-plan`](#rule-app-service-plan)
- [`flex-consumption-function-app`](#rule-flex-consumption-function-app)
- [`linux-function-app`](#rule-linux-function-app)
- [`linux-web-app`](#rule-linux-web-app)
- [`windows-function-app`](#rule-windows-function-app)
- [`windows-web-app`](#rule-windows-web-app)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-application-insights"><code>azure.concept.application-insights</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Monitor Application Insights application resource.

</dd>
<dd>

Used by [`application-insights`](#rule-application-insights), [`linux-function-app`](#rule-linux-function-app), [`windows-function-app`](#rule-windows-function-app).

</dd>
</div>

<div>
<dt id="azure-concept-arc-enabled-server"><code>azure.concept.arc-enabled-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L2-L4">Source</a></dt>
<dd>

A server connected to Azure through Azure Arc.

</dd>
<dd>

Used by [`arc-enabled-server`](#rule-arc-enabled-server).

</dd>
</div>

<div>
<dt id="azure-concept-arc-resource-bridge"><code>azure.concept.arc-resource-bridge</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Arc resource bridge connecting an external platform.

</dd>
<dd>

Used by [`arc-resource-bridge`](#rule-arc-resource-bridge).

</dd>
</div>

<div>
<dt id="azure-concept-attestation-provider"><code>azure.concept.attestation-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/attestation-provider.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Azure Attestation provider.

</dd>
<dd>

Used by [`attestation-provider`](#rule-attestation-provider).

</dd>
</div>

<div>
<dt id="azure-concept-automation-account"><code>azure.concept.automation-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/automation-account.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Automation account owning runbooks and schedules.

</dd>
<dd>

Used by [`automation-account`](#rule-automation-account).

</dd>
</div>

<div>
<dt id="azure-concept-azure-enclave"><code>azure.concept.azure-enclave</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/azure-enclave.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Enclave isolated workload and connectivity boundary.

</dd>
<dd>

Used by [`azure-enclave`](#rule-azure-enclave).

</dd>
</div>

<div>
<dt id="azure-concept-azure-firewall"><code>azure.concept.azure-firewall</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Firewall managed network security service.

</dd>
<dd>

Used by [`azure-firewall`](#rule-azure-firewall).

</dd>
</div>

<div>
<dt id="azure-concept-azure-local-cluster"><code>azure.concept.azure-local-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/azure-local.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Local or Azure Stack HCI cluster.

</dd>
<dd>

Used by [`azure-local-cluster`](#rule-azure-local-cluster).

</dd>
</div>

<div>
<dt id="azure-concept-backup-plan"><code>azure.concept.backup-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L9-L11">Source</a></dt>
<dd>

A managed policy scheduling and retaining backups.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`data-protection-blob-backup-policy`](#rule-data-protection-blob-backup-policy)
- [`data-protection-disk-backup-policy`](#rule-data-protection-disk-backup-policy)
- [`file-share-backup-policy`](#rule-file-share-backup-policy)
- [`netapp-backup-policy`](#rule-netapp-backup-policy)
- [`virtual-machine-backup-policy`](#rule-virtual-machine-backup-policy)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-backup-vault"><code>azure.concept.backup-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L13-L15">Source</a></dt>
<dd>

A managed vault storing protected recovery data.

</dd>
<dd>

Used by [`data-protection-backup-vault`](#rule-data-protection-backup-vault), [`netapp-backup-vault`](#rule-netapp-backup-vault), [`recovery-services-vault`](#rule-recovery-services-vault).

</dd>
</div>

<div>
<dt id="azure-concept-bastion-host"><code>azure.concept.bastion-host</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/bastion.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Bastion service providing managed private administration access.

</dd>
<dd>

Used by [`bastion-host`](#rule-bastion-host).

</dd>
</div>

<div>
<dt id="azure-concept-batch-account"><code>azure.concept.batch-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/batch.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Batch account owning pools, jobs, and applications.

</dd>
<dd>

Used by [`batch-account`](#rule-batch-account).

</dd>
</div>

<div>
<dt id="azure-concept-batch-pool"><code>azure.concept.batch-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/batch.rf.hcl#L7-L9">Source</a></dt>
<dd>

A pool providing compute capacity to Azure Batch.

</dd>
<dd>

Used by [`batch-application`](#rule-batch-application), [`batch-pool`](#rule-batch-pool).

</dd>
</div>

<div>
<dt id="azure-concept-block-storage-volume"><code>azure.concept.block-storage-volume</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L17-L19">Source</a></dt>
<dd>

A durable block-storage volume attachable to compute workloads.

</dd>
<dd>

Used by [`elastic-san-volume`](#rule-elastic-san-volume), [`managed-disk`](#rule-managed-disk), [`stack-hci-virtual-hard-disk`](#rule-stack-hci-virtual-hard-disk).

</dd>
</div>

<div>
<dt id="azure-concept-bot-service"><code>azure.concept.bot-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/bot-services.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Bot Service bot registration or application.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`azure-bot`](#rule-azure-bot)
- [`bot-channels-registration`](#rule-bot-channels-registration)
- [`bot-web-app`](#rule-bot-web-app)
- [`health-bot`](#rule-health-bot)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-chaos-experiment"><code>azure.concept.chaos-experiment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/chaos-studio.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Chaos Studio experiment.

</dd>
<dd>

Used by [`chaos-studio-experiment`](#rule-chaos-studio-experiment).

</dd>
</div>

<div>
<dt id="azure-concept-communication-service"><code>azure.concept.communication-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/communication-services.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Communication Services resource.

</dd>
<dd>

Used by [`communication-service`](#rule-communication-service).

</dd>
</div>

<div>
<dt id="azure-concept-compute-image"><code>azure.concept.compute-image</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/compute-gallery.rf.hcl#L2-L4">Source</a></dt>
<dd>

A reusable Azure compute image or image definition.

</dd>
<dd>

Used by [`compute-image`](#rule-compute-image), [`shared-image`](#rule-shared-image).

</dd>
</div>

<div>
<dt id="azure-concept-compute-instance"><code>azure.concept.compute-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L21-L23">Source</a></dt>
<dd>

A provisioned compute instance running a workload.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`dev-test-linux-virtual-machine`](#rule-dev-test-linux-virtual-machine)
- [`dev-test-windows-virtual-machine`](#rule-dev-test-windows-virtual-machine)
- [`linux-virtual-machine`](#rule-linux-virtual-machine)
- [`system-center-virtual-machine`](#rule-system-center-virtual-machine)
- [`virtual-machine`](#rule-virtual-machine)
- [`windows-virtual-machine`](#rule-windows-virtual-machine)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-compute-placement"><code>azure.concept.compute-placement</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

Availability, proximity, reservation, or host placement supporting Azure compute.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`availability-set`](#rule-availability-set)
- [`capacity-reservation`](#rule-capacity-reservation)
- [`capacity-reservation-group`](#rule-capacity-reservation-group)
- [`proximity-placement-group`](#rule-proximity-placement-group)
- [`virtual-desktop-application`](#rule-virtual-desktop-application)
- [`virtual-desktop-scaling-plan`](#rule-virtual-desktop-scaling-plan)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-confidential-ledger"><code>azure.concept.confidential-ledger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/confidential-ledger.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure confidential ledger providing tamper-evident storage.

</dd>
<dd>

Used by [`confidential-ledger`](#rule-confidential-ledger).

</dd>
</div>

<div>
<dt id="azure-concept-container-app"><code>azure.concept.container-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Container Apps service running container revisions.

</dd>
<dd>

Used by [`container-app`](#rule-container-app).

</dd>
</div>

<div>
<dt id="azure-concept-container-app-environment"><code>azure.concept.container-app-environment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Container Apps environment sharing network and operational boundaries.

</dd>
<dd>

Used by [`container-app`](#rule-container-app), [`container-app-environment`](#rule-container-app-environment), [`container-app-job`](#rule-container-app-job).

</dd>
</div>

<div>
<dt id="azure-concept-container-app-job"><code>azure.concept.container-app-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Container Apps job running finite container work.

</dd>
<dd>

Used by [`container-app-job`](#rule-container-app-job).

</dd>
</div>

<div>
<dt id="azure-concept-container-instance-group"><code>azure.concept.container-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-instances.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Container Instances container group scheduled as one unit.

</dd>
<dd>

Used by [`container-instance-group`](#rule-container-instance-group).

</dd>
</div>

<div>
<dt id="azure-concept-container-registry"><code>azure.concept.container-registry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-registry.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Container Registry storing and distributing OCI artifacts.

</dd>
<dd>

Used by [`connected-container-registry`](#rule-connected-container-registry), [`container-registry`](#rule-container-registry).

</dd>
</div>

<div>
<dt id="azure-concept-content-delivery-profile"><code>azure.concept.content-delivery-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/cdn.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure content delivery profile serving cached content globally.

</dd>
<dd>

Used by [`cdn-endpoint`](#rule-cdn-endpoint), [`cdn-profile`](#rule-cdn-profile).

</dd>
</div>

<div>
<dt id="azure-concept-cosmos-account"><code>azure.concept.cosmos-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Cosmos DB account defining global distribution and API boundaries.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`cosmos-account`](#rule-cosmos-account)
- [`cosmos-cassandra-keyspace`](#rule-cosmos-cassandra-keyspace)
- [`cosmos-dedicated-gateway`](#rule-cosmos-dedicated-gateway)
- [`cosmos-gremlin-database`](#rule-cosmos-gremlin-database)
- [`cosmos-mongo-database`](#rule-cosmos-mongo-database)
- [`cosmos-sql-database`](#rule-cosmos-sql-database)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-custom-location"><code>azure.concept.custom-location</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Arc custom location extending Azure resource placement.

</dd>
<dd>

Used by [`arc-custom-location`](#rule-arc-custom-location).

</dd>
</div>

<div>
<dt id="azure-concept-data-explorer-cluster"><code>azure.concept.data-explorer-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/data-explorer.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Data Explorer cluster serving real-time analytics.

</dd>
<dd>

Used by [`data-explorer-cluster`](#rule-data-explorer-cluster).

</dd>
</div>

<div>
<dt id="azure-concept-data-factory"><code>azure.concept.data-factory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Data Factory integration and orchestration boundary.

</dd>
<dd>

Used by [`data-factory`](#rule-data-factory).

</dd>
</div>

<div>
<dt id="azure-concept-data-integration-detail"><code>azure.concept.data-integration-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L6-L8">Source</a></dt>
<dd>

A dataset, linked service, trigger, connection, or data-flow supporting integration.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`data-factory-blob-dataset`](#rule-data-factory-blob-dataset)
- [`data-factory-blob-linked-service`](#rule-data-factory-blob-linked-service)
- [`data-factory-data-flow`](#rule-data-factory-data-flow)
- [`data-factory-managed-private-endpoint`](#rule-data-factory-managed-private-endpoint)
- [`data-factory-schedule-trigger`](#rule-data-factory-schedule-trigger)
- [`data-factory-sql-dataset`](#rule-data-factory-sql-dataset)
- [`data-factory-sql-linked-service`](#rule-data-factory-sql-linked-service)
- [`stream-analytics-blob-output`](#rule-stream-analytics-blob-output)
- [`stream-analytics-event-hubs-input`](#rule-stream-analytics-event-hubs-input)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-data-integration-runtime"><code>azure.concept.data-integration-runtime</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L10-L12">Source</a></dt>
<dd>

A managed or self-hosted Azure data integration runtime.

</dd>
<dd>

Used by [`data-factory-azure-integration-runtime`](#rule-data-factory-azure-integration-runtime), [`data-factory-self-hosted-integration-runtime`](#rule-data-factory-self-hosted-integration-runtime).

</dd>
</div>

<div>
<dt id="azure-concept-data-share-account"><code>azure.concept.data-share-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-share.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Data Share account.

</dd>
<dd>

Used by [`data-share-account`](#rule-data-share-account).

</dd>
</div>

<div>
<dt id="azure-concept-database-component"><code>azure.concept.database-component</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A table, container, graph, configuration, replica, or policy supporting an Azure database.

</dd>
<dd>


<details>
<summary>Used by 11 Rules</summary>

- [`cosmos-cassandra-table`](#rule-cosmos-cassandra-table)
- [`cosmos-dedicated-gateway`](#rule-cosmos-dedicated-gateway)
- [`cosmos-gremlin-graph`](#rule-cosmos-gremlin-graph)
- [`cosmos-mongo-collection`](#rule-cosmos-mongo-collection)
- [`cosmos-sql-container`](#rule-cosmos-sql-container)
- [`data-explorer-event-grid-connection`](#rule-data-explorer-event-grid-connection)
- [`data-explorer-event-hubs-connection`](#rule-data-explorer-event-hubs-connection)
- [`managed-redis-geo-replication`](#rule-managed-redis-geo-replication)
- [`postgresql-backup`](#rule-postgresql-backup)
- [`sql-elastic-pool`](#rule-sql-elastic-pool)
- [`sql-failover-group`](#rule-sql-failover-group)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-databricks-workspace"><code>azure.concept.databricks-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/databricks.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Databricks workspace.

</dd>
<dd>

Used by [`databricks-workspace`](#rule-databricks-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-ddos-protection-plan"><code>azure.concept.ddos-protection-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/ddos-protection.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure DDoS Protection plan protecting virtual networks.

</dd>
<dd>

Used by [`ddos-protection-plan`](#rule-ddos-protection-plan).

</dd>
</div>

<div>
<dt id="azure-concept-dedicated-host-group"><code>azure.concept.dedicated-host-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Dedicated Host placement group.

</dd>
<dd>

Used by [`dedicated-host-group`](#rule-dedicated-host-group).

</dd>
</div>

<div>
<dt id="azure-concept-dedicated-interconnect"><code>azure.concept.dedicated-interconnect</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L25-L27">Source</a></dt>
<dd>

A dedicated private connection between an external network and a cloud provider.

</dd>
<dd>

Used by [`expressroute-circuit`](#rule-expressroute-circuit), [`expressroute-port`](#rule-expressroute-port).

</dd>
</div>

<div>
<dt id="azure-concept-defender-plan"><code>azure.concept.defender-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Defender for Cloud protection plan or workspace integration.

</dd>
<dd>

Used by [`defender-subscription-plan`](#rule-defender-subscription-plan), [`defender-workspace`](#rule-defender-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-dev-center"><code>azure.concept.dev-center</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-center.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Dev Box and deployment-environment Dev Center.

</dd>
<dd>

Used by [`dev-center`](#rule-dev-center).

</dd>
</div>

<div>
<dt id="azure-concept-dev-center-project"><code>azure.concept.dev-center-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-center.rf.hcl#L6-L8">Source</a></dt>
<dd>

A Dev Center project boundary.

</dd>
<dd>

Used by [`dev-center-project`](#rule-dev-center-project).

</dd>
</div>

<div>
<dt id="azure-concept-developer-environment"><code>azure.concept.developer-environment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A developer workstation, environment, or testing workspace.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`dev-box-definition`](#rule-dev-box-definition)
- [`dev-test-lab`](#rule-dev-test-lab)
- [`managed-devops-pool`](#rule-managed-devops-pool)
- [`playwright-workspace`](#rule-playwright-workspace)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-digital-twins-instance"><code>azure.concept.digital-twins-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/digital-twins.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Digital Twins service instance.

</dd>
<dd>

Used by [`digital-twins-instance`](#rule-digital-twins-instance).

</dd>
</div>

<div>
<dt id="azure-concept-disk-snapshot"><code>azure.concept.disk-snapshot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

A point-in-time snapshot of Azure disk storage.

</dd>
<dd>

Used by [`disk-snapshot`](#rule-disk-snapshot), [`virtual-machine-restore-point`](#rule-virtual-machine-restore-point).

</dd>
</div>

<div>
<dt id="azure-concept-dns-record"><code>azure.concept.dns-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L2-L4">Source</a></dt>
<dd>

A DNS record inside an Azure DNS zone.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`dns-a-record`](#rule-dns-a-record)
- [`dns-aaaa-record`](#rule-dns-aaaa-record)
- [`dns-cname-record`](#rule-dns-cname-record)
- [`dns-mx-record`](#rule-dns-mx-record)
- [`dns-ns-record`](#rule-dns-ns-record)
- [`dns-ptr-record`](#rule-dns-ptr-record)
- [`dns-srv-record`](#rule-dns-srv-record)
- [`dns-txt-record`](#rule-dns-txt-record)
- [`private-dns-a-record`](#rule-private-dns-a-record)
- [`private-dns-cname-record`](#rule-private-dns-cname-record)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-dns-zone"><code>azure.concept.dns-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L29-L31">Source</a></dt>
<dd>

A managed DNS namespace containing resource records.

</dd>
<dd>


<details>
<summary>Used by 14 Rules</summary>

- [`dns-a-record`](#rule-dns-a-record)
- [`dns-aaaa-record`](#rule-dns-aaaa-record)
- [`dns-cname-record`](#rule-dns-cname-record)
- [`dns-mx-record`](#rule-dns-mx-record)
- [`dns-ns-record`](#rule-dns-ns-record)
- [`dns-ptr-record`](#rule-dns-ptr-record)
- [`dns-srv-record`](#rule-dns-srv-record)
- [`dns-txt-record`](#rule-dns-txt-record)
- [`dns-zone`](#rule-dns-zone)
- [`postgresql-flexible-server`](#rule-postgresql-flexible-server)
- [`private-dns-a-record`](#rule-private-dns-a-record)
- [`private-dns-cname-record`](#rule-private-dns-cname-record)
- [`private-dns-zone`](#rule-private-dns-zone)
- [`private-dns-zone-vnet-link`](#rule-private-dns-zone-vnet-link)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-elastic-san"><code>azure.concept.elastic-san</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/elastic-san.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Elastic SAN storage boundary.

</dd>
<dd>

Used by [`elastic-san`](#rule-elastic-san), [`elastic-san-volume-group`](#rule-elastic-san-volume-group).

</dd>
</div>

<div>
<dt id="azure-concept-email-communication-service"><code>azure.concept.email-communication-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/communication-services.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Communication Services Email resource.

</dd>
<dd>

Used by [`email-communication-service`](#rule-email-communication-service).

</dd>
</div>

<div>
<dt id="azure-concept-encryption-key"><code>azure.concept.encryption-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L33-L35">Source</a></dt>
<dd>

A managed key used for cryptographic operations.

</dd>
<dd>

Used by [`key-vault-key`](#rule-key-vault-key), [`managed-hsm-key`](#rule-managed-hsm-key).

</dd>
</div>

<div>
<dt id="azure-concept-entra-application"><code>azure.concept.entra-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L6-L8">Source</a></dt>
<dd>

A Microsoft Entra application identity definition.

</dd>
<dd>

Used by [`entra-application`](#rule-entra-application), [`entra-application-registration`](#rule-entra-application-registration).

</dd>
</div>

<div>
<dt id="azure-concept-entra-directory"><code>azure.concept.entra-directory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L10-L12">Source</a></dt>
<dd>

A Microsoft Entra External ID directory boundary.

</dd>
<dd>

Used by [`entra-external-id-directory`](#rule-entra-external-id-directory).

</dd>
</div>

<div>
<dt id="azure-concept-entra-domain-service"><code>azure.concept.entra-domain-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L14-L16">Source</a></dt>
<dd>

A Microsoft Entra Domain Services managed domain.

</dd>
<dd>

Used by [`entra-domain-services`](#rule-entra-domain-services).

</dd>
</div>

<div>
<dt id="azure-concept-event-grid-domain"><code>azure.concept.event-grid-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Event Grid domain or namespace owning event topics.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`event-grid-domain`](#rule-event-grid-domain)
- [`event-grid-domain-topic`](#rule-event-grid-domain-topic)
- [`event-grid-namespace`](#rule-event-grid-namespace)
- [`event-grid-namespace-topic`](#rule-event-grid-namespace-topic)
- [`event-grid-partner-namespace`](#rule-event-grid-partner-namespace)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-event-grid-topic"><code>azure.concept.event-grid-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/concepts.rf.hcl#L14-L16">Source</a></dt>
<dd>

An Azure Event Grid custom, domain, or system topic owning event subscriptions.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`event-grid-domain-topic`](#rule-event-grid-domain-topic)
- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic`](#rule-event-grid-system-topic)
- [`event-grid-topic`](#rule-event-grid-topic)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-event-stream"><code>azure.concept.event-stream</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Event Hubs append-only event stream.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`event-hub`](#rule-event-hub)
- [`event-hubs-cluster`](#rule-event-hubs-cluster)
- [`event-hubs-consumer-group`](#rule-event-hubs-consumer-group)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-expressroute-gateway"><code>azure.concept.expressroute-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/expressroute.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure ExpressRoute gateway connecting a virtual network to private circuits.

</dd>
<dd>

Used by [`expressroute-gateway`](#rule-expressroute-gateway).

</dd>
</div>

<div>
<dt id="azure-concept-firewall-policy"><code>azure.concept.firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Firewall or web application firewall policy.

</dd>
<dd>

Used by [`azure-firewall-policy`](#rule-azure-firewall-policy), [`azure-firewall-policy-rule-collection-group`](#rule-azure-firewall-policy-rule-collection-group).

</dd>
</div>

<div>
<dt id="azure-concept-front-door-profile"><code>azure.concept.front-door-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Front Door global application delivery profile.

</dd>
<dd>

Used by [`classic-front-door`](#rule-classic-front-door), [`front-door-profile`](#rule-front-door-profile).

</dd>
</div>

<div>
<dt id="azure-concept-governance-detail"><code>azure.concept.governance-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure policy, role, deployment, budget, or governance configuration.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`lighthouse-definition`](#rule-lighthouse-definition)
- [`policy-definition`](#rule-policy-definition)
- [`policy-set-definition`](#rule-policy-set-definition)
- [`resource-policy-assignment`](#rule-resource-policy-assignment)
- [`role-assignment`](#rule-role-assignment)
- [`role-definition`](#rule-role-definition)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-graph-data-connect-account"><code>azure.concept.graph-data-connect-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/graph-data.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Graph Data Connect service account.

</dd>
<dd>

Used by [`graph-data-connect-account`](#rule-graph-data-connect-account).

</dd>
</div>

<div>
<dt id="azure-concept-health-data-service"><code>azure.concept.health-data-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L2-L4">Source</a></dt>
<dd>

A FHIR, DICOM, or MedTech service in Azure Health Data Services.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`health-data-dicom-service`](#rule-health-data-dicom-service)
- [`health-data-fhir-service`](#rule-health-data-fhir-service)
- [`health-data-medtech-service`](#rule-health-data-medtech-service)
- [`healthcare-service`](#rule-healthcare-service)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-health-data-workspace"><code>azure.concept.health-data-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Health Data Services workspace owning healthcare data services.

</dd>
<dd>

Used by [`health-data-services-workspace`](#rule-health-data-services-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-hybrid-platform"><code>azure.concept.hybrid-platform</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A hybrid or partner platform managed through Azure.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`nginx-deployment`](#rule-nginx-deployment)
- [`oracle-cloud-vm-cluster`](#rule-oracle-cloud-vm-cluster)
- [`oracle-exadata-infrastructure`](#rule-oracle-exadata-infrastructure)
- [`oracle-resource-anchor`](#rule-oracle-resource-anchor)
- [`palo-alto-firewall`](#rule-palo-alto-firewall)
- [`sap-discovery-virtual-instance`](#rule-sap-discovery-virtual-instance)
- [`sap-single-node-virtual-instance`](#rule-sap-single-node-virtual-instance)
- [`sap-three-tier-virtual-instance`](#rule-sap-three-tier-virtual-instance)
- [`system-center-vmm-server`](#rule-system-center-vmm-server)
- [`vmware-cluster`](#rule-vmware-cluster)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-identity-governance-detail"><code>azure.concept.identity-governance-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L18-L20">Source</a></dt>
<dd>

A location, assignment, federation, role, or policy supporting identity governance.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`entra-access-package-assignment-policy`](#rule-entra-access-package-assignment-policy)
- [`entra-app-role-assignment`](#rule-entra-app-role-assignment)
- [`entra-application-federated-identity`](#rule-entra-application-federated-identity)
- [`entra-authentication-strength-policy`](#rule-entra-authentication-strength-policy)
- [`entra-domain-services-replica-set`](#rule-entra-domain-services-replica-set)
- [`entra-domain-services-trust`](#rule-entra-domain-services-trust)
- [`entra-named-location`](#rule-entra-named-location)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-identity-group"><code>azure.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L37-L39">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>

Used by [`entra-group`](#rule-entra-group), [`entra-group-without-members`](#rule-entra-group-without-members).

</dd>
</div>

<div>
<dt id="azure-concept-image-gallery"><code>azure.concept.image-gallery</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/compute-gallery.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Compute Gallery owning image definitions and versions.

</dd>
<dd>

Used by [`compute-gallery`](#rule-compute-gallery).

</dd>
</div>

<div>
<dt id="azure-concept-integration-account"><code>azure.concept.integration-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Logic Apps integration account.

</dd>
<dd>

Used by [`logic-app-integration-account`](#rule-logic-app-integration-account).

</dd>
</div>

<div>
<dt id="azure-concept-integration-connection"><code>azure.concept.integration-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure API or App Service connection supporting integration.

</dd>
<dd>

Used by [`api-connection`](#rule-api-connection), [`app-service-connection`](#rule-app-service-connection).

</dd>
</div>

<div>
<dt id="azure-concept-iot-central-application"><code>azure.concept.iot-central-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-central.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure IoT Central application.

</dd>
<dd>

Used by [`iot-central-application`](#rule-iot-central-application).

</dd>
</div>

<div>
<dt id="azure-concept-iot-detail"><code>azure.concept.iot-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L2-L4">Source</a></dt>
<dd>

A route, endpoint, consumer group, certificate, or organization supporting Azure IoT.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`digital-twins-event-grid-endpoint`](#rule-digital-twins-event-grid-endpoint)
- [`iot-hub-device-update-instance`](#rule-iot-hub-device-update-instance)
- [`iot-hub-event-hubs-endpoint`](#rule-iot-hub-event-hubs-endpoint)
- [`iot-hub-service-bus-queue-endpoint`](#rule-iot-hub-service-bus-queue-endpoint)
- [`iot-hub-storage-endpoint`](#rule-iot-hub-storage-endpoint)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-iot-hub"><code>azure.concept.iot-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure IoT Hub device messaging service.

</dd>
<dd>

Used by [`iot-hub`](#rule-iot-hub).

</dd>
</div>

<div>
<dt id="azure-concept-iot-provisioning-service"><code>azure.concept.iot-provisioning-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure IoT Hub Device Provisioning Service.

</dd>
<dd>

Used by [`iot-hub-device-provisioning-service`](#rule-iot-hub-device-provisioning-service).

</dd>
</div>

<div>
<dt id="azure-concept-iot-update-service"><code>azure.concept.iot-update-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L14-L16">Source</a></dt>
<dd>

An Azure Device Update for IoT Hub account boundary.

</dd>
<dd>

Used by [`iot-hub-device-update-account`](#rule-iot-hub-device-update-account).

</dd>
</div>

<div>
<dt id="azure-concept-key-vault"><code>azure.concept.key-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Key Vault security boundary for keys, secrets, and certificates.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`key-vault`](#rule-key-vault)
- [`key-vault-access-policy`](#rule-key-vault-access-policy)
- [`key-vault-certificate`](#rule-key-vault-certificate)
- [`key-vault-key`](#rule-key-vault-key)
- [`key-vault-secret`](#rule-key-vault-secret)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-kubernetes-fleet"><code>azure.concept.kubernetes-fleet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/kubernetes-fleet-manager.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Kubernetes Fleet Manager fleet coordinating Kubernetes clusters.

</dd>
<dd>

Used by [`kubernetes-fleet`](#rule-kubernetes-fleet).

</dd>
</div>

<div>
<dt id="azure-concept-kubernetes-node-pool"><code>azure.concept.kubernetes-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L41-L43">Source</a></dt>
<dd>

A node pool contributing compute capacity to a Kubernetes cluster.

</dd>
<dd>

Used by [`aks-node-pool`](#rule-aks-node-pool).

</dd>
</div>

<div>
<dt id="azure-concept-load-balancer"><code>azure.concept.load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L45-L47">Source</a></dt>
<dd>

A load-balancing service composed from routing infrastructure.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`application-gateway`](#rule-application-gateway)
- [`application-load-balancer`](#rule-application-load-balancer)
- [`load-balancer`](#rule-load-balancer)
- [`load-balancer-backend-pool`](#rule-load-balancer-backend-pool)
- [`load-balancer-rule`](#rule-load-balancer-rule)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-load-balancer-component"><code>azure.concept.load-balancer-component</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A frontend, backend, route, probe, rule, or policy supporting Azure load balancing.

</dd>
<dd>


<details>
<summary>Used by 11 Rules</summary>

- [`application-load-balancer-frontend`](#rule-application-load-balancer-frontend)
- [`front-door-endpoint`](#rule-front-door-endpoint)
- [`front-door-origin`](#rule-front-door-origin)
- [`front-door-origin-group`](#rule-front-door-origin-group)
- [`front-door-route`](#rule-front-door-route)
- [`load-balancer-backend-pool`](#rule-load-balancer-backend-pool)
- [`load-balancer-nat-rule`](#rule-load-balancer-nat-rule)
- [`load-balancer-outbound-rule`](#rule-load-balancer-outbound-rule)
- [`load-balancer-probe`](#rule-load-balancer-probe)
- [`load-balancer-rule`](#rule-load-balancer-rule)
- [`traffic-manager-azure-endpoint`](#rule-traffic-manager-azure-endpoint)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-load-test"><code>azure.concept.load-test</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/load-test.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Load Testing resource.

</dd>
<dd>

Used by [`load-test`](#rule-load-test).

</dd>
</div>

<div>
<dt id="azure-concept-local-network-gateway"><code>azure.concept.local-network-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure representation of an external VPN site gateway.

</dd>
<dd>

Used by [`local-network-gateway`](#rule-local-network-gateway), [`vpn-site`](#rule-vpn-site).

</dd>
</div>

<div>
<dt id="azure-concept-log-analytics-workspace"><code>azure.concept.log-analytics-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Log Analytics workspace collecting operational data.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`aks-cluster`](#rule-aks-cluster)
- [`application-insights`](#rule-application-insights)
- [`container-app-environment`](#rule-container-app-environment)
- [`log-analytics-cluster`](#rule-log-analytics-cluster)
- [`log-analytics-data-export-rule`](#rule-log-analytics-data-export-rule)
- [`log-analytics-saved-search`](#rule-log-analytics-saved-search)
- [`log-analytics-solution`](#rule-log-analytics-solution)
- [`log-analytics-workspace`](#rule-log-analytics-workspace)
- [`log-analytics-workspace-table`](#rule-log-analytics-workspace-table)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-logical-database"><code>azure.concept.logical-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

A logical database or keyspace contained by an Azure managed database service.

</dd>
<dd>


<details>
<summary>Used by 12 Rules</summary>

- [`cosmos-cassandra-keyspace`](#rule-cosmos-cassandra-keyspace)
- [`cosmos-cassandra-table`](#rule-cosmos-cassandra-table)
- [`cosmos-gremlin-database`](#rule-cosmos-gremlin-database)
- [`cosmos-gremlin-graph`](#rule-cosmos-gremlin-graph)
- [`cosmos-mongo-collection`](#rule-cosmos-mongo-collection)
- [`cosmos-mongo-database`](#rule-cosmos-mongo-database)
- [`cosmos-sql-container`](#rule-cosmos-sql-container)
- [`cosmos-sql-database`](#rule-cosmos-sql-database)
- [`mssql-database`](#rule-mssql-database)
- [`mysql-database`](#rule-mysql-database)
- [`postgresql-database`](#rule-postgresql-database)
- [`sql-managed-database`](#rule-sql-managed-database)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-machine-learning-compute"><code>azure.concept.machine-learning-compute</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/machine-learning.rf.hcl#L2-L4">Source</a></dt>
<dd>

Compute capacity attached to Azure Machine Learning.

</dd>
<dd>

Used by [`machine-learning-compute-cluster`](#rule-machine-learning-compute-cluster), [`machine-learning-compute-instance`](#rule-machine-learning-compute-instance).

</dd>
</div>

<div>
<dt id="azure-concept-machine-learning-workspace"><code>azure.concept.machine-learning-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Machine Learning workspace.

</dd>
<dd>

Used by [`machine-learning-workspace`](#rule-machine-learning-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-maintenance-configuration"><code>azure.concept.maintenance-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/maintenance-configuration.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure maintenance configuration defining update windows.

</dd>
<dd>

Used by [`maintenance-configuration`](#rule-maintenance-configuration).

</dd>
</div>

<div>
<dt id="azure-concept-managed-application"><code>azure.concept.managed-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/managed-application.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Managed Application deployment.

</dd>
<dd>

Used by [`managed-application`](#rule-managed-application).

</dd>
</div>

<div>
<dt id="azure-concept-managed-cache"><code>azure.concept.managed-cache</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L49-L51">Source</a></dt>
<dd>

A managed in-memory cache service.

</dd>
<dd>

Used by [`azure-cache-for-redis`](#rule-azure-cache-for-redis), [`azure-managed-redis`](#rule-azure-managed-redis).

</dd>
</div>

<div>
<dt id="azure-concept-managed-file-storage"><code>azure.concept.managed-file-storage</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L53-L55">Source</a></dt>
<dd>

A managed shared file-storage service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`azure-files-share`](#rule-azure-files-share)
- [`managed-lustre-file-system`](#rule-managed-lustre-file-system)
- [`netapp-volume`](#rule-netapp-volume)
- [`qumulo-file-system`](#rule-qumulo-file-system)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-managed-grafana"><code>azure.concept.managed-grafana</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/managed-grafana.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Managed Grafana workspace.

</dd>
<dd>

Used by [`managed-grafana`](#rule-managed-grafana).

</dd>
</div>

<div>
<dt id="azure-concept-managed-hsm"><code>azure.concept.managed-hsm</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Key Vault Managed HSM security boundary.

</dd>
<dd>

Used by [`dedicated-hardware-security-module`](#rule-dedicated-hardware-security-module), [`managed-hsm`](#rule-managed-hsm), [`managed-hsm-key`](#rule-managed-hsm-key).

</dd>
</div>

<div>
<dt id="azure-concept-managed-nat"><code>azure.concept.managed-nat</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L57-L59">Source</a></dt>
<dd>

A managed network address translation service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`nat-gateway`](#rule-nat-gateway)
- [`nat-gateway-public-ip-association`](#rule-nat-gateway-public-ip-association)
- [`nat-gateway-public-ip-prefix-association`](#rule-nat-gateway-public-ip-prefix-association)
- [`subnet-nat-gateway-association`](#rule-subnet-nat-gateway-association)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-managed-secret"><code>azure.concept.managed-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L61-L63">Source</a></dt>
<dd>

A managed secret identity whose sensitive value stays outside architecture output.

</dd>
<dd>

Used by [`key-vault-secret`](#rule-key-vault-secret).

</dd>
</div>

<div>
<dt id="azure-concept-maps-account"><code>azure.concept.maps-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/maps-account.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Maps account exposing geospatial platform APIs.

</dd>
<dd>

Used by [`maps-account`](#rule-maps-account).

</dd>
</div>

<div>
<dt id="azure-concept-message-queue"><code>azure.concept.message-queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L65-L67">Source</a></dt>
<dd>

A managed queue buffering work or messages for asynchronous consumers.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`queue-storage-queue`](#rule-queue-storage-queue)
- [`service-bus-queue`](#rule-service-bus-queue)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-message-subscription"><code>azure.concept.message-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L69-L71">Source</a></dt>
<dd>

A durable subscription consuming messages from a topic.

</dd>
<dd>

Used by [`event-grid-event-subscription`](#rule-event-grid-event-subscription), [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription), [`service-bus-subscription`](#rule-service-bus-subscription).

</dd>
</div>

<div>
<dt id="azure-concept-message-topic"><code>azure.concept.message-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L73-L75">Source</a></dt>
<dd>

A messaging topic receiving messages from publishers.

</dd>
<dd>

Used by [`event-grid-namespace-topic`](#rule-event-grid-namespace-topic).

</dd>
</div>

<div>
<dt id="azure-concept-messaging-detail"><code>azure.concept.messaging-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

A consumer group, authorization rule, schema, route, or endpoint supporting messaging.

</dd>
<dd>

Used by [`event-hubs-consumer-group`](#rule-event-hubs-consumer-group), [`event-hubs-schema-group`](#rule-event-hubs-schema-group), [`service-bus-subscription-rule`](#rule-service-bus-subscription-rule).

</dd>
</div>

<div>
<dt id="azure-concept-messaging-namespace"><code>azure.concept.messaging-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure messaging namespace owning queues, topics, or event streams.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`event-hub`](#rule-event-hub)
- [`event-hubs-namespace`](#rule-event-hubs-namespace)
- [`event-hubs-schema-group`](#rule-event-hubs-schema-group)
- [`service-bus-namespace`](#rule-service-bus-namespace)
- [`service-bus-queue`](#rule-service-bus-queue)
- [`service-bus-topic`](#rule-service-bus-topic)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-migration-service"><code>azure.concept.migration-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure migration or movement service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`data-box-edge-device`](#rule-data-box-edge-device)
- [`database-migration-project`](#rule-database-migration-project)
- [`database-migration-service`](#rule-database-migration-service)
- [`storage-mover`](#rule-storage-mover)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-monitor-workspace"><code>azure.concept.monitor-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Monitor workspace.

</dd>
<dd>

Used by [`monitor-workspace`](#rule-monitor-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-netapp-account"><code>azure.concept.netapp-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/netapp-files.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure NetApp Files account.

</dd>
<dd>

Used by [`netapp-account`](#rule-netapp-account).

</dd>
</div>

<div>
<dt id="azure-concept-netapp-capacity-pool"><code>azure.concept.netapp-capacity-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/netapp-files.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure NetApp Files capacity pool.

</dd>
<dd>

Used by [`netapp-capacity-pool`](#rule-netapp-capacity-pool).

</dd>
</div>

<div>
<dt id="azure-concept-network-function-service"><code>azure.concept.network-function-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-function.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure managed network-function collection or control service.

</dd>
<dd>

Used by [`network-function-traffic-collector`](#rule-network-function-traffic-collector).

</dd>
</div>

<div>
<dt id="azure-concept-network-peering"><code>azure.concept.network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L77-L79">Source</a></dt>
<dd>

A direct private connectivity agreement between virtual networks.

</dd>
<dd>

Used by [`databricks-virtual-network-peering`](#rule-databricks-virtual-network-peering), [`virtual-network-peering`](#rule-virtual-network-peering).

</dd>
</div>

<div>
<dt id="azure-concept-network-policy-detail"><code>azure.concept.network-policy-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

A route, security rule, association, or network policy supporting Azure networking.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`application-security-group`](#rule-application-security-group)
- [`ip-group`](#rule-ip-group)
- [`nat-gateway-public-ip-association`](#rule-nat-gateway-public-ip-association)
- [`nat-gateway-public-ip-prefix-association`](#rule-nat-gateway-public-ip-prefix-association)
- [`network-manager-ipam-pool`](#rule-network-manager-ipam-pool)
- [`network-security-rule`](#rule-network-security-rule)
- [`route`](#rule-route)
- [`subnet-nat-gateway-association`](#rule-subnet-nat-gateway-association)
- [`subnet-network-security-group-association`](#rule-subnet-network-security-group-association)
- [`subnet-route-table-association`](#rule-subnet-route-table-association)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-network-security-group"><code>azure.concept.network-security-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Network Security Group containing stateful traffic rules.

</dd>
<dd>

Used by [`network-security-group`](#rule-network-security-group).

</dd>
</div>

<div>
<dt id="azure-concept-network-security-perimeter"><code>azure.concept.network-security-perimeter</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Network Security Perimeter isolating platform services.

</dd>
<dd>

Used by [`network-security-perimeter`](#rule-network-security-perimeter).

</dd>
</div>

<div>
<dt id="azure-concept-network-watcher"><code>azure.concept.network-watcher</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L14-L16">Source</a></dt>
<dd>

An Azure Network Watcher regional network monitoring service.

</dd>
<dd>

Used by [`network-watcher`](#rule-network-watcher).

</dd>
</div>

<div>
<dt id="azure-concept-notification-hub"><code>azure.concept.notification-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/notification-hubs.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Notification Hubs push-notification hub.

</dd>
<dd>

Used by [`notification-hub`](#rule-notification-hub).

</dd>
</div>

<div>
<dt id="azure-concept-notification-namespace"><code>azure.concept.notification-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/notification-hubs.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Notification Hubs namespace.

</dd>
<dd>

Used by [`notification-hubs-namespace`](#rule-notification-hubs-namespace).

</dd>
</div>

<div>
<dt id="azure-concept-operations-detail"><code>azure.concept.operations-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An alert, diagnostic, workbook, schedule, dashboard, or operational configuration.

</dd>
<dd>


<details>
<summary>Used by 13 Rules</summary>

- [`application-insights-web-test`](#rule-application-insights-web-test)
- [`automation-schedule`](#rule-automation-schedule)
- [`log-analytics-data-export-rule`](#rule-log-analytics-data-export-rule)
- [`log-analytics-saved-search`](#rule-log-analytics-saved-search)
- [`log-analytics-solution`](#rule-log-analytics-solution)
- [`log-analytics-workspace-table`](#rule-log-analytics-workspace-table)
- [`monitor-action-group`](#rule-monitor-action-group)
- [`monitor-data-collection-endpoint`](#rule-monitor-data-collection-endpoint)
- [`monitor-diagnostic-setting`](#rule-monitor-diagnostic-setting)
- [`monitor-metric-alert`](#rule-monitor-metric-alert)
- [`monitor-scheduled-query-alert`](#rule-monitor-scheduled-query-alert)
- [`network-watcher-flow-log`](#rule-network-watcher-flow-log)
- [`portal-dashboard`](#rule-portal-dashboard)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-private-dns-resolver"><code>azure.concept.private-dns-resolver</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure DNS Private Resolver forwarding DNS between networks.

</dd>
<dd>

Used by [`private-dns-resolver`](#rule-private-dns-resolver).

</dd>
</div>

<div>
<dt id="azure-concept-private-endpoint"><code>azure.concept.private-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L81-L83">Source</a></dt>
<dd>

A private endpoint exposing a service inside a virtual network.

</dd>
<dd>

Used by [`private-endpoint`](#rule-private-endpoint).

</dd>
</div>

<div>
<dt id="azure-concept-private-link-scope"><code>azure.concept.private-link-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/concepts.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure private-link scope or hub grouping private service connectivity.

</dd>
<dd>

Used by [`arc-private-link-scope`](#rule-arc-private-link-scope), [`monitor-private-link-scope`](#rule-monitor-private-link-scope), [`synapse-private-link-hub`](#rule-synapse-private-link-hub).

</dd>
</div>

<div>
<dt id="azure-concept-private-link-service"><code>azure.concept.private-link-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/private-link.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Private Link service publishing a private endpoint target.

</dd>
<dd>

Used by [`private-link-service`](#rule-private-link-service).

</dd>
</div>

<div>
<dt id="azure-concept-private-network-link"><code>azure.concept.private-network-link</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Private DNS virtual network link.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`private-dns-forwarding-ruleset`](#rule-private-dns-forwarding-ruleset)
- [`private-dns-inbound-endpoint`](#rule-private-dns-inbound-endpoint)
- [`private-dns-outbound-endpoint`](#rule-private-dns-outbound-endpoint)
- [`private-dns-zone-vnet-link`](#rule-private-dns-zone-vnet-link)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-public-address"><code>azure.concept.public-address</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/concepts.rf.hcl#L14-L16">Source</a></dt>
<dd>

A public Azure IP address exposed to network traffic.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`custom-ip-prefix`](#rule-custom-ip-prefix)
- [`nat-gateway-public-ip-association`](#rule-nat-gateway-public-ip-association)
- [`nat-gateway-public-ip-prefix-association`](#rule-nat-gateway-public-ip-prefix-association)
- [`public-address`](#rule-public-address)
- [`public-ip-prefix`](#rule-public-ip-prefix)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-purview-account"><code>azure.concept.purview-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/purview-account.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Microsoft Purview data governance account.

</dd>
<dd>

Used by [`purview-account`](#rule-purview-account).

</dd>
</div>

<div>
<dt id="azure-concept-realtime-communication-service"><code>azure.concept.realtime-communication-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure managed real-time communication service.

</dd>
<dd>

Used by [`fluid-relay`](#rule-fluid-relay), [`signalr-service`](#rule-signalr-service), [`web-pubsub`](#rule-web-pubsub).

</dd>
</div>

<div>
<dt id="azure-concept-relay-connection"><code>azure.concept.relay-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/relay.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Relay hybrid connection.

</dd>
<dd>

Used by [`relay-hybrid-connection`](#rule-relay-hybrid-connection).

</dd>
</div>

<div>
<dt id="azure-concept-relay-namespace"><code>azure.concept.relay-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/relay.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Relay namespace.

</dd>
<dd>

Used by [`relay-namespace`](#rule-relay-namespace).

</dd>
</div>

<div>
<dt id="azure-concept-resource-group"><code>azure.concept.resource-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/resource-group.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Resource Group lifecycle and access boundary.

</dd>
<dd>


<details>
<summary>Used by 224 Rules</summary>

- [`ai-foundry`](#rule-ai-foundry)
- [`ai-search-service`](#rule-ai-search-service)
- [`ai-services-account`](#rule-ai-services-account)
- [`aks-cluster`](#rule-aks-cluster)
- [`analysis-services-server`](#rule-analysis-services-server)
- [`api-management`](#rule-api-management)
- [`api-management-standalone-gateway`](#rule-api-management-standalone-gateway)
- [`app-configuration`](#rule-app-configuration)
- [`app-service-environment`](#rule-app-service-environment)
- [`app-service-plan`](#rule-app-service-plan)
- [`application-gateway`](#rule-application-gateway)
- [`application-insights`](#rule-application-insights)
- [`application-load-balancer`](#rule-application-load-balancer)
- [`arc-custom-location`](#rule-arc-custom-location)
- [`arc-enabled-server`](#rule-arc-enabled-server)
- [`arc-kubernetes-cluster`](#rule-arc-kubernetes-cluster)
- [`arc-private-link-scope`](#rule-arc-private-link-scope)
- [`arc-provisioned-kubernetes-cluster`](#rule-arc-provisioned-kubernetes-cluster)
- [`arc-resource-bridge`](#rule-arc-resource-bridge)
- [`attestation-provider`](#rule-attestation-provider)
- [`automatic-kubernetes-cluster`](#rule-automatic-kubernetes-cluster)
- [`automation-account`](#rule-automation-account)
- [`automation-runbook`](#rule-automation-runbook)
- [`azure-bot`](#rule-azure-bot)
- [`azure-cache-for-redis`](#rule-azure-cache-for-redis)
- [`azure-firewall`](#rule-azure-firewall)
- [`azure-local-cluster`](#rule-azure-local-cluster)
- [`azure-managed-redis`](#rule-azure-managed-redis)
- [`bastion-host`](#rule-bastion-host)
- [`batch-account`](#rule-batch-account)
- [`bot-channels-registration`](#rule-bot-channels-registration)
- [`bot-web-app`](#rule-bot-web-app)
- [`cdn-endpoint`](#rule-cdn-endpoint)
- [`cdn-profile`](#rule-cdn-profile)
- [`chaos-studio-experiment`](#rule-chaos-studio-experiment)
- [`classic-front-door`](#rule-classic-front-door)
- [`communication-service`](#rule-communication-service)
- [`compute-gallery`](#rule-compute-gallery)
- [`compute-image`](#rule-compute-image)
- [`confidential-ledger`](#rule-confidential-ledger)
- [`container-app`](#rule-container-app)
- [`container-app-environment`](#rule-container-app-environment)
- [`container-app-job`](#rule-container-app-job)
- [`container-instance-group`](#rule-container-instance-group)
- [`container-registry`](#rule-container-registry)
- [`cosmos-account`](#rule-cosmos-account)
- [`cosmos-cassandra-cluster`](#rule-cosmos-cassandra-cluster)
- [`cosmos-postgresql-cluster`](#rule-cosmos-postgresql-cluster)
- [`custom-ip-prefix`](#rule-custom-ip-prefix)
- [`data-box-edge-device`](#rule-data-box-edge-device)
- [`data-explorer-cluster`](#rule-data-explorer-cluster)
- [`data-factory`](#rule-data-factory)
- [`data-protection-backup-vault`](#rule-data-protection-backup-vault)
- [`data-share-account`](#rule-data-share-account)
- [`database-migration-project`](#rule-database-migration-project)
- [`database-migration-service`](#rule-database-migration-service)
- [`databricks-virtual-network-peering`](#rule-databricks-virtual-network-peering)
- [`databricks-workspace`](#rule-databricks-workspace)
- [`datadog-monitor`](#rule-datadog-monitor)
- [`ddos-protection-plan`](#rule-ddos-protection-plan)
- [`dedicated-hardware-security-module`](#rule-dedicated-hardware-security-module)
- [`dedicated-host-group`](#rule-dedicated-host-group)
- [`dev-center`](#rule-dev-center)
- [`dev-center-project`](#rule-dev-center-project)
- [`dev-test-lab`](#rule-dev-test-lab)
- [`dev-test-linux-virtual-machine`](#rule-dev-test-linux-virtual-machine)
- [`dev-test-windows-virtual-machine`](#rule-dev-test-windows-virtual-machine)
- [`digital-twins-instance`](#rule-digital-twins-instance)
- [`disk-snapshot`](#rule-disk-snapshot)
- [`dns-zone`](#rule-dns-zone)
- [`dynatrace-monitor`](#rule-dynatrace-monitor)
- [`elastic-cloud`](#rule-elastic-cloud)
- [`elastic-san`](#rule-elastic-san)
- [`email-communication-service`](#rule-email-communication-service)
- [`entra-domain-services`](#rule-entra-domain-services)
- [`entra-external-id-directory`](#rule-entra-external-id-directory)
- [`event-grid-domain`](#rule-event-grid-domain)
- [`event-grid-namespace`](#rule-event-grid-namespace)
- [`event-grid-partner-namespace`](#rule-event-grid-partner-namespace)
- [`event-grid-system-topic`](#rule-event-grid-system-topic)
- [`event-grid-topic`](#rule-event-grid-topic)
- [`event-hubs-cluster`](#rule-event-hubs-cluster)
- [`event-hubs-namespace`](#rule-event-hubs-namespace)
- [`expressroute-circuit`](#rule-expressroute-circuit)
- [`expressroute-gateway`](#rule-expressroute-gateway)
- [`expressroute-port`](#rule-expressroute-port)
- [`fabric-capacity`](#rule-fabric-capacity)
- [`file-share-backup-policy`](#rule-file-share-backup-policy)
- [`flex-consumption-function-app`](#rule-flex-consumption-function-app)
- [`fluid-relay`](#rule-fluid-relay)
- [`front-door-profile`](#rule-front-door-profile)
- [`graph-data-connect-account`](#rule-graph-data-connect-account)
- [`hdinsight-hadoop-cluster`](#rule-hdinsight-hadoop-cluster)
- [`hdinsight-hbase-cluster`](#rule-hdinsight-hbase-cluster)
- [`hdinsight-interactive-query-cluster`](#rule-hdinsight-interactive-query-cluster)
- [`hdinsight-kafka-cluster`](#rule-hdinsight-kafka-cluster)
- [`hdinsight-spark-cluster`](#rule-hdinsight-spark-cluster)
- [`health-bot`](#rule-health-bot)
- [`health-data-fhir-service`](#rule-health-data-fhir-service)
- [`health-data-services-workspace`](#rule-health-data-services-workspace)
- [`healthcare-service`](#rule-healthcare-service)
- [`iot-central-application`](#rule-iot-central-application)
- [`iot-hub`](#rule-iot-hub)
- [`iot-hub-device-provisioning-service`](#rule-iot-hub-device-provisioning-service)
- [`iot-hub-device-update-account`](#rule-iot-hub-device-update-account)
- [`key-vault`](#rule-key-vault)
- [`kubernetes-fleet`](#rule-kubernetes-fleet)
- [`linux-function-app`](#rule-linux-function-app)
- [`linux-virtual-machine`](#rule-linux-virtual-machine)
- [`linux-virtual-machine-scale-set`](#rule-linux-virtual-machine-scale-set)
- [`linux-web-app`](#rule-linux-web-app)
- [`load-balancer`](#rule-load-balancer)
- [`load-test`](#rule-load-test)
- [`local-network-gateway`](#rule-local-network-gateway)
- [`log-analytics-cluster`](#rule-log-analytics-cluster)
- [`log-analytics-solution`](#rule-log-analytics-solution)
- [`log-analytics-workspace`](#rule-log-analytics-workspace)
- [`logic-app-integration-account`](#rule-logic-app-integration-account)
- [`logic-app-standard`](#rule-logic-app-standard)
- [`logic-app-workflow`](#rule-logic-app-workflow)
- [`machine-learning-workspace`](#rule-machine-learning-workspace)
- [`maintenance-configuration`](#rule-maintenance-configuration)
- [`managed-application`](#rule-managed-application)
- [`managed-devops-pool`](#rule-managed-devops-pool)
- [`managed-disk`](#rule-managed-disk)
- [`managed-grafana`](#rule-managed-grafana)
- [`managed-hsm`](#rule-managed-hsm)
- [`managed-lustre-file-system`](#rule-managed-lustre-file-system)
- [`managed-service-fabric-cluster`](#rule-managed-service-fabric-cluster)
- [`maps-account`](#rule-maps-account)
- [`mongo-cluster`](#rule-mongo-cluster)
- [`monitor-private-link-scope`](#rule-monitor-private-link-scope)
- [`monitor-workspace`](#rule-monitor-workspace)
- [`mssql-server`](#rule-mssql-server)
- [`mysql-database`](#rule-mysql-database)
- [`mysql-flexible-server`](#rule-mysql-flexible-server)
- [`nat-gateway`](#rule-nat-gateway)
- [`netapp-account`](#rule-netapp-account)
- [`netapp-backup-policy`](#rule-netapp-backup-policy)
- [`netapp-backup-vault`](#rule-netapp-backup-vault)
- [`netapp-capacity-pool`](#rule-netapp-capacity-pool)
- [`netapp-volume`](#rule-netapp-volume)
- [`network-function-traffic-collector`](#rule-network-function-traffic-collector)
- [`network-security-group`](#rule-network-security-group)
- [`network-security-perimeter`](#rule-network-security-perimeter)
- [`network-watcher`](#rule-network-watcher)
- [`new-relic-monitor`](#rule-new-relic-monitor)
- [`nginx-deployment`](#rule-nginx-deployment)
- [`notification-hub`](#rule-notification-hub)
- [`notification-hubs-namespace`](#rule-notification-hubs-namespace)
- [`oracle-autonomous-database`](#rule-oracle-autonomous-database)
- [`oracle-cloud-vm-cluster`](#rule-oracle-cloud-vm-cluster)
- [`oracle-exadata-infrastructure`](#rule-oracle-exadata-infrastructure)
- [`oracle-resource-anchor`](#rule-oracle-resource-anchor)
- [`orchestrated-virtual-machine-scale-set`](#rule-orchestrated-virtual-machine-scale-set)
- [`palo-alto-firewall`](#rule-palo-alto-firewall)
- [`playwright-workspace`](#rule-playwright-workspace)
- [`point-to-site-vpn-gateway`](#rule-point-to-site-vpn-gateway)
- [`postgresql-flexible-server`](#rule-postgresql-flexible-server)
- [`power-bi-embedded-capacity`](#rule-power-bi-embedded-capacity)
- [`private-dns-resolver`](#rule-private-dns-resolver)
- [`private-dns-zone`](#rule-private-dns-zone)
- [`private-endpoint`](#rule-private-endpoint)
- [`private-link-service`](#rule-private-link-service)
- [`public-address`](#rule-public-address)
- [`public-ip-prefix`](#rule-public-ip-prefix)
- [`purview-account`](#rule-purview-account)
- [`qumulo-file-system`](#rule-qumulo-file-system)
- [`recovery-services-vault`](#rule-recovery-services-vault)
- [`red-hat-openshift-cluster`](#rule-red-hat-openshift-cluster)
- [`relay-hybrid-connection`](#rule-relay-hybrid-connection)
- [`relay-namespace`](#rule-relay-namespace)
- [`resource-group`](#rule-resource-group)
- [`route-server`](#rule-route-server)
- [`route-table`](#rule-route-table)
- [`sap-discovery-virtual-instance`](#rule-sap-discovery-virtual-instance)
- [`sap-single-node-virtual-instance`](#rule-sap-single-node-virtual-instance)
- [`sap-three-tier-virtual-instance`](#rule-sap-three-tier-virtual-instance)
- [`service-bus-namespace`](#rule-service-bus-namespace)
- [`service-fabric-cluster`](#rule-service-fabric-cluster)
- [`shared-image`](#rule-shared-image)
- [`signalr-service`](#rule-signalr-service)
- [`site-recovery-fabric`](#rule-site-recovery-fabric)
- [`site-recovery-protection-container`](#rule-site-recovery-protection-container)
- [`spring-app`](#rule-spring-app)
- [`spring-apps-service`](#rule-spring-apps-service)
- [`sql-managed-instance`](#rule-sql-managed-instance)
- [`stack-hci-virtual-hard-disk`](#rule-stack-hci-virtual-hard-disk)
- [`static-web-app`](#rule-static-web-app)
- [`storage-account`](#rule-storage-account)
- [`storage-mover`](#rule-storage-mover)
- [`storage-sync-service`](#rule-storage-sync-service)
- [`stream-analytics-cluster`](#rule-stream-analytics-cluster)
- [`stream-analytics-job`](#rule-stream-analytics-job)
- [`subnet`](#rule-subnet)
- [`synapse-private-link-hub`](#rule-synapse-private-link-hub)
- [`synapse-workspace`](#rule-synapse-workspace)
- [`system-center-vmm-server`](#rule-system-center-vmm-server)
- [`traffic-manager-profile`](#rule-traffic-manager-profile)
- [`trusted-signing-account`](#rule-trusted-signing-account)
- [`user-assigned-managed-identity`](#rule-user-assigned-managed-identity)
- [`video-indexer-account`](#rule-video-indexer-account)
- [`virtual-desktop-application-group`](#rule-virtual-desktop-application-group)
- [`virtual-desktop-host-pool`](#rule-virtual-desktop-host-pool)
- [`virtual-desktop-workspace`](#rule-virtual-desktop-workspace)
- [`virtual-hub`](#rule-virtual-hub)
- [`virtual-machine`](#rule-virtual-machine)
- [`virtual-machine-backup-policy`](#rule-virtual-machine-backup-policy)
- [`virtual-machine-scale-set`](#rule-virtual-machine-scale-set)
- [`virtual-network`](#rule-virtual-network)
- [`virtual-network-gateway`](#rule-virtual-network-gateway)
- [`virtual-network-gateway-connection`](#rule-virtual-network-gateway-connection)
- [`virtual-network-manager`](#rule-virtual-network-manager)
- [`virtual-network-peering`](#rule-virtual-network-peering)
- [`virtual-wan`](#rule-virtual-wan)
- [`vmware-private-cloud`](#rule-vmware-private-cloud)
- [`vpn-gateway`](#rule-vpn-gateway)
- [`vpn-site`](#rule-vpn-site)
- [`web-application-firewall-policy`](#rule-web-application-firewall-policy)
- [`web-pubsub`](#rule-web-pubsub)
- [`windows-function-app`](#rule-windows-function-app)
- [`windows-virtual-machine`](#rule-windows-virtual-machine)
- [`windows-virtual-machine-scale-set`](#rule-windows-virtual-machine-scale-set)
- [`windows-web-app`](#rule-windows-web-app)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-route-table"><code>azure.concept.route-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/routing.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure route table controlling subnet traffic paths.

</dd>
<dd>

Used by [`route-server`](#rule-route-server), [`route-table`](#rule-route-table).

</dd>
</div>

<div>
<dt id="azure-concept-security-detail"><code>azure.concept.security-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/concepts.rf.hcl#L10-L12">Source</a></dt>
<dd>

A certificate, access policy, alert, connector, or security configuration.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`advanced-threat-protection`](#rule-advanced-threat-protection)
- [`key-vault-access-policy`](#rule-key-vault-access-policy)
- [`key-vault-certificate`](#rule-key-vault-certificate)
- [`sentinel-automation-rule`](#rule-sentinel-automation-rule)
- [`sentinel-aws-cloudtrail-connector`](#rule-sentinel-aws-cloudtrail-connector)
- [`sentinel-entra-connector`](#rule-sentinel-entra-connector)
- [`sentinel-nrt-alert-rule`](#rule-sentinel-nrt-alert-rule)
- [`sentinel-scheduled-alert-rule`](#rule-sentinel-scheduled-alert-rule)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-serverless-function"><code>azure.concept.serverless-function</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L85-L87">Source</a></dt>
<dd>

A managed event-driven function runtime.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`flex-consumption-function-app`](#rule-flex-consumption-function-app)
- [`function-app-function`](#rule-function-app-function)
- [`linux-function-app`](#rule-linux-function-app)
- [`windows-function-app`](#rule-windows-function-app)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-service-bus-topic"><code>azure.concept.service-bus-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/concepts.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Service Bus topic owning durable subscriptions.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`service-bus-subscription`](#rule-service-bus-subscription)
- [`service-bus-topic`](#rule-service-bus-topic)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-service-fabric-cluster"><code>azure.concept.service-fabric-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Service Fabric cluster running distributed applications.

</dd>
<dd>

Used by [`managed-service-fabric-cluster`](#rule-managed-service-fabric-cluster), [`service-fabric-cluster`](#rule-service-fabric-cluster).

</dd>
</div>

<div>
<dt id="azure-concept-service-identity-binding"><code>azure.concept.service-identity-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L89-L91">Source</a></dt>
<dd>

An access-control binding that contributes to a service identity.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="azure-concept-site-recovery-detail"><code>azure.concept.site-recovery-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

A recovery plan, mapping, replicated machine, or protection configuration.

</dd>
<dd>

Used by [`backup-protected-vm`](#rule-backup-protected-vm), [`site-recovery-plan`](#rule-site-recovery-plan), [`site-recovery-replicated-vm`](#rule-site-recovery-replicated-vm).

</dd>
</div>

<div>
<dt id="azure-concept-site-recovery-fabric"><code>azure.concept.site-recovery-fabric</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/site-recovery.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Site Recovery source or target fabric.

</dd>
<dd>

Used by [`site-recovery-fabric`](#rule-site-recovery-fabric), [`site-recovery-protection-container`](#rule-site-recovery-protection-container).

</dd>
</div>

<div>
<dt id="azure-concept-spring-app"><code>azure.concept.spring-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An application deployed in Azure Spring Apps.

</dd>
<dd>

Used by [`spring-app`](#rule-spring-app), [`spring-apps-gateway`](#rule-spring-apps-gateway).

</dd>
</div>

<div>
<dt id="azure-concept-spring-apps-service"><code>azure.concept.spring-apps-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/spring-apps.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Spring Apps service boundary.

</dd>
<dd>

Used by [`spring-apps-service`](#rule-spring-apps-service).

</dd>
</div>

<div>
<dt id="azure-concept-sql-server"><code>azure.concept.sql-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/sql-database.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure SQL logical server owning managed databases.

</dd>
<dd>

Used by [`mssql-database`](#rule-mssql-database), [`mssql-server`](#rule-mssql-server).

</dd>
</div>

<div>
<dt id="azure-concept-sre-agent"><code>azure.concept.sre-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/sre-agent.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure SRE Agent operating against explicitly assigned Azure resources.

</dd>
<dd>

Used by [`sre-agent`](#rule-sre-agent).

</dd>
</div>

<div>
<dt id="azure-concept-static-web-app"><code>azure.concept.static-web-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/static-web.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Static Web Apps site with managed hosting and APIs.

</dd>
<dd>

Used by [`static-web-app`](#rule-static-web-app).

</dd>
</div>

<div>
<dt id="azure-concept-storage-account"><code>azure.concept.storage-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage-account.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Storage account owning data services and their security boundary.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`azure-files-share`](#rule-azure-files-share)
- [`blob-container`](#rule-blob-container)
- [`data-lake-filesystem`](#rule-data-lake-filesystem)
- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`queue-storage-queue`](#rule-queue-storage-queue)
- [`storage-account`](#rule-storage-account)
- [`storage-encryption-scope`](#rule-storage-encryption-scope)
- [`storage-management-policy`](#rule-storage-management-policy)
- [`table-storage-table`](#rule-table-storage-table)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-storage-object-detail"><code>azure.concept.storage-object-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/concepts.rf.hcl#L2-L4">Source</a></dt>
<dd>

An object, path, directory, table entity, or policy inside Azure Storage.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`data-lake-path`](#rule-data-lake-path)
- [`storage-blob`](#rule-storage-blob)
- [`storage-encryption-scope`](#rule-storage-encryption-scope)
- [`storage-management-policy`](#rule-storage-management-policy)
- [`storage-share-directory`](#rule-storage-share-directory)
- [`storage-share-file`](#rule-storage-share-file)
- [`storage-table-entity`](#rule-storage-table-entity)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-storage-sync-service"><code>azure.concept.storage-sync-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure File Sync service synchronizing file servers and Azure Files.

</dd>
<dd>

Used by [`storage-sync-service`](#rule-storage-sync-service).

</dd>
</div>

<div>
<dt id="azure-concept-stream-analytics-job"><code>azure.concept.stream-analytics-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/stream-analytics.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Stream Analytics streaming query job.

</dd>
<dd>

Used by [`stream-analytics-job`](#rule-stream-analytics-job).

</dd>
</div>

<div>
<dt id="azure-concept-synapse-workspace"><code>azure.concept.synapse-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/synapse.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Synapse Analytics workspace.

</dd>
<dd>

Used by [`synapse-workspace`](#rule-synapse-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-table-storage-table"><code>azure.concept.table-storage-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/table-storage.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Table Storage table.

</dd>
<dd>

Used by [`storage-table-entity`](#rule-storage-table-entity), [`table-storage-table`](#rule-table-storage-table).

</dd>
</div>

<div>
<dt id="azure-concept-third-party-monitor"><code>azure.concept.third-party-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/concepts.rf.hcl#L6-L8">Source</a></dt>
<dd>

A third-party observability service managed through Azure.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`datadog-monitor`](#rule-datadog-monitor)
- [`dynatrace-monitor`](#rule-dynatrace-monitor)
- [`elastic-cloud`](#rule-elastic-cloud)
- [`new-relic-monitor`](#rule-new-relic-monitor)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-traffic-manager-profile"><code>azure.concept.traffic-manager-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/traffic-manager.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Traffic Manager DNS traffic-routing profile.

</dd>
<dd>

Used by [`traffic-manager-profile`](#rule-traffic-manager-profile).

</dd>
</div>

<div>
<dt id="azure-concept-trusted-signing-account"><code>azure.concept.trusted-signing-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/trusted-signing.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Artifact Signing account.

</dd>
<dd>

Used by [`trusted-signing-account`](#rule-trusted-signing-account).

</dd>
</div>

<div>
<dt id="azure-concept-video-indexer-account"><code>azure.concept.video-indexer-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/video-indexer.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure AI Video Indexer account.

</dd>
<dd>

Used by [`video-indexer-account`](#rule-video-indexer-account).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-desktop-application-group"><code>azure.concept.virtual-desktop-application-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Virtual Desktop desktop or RemoteApp publication group.

</dd>
<dd>

Used by [`virtual-desktop-application-group`](#rule-virtual-desktop-application-group).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-desktop-host-pool"><code>azure.concept.virtual-desktop-host-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L6-L8">Source</a></dt>
<dd>

An Azure Virtual Desktop host pool providing session hosts.

</dd>
<dd>

Used by [`virtual-desktop-host-pool`](#rule-virtual-desktop-host-pool).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-desktop-workspace"><code>azure.concept.virtual-desktop-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L10-L12">Source</a></dt>
<dd>

An Azure Virtual Desktop workspace publishing application groups.

</dd>
<dd>

Used by [`virtual-desktop-workspace`](#rule-virtual-desktop-workspace).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-hub"><code>azure.concept.virtual-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-hub.rf.hcl#L3-L5">Source</a></dt>
<dd>

An Azure Virtual WAN regional transit hub.

</dd>
<dd>

Used by [`virtual-hub`](#rule-virtual-hub).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-machine-scale-set"><code>azure.concept.virtual-machine-scale-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/vm-scale-set.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure-managed group of virtual machines that scales as one compute workload.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`linux-virtual-machine-scale-set`](#rule-linux-virtual-machine-scale-set)
- [`orchestrated-virtual-machine-scale-set`](#rule-orchestrated-virtual-machine-scale-set)
- [`virtual-machine-scale-set`](#rule-virtual-machine-scale-set)
- [`windows-virtual-machine-scale-set`](#rule-windows-virtual-machine-scale-set)

</details>

</dd>
</div>

<div>
<dt id="azure-concept-virtual-network-manager"><code>azure.concept.virtual-network-manager</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-network.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Virtual Network Manager control plane for network groups and policy.

</dd>
<dd>

Used by [`virtual-network-manager`](#rule-virtual-network-manager).

</dd>
</div>

<div>
<dt id="azure-concept-virtual-wan"><code>azure.concept.virtual-wan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-wan.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure Virtual WAN global transit network.

</dd>
<dd>

Used by [`virtual-wan`](#rule-virtual-wan).

</dd>
</div>

<div>
<dt id="azure-concept-vmware-private-cloud"><code>azure.concept.vmware-private-cloud</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/vmware-solution.rf.hcl#L2-L4">Source</a></dt>
<dd>

An Azure VMware Solution private cloud.

</dd>
<dd>

Used by [`vmware-private-cloud`](#rule-vmware-private-cloud).

</dd>
</div>

<div>
<dt id="azure-concept-vpn-connection"><code>azure.concept.vpn-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L93-L95">Source</a></dt>
<dd>

A virtual private network connection between network endpoints.

</dd>
<dd>

Used by [`virtual-network-gateway-connection`](#rule-virtual-network-gateway-connection), [`vpn-gateway-connection`](#rule-vpn-gateway-connection).

</dd>
</div>

<div>
<dt id="azure-concept-vpn-gateway"><code>azure.concept.vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L97-L99">Source</a></dt>
<dd>

A managed gateway terminating virtual private network connections.

</dd>
<dd>

Used by [`point-to-site-vpn-gateway`](#rule-point-to-site-vpn-gateway), [`virtual-network-gateway`](#rule-virtual-network-gateway), [`vpn-gateway`](#rule-vpn-gateway).

</dd>
</div>

<div>
<dt id="azure-concept-web-application-firewall-policy"><code>azure.concept.web-application-firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L10-L12">Source</a></dt>
<dd>

A reusable Azure Web Application Firewall policy applied to Application Gateway traffic.

</dd>
<dd>

Used by [`application-gateway`](#rule-application-gateway), [`web-application-firewall-policy`](#rule-web-application-firewall-policy).

</dd>
</div>

<div>
<dt id="azure-concept-workflow"><code>azure.concept.workflow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L101-L103">Source</a></dt>
<dd>

A managed workflow coordinating steps and service calls.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`automation-runbook`](#rule-automation-runbook)
- [`data-factory-pipeline`](#rule-data-factory-pipeline)
- [`logic-app-standard`](#rule-logic-app-standard)
- [`logic-app-workflow`](#rule-logic-app-workflow)

</details>

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="azure-context-ownership"><code>azure.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/vocabulary.rf.hcl#L105-L107">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>


<details>
<summary>Used by 257 Rules</summary>

- [`ai-foundry`](#rule-ai-foundry)
- [`ai-search-service`](#rule-ai-search-service)
- [`ai-services-account`](#rule-ai-services-account)
- [`aks-cluster`](#rule-aks-cluster)
- [`analysis-services-server`](#rule-analysis-services-server)
- [`api-management`](#rule-api-management)
- [`api-management-standalone-gateway`](#rule-api-management-standalone-gateway)
- [`app-configuration`](#rule-app-configuration)
- [`app-service-environment`](#rule-app-service-environment)
- [`app-service-plan`](#rule-app-service-plan)
- [`application-gateway`](#rule-application-gateway)
- [`application-insights`](#rule-application-insights)
- [`application-load-balancer`](#rule-application-load-balancer)
- [`arc-custom-location`](#rule-arc-custom-location)
- [`arc-enabled-server`](#rule-arc-enabled-server)
- [`arc-kubernetes-cluster`](#rule-arc-kubernetes-cluster)
- [`arc-private-link-scope`](#rule-arc-private-link-scope)
- [`arc-provisioned-kubernetes-cluster`](#rule-arc-provisioned-kubernetes-cluster)
- [`arc-resource-bridge`](#rule-arc-resource-bridge)
- [`attestation-provider`](#rule-attestation-provider)
- [`automatic-kubernetes-cluster`](#rule-automatic-kubernetes-cluster)
- [`automation-account`](#rule-automation-account)
- [`automation-runbook`](#rule-automation-runbook)
- [`azure-bot`](#rule-azure-bot)
- [`azure-cache-for-redis`](#rule-azure-cache-for-redis)
- [`azure-files-share`](#rule-azure-files-share)
- [`azure-firewall`](#rule-azure-firewall)
- [`azure-local-cluster`](#rule-azure-local-cluster)
- [`azure-managed-redis`](#rule-azure-managed-redis)
- [`bastion-host`](#rule-bastion-host)
- [`batch-account`](#rule-batch-account)
- [`blob-container`](#rule-blob-container)
- [`bot-channels-registration`](#rule-bot-channels-registration)
- [`bot-web-app`](#rule-bot-web-app)
- [`cdn-endpoint`](#rule-cdn-endpoint)
- [`cdn-profile`](#rule-cdn-profile)
- [`chaos-studio-experiment`](#rule-chaos-studio-experiment)
- [`classic-front-door`](#rule-classic-front-door)
- [`communication-service`](#rule-communication-service)
- [`compute-gallery`](#rule-compute-gallery)
- [`compute-image`](#rule-compute-image)
- [`confidential-ledger`](#rule-confidential-ledger)
- [`container-app`](#rule-container-app)
- [`container-app-environment`](#rule-container-app-environment)
- [`container-app-job`](#rule-container-app-job)
- [`container-instance-group`](#rule-container-instance-group)
- [`container-registry`](#rule-container-registry)
- [`cosmos-account`](#rule-cosmos-account)
- [`cosmos-cassandra-cluster`](#rule-cosmos-cassandra-cluster)
- [`cosmos-cassandra-keyspace`](#rule-cosmos-cassandra-keyspace)
- [`cosmos-gremlin-database`](#rule-cosmos-gremlin-database)
- [`cosmos-mongo-database`](#rule-cosmos-mongo-database)
- [`cosmos-postgresql-cluster`](#rule-cosmos-postgresql-cluster)
- [`cosmos-sql-container`](#rule-cosmos-sql-container)
- [`cosmos-sql-database`](#rule-cosmos-sql-database)
- [`custom-ip-prefix`](#rule-custom-ip-prefix)
- [`data-box-edge-device`](#rule-data-box-edge-device)
- [`data-explorer-cluster`](#rule-data-explorer-cluster)
- [`data-factory`](#rule-data-factory)
- [`data-lake-filesystem`](#rule-data-lake-filesystem)
- [`data-protection-backup-vault`](#rule-data-protection-backup-vault)
- [`data-share-account`](#rule-data-share-account)
- [`database-migration-project`](#rule-database-migration-project)
- [`database-migration-service`](#rule-database-migration-service)
- [`databricks-virtual-network-peering`](#rule-databricks-virtual-network-peering)
- [`databricks-workspace`](#rule-databricks-workspace)
- [`datadog-monitor`](#rule-datadog-monitor)
- [`ddos-protection-plan`](#rule-ddos-protection-plan)
- [`dedicated-hardware-security-module`](#rule-dedicated-hardware-security-module)
- [`dedicated-host-group`](#rule-dedicated-host-group)
- [`dev-center`](#rule-dev-center)
- [`dev-center-project`](#rule-dev-center-project)
- [`dev-test-lab`](#rule-dev-test-lab)
- [`dev-test-linux-virtual-machine`](#rule-dev-test-linux-virtual-machine)
- [`dev-test-windows-virtual-machine`](#rule-dev-test-windows-virtual-machine)
- [`digital-twins-instance`](#rule-digital-twins-instance)
- [`disk-snapshot`](#rule-disk-snapshot)
- [`dns-a-record`](#rule-dns-a-record)
- [`dns-aaaa-record`](#rule-dns-aaaa-record)
- [`dns-cname-record`](#rule-dns-cname-record)
- [`dns-mx-record`](#rule-dns-mx-record)
- [`dns-ns-record`](#rule-dns-ns-record)
- [`dns-ptr-record`](#rule-dns-ptr-record)
- [`dns-srv-record`](#rule-dns-srv-record)
- [`dns-txt-record`](#rule-dns-txt-record)
- [`dns-zone`](#rule-dns-zone)
- [`dynatrace-monitor`](#rule-dynatrace-monitor)
- [`elastic-cloud`](#rule-elastic-cloud)
- [`elastic-san`](#rule-elastic-san)
- [`email-communication-service`](#rule-email-communication-service)
- [`entra-domain-services`](#rule-entra-domain-services)
- [`entra-external-id-directory`](#rule-entra-external-id-directory)
- [`event-grid-domain`](#rule-event-grid-domain)
- [`event-grid-domain-topic`](#rule-event-grid-domain-topic)
- [`event-grid-event-subscription`](#rule-event-grid-event-subscription)
- [`event-grid-namespace`](#rule-event-grid-namespace)
- [`event-grid-namespace-topic`](#rule-event-grid-namespace-topic)
- [`event-grid-partner-namespace`](#rule-event-grid-partner-namespace)
- [`event-grid-system-topic`](#rule-event-grid-system-topic)
- [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription)
- [`event-grid-topic`](#rule-event-grid-topic)
- [`event-hub`](#rule-event-hub)
- [`event-hubs-cluster`](#rule-event-hubs-cluster)
- [`event-hubs-consumer-group`](#rule-event-hubs-consumer-group)
- [`event-hubs-namespace`](#rule-event-hubs-namespace)
- [`expressroute-circuit`](#rule-expressroute-circuit)
- [`expressroute-gateway`](#rule-expressroute-gateway)
- [`expressroute-port`](#rule-expressroute-port)
- [`fabric-capacity`](#rule-fabric-capacity)
- [`file-share-backup-policy`](#rule-file-share-backup-policy)
- [`flex-consumption-function-app`](#rule-flex-consumption-function-app)
- [`fluid-relay`](#rule-fluid-relay)
- [`front-door-profile`](#rule-front-door-profile)
- [`graph-data-connect-account`](#rule-graph-data-connect-account)
- [`hdinsight-hadoop-cluster`](#rule-hdinsight-hadoop-cluster)
- [`hdinsight-hbase-cluster`](#rule-hdinsight-hbase-cluster)
- [`hdinsight-interactive-query-cluster`](#rule-hdinsight-interactive-query-cluster)
- [`hdinsight-kafka-cluster`](#rule-hdinsight-kafka-cluster)
- [`hdinsight-spark-cluster`](#rule-hdinsight-spark-cluster)
- [`health-bot`](#rule-health-bot)
- [`health-data-fhir-service`](#rule-health-data-fhir-service)
- [`health-data-services-workspace`](#rule-health-data-services-workspace)
- [`healthcare-service`](#rule-healthcare-service)
- [`iot-central-application`](#rule-iot-central-application)
- [`iot-hub`](#rule-iot-hub)
- [`iot-hub-device-provisioning-service`](#rule-iot-hub-device-provisioning-service)
- [`iot-hub-device-update-account`](#rule-iot-hub-device-update-account)
- [`key-vault`](#rule-key-vault)
- [`key-vault-key`](#rule-key-vault-key)
- [`key-vault-secret`](#rule-key-vault-secret)
- [`kubernetes-fleet`](#rule-kubernetes-fleet)
- [`linux-function-app`](#rule-linux-function-app)
- [`linux-virtual-machine`](#rule-linux-virtual-machine)
- [`linux-virtual-machine-scale-set`](#rule-linux-virtual-machine-scale-set)
- [`linux-web-app`](#rule-linux-web-app)
- [`load-balancer`](#rule-load-balancer)
- [`load-test`](#rule-load-test)
- [`local-network-gateway`](#rule-local-network-gateway)
- [`log-analytics-cluster`](#rule-log-analytics-cluster)
- [`log-analytics-solution`](#rule-log-analytics-solution)
- [`log-analytics-workspace`](#rule-log-analytics-workspace)
- [`logic-app-integration-account`](#rule-logic-app-integration-account)
- [`logic-app-standard`](#rule-logic-app-standard)
- [`logic-app-workflow`](#rule-logic-app-workflow)
- [`machine-learning-workspace`](#rule-machine-learning-workspace)
- [`maintenance-configuration`](#rule-maintenance-configuration)
- [`managed-application`](#rule-managed-application)
- [`managed-devops-pool`](#rule-managed-devops-pool)
- [`managed-disk`](#rule-managed-disk)
- [`managed-grafana`](#rule-managed-grafana)
- [`managed-hsm`](#rule-managed-hsm)
- [`managed-hsm-key`](#rule-managed-hsm-key)
- [`managed-lustre-file-system`](#rule-managed-lustre-file-system)
- [`managed-service-fabric-cluster`](#rule-managed-service-fabric-cluster)
- [`maps-account`](#rule-maps-account)
- [`mongo-cluster`](#rule-mongo-cluster)
- [`monitor-private-link-scope`](#rule-monitor-private-link-scope)
- [`monitor-workspace`](#rule-monitor-workspace)
- [`mssql-database`](#rule-mssql-database)
- [`mssql-server`](#rule-mssql-server)
- [`mysql-database`](#rule-mysql-database)
- [`mysql-flexible-server`](#rule-mysql-flexible-server)
- [`nat-gateway`](#rule-nat-gateway)
- [`netapp-account`](#rule-netapp-account)
- [`netapp-backup-policy`](#rule-netapp-backup-policy)
- [`netapp-backup-vault`](#rule-netapp-backup-vault)
- [`netapp-capacity-pool`](#rule-netapp-capacity-pool)
- [`netapp-volume`](#rule-netapp-volume)
- [`network-function-traffic-collector`](#rule-network-function-traffic-collector)
- [`network-security-group`](#rule-network-security-group)
- [`network-security-perimeter`](#rule-network-security-perimeter)
- [`network-watcher`](#rule-network-watcher)
- [`new-relic-monitor`](#rule-new-relic-monitor)
- [`nginx-deployment`](#rule-nginx-deployment)
- [`notification-hub`](#rule-notification-hub)
- [`notification-hubs-namespace`](#rule-notification-hubs-namespace)
- [`oracle-autonomous-database`](#rule-oracle-autonomous-database)
- [`oracle-cloud-vm-cluster`](#rule-oracle-cloud-vm-cluster)
- [`oracle-exadata-infrastructure`](#rule-oracle-exadata-infrastructure)
- [`oracle-resource-anchor`](#rule-oracle-resource-anchor)
- [`orchestrated-virtual-machine-scale-set`](#rule-orchestrated-virtual-machine-scale-set)
- [`palo-alto-firewall`](#rule-palo-alto-firewall)
- [`playwright-workspace`](#rule-playwright-workspace)
- [`point-to-site-vpn-gateway`](#rule-point-to-site-vpn-gateway)
- [`postgresql-flexible-server`](#rule-postgresql-flexible-server)
- [`power-bi-embedded-capacity`](#rule-power-bi-embedded-capacity)
- [`private-dns-a-record`](#rule-private-dns-a-record)
- [`private-dns-cname-record`](#rule-private-dns-cname-record)
- [`private-dns-resolver`](#rule-private-dns-resolver)
- [`private-dns-zone`](#rule-private-dns-zone)
- [`private-dns-zone-vnet-link`](#rule-private-dns-zone-vnet-link)
- [`private-endpoint`](#rule-private-endpoint)
- [`private-link-service`](#rule-private-link-service)
- [`public-address`](#rule-public-address)
- [`public-ip-prefix`](#rule-public-ip-prefix)
- [`purview-account`](#rule-purview-account)
- [`queue-storage-queue`](#rule-queue-storage-queue)
- [`qumulo-file-system`](#rule-qumulo-file-system)
- [`recovery-services-vault`](#rule-recovery-services-vault)
- [`red-hat-openshift-cluster`](#rule-red-hat-openshift-cluster)
- [`relay-hybrid-connection`](#rule-relay-hybrid-connection)
- [`relay-namespace`](#rule-relay-namespace)
- [`route-server`](#rule-route-server)
- [`route-table`](#rule-route-table)
- [`sap-discovery-virtual-instance`](#rule-sap-discovery-virtual-instance)
- [`sap-single-node-virtual-instance`](#rule-sap-single-node-virtual-instance)
- [`sap-three-tier-virtual-instance`](#rule-sap-three-tier-virtual-instance)
- [`service-bus-namespace`](#rule-service-bus-namespace)
- [`service-bus-queue`](#rule-service-bus-queue)
- [`service-bus-subscription`](#rule-service-bus-subscription)
- [`service-bus-topic`](#rule-service-bus-topic)
- [`service-fabric-cluster`](#rule-service-fabric-cluster)
- [`shared-image`](#rule-shared-image)
- [`signalr-service`](#rule-signalr-service)
- [`site-recovery-fabric`](#rule-site-recovery-fabric)
- [`site-recovery-protection-container`](#rule-site-recovery-protection-container)
- [`spring-app`](#rule-spring-app)
- [`spring-apps-service`](#rule-spring-apps-service)
- [`sql-managed-instance`](#rule-sql-managed-instance)
- [`stack-hci-virtual-hard-disk`](#rule-stack-hci-virtual-hard-disk)
- [`static-web-app`](#rule-static-web-app)
- [`storage-account`](#rule-storage-account)
- [`storage-mover`](#rule-storage-mover)
- [`storage-sync-service`](#rule-storage-sync-service)
- [`stream-analytics-cluster`](#rule-stream-analytics-cluster)
- [`stream-analytics-job`](#rule-stream-analytics-job)
- [`subnet`](#rule-subnet)
- [`synapse-private-link-hub`](#rule-synapse-private-link-hub)
- [`synapse-workspace`](#rule-synapse-workspace)
- [`system-center-vmm-server`](#rule-system-center-vmm-server)
- [`table-storage-table`](#rule-table-storage-table)
- [`traffic-manager-profile`](#rule-traffic-manager-profile)
- [`trusted-signing-account`](#rule-trusted-signing-account)
- [`user-assigned-managed-identity`](#rule-user-assigned-managed-identity)
- [`video-indexer-account`](#rule-video-indexer-account)
- [`virtual-desktop-application-group`](#rule-virtual-desktop-application-group)
- [`virtual-desktop-host-pool`](#rule-virtual-desktop-host-pool)
- [`virtual-desktop-workspace`](#rule-virtual-desktop-workspace)
- [`virtual-hub`](#rule-virtual-hub)
- [`virtual-machine`](#rule-virtual-machine)
- [`virtual-machine-backup-policy`](#rule-virtual-machine-backup-policy)
- [`virtual-machine-scale-set`](#rule-virtual-machine-scale-set)
- [`virtual-network`](#rule-virtual-network)
- [`virtual-network-gateway`](#rule-virtual-network-gateway)
- [`virtual-network-gateway-connection`](#rule-virtual-network-gateway-connection)
- [`virtual-network-manager`](#rule-virtual-network-manager)
- [`virtual-network-peering`](#rule-virtual-network-peering)
- [`virtual-wan`](#rule-virtual-wan)
- [`vmware-private-cloud`](#rule-vmware-private-cloud)
- [`vpn-gateway`](#rule-vpn-gateway)
- [`vpn-site`](#rule-vpn-site)
- [`web-application-firewall-policy`](#rule-web-application-firewall-policy)
- [`web-pubsub`](#rule-web-pubsub)
- [`windows-function-app`](#rule-windows-function-app)
- [`windows-virtual-machine`](#rule-windows-virtual-machine)
- [`windows-virtual-machine-scale-set`](#rule-windows-virtual-machine-scale-set)
- [`windows-web-app`](#rule-windows-web-app)

</details>

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="azure-relation-delivers-to"><code>azure.relation.delivers-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L101-L111">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`event-grid-event-subscription`](#rule-event-grid-event-subscription), [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription).

</dd>
</div>

<div>
<dt id="azure-relation-observed-by"><code>azure.relation.observed-by</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/aks.rf.hcl#L51-L64">Source</a></dt>
<dd>

Introduced by a labeled emission.

<details>
<summary>Used by 5 Rules</summary>

- [`aks-cluster`](#rule-aks-cluster)
- [`application-insights`](#rule-application-insights)
- [`container-app-environment`](#rule-container-app-environment)
- [`linux-function-app`](#rule-linux-function-app)
- [`windows-function-app`](#rule-windows-function-app)

</details>

</dd>
</div>

<div>
<dt id="azure-relation-peers-with"><code>azure.relation.peers-with</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-network.rf.hcl#L69-L82">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`virtual-network-peering`](#rule-virtual-network-peering).

</dd>
</div>

<div>
<dt id="azure-relation-private-name-resolution"><code>azure.relation.private-name-resolution</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases-topology.rf.hcl#L24-L37">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`postgresql-flexible-server`](#rule-postgresql-flexible-server).

</dd>
</div>

<div>
<dt id="azure-relation-subscribes-to"><code>azure.relation.subscribes-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L89-L99">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`event-grid-event-subscription`](#rule-event-grid-event-subscription), [`event-grid-system-topic-subscription`](#rule-event-grid-system-topic-subscription), [`service-bus-subscription`](#rule-service-bus-subscription).

</dd>
</div>

<div>
<dt id="azure-relation-uses-waf-policy"><code>azure.relation.uses-waf-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancers.rf.hcl#L82-L92">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`application-gateway`](#rule-application-gateway).

</dd>
</div>

</dl>

## RF Vocabulary used

- [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster)
- [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database)
- [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container)
- [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity)
- [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet)
- [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network)
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network)
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime)

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>azure.rule.azure-enclave</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/azure-enclave.rf.hcl#L6-L13">Source</a></summary>

<div id="rule-azure-enclave"></div>

Matches `resource` instances of `azapi_resource`.

**Classification:** [`azure.concept.azure-enclave`](#azure-concept-azure-enclave).

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.type == "Microsoft.Mission/virtualEnclaves@2026-03-01-preview"
```

</details>

</details>

<details>
<summary><code>azure.rule.horizondb-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/horizondb-cluster.rf.hcl#L2-L9">Source</a></summary>

<div id="rule-horizondb-cluster"></div>

Matches `resource` instances of `azapi_resource`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.type == "Microsoft.HorizonDb/clusters@2026-01-20-preview"
```

</details>

</details>

<details>
<summary><code>azure.rule.sre-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/sre-agent.rf.hcl#L6-L13">Source</a></summary>

<div id="rule-sre-agent"></div>

Matches `resource` instances of `azapi_resource`.

**Classification:** [`azure.concept.sre-agent`](#azure-concept-sre-agent).

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.type == "Microsoft.App/agents@2026-01-01"
```

</details>

</details>

<details>
<summary><code>azure.rule.entra-access-package-assignment-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L24-L30">Source</a></summary>

<div id="rule-entra-access-package-assignment-policy"></div>

Matches `resource` instances of `azuread_access_package_assignment_policy`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-app-role-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-entra-app-role-assignment"></div>

Matches `resource` instances of `azuread_app_role_assignment`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-application-federated-identity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L50-L56">Source</a></summary>

<div id="rule-entra-application-federated-identity"></div>

Matches `resource` instances of `azuread_application_federated_identity_credential`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-application-registration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L58-L64">Source</a></summary>

<div id="rule-entra-application-registration"></div>

Matches `resource` instances of `azuread_application_registration`.

**Classification:** [`azure.concept.entra-application`](#azure-concept-entra-application).

</details>

<details>
<summary><code>azure.rule.entra-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-entra-application"></div>

Matches `resource` instances of `azuread_application`.

**Classification:** [`azure.concept.entra-application`](#azure-concept-entra-application).

</details>

<details>
<summary><code>azure.rule.entra-authentication-strength-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L66-L72">Source</a></summary>

<div id="rule-entra-authentication-strength-policy"></div>

Matches `resource` instances of `azuread_authentication_strength_policy`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-group-without-members</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L147-L153">Source</a></summary>

<div id="rule-entra-group-without-members"></div>

Matches `resource` instances of `azuread_group_without_members`.

**Classification:** [`azure.concept.identity-group`](#azure-concept-identity-group).

</details>

<details>
<summary><code>azure.rule.entra-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L139-L145">Source</a></summary>

<div id="rule-entra-group"></div>

Matches `resource` instances of `azuread_group`.

**Classification:** [`azure.concept.identity-group`](#azure-concept-identity-group).

</details>

<details>
<summary><code>azure.rule.entra-named-location</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L155-L161">Source</a></summary>

<div id="rule-entra-named-location"></div>

Matches `resource` instances of `azuread_named_location`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-service-principal</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L163-L178">Source</a></summary>

<div id="rule-entra-service-principal"></div>

Matches `resource` instances of `azuread_service_principal`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["client_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["client_id"]`

</details>

</details>

<details>
<summary><code>azure.rule.entra-external-id-directory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L115-L137">Source</a></summary>

<div id="rule-entra-external-id-directory"></div>

Matches `resource` instances of `azurerm_aadb2c_directory`.

**Classification:** [`azure.concept.entra-directory`](#azure-concept-entra-directory).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.entra-domain-services-replica-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L99-L105">Source</a></summary>

<div id="rule-entra-domain-services-replica-set"></div>

Matches `resource` instances of `azurerm_active_directory_domain_service_replica_set`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-domain-services-trust</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L107-L113">Source</a></summary>

<div id="rule-entra-domain-services-trust"></div>

Matches `resource` instances of `azurerm_active_directory_domain_service_trust`.

**Classification:** [`azure.concept.identity-governance-detail`](#azure-concept-identity-governance-detail).

</details>

<details>
<summary><code>azure.rule.entra-domain-services</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/entra-id.rf.hcl#L75-L97">Source</a></summary>

<div id="rule-entra-domain-services"></div>

Matches `resource` instances of `azurerm_active_directory_domain_service`.

**Classification:** [`azure.concept.entra-domain-service`](#azure-concept-entra-domain-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.advanced-threat-protection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/advanced-threat.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-advanced-threat-protection"></div>

Matches `resource` instances of `azurerm_advanced_threat_protection`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.ai-foundry-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-ai-foundry-project"></div>

Matches `resource` instances of `azurerm_ai_foundry_project`.

**Classification:** [`azure.concept.ai-foundry`](#azure-concept-ai-foundry).

</details>

<details>
<summary><code>azure.rule.ai-foundry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-ai-foundry"></div>

Matches `resource` instances of `azurerm_ai_foundry`.

**Classification:** [`azure.concept.ai-foundry`](#azure-concept-ai-foundry).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.analysis-services-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/analysis-services.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-analysis-services-server"></div>

Matches `resource` instances of `azurerm_analysis_services_server`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.api-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/integration-connections.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-api-connection"></div>

Matches `resource` instances of `azurerm_api_connection`.

**Classification:** [`azure.concept.integration-connection`](#azure-concept-integration-connection).

</details>

<details>
<summary><code>azure.rule.api-management-api</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-api-management-api"></div>

Matches `resource` instances of `azurerm_api_management_api`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-api-management-backend"></div>

Matches `resource` instances of `azurerm_api_management_backend`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-api-management-gateway"></div>

Matches `resource` instances of `azurerm_api_management_gateway`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L50-L56">Source</a></summary>

<div id="rule-api-management-policy"></div>

Matches `resource` instances of `azurerm_api_management_policy`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management-product</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L58-L64">Source</a></summary>

<div id="rule-api-management-product"></div>

Matches `resource` instances of `azurerm_api_management_product`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management-standalone-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L66-L88">Source</a></summary>

<div id="rule-api-management-standalone-gateway"></div>

Matches `resource` instances of `azurerm_api_management_standalone_gateway`.

**Classification:** [`azure.concept.api-gateway`](#azure-concept-api-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.api-management-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L90-L96">Source</a></summary>

<div id="rule-api-management-workspace"></div>

Matches `resource` instances of `azurerm_api_management_workspace`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.api-management</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/api-management.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-api-management"></div>

Matches `resource` instances of `azurerm_api_management`.

**Classification:** [`azure.concept.api-gateway`](#azure-concept-api-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.app-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/app-configuration.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-app-configuration"></div>

Matches `resource` instances of `azurerm_app_configuration`.

**Classification:** [`azure.concept.app-configuration`](#azure-concept-app-configuration).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.app-service-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/app-service.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-app-service-connection"></div>

Matches `resource` instances of `azurerm_app_service_connection`.

**Classification:** [`azure.concept.integration-connection`](#azure-concept-integration-connection).

</details>

<details>
<summary><code>azure.rule.app-service-environment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-app-service-environment"></div>

Matches `resource` instances of `azurerm_app_service_environment_v3`.

**Classification:** [`azure.concept.app-service-environment`](#azure-concept-app-service-environment).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.application-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancers.rf.hcl#L34-L93">Source</a></summary>

<div id="rule-application-gateway"></div>

Matches `resource` instances of `azurerm_application_gateway`.

**Classification:** [`azure.concept.load-balancer`](#azure-concept-load-balancer).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.gateway_ip_configuration[0].subnet_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Relations**

- [`azure.relation.uses-waf-policy`](#azure-relation-uses-waf-policy): targets [`azure.concept.web-application-firewall-policy`](#azure-concept-web-application-firewall-policy) through `source.firewall_policy_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.gateway_ip_configuration[0].subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.firewall_policy_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.application-insights-web-test</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L66-L72">Source</a></summary>

<div id="rule-application-insights-web-test"></div>

Matches `resource` instances of `azurerm_application_insights_standard_web_test`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.application-insights</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L18-L64">Source</a></summary>

<div id="rule-application-insights"></div>

Matches `resource` instances of `azurerm_application_insights`.

**Classification:** [`azure.concept.application-insights`](#azure-concept-application-insights).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Relations**

- [`azure.relation.observed-by`](#azure-relation-observed-by): targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.workspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "connection_string"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "connection_string", "instrumentation_key"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.workspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.application-load-balancer-frontend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancer.rf.hcl#L35-L41">Source</a></summary>

<div id="rule-application-load-balancer-frontend"></div>

Matches `resource` instances of `azurerm_application_load_balancer_frontend`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.application-load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancer.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-application-load-balancer"></div>

Matches `resource` instances of `azurerm_application_load_balancer`.

**Classification:** [`azure.concept.load-balancer`](#azure-concept-load-balancer).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.application-security-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-application-security-group"></div>

Matches `resource` instances of `azurerm_application_security_group`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.arc-kubernetes-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/arc.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-arc-kubernetes-cluster"></div>

Matches `resource` instances of `azurerm_arc_kubernetes_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.arc-provisioned-kubernetes-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/arc.rf.hcl#L35-L66">Source</a></summary>

<div id="rule-arc-provisioned-kubernetes-cluster"></div>

Matches `resource` instances of `azurerm_arc_kubernetes_provisioned_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.arc-enabled-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L38-L60">Source</a></summary>

<div id="rule-arc-enabled-server"></div>

Matches `resource` instances of `azurerm_arc_machine`.

**Classification:** [`azure.concept.arc-enabled-server`](#azure-concept-arc-enabled-server).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.arc-private-link-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/arc.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-arc-private-link-scope"></div>

Matches `resource` instances of `azurerm_arc_private_link_scope`.

**Classification:** [`azure.concept.private-link-scope`](#azure-concept-private-link-scope).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.arc-resource-bridge</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L62-L84">Source</a></summary>

<div id="rule-arc-resource-bridge"></div>

Matches `resource` instances of `azurerm_arc_resource_bridge_appliance`.

**Classification:** [`azure.concept.arc-resource-bridge`](#azure-concept-arc-resource-bridge).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.attestation-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/attestation-provider.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-attestation-provider"></div>

Matches `resource` instances of `azurerm_attestation_provider`.

**Classification:** [`azure.concept.attestation-provider`](#azure-concept-attestation-provider).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.automation-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/automation-account.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-automation-account"></div>

Matches `resource` instances of `azurerm_automation_account`.

**Classification:** [`azure.concept.automation-account`](#azure-concept-automation-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.automation-runbook</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/automation-runbook.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-automation-runbook"></div>

Matches `resource` instances of `azurerm_automation_runbook`.

**Classification:** [`azure.concept.workflow`](#azure-concept-workflow).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.automation-schedule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/automation-schedule.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-automation-schedule"></div>

Matches `resource` instances of `azurerm_automation_schedule`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.availability-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-availability-set"></div>

Matches `resource` instances of `azurerm_availability_set`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.file-share-backup-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/backup.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-file-share-backup-policy"></div>

Matches `resource` instances of `azurerm_backup_policy_file_share`.

**Classification:** [`azure.concept.backup-plan`](#azure-concept-backup-plan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-machine-backup-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/backup.rf.hcl#L58-L80">Source</a></summary>

<div id="rule-virtual-machine-backup-policy"></div>

Matches `resource` instances of `azurerm_backup_policy_vm`.

**Classification:** [`azure.concept.backup-plan`](#azure-concept-backup-plan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.backup-protected-vm</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/backup.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-backup-protected-vm"></div>

Matches `resource` instances of `azurerm_backup_protected_vm`.

**Classification:** [`azure.concept.site-recovery-detail`](#azure-concept-site-recovery-detail).

</details>

<details>
<summary><code>azure.rule.bastion-host</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/bastion.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-bastion-host"></div>

Matches `resource` instances of `azurerm_bastion_host`.

**Classification:** [`azure.concept.bastion-host`](#azure-concept-bastion-host).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.batch-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/batch.rf.hcl#L11-L33">Source</a></summary>

<div id="rule-batch-account"></div>

Matches `resource` instances of `azurerm_batch_account`.

**Classification:** [`azure.concept.batch-account`](#azure-concept-batch-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.batch-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/batch.rf.hcl#L35-L41">Source</a></summary>

<div id="rule-batch-application"></div>

Matches `resource` instances of `azurerm_batch_application`.

**Classification:** [`azure.concept.batch-pool`](#azure-concept-batch-pool).

</details>

<details>
<summary><code>azure.rule.batch-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/batch.rf.hcl#L44-L50">Source</a></summary>

<div id="rule-batch-pool"></div>

Matches `resource` instances of `azurerm_batch_pool`.

**Classification:** [`azure.concept.batch-pool`](#azure-concept-batch-pool).

</details>

<details>
<summary><code>azure.rule.bot-channels-registration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/bot-services.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-bot-channels-registration"></div>

Matches `resource` instances of `azurerm_bot_channels_registration`.

**Classification:** [`azure.concept.bot-service`](#azure-concept-bot-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.azure-bot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/bot-services.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-azure-bot"></div>

Matches `resource` instances of `azurerm_bot_service_azure_bot`.

**Classification:** [`azure.concept.bot-service`](#azure-concept-bot-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.bot-web-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/bot-services.rf.hcl#L54-L76">Source</a></summary>

<div id="rule-bot-web-app"></div>

Matches `resource` instances of `azurerm_bot_web_app`.

**Classification:** [`azure.concept.bot-service`](#azure-concept-bot-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.capacity-reservation-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L22-L28">Source</a></summary>

<div id="rule-capacity-reservation-group"></div>

Matches `resource` instances of `azurerm_capacity_reservation_group`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.capacity-reservation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L14-L20">Source</a></summary>

<div id="rule-capacity-reservation"></div>

Matches `resource` instances of `azurerm_capacity_reservation`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.cdn-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/cdn.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-cdn-endpoint"></div>

Matches `resource` instances of `azurerm_cdn_endpoint`.

**Classification:** [`azure.concept.content-delivery-profile`](#azure-concept-content-delivery-profile).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.front-door-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L30-L36">Source</a></summary>

<div id="rule-front-door-endpoint"></div>

Matches `resource` instances of `azurerm_cdn_frontdoor_endpoint`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.front-door-origin-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L46-L52">Source</a></summary>

<div id="rule-front-door-origin-group"></div>

Matches `resource` instances of `azurerm_cdn_frontdoor_origin_group`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.front-door-origin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L38-L44">Source</a></summary>

<div id="rule-front-door-origin"></div>

Matches `resource` instances of `azurerm_cdn_frontdoor_origin`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.front-door-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L54-L76">Source</a></summary>

<div id="rule-front-door-profile"></div>

Matches `resource` instances of `azurerm_cdn_frontdoor_profile`.

**Classification:** [`azure.concept.front-door-profile`](#azure-concept-front-door-profile).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.front-door-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L78-L84">Source</a></summary>

<div id="rule-front-door-route"></div>

Matches `resource` instances of `azurerm_cdn_frontdoor_route`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.cdn-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/cdn.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-cdn-profile"></div>

Matches `resource` instances of `azurerm_cdn_profile`.

**Classification:** [`azure.concept.content-delivery-profile`](#azure-concept-content-delivery-profile).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.chaos-studio-experiment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/chaos-studio.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-chaos-studio-experiment"></div>

Matches `resource` instances of `azurerm_chaos_studio_experiment`.

**Classification:** [`azure.concept.chaos-experiment`](#azure-concept-chaos-experiment).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.ai-services-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-ai-services-project"></div>

Matches `resource` instances of `azurerm_cognitive_account_project`.

**Classification:** [`azure.concept.ai-foundry`](#azure-concept-ai-foundry).

</details>

<details>
<summary><code>azure.rule.ai-services-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-services.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-ai-services-account"></div>

Matches `resource` instances of `azurerm_cognitive_account`.

**Classification:** [`azure.concept.ai-service-account`](#azure-concept-ai-service-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.ai-model-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-model.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-ai-model-deployment"></div>

Matches `resource` instances of `azurerm_cognitive_deployment`.

**Classification:** [`azure.concept.ai-inference-endpoint`](#azure-concept-ai-inference-endpoint).

</details>

<details>
<summary><code>azure.rule.communication-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/communication-services.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-communication-service"></div>

Matches `resource` instances of `azurerm_communication_service`.

**Classification:** [`azure.concept.communication-service`](#azure-concept-communication-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.confidential-ledger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/confidential-ledger.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-confidential-ledger"></div>

Matches `resource` instances of `azurerm_confidential_ledger`.

**Classification:** [`azure.concept.confidential-ledger`](#azure-concept-confidential-ledger).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.container-app-environment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L54-L116">Source</a></summary>

<div id="rule-container-app-environment"></div>

Matches `resource` instances of `azurerm_container_app_environment`.

**Classification:** [`azure.concept.container-app-environment`](#azure-concept-container-app-environment).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.infrastructure_subnet_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Relations**

- [`azure.relation.observed-by`](#azure-relation-observed-by): targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.log_analytics_workspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.infrastructure_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.log_analytics_workspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.container-app-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L118-L153">Source</a></summary>

<div id="rule-container-app-job"></div>

Matches `resource` instances of `azurerm_container_app_job`.

**Classification:** [`azure.concept.container-app-job`](#azure-concept-container-app-job).

**Contexts**

- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.container-app-environment`](#azure-concept-container-app-environment) through `source.container_app_environment_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.container_app_environment_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.container-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-apps.rf.hcl#L14-L52">Source</a></summary>

<div id="rule-container-app"></div>

Matches `resource` instances of `azurerm_container_app`.

**Classification:** [`azure.concept.container-app`](#azure-concept-container-app).

**Contexts**

- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.container-app-environment`](#azure-concept-container-app-environment) through `source.container_app_environment_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.container_app_environment_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.connected-container-registry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-registry.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-connected-container-registry"></div>

Matches `resource` instances of `azurerm_container_connected_registry`.

**Classification:** [`azure.concept.container-registry`](#azure-concept-container-registry).

</details>

<details>
<summary><code>azure.rule.container-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-instances.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-container-instance-group"></div>

Matches `resource` instances of `azurerm_container_group`.

**Classification:** [`azure.concept.container-instance-group`](#azure-concept-container-instance-group).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.container-registry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/container-registry.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-container-registry"></div>

Matches `resource` instances of `azurerm_container_registry`.

**Classification:** [`azure.concept.container-registry`](#azure-concept-container-registry).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L6-L37">Source</a></summary>

<div id="rule-cosmos-account"></div>

Matches `resource` instances of `azurerm_cosmosdb_account`.

**Classification:** [`azure.concept.cosmos-account`](#azure-concept-cosmos-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-cassandra-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L39-L61">Source</a></summary>

<div id="rule-cosmos-cassandra-cluster"></div>

Matches `resource` instances of `azurerm_cosmosdb_cassandra_cluster`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-cassandra-keyspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L63-L91">Source</a></summary>

<div id="rule-cosmos-cassandra-keyspace"></div>

Matches `resource` instances of `azurerm_cosmosdb_cassandra_keyspace`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.cosmos-account`](#azure-concept-cosmos-account) through `source.account_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.account_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-cassandra-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L93-L111">Source</a></summary>

<div id="rule-cosmos-cassandra-table"></div>

Matches `resource` instances of `azurerm_cosmosdb_cassandra_table`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

**Contributions**

- targets [`azure.concept.logical-database`](#azure-concept-logical-database) through `source.cassandra_keyspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.cassandra_keyspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-gremlin-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L133-L161">Source</a></summary>

<div id="rule-cosmos-gremlin-database"></div>

Matches `resource` instances of `azurerm_cosmosdb_gremlin_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.cosmos-account`](#azure-concept-cosmos-account) through `source.account_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.account_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-gremlin-graph</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L163-L181">Source</a></summary>

<div id="rule-cosmos-gremlin-graph"></div>

Matches `resource` instances of `azurerm_cosmosdb_gremlin_graph`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

**Contributions**

- targets [`azure.concept.logical-database`](#azure-concept-logical-database) through `source.database_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.database_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-mongo-collection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L183-L201">Source</a></summary>

<div id="rule-cosmos-mongo-collection"></div>

Matches `resource` instances of `azurerm_cosmosdb_mongo_collection`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

**Contributions**

- targets [`azure.concept.logical-database`](#azure-concept-logical-database) through `source.database_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.database_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-mongo-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L203-L231">Source</a></summary>

<div id="rule-cosmos-mongo-database"></div>

Matches `resource` instances of `azurerm_cosmosdb_mongo_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.cosmos-account`](#azure-concept-cosmos-account) through `source.account_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.account_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-postgresql-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L233-L255">Source</a></summary>

<div id="rule-cosmos-postgresql-cluster"></div>

Matches `resource` instances of `azurerm_cosmosdb_postgresql_cluster`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-sql-container</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L257-L288">Source</a></summary>

<div id="rule-cosmos-sql-container"></div>

Matches `resource` instances of `azurerm_cosmosdb_sql_container`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.logical-database`](#azure-concept-logical-database) through `source.database_name`.

**Contributions**

- targets [`azure.concept.logical-database`](#azure-concept-logical-database) through `source.database_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.database_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.database_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-sql-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L290-L318">Source</a></summary>

<div id="rule-cosmos-sql-database"></div>

Matches `resource` instances of `azurerm_cosmosdb_sql_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.cosmos-account`](#azure-concept-cosmos-account) through `source.account_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.account_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.cosmos-dedicated-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/cosmos-db.rf.hcl#L113-L131">Source</a></summary>

<div id="rule-cosmos-dedicated-gateway"></div>

Matches `resource` instances of `azurerm_cosmosdb_sql_dedicated_gateway`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

**Contributions**

- targets [`azure.concept.cosmos-account`](#azure-concept-cosmos-account) through `source.cosmosdb_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.cosmosdb_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.custom-ip-prefix</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/public-ip-addresses.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-custom-ip-prefix"></div>

Matches `resource` instances of `azurerm_custom_ip_prefix`.

**Classification:** [`azure.concept.public-address`](#azure-concept-public-address).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-grafana</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/managed-grafana.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-managed-grafana"></div>

Matches `resource` instances of `azurerm_dashboard_grafana`.

**Classification:** [`azure.concept.managed-grafana`](#azure-concept-managed-grafana).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-factory-data-flow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L62-L68">Source</a></summary>

<div id="rule-data-factory-data-flow"></div>

Matches `resource` instances of `azurerm_data_factory_data_flow`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-blob-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L46-L52">Source</a></summary>

<div id="rule-data-factory-blob-dataset"></div>

Matches `resource` instances of `azurerm_data_factory_dataset_azure_blob`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-sql-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L102-L108">Source</a></summary>

<div id="rule-data-factory-sql-dataset"></div>

Matches `resource` instances of `azurerm_data_factory_dataset_azure_sql_table`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-azure-integration-runtime</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L38-L44">Source</a></summary>

<div id="rule-data-factory-azure-integration-runtime"></div>

Matches `resource` instances of `azurerm_data_factory_integration_runtime_azure`.

**Classification:** [`azure.concept.data-integration-runtime`](#azure-concept-data-integration-runtime).

</details>

<details>
<summary><code>azure.rule.data-factory-self-hosted-integration-runtime</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L94-L100">Source</a></summary>

<div id="rule-data-factory-self-hosted-integration-runtime"></div>

Matches `resource` instances of `azurerm_data_factory_integration_runtime_self_hosted`.

**Classification:** [`azure.concept.data-integration-runtime`](#azure-concept-data-integration-runtime).

</details>

<details>
<summary><code>azure.rule.data-factory-blob-linked-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L54-L60">Source</a></summary>

<div id="rule-data-factory-blob-linked-service"></div>

Matches `resource` instances of `azurerm_data_factory_linked_service_azure_blob_storage`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-sql-linked-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L110-L116">Source</a></summary>

<div id="rule-data-factory-sql-linked-service"></div>

Matches `resource` instances of `azurerm_data_factory_linked_service_azure_sql_database`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-managed-private-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L70-L76">Source</a></summary>

<div id="rule-data-factory-managed-private-endpoint"></div>

Matches `resource` instances of `azurerm_data_factory_managed_private_endpoint`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory-pipeline</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L78-L84">Source</a></summary>

<div id="rule-data-factory-pipeline"></div>

Matches `resource` instances of `azurerm_data_factory_pipeline`.

**Classification:** [`azure.concept.workflow`](#azure-concept-workflow).

</details>

<details>
<summary><code>azure.rule.data-factory-schedule-trigger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L86-L92">Source</a></summary>

<div id="rule-data-factory-schedule-trigger"></div>

Matches `resource` instances of `azurerm_data_factory_trigger_schedule`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.data-factory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-data-factory"></div>

Matches `resource` instances of `azurerm_data_factory`.

**Classification:** [`azure.concept.data-factory`](#azure-concept-data-factory).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-protection-blob-backup-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/backup.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-data-protection-blob-backup-policy"></div>

Matches `resource` instances of `azurerm_data_protection_backup_policy_blob_storage`.

**Classification:** [`azure.concept.backup-plan`](#azure-concept-backup-plan).

</details>

<details>
<summary><code>azure.rule.data-protection-disk-backup-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/backup.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-data-protection-disk-backup-policy"></div>

Matches `resource` instances of `azurerm_data_protection_backup_policy_disk`.

**Classification:** [`azure.concept.backup-plan`](#azure-concept-backup-plan).

</details>

<details>
<summary><code>azure.rule.data-protection-backup-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/backup.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-data-protection-backup-vault"></div>

Matches `resource` instances of `azurerm_data_protection_backup_vault`.

**Classification:** [`azure.concept.backup-vault`](#azure-concept-backup-vault).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-share-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-share.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-data-share-account"></div>

Matches `resource` instances of `azurerm_data_share_account`.

**Classification:** [`azure.concept.data-share-account`](#azure-concept-data-share-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.database-migration-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/database-migration.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-database-migration-project"></div>

Matches `resource` instances of `azurerm_database_migration_project`.

**Classification:** [`azure.concept.migration-service`](#azure-concept-migration-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.database-migration-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/database-migration.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-database-migration-service"></div>

Matches `resource` instances of `azurerm_database_migration_service`.

**Classification:** [`azure.concept.migration-service`](#azure-concept-migration-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-box-edge-device</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/data-box.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-data-box-edge-device"></div>

Matches `resource` instances of `azurerm_databox_edge_device`.

**Classification:** [`azure.concept.migration-service`](#azure-concept-migration-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.databricks-virtual-network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/databricks.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-databricks-virtual-network-peering"></div>

Matches `resource` instances of `azurerm_databricks_virtual_network_peering`.

**Classification:** [`azure.concept.network-peering`](#azure-concept-network-peering).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.databricks-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/databricks.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-databricks-workspace"></div>

Matches `resource` instances of `azurerm_databricks_workspace`.

**Classification:** [`azure.concept.databricks-workspace`](#azure-concept-databricks-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.datadog-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/datadog-monitor.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-datadog-monitor"></div>

Matches `resource` instances of `azurerm_datadog_monitor`.

**Classification:** [`azure.concept.third-party-monitor`](#azure-concept-third-party-monitor).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dedicated-hardware-security-module</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/dedicated-hsm.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-dedicated-hardware-security-module"></div>

Matches `resource` instances of `azurerm_dedicated_hardware_security_module`.

**Classification:** [`azure.concept.managed-hsm`](#azure-concept-managed-hsm).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dedicated-host-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-dedicated-host-group"></div>

Matches `resource` instances of `azurerm_dedicated_host_group`.

**Classification:** [`azure.concept.dedicated-host-group`](#azure-concept-dedicated-host-group).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dev-box-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-box.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-dev-box-definition"></div>

Matches `resource` instances of `azurerm_dev_center_dev_box_definition`.

**Classification:** [`azure.concept.developer-environment`](#azure-concept-developer-environment).

</details>

<details>
<summary><code>azure.rule.dev-center-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-center.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-dev-center-project"></div>

Matches `resource` instances of `azurerm_dev_center_project`.

**Classification:** [`azure.concept.dev-center-project`](#azure-concept-dev-center-project).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dev-center</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-center.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-dev-center"></div>

Matches `resource` instances of `azurerm_dev_center`.

**Classification:** [`azure.concept.dev-center`](#azure-concept-dev-center).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dev-test-lab</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/dev-test.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-dev-test-lab"></div>

Matches `resource` instances of `azurerm_dev_test_lab`.

**Classification:** [`azure.concept.developer-environment`](#azure-concept-developer-environment).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dev-test-linux-virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-dev-test-linux-virtual-machine"></div>

Matches `resource` instances of `azurerm_dev_test_linux_virtual_machine`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dev-test-windows-virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-dev-test-windows-virtual-machine"></div>

Matches `resource` instances of `azurerm_dev_test_windows_virtual_machine`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.digital-twins-event-grid-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-digital-twins-event-grid-endpoint"></div>

Matches `resource` instances of `azurerm_digital_twins_endpoint_eventgrid`.

**Classification:** [`azure.concept.iot-detail`](#azure-concept-iot-detail).

</details>

<details>
<summary><code>azure.rule.digital-twins-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/digital-twins.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-digital-twins-instance"></div>

Matches `resource` instances of `azurerm_digital_twins_instance`.

**Classification:** [`azure.concept.digital-twins-instance`](#azure-concept-digital-twins-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-a-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L14-L51">Source</a></summary>

<div id="rule-dns-a-record"></div>

Matches `resource` instances of `azurerm_dns_a_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-aaaa-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L53-L90">Source</a></summary>

<div id="rule-dns-aaaa-record"></div>

Matches `resource` instances of `azurerm_dns_aaaa_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-cname-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L92-L129">Source</a></summary>

<div id="rule-dns-cname-record"></div>

Matches `resource` instances of `azurerm_dns_cname_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-mx-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L131-L168">Source</a></summary>

<div id="rule-dns-mx-record"></div>

Matches `resource` instances of `azurerm_dns_mx_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-ns-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L170-L207">Source</a></summary>

<div id="rule-dns-ns-record"></div>

Matches `resource` instances of `azurerm_dns_ns_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-ptr-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L209-L246">Source</a></summary>

<div id="rule-dns-ptr-record"></div>

Matches `resource` instances of `azurerm_dns_ptr_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-srv-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L248-L285">Source</a></summary>

<div id="rule-dns-srv-record"></div>

Matches `resource` instances of `azurerm_dns_srv_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-txt-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L287-L324">Source</a></summary>

<div id="rule-dns-txt-record"></div>

Matches `resource` instances of `azurerm_dns_txt_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.zone_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dns-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L326-L357">Source</a></summary>

<div id="rule-dns-zone"></div>

Matches `resource` instances of `azurerm_dns_zone`.

**Classification:** [`azure.concept.dns-zone`](#azure-concept-dns-zone).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.dynatrace-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/dynatrace-monitor.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-dynatrace-monitor"></div>

Matches `resource` instances of `azurerm_dynatrace_monitor`.

**Classification:** [`azure.concept.third-party-monitor`](#azure-concept-third-party-monitor).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.elastic-cloud</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/elastic-cloud.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-elastic-cloud"></div>

Matches `resource` instances of `azurerm_elastic_cloud_elasticsearch`.

**Classification:** [`azure.concept.third-party-monitor`](#azure-concept-third-party-monitor).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.elastic-san-volume-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/elastic-san.rf.hcl#L30-L36">Source</a></summary>

<div id="rule-elastic-san-volume-group"></div>

Matches `resource` instances of `azurerm_elastic_san_volume_group`.

**Classification:** [`azure.concept.elastic-san`](#azure-concept-elastic-san).

</details>

<details>
<summary><code>azure.rule.elastic-san-volume</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/disk.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-elastic-san-volume"></div>

Matches `resource` instances of `azurerm_elastic_san_volume`.

**Classification:** [`azure.concept.block-storage-volume`](#azure-concept-block-storage-volume).

</details>

<details>
<summary><code>azure.rule.elastic-san</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/elastic-san.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-elastic-san"></div>

Matches `resource` instances of `azurerm_elastic_san`.

**Classification:** [`azure.concept.elastic-san`](#azure-concept-elastic-san).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.email-communication-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/communication-services.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-email-communication-service"></div>

Matches `resource` instances of `azurerm_email_communication_service`.

**Classification:** [`azure.concept.email-communication-service`](#azure-concept-email-communication-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-domain-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L39-L67">Source</a></summary>

<div id="rule-event-grid-domain-topic"></div>

Matches `resource` instances of `azurerm_eventgrid_domain_topic`.

**Classification:** [`azure.concept.event-grid-topic`](#azure-concept-event-grid-topic).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.event-grid-domain`](#azure-concept-event-grid-domain) through `source.domain_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.domain_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L6-L37">Source</a></summary>

<div id="rule-event-grid-domain"></div>

Matches `resource` instances of `azurerm_eventgrid_domain`.

**Classification:** [`azure.concept.event-grid-domain`](#azure-concept-event-grid-domain).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-event-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L69-L163">Source</a></summary>

<div id="rule-event-grid-event-subscription"></div>

Matches `resource` instances of `azurerm_eventgrid_event_subscription`.

**Classification:** [`azure.concept.message-subscription`](#azure-concept-message-subscription).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.event-grid-topic`](#azure-concept-event-grid-topic) through `source.scope`.

**Relations**

- [`azure.relation.subscribes-to`](#azure-relation-subscribes-to): targets [`azure.concept.event-grid-topic`](#azure-concept-event-grid-topic) through `source.scope`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.event-stream`](#azure-concept-event-stream) through `source.eventhub_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.message-queue`](#azure-concept-message-queue) through `source.service_bus_queue_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.service-bus-topic`](#azure-concept-service-bus-topic) through `source.service_bus_topic_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.serverless-function`](#azure-concept-serverless-function) through `source.azure_function_endpoint[0].function_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_queue_endpoint[0].storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.scope`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.scope`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.eventhub_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.service_bus_queue_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.service_bus_topic_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.azure_function_endpoint[0].function_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.storage_queue_endpoint[0].storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-namespace-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L198-L217">Source</a></summary>

<div id="rule-event-grid-namespace-topic"></div>

Matches `resource` instances of `azurerm_eventgrid_namespace_topic`.

**Classification:** [`azure.concept.message-topic`](#azure-concept-message-topic).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.event-grid-domain`](#azure-concept-event-grid-domain) through `source.eventgrid_namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.eventgrid_namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L165-L196">Source</a></summary>

<div id="rule-event-grid-namespace"></div>

Matches `resource` instances of `azurerm_eventgrid_namespace`.

**Classification:** [`azure.concept.event-grid-domain`](#azure-concept-event-grid-domain).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-partner-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L219-L250">Source</a></summary>

<div id="rule-event-grid-partner-namespace"></div>

Matches `resource` instances of `azurerm_eventgrid_partner_namespace`.

**Classification:** [`azure.concept.event-grid-domain`](#azure-concept-event-grid-domain).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-system-topic-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L285-L381">Source</a></summary>

<div id="rule-event-grid-system-topic-subscription"></div>

Matches `resource` instances of `azurerm_eventgrid_system_topic_event_subscription`.

**Classification:** [`azure.concept.message-subscription`](#azure-concept-message-subscription).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.rule.event-grid-system-topic`](#rule-event-grid-system-topic) through `source.system_topic`.

**Relations**

- [`azure.relation.subscribes-to`](#azure-relation-subscribes-to): targets [`azure.rule.event-grid-system-topic`](#rule-event-grid-system-topic) through `source.system_topic`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.event-stream`](#azure-concept-event-stream) through `source.eventhub_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.message-queue`](#azure-concept-message-queue) through `source.service_bus_queue_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.service-bus-topic`](#azure-concept-service-bus-topic) through `source.service_bus_topic_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.serverless-function`](#azure-concept-serverless-function) through `source.azure_function_endpoint[0].function_id`.
- [`azure.relation.delivers-to`](#azure-relation-delivers-to): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_queue_endpoint[0].storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.system_topic`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.system_topic`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.eventhub_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.service_bus_queue_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.service_bus_topic_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.azure_function_endpoint[0].function_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.storage_queue_endpoint[0].storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-system-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L252-L283">Source</a></summary>

<div id="rule-event-grid-system-topic"></div>

Matches `resource` instances of `azurerm_eventgrid_system_topic`.

**Classification:** [`azure.concept.event-grid-topic`](#azure-concept-event-grid-topic).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-grid-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-grid.rf.hcl#L383-L414">Source</a></summary>

<div id="rule-event-grid-topic"></div>

Matches `resource` instances of `azurerm_eventgrid_topic`.

**Classification:** [`azure.concept.event-grid-topic`](#azure-concept-event-grid-topic).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-hubs-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L39-L70">Source</a></summary>

<div id="rule-event-hubs-cluster"></div>

Matches `resource` instances of `azurerm_eventhub_cluster`.

**Classification:** [`azure.concept.event-stream`](#azure-concept-event-stream).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-hubs-consumer-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L72-L103">Source</a></summary>

<div id="rule-event-hubs-consumer-group"></div>

Matches `resource` instances of `azurerm_eventhub_consumer_group`.

**Classification:** [`azure.concept.messaging-detail`](#azure-concept-messaging-detail).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.event-stream`](#azure-concept-event-stream) through `source.eventhub_name`.

**Contributions**

- targets [`azure.concept.event-stream`](#azure-concept-event-stream) through `source.eventhub_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.eventhub_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.eventhub_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-hubs-schema-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L138-L156">Source</a></summary>

<div id="rule-event-hubs-schema-group"></div>

Matches `resource` instances of `azurerm_eventhub_namespace_schema_group`.

**Classification:** [`azure.concept.messaging-detail`](#azure-concept-messaging-detail).

**Contributions**

- targets [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace) through `source.namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-hubs-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L105-L136">Source</a></summary>

<div id="rule-event-hubs-namespace"></div>

Matches `resource` instances of `azurerm_eventhub_namespace`.

**Classification:** [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.event-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/event-hubs.rf.hcl#L6-L37">Source</a></summary>

<div id="rule-event-hub"></div>

Matches `resource` instances of `azurerm_eventhub`.

**Classification:** [`azure.concept.event-stream`](#azure-concept-event-stream).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace) through `source.namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.expressroute-circuit</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/expressroute.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-expressroute-circuit"></div>

Matches `resource` instances of `azurerm_express_route_circuit`.

**Classification:** [`azure.concept.dedicated-interconnect`](#azure-concept-dedicated-interconnect).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.expressroute-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/expressroute.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-expressroute-gateway"></div>

Matches `resource` instances of `azurerm_express_route_gateway`.

**Classification:** [`azure.concept.expressroute-gateway`](#azure-concept-expressroute-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.expressroute-port</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/expressroute.rf.hcl#L54-L76">Source</a></summary>

<div id="rule-expressroute-port"></div>

Matches `resource` instances of `azurerm_express_route_port`.

**Classification:** [`azure.concept.dedicated-interconnect`](#azure-concept-dedicated-interconnect).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.arc-custom-location</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/arc.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-arc-custom-location"></div>

Matches `resource` instances of `azurerm_extended_location_custom_location`.

**Classification:** [`azure.concept.custom-location`](#azure-concept-custom-location).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.fabric-capacity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/fabric-capacity.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-fabric-capacity"></div>

Matches `resource` instances of `azurerm_fabric_capacity`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.azure-firewall-policy-rule-collection-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L46-L52">Source</a></summary>

<div id="rule-azure-firewall-policy-rule-collection-group"></div>

Matches `resource` instances of `azurerm_firewall_policy_rule_collection_group`.

**Classification:** [`azure.concept.firewall-policy`](#azure-concept-firewall-policy).

</details>

<details>
<summary><code>azure.rule.azure-firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L38-L44">Source</a></summary>

<div id="rule-azure-firewall-policy"></div>

Matches `resource` instances of `azurerm_firewall_policy`.

**Classification:** [`azure.concept.firewall-policy`](#azure-concept-firewall-policy).

</details>

<details>
<summary><code>azure.rule.azure-firewall</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-azure-firewall"></div>

Matches `resource` instances of `azurerm_firewall`.

**Classification:** [`azure.concept.azure-firewall`](#azure-concept-azure-firewall).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.fluid-relay</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/fluid-relay.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-fluid-relay"></div>

Matches `resource` instances of `azurerm_fluid_relay_server`.

**Classification:** [`azure.concept.realtime-communication-service`](#azure-concept-realtime-communication-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.classic-front-door</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/front-door.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-classic-front-door"></div>

Matches `resource` instances of `azurerm_frontdoor`.

**Classification:** [`azure.concept.front-door-profile`](#azure-concept-front-door-profile).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.flex-consumption-function-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/functions.rf.hcl#L2-L62">Source</a></summary>

<div id="rule-flex-consumption-function-app"></div>

Matches `resource` instances of `azurerm_function_app_flex_consumption`.

**Classification:** [`azure.concept.serverless-function`](#azure-concept-serverless-function).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.virtual_network_subnet_id`.
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.app-service-plan`](#azure-concept-app-service-plan) through `source.service_plan_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.service_plan_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.function-app-function</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/functions.rf.hcl#L64-L79">Source</a></summary>

<div id="rule-function-app-function"></div>

Matches `resource` instances of `azurerm_function_app_function`.

**Classification:** [`azure.concept.serverless-function`](#azure-concept-serverless-function).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>azure.rule.graph-data-connect-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/graph-data.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-graph-data-connect-account"></div>

Matches `resource` instances of `azurerm_graph_services_account`.

**Classification:** [`azure.concept.graph-data-connect-account`](#azure-concept-graph-data-connect-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.hdinsight-hadoop-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/hdinsight.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-hdinsight-hadoop-cluster"></div>

Matches `resource` instances of `azurerm_hdinsight_hadoop_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.hdinsight-hbase-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/hdinsight.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-hdinsight-hbase-cluster"></div>

Matches `resource` instances of `azurerm_hdinsight_hbase_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.hdinsight-interactive-query-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/hdinsight.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-hdinsight-interactive-query-cluster"></div>

Matches `resource` instances of `azurerm_hdinsight_interactive_query_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.hdinsight-kafka-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/hdinsight.rf.hcl#L74-L96">Source</a></summary>

<div id="rule-hdinsight-kafka-cluster"></div>

Matches `resource` instances of `azurerm_hdinsight_kafka_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.hdinsight-spark-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/hdinsight.rf.hcl#L98-L120">Source</a></summary>

<div id="rule-hdinsight-spark-cluster"></div>

Matches `resource` instances of `azurerm_hdinsight_spark_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.health-bot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/bot-services.rf.hcl#L78-L100">Source</a></summary>

<div id="rule-health-bot"></div>

Matches `resource` instances of `azurerm_healthbot`.

**Classification:** [`azure.concept.bot-service`](#azure-concept-bot-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.health-data-dicom-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-health-data-dicom-service"></div>

Matches `resource` instances of `azurerm_healthcare_dicom_service`.

**Classification:** [`azure.concept.health-data-service`](#azure-concept-health-data-service).

</details>

<details>
<summary><code>azure.rule.health-data-fhir-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L18-L40">Source</a></summary>

<div id="rule-health-data-fhir-service"></div>

Matches `resource` instances of `azurerm_healthcare_fhir_service`.

**Classification:** [`azure.concept.health-data-service`](#azure-concept-health-data-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.health-data-medtech-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-health-data-medtech-service"></div>

Matches `resource` instances of `azurerm_healthcare_medtech_service`.

**Classification:** [`azure.concept.health-data-service`](#azure-concept-health-data-service).

</details>

<details>
<summary><code>azure.rule.healthcare-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L74-L96">Source</a></summary>

<div id="rule-healthcare-service"></div>

Matches `resource` instances of `azurerm_healthcare_service`.

**Classification:** [`azure.concept.health-data-service`](#azure-concept-health-data-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.health-data-services-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/healthcare-apis.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-health-data-services-workspace"></div>

Matches `resource` instances of `azurerm_healthcare_workspace`.

**Classification:** [`azure.concept.health-data-workspace`](#azure-concept-health-data-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.compute-image</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/compute-gallery.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-compute-image"></div>

Matches `resource` instances of `azurerm_image`.

**Classification:** [`azure.concept.compute-image`](#azure-concept-compute-image).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.iot-central-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-central.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-iot-central-application"></div>

Matches `resource` instances of `azurerm_iotcentral_application`.

**Classification:** [`azure.concept.iot-central-application`](#azure-concept-iot-central-application).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.iot-hub-device-update-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L74-L96">Source</a></summary>

<div id="rule-iot-hub-device-update-account"></div>

Matches `resource` instances of `azurerm_iothub_device_update_account`.

**Classification:** [`azure.concept.iot-update-service`](#azure-concept-iot-update-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.iot-hub-device-update-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L98-L104">Source</a></summary>

<div id="rule-iot-hub-device-update-instance"></div>

Matches `resource` instances of `azurerm_iothub_device_update_instance`.

**Classification:** [`azure.concept.iot-detail`](#azure-concept-iot-detail).

</details>

<details>
<summary><code>azure.rule.iot-hub-device-provisioning-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-iot-hub-device-provisioning-service"></div>

Matches `resource` instances of `azurerm_iothub_dps`.

**Classification:** [`azure.concept.iot-provisioning-service`](#azure-concept-iot-provisioning-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.iot-hub-event-hubs-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L106-L112">Source</a></summary>

<div id="rule-iot-hub-event-hubs-endpoint"></div>

Matches `resource` instances of `azurerm_iothub_endpoint_eventhub`.

**Classification:** [`azure.concept.iot-detail`](#azure-concept-iot-detail).

</details>

<details>
<summary><code>azure.rule.iot-hub-service-bus-queue-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L114-L120">Source</a></summary>

<div id="rule-iot-hub-service-bus-queue-endpoint"></div>

Matches `resource` instances of `azurerm_iothub_endpoint_servicebus_queue`.

**Classification:** [`azure.concept.iot-detail`](#azure-concept-iot-detail).

</details>

<details>
<summary><code>azure.rule.iot-hub-storage-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L122-L128">Source</a></summary>

<div id="rule-iot-hub-storage-endpoint"></div>

Matches `resource` instances of `azurerm_iothub_endpoint_storage_container`.

**Classification:** [`azure.concept.iot-detail`](#azure-concept-iot-detail).

</details>

<details>
<summary><code>azure.rule.iot-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/iot/iot-hub.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-iot-hub"></div>

Matches `resource` instances of `azurerm_iothub`.

**Classification:** [`azure.concept.iot-hub`](#azure-concept-iot-hub).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.ip-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-ip-group"></div>

Matches `resource` instances of `azurerm_ip_group`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.key-vault-access-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L39-L60">Source</a></summary>

<div id="rule-key-vault-access-policy"></div>

Matches `resource` instances of `azurerm_key_vault_access_policy`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

**Contributions**

- targets [`azure.concept.key-vault`](#azure-concept-key-vault) through `source.key_vault_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.key_vault_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.key-vault-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L62-L83">Source</a></summary>

<div id="rule-key-vault-certificate"></div>

Matches `resource` instances of `azurerm_key_vault_certificate`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

**Contributions**

- targets [`azure.concept.key-vault`](#azure-concept-key-vault) through `source.key_vault_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.key_vault_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.key-vault-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L85-L107">Source</a></summary>

<div id="rule-key-vault-key"></div>

Matches `resource` instances of `azurerm_key_vault_key`.

**Classification:** [`azure.concept.encryption-key`](#azure-concept-encryption-key).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.key-vault`](#azure-concept-key-vault) through `source.key_vault_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.key_vault_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-hsm-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L166-L185">Source</a></summary>

<div id="rule-managed-hsm-key"></div>

Matches `resource` instances of `azurerm_key_vault_managed_hardware_security_module_key`.

**Classification:** [`azure.concept.encryption-key`](#azure-concept-encryption-key).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.managed-hsm`](#azure-concept-managed-hsm) through `source.managed_hsm_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.managed_hsm_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-hsm</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L133-L164">Source</a></summary>

<div id="rule-managed-hsm"></div>

Matches `resource` instances of `azurerm_key_vault_managed_hardware_security_module`.

**Classification:** [`azure.concept.managed-hsm`](#azure-concept-managed-hsm).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.key-vault-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L109-L131">Source</a></summary>

<div id="rule-key-vault-secret"></div>

Matches `resource` instances of `azurerm_key_vault_secret`.

**Classification:** [`azure.concept.managed-secret`](#azure-concept-managed-secret).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.key-vault`](#azure-concept-key-vault) through `source.key_vault_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.key_vault_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.key-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/key-vault.rf.hcl#L6-L37">Source</a></summary>

<div id="rule-key-vault"></div>

Matches `resource` instances of `azurerm_key_vault`.

**Classification:** [`azure.concept.key-vault`](#azure-concept-key-vault).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.automatic-kubernetes-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/kubernetes-services.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-automatic-kubernetes-cluster"></div>

Matches `resource` instances of `azurerm_kubernetes_automatic_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.aks-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/aks.rf.hcl#L67-L104">Source</a></summary>

<div id="rule-aks-node-pool"></div>

Matches `resource` instances of `azurerm_kubernetes_cluster_node_pool`.

**Classification:** [`azure.concept.kubernetes-node-pool`](#azure-concept-kubernetes-node-pool).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.vnet_subnet_id`.

**Contributions**

- targets [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) through `source.kubernetes_cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.vnet_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.kubernetes_cluster_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.aks-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/aks.rf.hcl#L1-L65">Source</a></summary>

<div id="rule-aks-cluster"></div>

Matches `resource` instances of `azurerm_kubernetes_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.default_node_pool[0].vnet_subnet_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Relations**

- [`azure.relation.observed-by`](#azure-relation-observed-by): targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.oms_agent[0].log_analytics_workspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "kube_config[0].host", "kube_admin_config[0].host"]`

**Context through `source.default_node_pool[0].vnet_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.oms_agent[0].log_analytics_workspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.kubernetes-fleet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/kubernetes-fleet-manager.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-kubernetes-fleet"></div>

Matches `resource` instances of `azurerm_kubernetes_fleet_manager`.

**Classification:** [`azure.concept.kubernetes-fleet`](#azure-concept-kubernetes-fleet).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-explorer-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/data-explorer.rf.hcl#L7-L29">Source</a></summary>

<div id="rule-data-explorer-cluster"></div>

Matches `resource` instances of `azurerm_kusto_cluster`.

**Classification:** [`azure.concept.data-explorer-cluster`](#azure-concept-data-explorer-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-explorer-event-grid-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/data-explorer.rf.hcl#L32-L38">Source</a></summary>

<div id="rule-data-explorer-event-grid-connection"></div>

Matches `resource` instances of `azurerm_kusto_eventgrid_data_connection`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.data-explorer-event-hubs-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/data-explorer.rf.hcl#L40-L46">Source</a></summary>

<div id="rule-data-explorer-event-hubs-connection"></div>

Matches `resource` instances of `azurerm_kusto_eventhub_data_connection`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.load-balancer-backend-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancers.rf.hcl#L95-L113">Source</a></summary>

<div id="rule-load-balancer-backend-pool"></div>

Matches `resource` instances of `azurerm_lb_backend_address_pool`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

**Contributions**

- targets [`azure.concept.load-balancer`](#azure-concept-load-balancer) through `source.loadbalancer_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.loadbalancer_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.load-balancer-nat-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancer.rf.hcl#L43-L49">Source</a></summary>

<div id="rule-load-balancer-nat-rule"></div>

Matches `resource` instances of `azurerm_lb_nat_rule`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.load-balancer-outbound-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancer.rf.hcl#L51-L57">Source</a></summary>

<div id="rule-load-balancer-outbound-rule"></div>

Matches `resource` instances of `azurerm_lb_outbound_rule`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.load-balancer-probe</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancer.rf.hcl#L59-L65">Source</a></summary>

<div id="rule-load-balancer-probe"></div>

Matches `resource` instances of `azurerm_lb_probe`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.load-balancer-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancers.rf.hcl#L115-L133">Source</a></summary>

<div id="rule-load-balancer-rule"></div>

Matches `resource` instances of `azurerm_lb_rule`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

**Contributions**

- targets [`azure.concept.load-balancer`](#azure-concept-load-balancer) through `source.loadbalancer_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.loadbalancer_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/load-balancers.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-load-balancer"></div>

Matches `resource` instances of `azurerm_lb`.

**Classification:** [`azure.concept.load-balancer`](#azure-concept-load-balancer).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.lighthouse-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/lighthouse-definition.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-lighthouse-definition"></div>

Matches `resource` instances of `azurerm_lighthouse_definition`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.linux-function-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/functions.rf.hcl#L81-L153">Source</a></summary>

<div id="rule-linux-function-app"></div>

Matches `resource` instances of `azurerm_linux_function_app`.

**Classification:** [`azure.concept.serverless-function`](#azure-concept-serverless-function).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.virtual_network_subnet_id`.
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.app-service-plan`](#azure-concept-app-service-plan) through `source.service_plan_id`.

**Relations**

- [`azure.relation.observed-by`](#azure-relation-observed-by): targets [`azure.concept.application-insights`](#azure-concept-application-insights) through `source.site_config[0].application_insights_connection_string`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.service_plan_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.site_config[0].application_insights_connection_string`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.connection_string`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.linux-virtual-machine-scale-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/vm-scale-set.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-linux-virtual-machine-scale-set"></div>

Matches `resource` instances of `azurerm_linux_virtual_machine_scale_set`.

**Classification:** [`azure.concept.virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.linux-virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-linux-virtual-machine"></div>

Matches `resource` instances of `azurerm_linux_virtual_machine`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.linux-web-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L71-L123">Source</a></summary>

<div id="rule-linux-web-app"></div>

Matches `resource` instances of `azurerm_linux_web_app`.

**Classification:** [`azure.concept.app-service`](#azure-concept-app-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.virtual_network_subnet_id`.
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.app-service-plan`](#azure-concept-app-service-plan) through `source.service_plan_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.service_plan_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.load-test</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/load-test.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-load-test"></div>

Matches `resource` instances of `azurerm_load_test`.

**Classification:** [`azure.concept.load-test`](#azure-concept-load-test).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.local-network-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/local-network.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-local-network-gateway"></div>

Matches `resource` instances of `azurerm_local_network_gateway`.

**Classification:** [`azure.concept.local-network-gateway`](#azure-concept-local-network-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L74-L105">Source</a></summary>

<div id="rule-log-analytics-cluster"></div>

Matches `resource` instances of `azurerm_log_analytics_cluster`.

**Classification:** [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-data-export-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L107-L128">Source</a></summary>

<div id="rule-log-analytics-data-export-rule"></div>

Matches `resource` instances of `azurerm_log_analytics_data_export_rule`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

**Contributions**

- targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.workspace_resource_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.workspace_resource_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-saved-search</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L130-L151">Source</a></summary>

<div id="rule-log-analytics-saved-search"></div>

Matches `resource` instances of `azurerm_log_analytics_saved_search`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

**Contributions**

- targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.log_analytics_workspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.log_analytics_workspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-solution</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L153-L190">Source</a></summary>

<div id="rule-log-analytics-solution"></div>

Matches `resource` instances of `azurerm_log_analytics_solution`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Contributions**

- targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.workspace_resource_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.workspace_resource_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-workspace-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L225-L246">Source</a></summary>

<div id="rule-log-analytics-workspace-table"></div>

Matches `resource` instances of `azurerm_log_analytics_workspace_table`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

**Contributions**

- targets [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace) through `source.workspace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.workspace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.log-analytics-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L192-L223">Source</a></summary>

<div id="rule-log-analytics-workspace"></div>

Matches `resource` instances of `azurerm_log_analytics_workspace`.

**Classification:** [`azure.concept.log-analytics-workspace`](#azure-concept-log-analytics-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.logic-app-http-action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-logic-app-http-action"></div>

Matches `resource` instances of `azurerm_logic_app_action_http`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.logic-app-integration-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-logic-app-integration-account"></div>

Matches `resource` instances of `azurerm_logic_app_integration_account`.

**Classification:** [`azure.concept.integration-account`](#azure-concept-integration-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.logic-app-standard</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L46-L68">Source</a></summary>

<div id="rule-logic-app-standard"></div>

Matches `resource` instances of `azurerm_logic_app_standard`.

**Classification:** [`azure.concept.workflow`](#azure-concept-workflow).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.logic-app-recurrence-trigger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L38-L44">Source</a></summary>

<div id="rule-logic-app-recurrence-trigger"></div>

Matches `resource` instances of `azurerm_logic_app_trigger_recurrence`.

**Classification:** [`azure.concept.api-management-detail`](#azure-concept-api-management-detail).

</details>

<details>
<summary><code>azure.rule.logic-app-workflow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/logic-apps.rf.hcl#L70-L92">Source</a></summary>

<div id="rule-logic-app-workflow"></div>

Matches `resource` instances of `azurerm_logic_app_workflow`.

**Classification:** [`azure.concept.workflow`](#azure-concept-workflow).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.machine-learning-compute-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/machine-learning.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-machine-learning-compute-cluster"></div>

Matches `resource` instances of `azurerm_machine_learning_compute_cluster`.

**Classification:** [`azure.concept.machine-learning-compute`](#azure-concept-machine-learning-compute).

</details>

<details>
<summary><code>azure.rule.machine-learning-compute-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/machine-learning.rf.hcl#L14-L20">Source</a></summary>

<div id="rule-machine-learning-compute-instance"></div>

Matches `resource` instances of `azurerm_machine_learning_compute_instance`.

**Classification:** [`azure.concept.machine-learning-compute`](#azure-concept-machine-learning-compute).

</details>

<details>
<summary><code>azure.rule.machine-learning-inference-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/machine-learning.rf.hcl#L22-L28">Source</a></summary>

<div id="rule-machine-learning-inference-cluster"></div>

Matches `resource` instances of `azurerm_machine_learning_inference_cluster`.

**Classification:** [`azure.concept.ai-inference-endpoint`](#azure-concept-ai-inference-endpoint).

</details>

<details>
<summary><code>azure.rule.machine-learning-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-foundry.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-machine-learning-workspace"></div>

Matches `resource` instances of `azurerm_machine_learning_workspace`.

**Classification:** [`azure.concept.machine-learning-workspace`](#azure-concept-machine-learning-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.maintenance-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/maintenance-configuration.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-maintenance-configuration"></div>

Matches `resource` instances of `azurerm_maintenance_configuration`.

**Classification:** [`azure.concept.maintenance-configuration`](#azure-concept-maintenance-configuration).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/managed-application.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-managed-application"></div>

Matches `resource` instances of `azurerm_managed_application`.

**Classification:** [`azure.concept.managed-application`](#azure-concept-managed-application).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-devops-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/managed-devops.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-managed-devops-pool"></div>

Matches `resource` instances of `azurerm_managed_devops_pool`.

**Classification:** [`azure.concept.developer-environment`](#azure-concept-developer-environment).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-disk</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/disk.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-managed-disk"></div>

Matches `resource` instances of `azurerm_managed_disk`.

**Classification:** [`azure.concept.block-storage-volume`](#azure-concept-block-storage-volume).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-lustre-file-system</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/managed-lustre.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-managed-lustre-file-system"></div>

Matches `resource` instances of `azurerm_managed_lustre_file_system`.

**Classification:** [`azure.concept.managed-file-storage`](#azure-concept-managed-file-storage).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-redis-geo-replication</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-redis.rf.hcl#L50-L56">Source</a></summary>

<div id="rule-managed-redis-geo-replication"></div>

Matches `resource` instances of `azurerm_managed_redis_geo_replication`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.azure-managed-redis</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-redis.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-azure-managed-redis"></div>

Matches `resource` instances of `azurerm_managed_redis`.

**Classification:** [`azure.concept.managed-cache`](#azure-concept-managed-cache).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.maps-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/api-integration/maps-account.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-maps-account"></div>

Matches `resource` instances of `azurerm_maps_account`.

**Classification:** [`azure.concept.maps-account`](#azure-concept-maps-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.mongo-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/mongo-cluster.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-mongo-cluster"></div>

Matches `resource` instances of `azurerm_mongo_cluster`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.monitor-action-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L248-L254">Source</a></summary>

<div id="rule-monitor-action-group"></div>

Matches `resource` instances of `azurerm_monitor_action_group`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.monitor-data-collection-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L256-L262">Source</a></summary>

<div id="rule-monitor-data-collection-endpoint"></div>

Matches `resource` instances of `azurerm_monitor_data_collection_endpoint`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.monitor-diagnostic-setting</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L264-L270">Source</a></summary>

<div id="rule-monitor-diagnostic-setting"></div>

Matches `resource` instances of `azurerm_monitor_diagnostic_setting`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.monitor-metric-alert</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L272-L278">Source</a></summary>

<div id="rule-monitor-metric-alert"></div>

Matches `resource` instances of `azurerm_monitor_metric_alert`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.monitor-private-link-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/monitor.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-monitor-private-link-scope"></div>

Matches `resource` instances of `azurerm_monitor_private_link_scope`.

**Classification:** [`azure.concept.private-link-scope`](#azure-concept-private-link-scope).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.monitor-scheduled-query-alert</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L280-L286">Source</a></summary>

<div id="rule-monitor-scheduled-query-alert"></div>

Matches `resource` instances of `azurerm_monitor_scheduled_query_rules_alert_v2`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.monitor-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L288-L310">Source</a></summary>

<div id="rule-monitor-workspace"></div>

Matches `resource` instances of `azurerm_monitor_workspace`.

**Classification:** [`azure.concept.monitor-workspace`](#azure-concept-monitor-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.mssql-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases-topology.rf.hcl#L89-L117">Source</a></summary>

<div id="rule-mssql-database"></div>

Matches `resource` instances of `azurerm_mssql_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.sql-server`](#azure-concept-sql-server) through `source.server_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.server_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.sql-elastic-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/sql-database.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-sql-elastic-pool"></div>

Matches `resource` instances of `azurerm_mssql_elasticpool`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.sql-failover-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/sql-database.rf.hcl#L14-L20">Source</a></summary>

<div id="rule-sql-failover-group"></div>

Matches `resource` instances of `azurerm_mssql_failover_group`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.sql-managed-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/sql-database.rf.hcl#L22-L37">Source</a></summary>

<div id="rule-sql-managed-database"></div>

Matches `resource` instances of `azurerm_mssql_managed_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>azure.rule.sql-managed-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/sql-database.rf.hcl#L39-L61">Source</a></summary>

<div id="rule-sql-managed-instance"></div>

Matches `resource` instances of `azurerm_mssql_managed_instance`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.mssql-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases-topology.rf.hcl#L56-L87">Source</a></summary>

<div id="rule-mssql-server"></div>

Matches `resource` instances of `azurerm_mssql_server`.

**Classification:** [`azure.concept.sql-server`](#azure-concept-sql-server).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.mysql-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-mysql-database"></div>

Matches `resource` instances of `azurerm_mysql_flexible_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.mysql-flexible-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases.rf.hcl#L35-L57">Source</a></summary>

<div id="rule-mysql-flexible-server"></div>

Matches `resource` instances of `azurerm_mysql_flexible_server`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.nat-gateway-public-ip-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/nat-gateway.rf.hcl#L35-L65">Source</a></summary>

<div id="rule-nat-gateway-public-ip-association"></div>

Matches `resource` instances of `azurerm_nat_gateway_public_ip_association`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

**Contributions**

- targets [`azure.concept.managed-nat`](#azure-concept-managed-nat) through `source.nat_gateway_id`.
- targets [`azure.concept.public-address`](#azure-concept-public-address) through `source.public_ip_address_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.nat_gateway_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.public_ip_address_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.nat-gateway-public-ip-prefix-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/nat-gateway.rf.hcl#L67-L97">Source</a></summary>

<div id="rule-nat-gateway-public-ip-prefix-association"></div>

Matches `resource` instances of `azurerm_nat_gateway_public_ip_prefix_association`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

**Contributions**

- targets [`azure.concept.managed-nat`](#azure-concept-managed-nat) through `source.nat_gateway_id`.
- targets [`azure.concept.public-address`](#azure-concept-public-address) through `source.public_ip_prefix_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.nat_gateway_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.public_ip_prefix_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.nat-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/nat-gateway.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-nat-gateway"></div>

Matches `resource` instances of `azurerm_nat_gateway`.

**Classification:** [`azure.concept.managed-nat`](#azure-concept-managed-nat).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.netapp-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/netapp-files.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-netapp-account"></div>

Matches `resource` instances of `azurerm_netapp_account`.

**Classification:** [`azure.concept.netapp-account`](#azure-concept-netapp-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.netapp-backup-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/backup.rf.hcl#L42-L64">Source</a></summary>

<div id="rule-netapp-backup-policy"></div>

Matches `resource` instances of `azurerm_netapp_backup_policy`.

**Classification:** [`azure.concept.backup-plan`](#azure-concept-backup-plan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.netapp-backup-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/backup.rf.hcl#L66-L88">Source</a></summary>

<div id="rule-netapp-backup-vault"></div>

Matches `resource` instances of `azurerm_netapp_backup_vault`.

**Classification:** [`azure.concept.backup-vault`](#azure-concept-backup-vault).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.netapp-capacity-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/netapp-files.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-netapp-capacity-pool"></div>

Matches `resource` instances of `azurerm_netapp_pool`.

**Classification:** [`azure.concept.netapp-capacity-pool`](#azure-concept-netapp-capacity-pool).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.netapp-volume</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/netapp-files.rf.hcl#L58-L80">Source</a></summary>

<div id="rule-netapp-volume"></div>

Matches `resource` instances of `azurerm_netapp_volume`.

**Classification:** [`azure.concept.managed-file-storage`](#azure-concept-managed-file-storage).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.ddos-protection-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/ddos-protection.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-ddos-protection-plan"></div>

Matches `resource` instances of `azurerm_network_ddos_protection_plan`.

**Classification:** [`azure.concept.ddos-protection-plan`](#azure-concept-ddos-protection-plan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.network-function-traffic-collector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-function.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-network-function-traffic-collector"></div>

Matches `resource` instances of `azurerm_network_function_azure_traffic_collector`.

**Classification:** [`azure.concept.network-function-service`](#azure-concept-network-function-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.network-manager-ipam-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-manager.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-network-manager-ipam-pool"></div>

Matches `resource` instances of `azurerm_network_manager_ipam_pool`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.virtual-network-manager</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-network.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-virtual-network-manager"></div>

Matches `resource` instances of `azurerm_network_manager`.

**Classification:** [`azure.concept.virtual-network-manager`](#azure-concept-virtual-network-manager).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.network-security-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-network-security-group"></div>

Matches `resource` instances of `azurerm_network_security_group`.

**Classification:** [`azure.concept.network-security-group`](#azure-concept-network-security-group).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.network-security-perimeter</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-network-security-perimeter"></div>

Matches `resource` instances of `azurerm_network_security_perimeter`.

**Classification:** [`azure.concept.network-security-perimeter`](#azure-concept-network-security-perimeter).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.network-security-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/network-security.rf.hcl#L74-L80">Source</a></summary>

<div id="rule-network-security-rule"></div>

Matches `resource` instances of `azurerm_network_security_rule`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.network-watcher-flow-log</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/network-watcher.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-network-watcher-flow-log"></div>

Matches `resource` instances of `azurerm_network_watcher_flow_log`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.network-watcher</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/monitor.rf.hcl#L312-L334">Source</a></summary>

<div id="rule-network-watcher"></div>

Matches `resource` instances of `azurerm_network_watcher`.

**Classification:** [`azure.concept.network-watcher`](#azure-concept-network-watcher).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.new-relic-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/new-relic.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-new-relic-monitor"></div>

Matches `resource` instances of `azurerm_new_relic_monitor`.

**Classification:** [`azure.concept.third-party-monitor`](#azure-concept-third-party-monitor).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.nginx-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/nginx-deployment.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-nginx-deployment"></div>

Matches `resource` instances of `azurerm_nginx_deployment`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.notification-hubs-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/notification-hubs.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-notification-hubs-namespace"></div>

Matches `resource` instances of `azurerm_notification_hub_namespace`.

**Classification:** [`azure.concept.notification-namespace`](#azure-concept-notification-namespace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.notification-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/notification-hubs.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-notification-hub"></div>

Matches `resource` instances of `azurerm_notification_hub`.

**Classification:** [`azure.concept.notification-hub`](#azure-concept-notification-hub).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.oracle-autonomous-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/oracle-database.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-oracle-autonomous-database"></div>

Matches `resource` instances of `azurerm_oracle_autonomous_database`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.oracle-cloud-vm-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/oracle-database.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-oracle-cloud-vm-cluster"></div>

Matches `resource` instances of `azurerm_oracle_cloud_vm_cluster`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.oracle-exadata-infrastructure</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/oracle-database.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-oracle-exadata-infrastructure"></div>

Matches `resource` instances of `azurerm_oracle_exadata_infrastructure`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.oracle-resource-anchor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/oracle-database.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-oracle-resource-anchor"></div>

Matches `resource` instances of `azurerm_oracle_resource_anchor`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.orchestrated-virtual-machine-scale-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/vm-scale-set.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-orchestrated-virtual-machine-scale-set"></div>

Matches `resource` instances of `azurerm_orchestrated_virtual_machine_scale_set`.

**Classification:** [`azure.concept.virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.palo-alto-firewall</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/palo-alto.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-palo-alto-firewall"></div>

Matches `resource` instances of `azurerm_palo_alto_next_generation_firewall_virtual_network_local_rulestack`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.playwright-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/developer-ci-cd/playwright-workspace.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-playwright-workspace"></div>

Matches `resource` instances of `azurerm_playwright_workspace`.

**Classification:** [`azure.concept.developer-environment`](#azure-concept-developer-environment).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.point-to-site-vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-point-to-site-vpn-gateway"></div>

Matches `resource` instances of `azurerm_point_to_site_vpn_gateway`.

**Classification:** [`azure.concept.vpn-gateway`](#azure-concept-vpn-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.policy-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/azure-policy.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-policy-definition"></div>

Matches `resource` instances of `azurerm_policy_definition`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.policy-set-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/azure-policy.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-policy-set-definition"></div>

Matches `resource` instances of `azurerm_policy_set_definition`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.portal-dashboard</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/operations/portal-dashboard.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-portal-dashboard"></div>

Matches `resource` instances of `azurerm_portal_dashboard`.

**Classification:** [`azure.concept.operations-detail`](#azure-concept-operations-detail).

</details>

<details>
<summary><code>azure.rule.postgresql-backup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases.rf.hcl#L59-L65">Source</a></summary>

<div id="rule-postgresql-backup"></div>

Matches `resource` instances of `azurerm_postgresql_flexible_server_backup`.

**Classification:** [`azure.concept.database-component`](#azure-concept-database-component).

</details>

<details>
<summary><code>azure.rule.postgresql-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases.rf.hcl#L67-L82">Source</a></summary>

<div id="rule-postgresql-database"></div>

Matches `resource` instances of `azurerm_postgresql_flexible_server_database`.

**Classification:** [`azure.concept.logical-database`](#azure-concept-logical-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>azure.rule.postgresql-flexible-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-databases-topology.rf.hcl#L1-L54">Source</a></summary>

<div id="rule-postgresql-flexible-server"></div>

Matches `resource` instances of `azurerm_postgresql_flexible_server`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.delegated_subnet_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

**Relations**

- [`azure.relation.private-name-resolution`](#azure-relation-private-name-resolution): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.delegated_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.power-bi-embedded-capacity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/power-bi.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-power-bi-embedded-capacity"></div>

Matches `resource` instances of `azurerm_powerbi_embedded`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-dns-a-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L359-L396">Source</a></summary>

<div id="rule-private-dns-a-record"></div>

Matches `resource` instances of `azurerm_private_dns_a_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-dns-cname-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L398-L435">Source</a></summary>

<div id="rule-private-dns-cname-record"></div>

Matches `resource` instances of `azurerm_private_dns_cname_record`.

**Classification:** [`azure.concept.dns-record`](#azure-concept-dns-record).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-dns-forwarding-ruleset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L437-L443">Source</a></summary>

<div id="rule-private-dns-forwarding-ruleset"></div>

Matches `resource` instances of `azurerm_private_dns_resolver_dns_forwarding_ruleset`.

**Classification:** [`azure.concept.private-network-link`](#azure-concept-private-network-link).

</details>

<details>
<summary><code>azure.rule.private-dns-inbound-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L445-L451">Source</a></summary>

<div id="rule-private-dns-inbound-endpoint"></div>

Matches `resource` instances of `azurerm_private_dns_resolver_inbound_endpoint`.

**Classification:** [`azure.concept.private-network-link`](#azure-concept-private-network-link).

</details>

<details>
<summary><code>azure.rule.private-dns-outbound-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L453-L459">Source</a></summary>

<div id="rule-private-dns-outbound-endpoint"></div>

Matches `resource` instances of `azurerm_private_dns_resolver_outbound_endpoint`.

**Classification:** [`azure.concept.private-network-link`](#azure-concept-private-network-link).

</details>

<details>
<summary><code>azure.rule.private-dns-resolver</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/dns.rf.hcl#L461-L483">Source</a></summary>

<div id="rule-private-dns-resolver"></div>

Matches `resource` instances of `azurerm_private_dns_resolver`.

**Classification:** [`azure.concept.private-dns-resolver`](#azure-concept-private-dns-resolver).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-dns-zone-vnet-link</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/private-dns.rf.hcl#L34-L86">Source</a></summary>

<div id="rule-private-dns-zone-vnet-link"></div>

Matches `resource` instances of `azurerm_private_dns_zone_virtual_network_link`.

**Classification:** [`azure.concept.private-network-link`](#azure-concept-private-network-link).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.

**Contributions**

- targets [`azure.concept.dns-zone`](#azure-concept-dns-zone) through `source.private_dns_zone_id`.
- targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.virtual_network_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.private_dns_zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.virtual_network_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-dns-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/dns-cdn/private-dns.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-private-dns-zone"></div>

Matches `resource` instances of `azurerm_private_dns_zone`.

**Classification:** [`azure.concept.dns-zone`](#azure-concept-dns-zone).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/private-endpoints.rf.hcl#L1-L39">Source</a></summary>

<div id="rule-private-endpoint"></div>

Matches `resource` instances of `azurerm_private_endpoint`.

**Classification:** [`azure.concept.private-endpoint`](#azure-concept-private-endpoint).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.subnet_id`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.private-link-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/private-link.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-private-link-service"></div>

Matches `resource` instances of `azurerm_private_link_service`.

**Classification:** [`azure.concept.private-link-service`](#azure-concept-private-link-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.proximity-placement-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L54-L60">Source</a></summary>

<div id="rule-proximity-placement-group"></div>

Matches `resource` instances of `azurerm_proximity_placement_group`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.public-ip-prefix</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/public-ip-addresses.rf.hcl#L35-L66">Source</a></summary>

<div id="rule-public-ip-prefix"></div>

Matches `resource` instances of `azurerm_public_ip_prefix`.

**Classification:** [`azure.concept.public-address`](#azure-concept-public-address).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.public-address</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/public-ip-topology.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-public-address"></div>

Matches `resource` instances of `azurerm_public_ip`.

**Classification:** [`azure.concept.public-address`](#azure-concept-public-address).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.purview-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/purview-account.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-purview-account"></div>

Matches `resource` instances of `azurerm_purview_account`.

**Classification:** [`azure.concept.purview-account`](#azure-concept-purview-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.qumulo-file-system</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/qumulo-file.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-qumulo-file-system"></div>

Matches `resource` instances of `azurerm_qumulo_file_system`.

**Classification:** [`azure.concept.managed-file-storage`](#azure-concept-managed-file-storage).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.recovery-services-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/backup.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-recovery-services-vault"></div>

Matches `resource` instances of `azurerm_recovery_services_vault`.

**Classification:** [`azure.concept.backup-vault`](#azure-concept-backup-vault).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.red-hat-openshift-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/kubernetes-services.rf.hcl#L35-L66">Source</a></summary>

<div id="rule-red-hat-openshift-cluster"></div>

Matches `resource` instances of `azurerm_redhat_openshift_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.azure-cache-for-redis</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/databases/managed-redis.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-azure-cache-for-redis"></div>

Matches `resource` instances of `azurerm_redis_cache`.

**Classification:** [`azure.concept.managed-cache`](#azure-concept-managed-cache).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.relay-hybrid-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/relay.rf.hcl#L10-L32">Source</a></summary>

<div id="rule-relay-hybrid-connection"></div>

Matches `resource` instances of `azurerm_relay_hybrid_connection`.

**Classification:** [`azure.concept.relay-connection`](#azure-concept-relay-connection).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.relay-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/relay.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-relay-namespace"></div>

Matches `resource` instances of `azurerm_relay_namespace`.

**Classification:** [`azure.concept.relay-namespace`](#azure-concept-relay-namespace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.resource-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/resource-groups.rf.hcl#L1-L16">Source</a></summary>

<div id="rule-resource-group"></div>

Matches `resource` instances of `azurerm_resource_group`.

**Classification:** [`azure.concept.resource-group`](#azure-concept-resource-group).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>azure.rule.resource-policy-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/azure-policy.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-resource-policy-assignment"></div>

Matches `resource` instances of `azurerm_resource_policy_assignment`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.role-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/rbac.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-role-assignment"></div>

Matches `resource` instances of `azurerm_role_assignment`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.role-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/governance-management/rbac.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-role-definition"></div>

Matches `resource` instances of `azurerm_role_definition`.

**Classification:** [`azure.concept.governance-detail`](#azure-concept-governance-detail).

</details>

<details>
<summary><code>azure.rule.route-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/routing.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-route-server"></div>

Matches `resource` instances of `azurerm_route_server`.

**Classification:** [`azure.concept.route-table`](#azure-concept-route-table).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.route-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/routing.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-route-table"></div>

Matches `resource` instances of `azurerm_route_table`.

**Classification:** [`azure.concept.route-table`](#azure-concept-route-table).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/route.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-route"></div>

Matches `resource` instances of `azurerm_route`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.ai-search-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/ai-search.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-ai-search-service"></div>

Matches `resource` instances of `azurerm_search_service`.

**Classification:** [`azure.concept.ai-search-service`](#azure-concept-ai-search-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.defender-subscription-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/defender-subscription.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-defender-subscription-plan"></div>

Matches `resource` instances of `azurerm_security_center_subscription_pricing`.

**Classification:** [`azure.concept.defender-plan`](#azure-concept-defender-plan).

</details>

<details>
<summary><code>azure.rule.defender-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/defender-workspace.rf.hcl#L2-L8">Source</a></summary>

<div id="rule-defender-workspace"></div>

Matches `resource` instances of `azurerm_security_center_workspace`.

**Classification:** [`azure.concept.defender-plan`](#azure-concept-defender-plan).

</details>

<details>
<summary><code>azure.rule.sentinel-nrt-alert-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/sentinel.rf.hcl#L27-L33">Source</a></summary>

<div id="rule-sentinel-nrt-alert-rule"></div>

Matches `resource` instances of `azurerm_sentinel_alert_rule_nrt`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.sentinel-scheduled-alert-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/sentinel.rf.hcl#L36-L42">Source</a></summary>

<div id="rule-sentinel-scheduled-alert-rule"></div>

Matches `resource` instances of `azurerm_sentinel_alert_rule_scheduled`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.sentinel-automation-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/sentinel.rf.hcl#L3-L9">Source</a></summary>

<div id="rule-sentinel-automation-rule"></div>

Matches `resource` instances of `azurerm_sentinel_automation_rule`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.sentinel-aws-cloudtrail-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/sentinel.rf.hcl#L11-L17">Source</a></summary>

<div id="rule-sentinel-aws-cloudtrail-connector"></div>

Matches `resource` instances of `azurerm_sentinel_data_connector_aws_cloud_trail`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.sentinel-entra-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/sentinel.rf.hcl#L19-L25">Source</a></summary>

<div id="rule-sentinel-entra-connector"></div>

Matches `resource` instances of `azurerm_sentinel_data_connector_azure_active_directory`.

**Classification:** [`azure.concept.security-detail`](#azure-concept-security-detail).

</details>

<details>
<summary><code>azure.rule.service-fabric-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/service-fabric.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-service-fabric-cluster"></div>

Matches `resource` instances of `azurerm_service_fabric_cluster`.

**Classification:** [`azure.concept.service-fabric-cluster`](#azure-concept-service-fabric-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.managed-service-fabric-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/containers/managed-service.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-managed-service-fabric-cluster"></div>

Matches `resource` instances of `azurerm_service_fabric_managed_cluster`.

**Classification:** [`azure.concept.service-fabric-cluster`](#azure-concept-service-fabric-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.app-service-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L38-L69">Source</a></summary>

<div id="rule-app-service-plan"></div>

Matches `resource` instances of `azurerm_service_plan`.

**Classification:** [`azure.concept.app-service-plan`](#azure-concept-app-service-plan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.service-bus-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/service-bus.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-service-bus-namespace"></div>

Matches `resource` instances of `azurerm_servicebus_namespace`.

**Classification:** [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.service-bus-queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/service-bus.rf.hcl#L35-L66">Source</a></summary>

<div id="rule-service-bus-queue"></div>

Matches `resource` instances of `azurerm_servicebus_queue`.

**Classification:** [`azure.concept.message-queue`](#azure-concept-message-queue).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace) through `source.namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.service-bus-subscription-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/service-bus.rf.hcl#L101-L107">Source</a></summary>

<div id="rule-service-bus-subscription-rule"></div>

Matches `resource` instances of `azurerm_servicebus_subscription_rule`.

**Classification:** [`azure.concept.messaging-detail`](#azure-concept-messaging-detail).

</details>

<details>
<summary><code>azure.rule.service-bus-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/service-bus.rf.hcl#L68-L99">Source</a></summary>

<div id="rule-service-bus-subscription"></div>

Matches `resource` instances of `azurerm_servicebus_subscription`.

**Classification:** [`azure.concept.message-subscription`](#azure-concept-message-subscription).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.service-bus-topic`](#azure-concept-service-bus-topic) through `source.topic_id`.

**Relations**

- [`azure.relation.subscribes-to`](#azure-relation-subscribes-to): targets [`azure.concept.service-bus-topic`](#azure-concept-service-bus-topic) through `source.topic_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.topic_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.topic_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.service-bus-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/messaging-eventing/service-bus.rf.hcl#L109-L140">Source</a></summary>

<div id="rule-service-bus-topic"></div>

Matches `resource` instances of `azurerm_servicebus_topic`.

**Classification:** [`azure.concept.service-bus-topic`](#azure-concept-service-bus-topic).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.messaging-namespace`](#azure-concept-messaging-namespace) through `source.namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.compute-gallery</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/compute-gallery.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-compute-gallery"></div>

Matches `resource` instances of `azurerm_shared_image_gallery`.

**Classification:** [`azure.concept.image-gallery`](#azure-concept-image-gallery).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.shared-image</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/compute-gallery.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-shared-image"></div>

Matches `resource` instances of `azurerm_shared_image`.

**Classification:** [`azure.concept.compute-image`](#azure-concept-compute-image).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.signalr-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/signalr-service.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-signalr-service"></div>

Matches `resource` instances of `azurerm_signalr_service`.

**Classification:** [`azure.concept.realtime-communication-service`](#azure-concept-realtime-communication-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.site-recovery-fabric</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/site-recovery.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-site-recovery-fabric"></div>

Matches `resource` instances of `azurerm_site_recovery_fabric`.

**Classification:** [`azure.concept.site-recovery-fabric`](#azure-concept-site-recovery-fabric).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.site-recovery-protection-container</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/site-recovery.rf.hcl#L38-L60">Source</a></summary>

<div id="rule-site-recovery-protection-container"></div>

Matches `resource` instances of `azurerm_site_recovery_protection_container`.

**Classification:** [`azure.concept.site-recovery-fabric`](#azure-concept-site-recovery-fabric).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.site-recovery-replicated-vm</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/site-recovery.rf.hcl#L62-L68">Source</a></summary>

<div id="rule-site-recovery-replicated-vm"></div>

Matches `resource` instances of `azurerm_site_recovery_replicated_vm`.

**Classification:** [`azure.concept.site-recovery-detail`](#azure-concept-site-recovery-detail).

</details>

<details>
<summary><code>azure.rule.site-recovery-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/site-recovery.rf.hcl#L30-L36">Source</a></summary>

<div id="rule-site-recovery-plan"></div>

Matches `resource` instances of `azurerm_site_recovery_replication_recovery_plan`.

**Classification:** [`azure.concept.site-recovery-detail`](#azure-concept-site-recovery-detail).

</details>

<details>
<summary><code>azure.rule.disk-snapshot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/managed-disks.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-disk-snapshot"></div>

Matches `resource` instances of `azurerm_snapshot`.

**Classification:** [`azure.concept.disk-snapshot`](#azure-concept-disk-snapshot).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.spring-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/spring-app.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-spring-app"></div>

Matches `resource` instances of `azurerm_spring_cloud_app`.

**Classification:** [`azure.concept.spring-app`](#azure-concept-spring-app).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.spring-apps-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/spring-apps.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-spring-apps-gateway"></div>

Matches `resource` instances of `azurerm_spring_cloud_gateway`.

**Classification:** [`azure.concept.spring-app`](#azure-concept-spring-app).

</details>

<details>
<summary><code>azure.rule.spring-apps-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/spring-apps.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-spring-apps-service"></div>

Matches `resource` instances of `azurerm_spring_cloud_service`.

**Classification:** [`azure.concept.spring-apps-service`](#azure-concept-spring-apps-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.azure-local-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/azure-local.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-azure-local-cluster"></div>

Matches `resource` instances of `azurerm_stack_hci_cluster`.

**Classification:** [`azure.concept.azure-local-cluster`](#azure-concept-azure-local-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.stack-hci-virtual-hard-disk</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/disk.rf.hcl#L34-L56">Source</a></summary>

<div id="rule-stack-hci-virtual-hard-disk"></div>

Matches `resource` instances of `azurerm_stack_hci_virtual_hard_disk`.

**Classification:** [`azure.concept.block-storage-volume`](#azure-concept-block-storage-volume).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.static-web-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/static-web.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-static-web-app"></div>

Matches `resource` instances of `azurerm_static_web_app`.

**Classification:** [`azure.concept.static-web-app`](#azure-concept-static-web-app).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage-accounts.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-storage-account"></div>

Matches `resource` instances of `azurerm_storage_account`.

**Classification:** [`azure.concept.storage-account`](#azure-concept-storage-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-blob</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L63-L84">Source</a></summary>

<div id="rule-storage-blob"></div>

Matches `resource` instances of `azurerm_storage_blob`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.storage_container_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.storage_container_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.blob-container</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L30-L61">Source</a></summary>

<div id="rule-blob-container"></div>

Matches `resource` instances of `azurerm_storage_container`.

**Classification:** [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-lake-filesystem</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/data-lake-storage.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-data-lake-filesystem"></div>

Matches `resource` instances of `azurerm_storage_data_lake_gen2_filesystem`.

**Classification:** [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.data-lake-path</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/data-lake-storage.rf.hcl#L35-L41">Source</a></summary>

<div id="rule-data-lake-path"></div>

Matches `resource` instances of `azurerm_storage_data_lake_gen2_path`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

</details>

<details>
<summary><code>azure.rule.storage-encryption-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L86-L107">Source</a></summary>

<div id="rule-storage-encryption-scope"></div>

Matches `resource` instances of `azurerm_storage_encryption_scope`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

**Contributions**

- targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-management-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L109-L130">Source</a></summary>

<div id="rule-storage-management-policy"></div>

Matches `resource` instances of `azurerm_storage_management_policy`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

**Contributions**

- targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-mover</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/migration/storage.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-storage-mover"></div>

Matches `resource` instances of `azurerm_storage_mover`.

**Classification:** [`azure.concept.migration-service`](#azure-concept-migration-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.queue-storage-queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/queue-storage.rf.hcl#L2-L33">Source</a></summary>

<div id="rule-queue-storage-queue"></div>

Matches `resource` instances of `azurerm_storage_queue`.

**Classification:** [`azure.concept.message-queue`](#azure-concept-message-queue).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-share-directory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L132-L138">Source</a></summary>

<div id="rule-storage-share-directory"></div>

Matches `resource` instances of `azurerm_storage_share_directory`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

</details>

<details>
<summary><code>azure.rule.storage-share-file</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L140-L146">Source</a></summary>

<div id="rule-storage-share-file"></div>

Matches `resource` instances of `azurerm_storage_share_file`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

</details>

<details>
<summary><code>azure.rule.azure-files-share</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-azure-files-share"></div>

Matches `resource` instances of `azurerm_storage_share`.

**Classification:** [`azure.concept.managed-file-storage`](#azure-concept-managed-file-storage).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-sync-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L148-L170">Source</a></summary>

<div id="rule-storage-sync-service"></div>

Matches `resource` instances of `azurerm_storage_sync`.

**Classification:** [`azure.concept.storage-sync-service`](#azure-concept-storage-sync-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.storage-table-entity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/storage.rf.hcl#L172-L190">Source</a></summary>

<div id="rule-storage-table-entity"></div>

Matches `resource` instances of `azurerm_storage_table_entity`.

**Classification:** [`azure.concept.storage-object-detail`](#azure-concept-storage-object-detail).

**Contributions**

- targets [`azure.concept.table-storage-table`](#azure-concept-table-storage-table) through `source.storage_table_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.storage_table_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.table-storage-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/storage/table-storage.rf.hcl#L6-L37">Source</a></summary>

<div id="rule-table-storage-table"></div>

Matches `resource` instances of `azurerm_storage_table`.

**Classification:** [`azure.concept.table-storage-table`](#azure-concept-table-storage-table).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.storage-account`](#azure-concept-storage-account) through `source.storage_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.storage_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.stream-analytics-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/stream-analytics.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-stream-analytics-cluster"></div>

Matches `resource` instances of `azurerm_stream_analytics_cluster`.

**Classification:** [`azure.concept.analytics-cluster`](#azure-concept-analytics-cluster).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.stream-analytics-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/stream-analytics.rf.hcl#L30-L52">Source</a></summary>

<div id="rule-stream-analytics-job"></div>

Matches `resource` instances of `azurerm_stream_analytics_job`.

**Classification:** [`azure.concept.stream-analytics-job`](#azure-concept-stream-analytics-job).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.stream-analytics-blob-output</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L118-L124">Source</a></summary>

<div id="rule-stream-analytics-blob-output"></div>

Matches `resource` instances of `azurerm_stream_analytics_output_blob`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.stream-analytics-event-hubs-input</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/data-factory.rf.hcl#L126-L132">Source</a></summary>

<div id="rule-stream-analytics-event-hubs-input"></div>

Matches `resource` instances of `azurerm_stream_analytics_stream_input_eventhub_v2`.

**Classification:** [`azure.concept.data-integration-detail`](#azure-concept-data-integration-detail).

</details>

<details>
<summary><code>azure.rule.subnet-nat-gateway-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/subnets.rf.hcl#L2-L35">Source</a></summary>

<div id="rule-subnet-nat-gateway-association"></div>

Matches `resource` instances of `azurerm_subnet_nat_gateway_association`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

**Contributions**

- targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.subnet_id`.
- targets [`azure.concept.managed-nat`](#azure-concept-managed-nat) through `source.nat_gateway_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.nat_gateway_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.subnet-network-security-group-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/subnets.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-subnet-network-security-group-association"></div>

Matches `resource` instances of `azurerm_subnet_network_security_group_association`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.subnet-route-table-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/routing.rf.hcl#L54-L60">Source</a></summary>

<div id="rule-subnet-route-table-association"></div>

Matches `resource` instances of `azurerm_subnet_route_table_association`.

**Classification:** [`azure.concept.network-policy-detail`](#azure-concept-network-policy-detail).

</details>

<details>
<summary><code>azure.rule.subnet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vnet.rf.hcl#L34-L81">Source</a></summary>

<div id="rule-subnet"></div>

Matches `resource` instances of `azurerm_subnet`.

**Classification:** [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.virtual_network_name`.
- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.virtual_network_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.synapse-private-link-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/synapse.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-synapse-private-link-hub"></div>

Matches `resource` instances of `azurerm_synapse_private_link_hub`.

**Classification:** [`azure.concept.private-link-scope`](#azure-concept-private-link-scope).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.synapse-spark-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/synapse.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-synapse-spark-pool"></div>

Matches `resource` instances of `azurerm_synapse_spark_pool`.

**Classification:** [`azure.concept.analytics-pool`](#azure-concept-analytics-pool).

</details>

<details>
<summary><code>azure.rule.synapse-sql-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/synapse.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-synapse-sql-pool"></div>

Matches `resource` instances of `azurerm_synapse_sql_pool`.

**Classification:** [`azure.concept.analytics-pool`](#azure-concept-analytics-pool).

</details>

<details>
<summary><code>azure.rule.synapse-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/data-analytics/synapse.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-synapse-workspace"></div>

Matches `resource` instances of `azurerm_synapse_workspace`.

**Classification:** [`azure.concept.synapse-workspace`](#azure-concept-synapse-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.system-center-vmm-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/system-center.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-system-center-vmm-server"></div>

Matches `resource` instances of `azurerm_system_center_virtual_machine_manager_server`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.system-center-virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L74-L80">Source</a></summary>

<div id="rule-system-center-virtual-machine"></div>

Matches `resource` instances of `azurerm_system_center_virtual_machine_manager_virtual_machine_instance`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

</details>

<details>
<summary><code>azure.rule.traffic-manager-azure-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/traffic-manager.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-traffic-manager-azure-endpoint"></div>

Matches `resource` instances of `azurerm_traffic_manager_azure_endpoint`.

**Classification:** [`azure.concept.load-balancer-component`](#azure-concept-load-balancer-component).

</details>

<details>
<summary><code>azure.rule.traffic-manager-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/load-balancing/traffic-manager.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-traffic-manager-profile"></div>

Matches `resource` instances of `azurerm_traffic_manager_profile`.

**Classification:** [`azure.concept.traffic-manager-profile`](#azure-concept-traffic-manager-profile).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.trusted-signing-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/security/trusted-signing.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-trusted-signing-account"></div>

Matches `resource` instances of `azurerm_trusted_signing_account`.

**Classification:** [`azure.concept.trusted-signing-account`](#azure-concept-trusted-signing-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.user-assigned-managed-identity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/identity-iam/managed-identities.rf.hcl#L1-L34">Source</a></summary>

<div id="rule-user-assigned-managed-identity"></div>

Matches `resource` instances of `azurerm_user_assigned_identity`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "principal_id", "client_id"]`
- `scope`: `"global"`

**Endpoint**

- `attributes`: `["id", "principal_id", "client_id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.video-indexer-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/ai-ml/video-indexer.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-video-indexer-account"></div>

Matches `resource` instances of `azurerm_video_indexer_account`.

**Classification:** [`azure.concept.video-indexer-account`](#azure-concept-video-indexer-account).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-desktop-application-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L22-L44">Source</a></summary>

<div id="rule-virtual-desktop-application-group"></div>

Matches `resource` instances of `azurerm_virtual_desktop_application_group`.

**Classification:** [`azure.concept.virtual-desktop-application-group`](#azure-concept-virtual-desktop-application-group).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-desktop-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L14-L20">Source</a></summary>

<div id="rule-virtual-desktop-application"></div>

Matches `resource` instances of `azurerm_virtual_desktop_application`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.virtual-desktop-host-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L46-L68">Source</a></summary>

<div id="rule-virtual-desktop-host-pool"></div>

Matches `resource` instances of `azurerm_virtual_desktop_host_pool`.

**Classification:** [`azure.concept.virtual-desktop-host-pool`](#azure-concept-virtual-desktop-host-pool).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-desktop-scaling-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L70-L76">Source</a></summary>

<div id="rule-virtual-desktop-scaling-plan"></div>

Matches `resource` instances of `azurerm_virtual_desktop_scaling_plan`.

**Classification:** [`azure.concept.compute-placement`](#azure-concept-compute-placement).

</details>

<details>
<summary><code>azure.rule.virtual-desktop-workspace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-desktop.rf.hcl#L78-L100">Source</a></summary>

<div id="rule-virtual-desktop-workspace"></div>

Matches `resource` instances of `azurerm_virtual_desktop_workspace`.

**Classification:** [`azure.concept.virtual-desktop-workspace`](#azure-concept-virtual-desktop-workspace).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-hub.rf.hcl#L7-L29">Source</a></summary>

<div id="rule-virtual-hub"></div>

Matches `resource` instances of `azurerm_virtual_hub`.

**Classification:** [`azure.concept.virtual-hub`](#azure-concept-virtual-hub).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-machine-restore-point</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machines.rf.hcl#L62-L68">Source</a></summary>

<div id="rule-virtual-machine-restore-point"></div>

Matches `resource` instances of `azurerm_virtual_machine_restore_point`.

**Classification:** [`azure.concept.disk-snapshot`](#azure-concept-disk-snapshot).

</details>

<details>
<summary><code>azure.rule.virtual-machine-scale-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/vm-scale-set.rf.hcl#L54-L76">Source</a></summary>

<div id="rule-virtual-machine-scale-set"></div>

Matches `resource` instances of `azurerm_virtual_machine_scale_set`.

**Classification:** [`azure.concept.virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L82-L104">Source</a></summary>

<div id="rule-virtual-machine"></div>

Matches `resource` instances of `azurerm_virtual_machine`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-network-gateway-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-virtual-network-gateway-connection"></div>

Matches `resource` instances of `azurerm_virtual_network_gateway_connection`.

**Classification:** [`azure.concept.vpn-connection`](#azure-concept-vpn-connection).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-network-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-virtual-network-gateway"></div>

Matches `resource` instances of `azurerm_virtual_network_gateway`.

**Classification:** [`azure.concept.vpn-gateway`](#azure-concept-vpn-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-network.rf.hcl#L30-L83">Source</a></summary>

<div id="rule-virtual-network-peering"></div>

Matches `resource` instances of `azurerm_virtual_network_peering`.

**Classification:** [`azure.concept.network-peering`](#azure-concept-network-peering).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.virtual_network_name`.

**Relations**

- [`azure.relation.peers-with`](#azure-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.remote_virtual_network_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.remote_virtual_network_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vnet.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-virtual-network"></div>

Matches `resource` instances of `azurerm_virtual_network`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.virtual-wan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/virtual-wan.rf.hcl#L6-L28">Source</a></summary>

<div id="rule-virtual-wan"></div>

Matches `resource` instances of `azurerm_virtual_wan`.

**Classification:** [`azure.concept.virtual-wan`](#azure-concept-virtual-wan).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.vmware-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/vmware-solution.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-vmware-cluster"></div>

Matches `resource` instances of `azurerm_vmware_cluster`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

</details>

<details>
<summary><code>azure.rule.vmware-private-cloud</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/vmware-solution.rf.hcl#L14-L36">Source</a></summary>

<div id="rule-vmware-private-cloud"></div>

Matches `resource` instances of `azurerm_vmware_private_cloud`.

**Classification:** [`azure.concept.vmware-private-cloud`](#azure-concept-vmware-private-cloud).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.vpn-gateway-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L98-L104">Source</a></summary>

<div id="rule-vpn-gateway-connection"></div>

Matches `resource` instances of `azurerm_vpn_gateway_connection`.

**Classification:** [`azure.concept.vpn-connection`](#azure-concept-vpn-connection).

</details>

<details>
<summary><code>azure.rule.vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L74-L96">Source</a></summary>

<div id="rule-vpn-gateway"></div>

Matches `resource` instances of `azurerm_vpn_gateway`.

**Classification:** [`azure.concept.vpn-gateway`](#azure-concept-vpn-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.vpn-site</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/vpn-gateway.rf.hcl#L106-L128">Source</a></summary>

<div id="rule-vpn-site"></div>

Matches `resource` instances of `azurerm_vpn_site`.

**Classification:** [`azure.concept.local-network-gateway`](#azure-concept-local-network-gateway).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.web-application-firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/network/firewall.rf.hcl#L54-L85">Source</a></summary>

<div id="rule-web-application-firewall-policy"></div>

Matches `resource` instances of `azurerm_web_application_firewall_policy`.

**Classification:** [`azure.concept.web-application-firewall-policy`](#azure-concept-web-application-firewall-policy).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.web-pubsub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/communication/web-pubsub.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-web-pubsub"></div>

Matches `resource` instances of `azurerm_web_pubsub`.

**Classification:** [`azure.concept.realtime-communication-service`](#azure-concept-realtime-communication-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.windows-function-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/functions.rf.hcl#L155-L227">Source</a></summary>

<div id="rule-windows-function-app"></div>

Matches `resource` instances of `azurerm_windows_function_app`.

**Classification:** [`azure.concept.serverless-function`](#azure-concept-serverless-function).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.virtual_network_subnet_id`.
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.app-service-plan`](#azure-concept-app-service-plan) through `source.service_plan_id`.

**Relations**

- [`azure.relation.observed-by`](#azure-relation-observed-by): targets [`azure.concept.application-insights`](#azure-concept-application-insights) through `source.site_config[0].application_insights_connection_string`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.service_plan_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.site_config[0].application_insights_connection_string`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.connection_string`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.windows-virtual-machine-scale-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/vm-scale-set.rf.hcl#L78-L100">Source</a></summary>

<div id="rule-windows-virtual-machine-scale-set"></div>

Matches `resource` instances of `azurerm_windows_virtual_machine_scale_set`.

**Classification:** [`azure.concept.virtual-machine-scale-set`](#azure-concept-virtual-machine-scale-set).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.windows-virtual-machine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/compute/virtual-machine.rf.hcl#L106-L128">Source</a></summary>

<div id="rule-windows-virtual-machine"></div>

Matches `resource` instances of `azurerm_windows_virtual_machine`.

**Classification:** [`azure.concept.compute-instance`](#azure-concept-compute-instance).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.windows-web-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/serverless/app-service.rf.hcl#L125-L177">Source</a></summary>

<div id="rule-windows-web-app"></div>

Matches `resource` instances of `azurerm_windows_web_app`.

**Classification:** [`azure.concept.app-service`](#azure-concept-app-service).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.virtual_network_subnet_id`.
- [`rf.context.runtime`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-runtime): targets [`azure.concept.app-service-plan`](#azure-concept-app-service-plan) through `source.service_plan_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.virtual_network_subnet_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.service_plan_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.sap-discovery-virtual-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/sap-solutions.rf.hcl#L2-L24">Source</a></summary>

<div id="rule-sap-discovery-virtual-instance"></div>

Matches `resource` instances of `azurerm_workloads_sap_discovery_virtual_instance`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.sap-single-node-virtual-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/sap-solutions.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-sap-single-node-virtual-instance"></div>

Matches `resource` instances of `azurerm_workloads_sap_single_node_virtual_instance`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>azure.rule.sap-three-tier-virtual-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/azure/hybrid/sap-solutions.rf.hcl#L50-L72">Source</a></summary>

<div id="rule-sap-three-tier-virtual-instance"></div>

Matches `resource` instances of `azurerm_workloads_sap_three_tier_virtual_instance`.

**Classification:** [`azure.concept.hybrid-platform`](#azure-concept-hybrid-platform).

**Contexts**

- [`azure.context.ownership`](#azure-context-ownership): targets [`azure.concept.resource-group`](#azure-concept-resource-group) through `source.resource_group_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.resource_group_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>
