# cloudflare Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `cloudflare/cloudflare`: `= 5.24.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `cloudflare_account_dns_settings_internal_view` | `resource` | [`dns-view`](#cloudflare-concept-dns-view) | [`account-dns-internal-view`](#rule-account-dns-internal-view) |
| `cloudflare_account_dns_settings` | `resource` | [`account-configuration`](#cloudflare-concept-account-configuration) | [`account-dns-settings`](#rule-account-dns-settings) |
| `cloudflare_account` | `resource` | [`account`](#cloudflare-concept-account) | [`account`](#rule-account) |
| `cloudflare_ai_gateway_dynamic_routing` | `resource` | [`ai-gateway-routing`](#cloudflare-concept-ai-gateway-routing) | [`ai-gateway-dynamic-routing`](#rule-ai-gateway-dynamic-routing) |
| `cloudflare_ai_gateway` | `resource` | [`ai-gateway`](#cloudflare-concept-ai-gateway) | [`ai-gateway`](#rule-ai-gateway) |
| `cloudflare_api_shield_discovery_operation` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield-discovery-operation`](#rule-api-shield-discovery-operation) |
| `cloudflare_api_shield_operation_schema_validation_settings` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield-operation-schema-validation`](#rule-api-shield-operation-schema-validation) |
| `cloudflare_api_shield_operation` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield-operation`](#rule-api-shield-operation) |
| `cloudflare_api_shield_schema_validation_settings` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield-schema-validation`](#rule-api-shield-schema-validation) |
| `cloudflare_api_shield_schema` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield-schema`](#rule-api-shield-schema) |
| `cloudflare_api_shield` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`api-shield`](#rule-api-shield) |
| `cloudflare_argo_smart_routing` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`argo-smart-routing`](#rule-argo-smart-routing) |
| `cloudflare_argo_tiered_caching` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`argo-tiered-caching`](#rule-argo-tiered-caching) |
| `cloudflare_authenticated_origin_pulls_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`authenticated-origin-pulls-certificate`](#rule-authenticated-origin-pulls-certificate) |
| `cloudflare_authenticated_origin_pulls_hostname_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`authenticated-origin-pulls-hostname-certificate`](#rule-authenticated-origin-pulls-hostname-certificate) |
| `cloudflare_authenticated_origin_pulls_settings` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`authenticated-origin-pulls-settings`](#rule-authenticated-origin-pulls-settings) |
| `cloudflare_authenticated_origin_pulls` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`authenticated-origin-pulls`](#rule-authenticated-origin-pulls) |
| `cloudflare_bot_management` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`bot-management`](#rule-bot-management) |
| `cloudflare_certificate_authorities_hostname_associations` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`certificate-authority-hostname-associations`](#rule-certificate-authority-hostname-associations) |
| `cloudflare_certificate_pack` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`certificate-pack`](#rule-certificate-pack) |
| `cloudflare_client_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`client-certificate`](#rule-client-certificate) |
| `cloudflare_cloud_connector_rules` | `resource` | [`network-route-configuration`](#cloudflare-concept-network-route-configuration) | [`cloud-connector-rules`](#rule-cloud-connector-rules) |
| `cloudflare_connectivity_directory_service` | `resource` | [`connectivity-service`](#cloudflare-concept-connectivity-service) | [`connectivity-directory-service`](#rule-connectivity-directory-service) |
| `cloudflare_content_scanning_expression` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`content-scanning-expression`](#rule-content-scanning-expression) |
| `cloudflare_content_scanning` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`content-scanning`](#rule-content-scanning) |
| `cloudflare_ct_alerting` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`certificate-transparency-alerting`](#rule-certificate-transparency-alerting) |
| `cloudflare_custom_csr` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`custom-csr`](#rule-custom-csr) |
| `cloudflare_custom_hostname_fallback_origin` | `resource` | [`saas-fallback-origin`](#cloudflare-concept-saas-fallback-origin) | [`custom-hostname-fallback-origin`](#rule-custom-hostname-fallback-origin) |
| `cloudflare_custom_hostname` | `resource` | [`custom-hostname`](#cloudflare-concept-custom-hostname) | [`custom-hostname`](#rule-custom-hostname) |
| `cloudflare_custom_origin_trust_store` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`custom-origin-trust-store`](#rule-custom-origin-trust-store) |
| `cloudflare_custom_ssl` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`custom-ssl`](#rule-custom-ssl) |
| `cloudflare_d1_database` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`d1-database`](#rule-d1-database) |
| `cloudflare_dns_record` | `resource` | [`dns-record-detail`](#cloudflare-concept-dns-record-detail)<br>[`edge-route`](#cloudflare-concept-edge-route) | [`dns-record`](#rule-dns-record) (conditional)<br>[`proxied-dns-record`](#rule-proxied-dns-record) (conditional) |
| `cloudflare_dns_zone_transfers_acl` | `resource` | [`dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration) | [`dns-transfer-acl`](#rule-dns-transfer-acl) |
| `cloudflare_dns_zone_transfers_incoming` | `resource` | [`dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration) | [`dns-transfer-incoming`](#rule-dns-transfer-incoming) |
| `cloudflare_dns_zone_transfers_outgoing` | `resource` | [`dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration) | [`dns-transfer-outgoing`](#rule-dns-transfer-outgoing) |
| `cloudflare_dns_zone_transfers_peer` | `resource` | [`dns-transfer-peer`](#cloudflare-concept-dns-transfer-peer) | [`dns-transfer-peer`](#rule-dns-transfer-peer) |
| `cloudflare_dns_zone_transfers_tsig` | `resource` | [`dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration) | [`dns-transfer-tsig`](#rule-dns-transfer-tsig) |
| `cloudflare_email_routing_catch_all` | `resource` | [`email-routing-configuration`](#cloudflare-concept-email-routing-configuration) | [`email-routing-catch-all`](#rule-email-routing-catch-all) |
| `cloudflare_email_routing_rule` | `resource` | [`email-routing-configuration`](#cloudflare-concept-email-routing-configuration) | [`email-routing-rule`](#rule-email-routing-rule) |
| `cloudflare_email_routing_settings` | `resource` | [`email-routing-configuration`](#cloudflare-concept-email-routing-configuration) | [`email-routing-settings`](#rule-email-routing-settings) |
| `cloudflare_email_security_block_sender` | `resource` | [`email-security-configuration`](#cloudflare-concept-email-security-configuration) | [`email-security-block-sender`](#rule-email-security-block-sender) |
| `cloudflare_email_security_impersonation_registry` | `resource` | [`email-security-configuration`](#cloudflare-concept-email-security-configuration) | [`email-security-impersonation-registry`](#rule-email-security-impersonation-registry) |
| `cloudflare_email_security_trusted_domains` | `resource` | [`email-security-configuration`](#cloudflare-concept-email-security-configuration) | [`email-security-trusted-domains`](#rule-email-security-trusted-domains) |
| `cloudflare_firewall_rule` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`firewall-rule`](#rule-firewall-rule) |
| `cloudflare_flagship_app` | `resource` | [`feature-flag-application`](#cloudflare-concept-feature-flag-application) | [`flagship-app`](#rule-flagship-app) |
| `cloudflare_flagship_flag` | `resource` | [`feature-flag`](#cloudflare-concept-feature-flag) | [`flagship-flag`](#rule-flagship-flag) |
| `cloudflare_google_tag_gateway` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`google-tag-gateway`](#rule-google-tag-gateway) |
| `cloudflare_healthcheck` | `resource` | [`load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring) | [`healthcheck`](#rule-healthcheck) |
| `cloudflare_hostname_tls_setting` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`hostname-tls-setting`](#rule-hostname-tls-setting) |
| `cloudflare_hyperdrive_config` | `resource` | [`hyperdrive-configuration`](#cloudflare-concept-hyperdrive-configuration) | [`hyperdrive-config`](#rule-hyperdrive-config) |
| `cloudflare_keyless_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`keyless-certificate`](#rule-keyless-certificate) |
| `cloudflare_load_balancer_monitor_group` | `resource` | [`load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring) | [`load-balancer-monitor-group`](#rule-load-balancer-monitor-group) |
| `cloudflare_load_balancer_monitor` | `resource` | [`load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring) | [`load-balancer-monitor`](#rule-load-balancer-monitor) |
| `cloudflare_load_balancer_pool` | `resource` | [`origin-pool`](#cloudflare-concept-origin-pool) | [`load-balancer-pool`](#rule-load-balancer-pool) |
| `cloudflare_load_balancer` | `resource` | [`load-balancer`](#cloudflare-concept-load-balancer) | [`load-balancer`](#rule-load-balancer) |
| `cloudflare_logpull_retention` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`logpull-retention`](#rule-logpull-retention) |
| `cloudflare_magic_network_monitoring_configuration` | `resource` | [`network-monitor`](#cloudflare-concept-network-monitor) | [`network-monitoring`](#rule-network-monitoring) |
| `cloudflare_magic_network_monitoring_rule` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`network-monitoring-rule`](#rule-network-monitoring-rule) |
| `cloudflare_magic_transit_cf1_site` | `resource` | [`magic-transit-site`](#cloudflare-concept-magic-transit-site) | [`magic-transit-cf1-site`](#rule-magic-transit-cf1-site) |
| `cloudflare_magic_transit_site_acl` | `resource` | [`network-route-configuration`](#cloudflare-concept-network-route-configuration) | [`magic-transit-site-acl`](#rule-magic-transit-site-acl) |
| `cloudflare_magic_transit_site_lan` | `resource` | [`network-route-configuration`](#cloudflare-concept-network-route-configuration) | [`magic-transit-site-lan`](#rule-magic-transit-site-lan) |
| `cloudflare_magic_transit_site_wan` | `resource` | [`network-route-configuration`](#cloudflare-concept-network-route-configuration) | [`magic-transit-site-wan`](#rule-magic-transit-site-wan) |
| `cloudflare_magic_transit_site` | `resource` | [`magic-transit-site`](#cloudflare-concept-magic-transit-site) | [`magic-transit-site`](#rule-magic-transit-site) |
| `cloudflare_magic_wan_static_route` | `resource` | [`network-route-configuration`](#cloudflare-concept-network-route-configuration) | [`magic-wan-static-route`](#rule-magic-wan-static-route) |
| `cloudflare_managed_transforms` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`managed-transforms`](#rule-managed-transforms) |
| `cloudflare_mtls_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`mtls-certificate`](#rule-mtls-certificate) |
| `cloudflare_notification_policy_webhooks` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`notification-webhook`](#rule-notification-webhook) |
| `cloudflare_notification_policy` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`notification-policy`](#rule-notification-policy) |
| `cloudflare_oauth_client` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`oauth-client`](#rule-oauth-client) |
| `cloudflare_origin_ca_certificate` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`origin-ca-certificate`](#rule-origin-ca-certificate) |
| `cloudflare_origin_cloud_region` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`origin-cloud-region`](#rule-origin-cloud-region) |
| `cloudflare_origin_tls_compliance_modes` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`origin-tls-compliance-modes`](#rule-origin-tls-compliance-modes) |
| `cloudflare_page_rule` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`page-rule`](#rule-page-rule) |
| `cloudflare_page_shield_policy` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`page-shield-policy`](#rule-page-shield-policy) |
| `cloudflare_pages_domain` | `resource` | [`pages-domain`](#cloudflare-concept-pages-domain) | [`pages-domain`](#rule-pages-domain) |
| `cloudflare_pages_project` | `resource` | [`pages-project`](#cloudflare-concept-pages-project) | [`pages-project`](#rule-pages-project) |
| `cloudflare_precursor` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`precursor`](#rule-precursor) |
| `cloudflare_queue_consumer` | `resource` | [`queue-consumer-binding`](#cloudflare-concept-queue-consumer-binding) | [`queue-consumer`](#rule-queue-consumer) |
| `cloudflare_queue` | `resource` | [`message-queue`](#cloudflare-concept-message-queue) | [`queue`](#rule-queue) |
| `cloudflare_r2_bucket_cors` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-bucket-cors`](#rule-r2-bucket-cors) |
| `cloudflare_r2_bucket_event_notification` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-bucket-event-notification`](#rule-r2-bucket-event-notification) |
| `cloudflare_r2_bucket_lifecycle` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-bucket-lifecycle`](#rule-r2-bucket-lifecycle) |
| `cloudflare_r2_bucket_lock` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-bucket-lock`](#rule-r2-bucket-lock) |
| `cloudflare_r2_bucket_sippy` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-bucket-sippy`](#rule-r2-bucket-sippy) |
| `cloudflare_r2_bucket` | `resource` | [`object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) | [`r2-bucket`](#rule-r2-bucket) |
| `cloudflare_r2_custom_domain` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-custom-domain`](#rule-r2-custom-domain) |
| `cloudflare_r2_data_catalog` | `resource` | [`r2-data-catalog`](#cloudflare-concept-r2-data-catalog) | [`r2-data-catalog`](#rule-r2-data-catalog) |
| `cloudflare_r2_managed_domain` | `resource` | [`r2-configuration`](#cloudflare-concept-r2-configuration) | [`r2-managed-domain`](#rule-r2-managed-domain) |
| `cloudflare_rate_limit` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`rate-limit`](#rule-rate-limit) |
| `cloudflare_regional_hostname` | `resource` | [`edge-route`](#cloudflare-concept-edge-route) | [`regional-hostname`](#rule-regional-hostname) |
| `cloudflare_regional_tiered_cache` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`regional-tiered-cache`](#rule-regional-tiered-cache) |
| `cloudflare_ruleset` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`ruleset`](#rule-ruleset) |
| `cloudflare_schema_validation_operation_settings` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`schema-validation-operation-settings`](#rule-schema-validation-operation-settings) |
| `cloudflare_schema_validation_schemas` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`schema-validation-schemas`](#rule-schema-validation-schemas) |
| `cloudflare_schema_validation_settings` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`schema-validation-settings`](#rule-schema-validation-settings) |
| `cloudflare_secrets_store_secret` | `resource` | [`managed-secret`](#cloudflare-concept-managed-secret) | [`secrets-store-secret`](#rule-secrets-store-secret) |
| `cloudflare_secrets_store` | `resource` | [`secrets-store`](#cloudflare-concept-secrets-store) | [`secrets-store`](#rule-secrets-store) |
| `cloudflare_snippet_rules` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`snippet-rules`](#rule-snippet-rules) |
| `cloudflare_snippet` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`snippet`](#rule-snippet) |
| `cloudflare_snippets` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`snippets`](#rule-snippets) |
| `cloudflare_spectrum_application` | `resource` | [`spectrum-application`](#cloudflare-concept-spectrum-application) | [`spectrum-application`](#rule-spectrum-application) |
| `cloudflare_sso_connector` | `resource` | [`identity-provider`](#cloudflare-concept-identity-provider) | [`sso-connector`](#rule-sso-connector) |
| `cloudflare_tiered_cache` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`tiered-cache`](#rule-tiered-cache) |
| `cloudflare_token_validation_config` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`token-validation-config`](#rule-token-validation-config) |
| `cloudflare_total_tls` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`total-tls`](#rule-total-tls) |
| `cloudflare_universal_ssl_setting` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`universal-ssl-setting`](#rule-universal-ssl-setting) |
| `cloudflare_url_normalization_settings` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`url-normalization-settings`](#rule-url-normalization-settings) |
| `cloudflare_user_agent_blocking_rule` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`user-agent-blocking-rule`](#rule-user-agent-blocking-rule) |
| `cloudflare_waiting_room_event` | `resource` | [`waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration) | [`waiting-room-event`](#rule-waiting-room-event) |
| `cloudflare_waiting_room_rules` | `resource` | [`waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration) | [`waiting-room-rules`](#rule-waiting-room-rules) |
| `cloudflare_waiting_room_settings` | `resource` | [`waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration) | [`waiting-room-settings`](#rule-waiting-room-settings) |
| `cloudflare_waiting_room` | `resource` | [`waiting-room`](#cloudflare-concept-waiting-room) | [`waiting-room`](#rule-waiting-room) |
| `cloudflare_web_analytics_rule` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`web-analytics-rule`](#rule-web-analytics-rule) |
| `cloudflare_web3_hostname` | `resource` | [`web3-hostname`](#cloudflare-concept-web3-hostname) | [`web3-hostname`](#rule-web3-hostname) |
| `cloudflare_worker_version` | `resource` | [`worker-version`](#cloudflare-concept-worker-version) | [`worker-version`](#rule-worker-version) |
| `cloudflare_worker` | `resource` | [`serverless-function`](#cloudflare-concept-serverless-function) | [`worker`](#rule-worker) |
| `cloudflare_workers_cron_trigger` | `resource` | [`worker-route`](#cloudflare-concept-worker-route) | [`workers-cron-trigger`](#rule-workers-cron-trigger) |
| `cloudflare_workers_custom_domain` | `resource` | [`edge-route`](#cloudflare-concept-edge-route) | [`workers-custom-domain`](#rule-workers-custom-domain) |
| `cloudflare_workers_deployment` | `resource` | [`worker-deployment`](#cloudflare-concept-worker-deployment) | [`workers-deployment`](#rule-workers-deployment) |
| `cloudflare_workers_kv_namespace` | `resource` | [`workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace) | [`workers-kv-namespace`](#rule-workers-kv-namespace) |
| `cloudflare_workers_kv` | `resource` | [`workers-kv-entry`](#cloudflare-concept-workers-kv-entry) | [`workers-kv`](#rule-workers-kv) |
| `cloudflare_workers_route` | `resource` | [`worker-route`](#cloudflare-concept-worker-route) | [`workers-route`](#rule-workers-route) |
| `cloudflare_workers_script_subdomain` | `resource` | [`worker-route`](#cloudflare-concept-worker-route) | [`workers-script-subdomain`](#rule-workers-script-subdomain) |
| `cloudflare_workers_script` | `resource` | [`serverless-function`](#cloudflare-concept-serverless-function) | [`workers-script`](#rule-workers-script) |
| `cloudflare_zero_trust_access_ai_controls_mcp_portal` | `resource` | [`ai-controls-endpoint`](#cloudflare-concept-ai-controls-endpoint) | [`access-ai-controls-mcp-portal`](#rule-access-ai-controls-mcp-portal) |
| `cloudflare_zero_trust_access_ai_controls_mcp_server` | `resource` | [`ai-controls-endpoint`](#cloudflare-concept-ai-controls-endpoint) | [`access-ai-controls-mcp-server`](#rule-access-ai-controls-mcp-server) |
| `cloudflare_zero_trust_access_application` | `resource` | [`access-application`](#cloudflare-concept-access-application) | [`access-application`](#rule-access-application) |
| `cloudflare_zero_trust_access_identity_provider` | `resource` | [`identity-provider`](#cloudflare-concept-identity-provider) | [`access-identity-provider`](#rule-access-identity-provider) |
| `cloudflare_zero_trust_access_service_token` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`access-service-token`](#rule-access-service-token) |
| `cloudflare_zero_trust_device_custom_profile` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-custom-profile`](#rule-device-custom-profile) |
| `cloudflare_zero_trust_device_default_profile` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-default-profile`](#rule-device-default-profile) |
| `cloudflare_zero_trust_device_deployment_groups` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-deployment-group`](#rule-device-deployment-group) |
| `cloudflare_zero_trust_device_ip_profile` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-ip-profile`](#rule-device-ip-profile) |
| `cloudflare_zero_trust_device_managed_networks` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-managed-network`](#rule-device-managed-network) |
| `cloudflare_zero_trust_device_posture_integration` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-posture-integration`](#rule-device-posture-integration) |
| `cloudflare_zero_trust_device_posture_rule` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-posture-rule`](#rule-device-posture-rule) |
| `cloudflare_zero_trust_device_settings` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-settings`](#rule-device-settings) |
| `cloudflare_zero_trust_device_subnet` | `resource` | [`device-posture-configuration`](#cloudflare-concept-device-posture-configuration) | [`device-subnet`](#rule-device-subnet) |
| `cloudflare_zero_trust_dex_rule` | `resource` | [`observability-configuration`](#cloudflare-concept-observability-configuration) | [`dex-rule`](#rule-dex-rule) |
| `cloudflare_zero_trust_dex_test` | `resource` | [`network-monitor`](#cloudflare-concept-network-monitor) | [`dex-test`](#rule-dex-test) |
| `cloudflare_zero_trust_dlp_custom_profile` | `resource` | [`data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration) | [`dlp-custom-profile`](#rule-dlp-custom-profile) |
| `cloudflare_zero_trust_dlp_dataset` | `resource` | [`data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration) | [`dlp-dataset`](#rule-dlp-dataset) |
| `cloudflare_zero_trust_dlp_integration_entry` | `resource` | [`data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration) | [`dlp-integration-entry`](#rule-dlp-integration-entry) |
| `cloudflare_zero_trust_dlp_predefined_profile` | `resource` | [`data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration) | [`dlp-predefined-profile`](#rule-dlp-predefined-profile) |
| `cloudflare_zero_trust_dlp_settings` | `resource` | [`data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration) | [`dlp-settings`](#rule-dlp-settings) |
| `cloudflare_zero_trust_gateway_logging` | `resource` | [`gateway-configuration`](#cloudflare-concept-gateway-configuration) | [`gateway-logging`](#rule-gateway-logging) |
| `cloudflare_zero_trust_gateway_settings` | `resource` | [`gateway-configuration`](#cloudflare-concept-gateway-configuration) | [`gateway-settings`](#rule-gateway-settings) |
| `cloudflare_zero_trust_network_hostname_route` | `resource` | [`tunnel-configuration`](#cloudflare-concept-tunnel-configuration) | [`cloudflare-tunnel-hostname-route`](#rule-cloudflare-tunnel-hostname-route) |
| `cloudflare_zero_trust_risk_scoring_integration` | `resource` | [`gateway-configuration`](#cloudflare-concept-gateway-configuration) | [`risk-scoring-integration`](#rule-risk-scoring-integration) |
| `cloudflare_zero_trust_tunnel_cloudflared_config` | `resource` | [`tunnel-configuration`](#cloudflare-concept-tunnel-configuration) | [`cloudflare-tunnel-config`](#rule-cloudflare-tunnel-config) |
| `cloudflare_zero_trust_tunnel_cloudflared_route` | `resource` | [`tunnel-configuration`](#cloudflare-concept-tunnel-configuration) | [`cloudflare-tunnel-route`](#rule-cloudflare-tunnel-route) |
| `cloudflare_zero_trust_tunnel_cloudflared` | `resource` | [`cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) | [`cloudflare-tunnel`](#rule-cloudflare-tunnel) |
| `cloudflare_zero_trust_tunnel_warp_connector_config` | `resource` | [`tunnel-configuration`](#cloudflare-concept-tunnel-configuration) | [`warp-connector-config`](#rule-warp-connector-config) |
| `cloudflare_zero_trust_tunnel_warp_connector` | `resource` | [`warp-connector`](#cloudflare-concept-warp-connector) | [`warp-connector`](#rule-warp-connector) |
| `cloudflare_zone_auto_origin_tls_kex` | `resource` | [`tls-configuration`](#cloudflare-concept-tls-configuration) | [`zone-auto-origin-tls-kex`](#rule-zone-auto-origin-tls-kex) |
| `cloudflare_zone_cache_reserve` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`zone-cache-reserve`](#rule-zone-cache-reserve) |
| `cloudflare_zone_cache_variants` | `resource` | [`edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration) | [`zone-cache-variants`](#rule-zone-cache-variants) |
| `cloudflare_zone_dns_settings` | `resource` | [`zone-configuration`](#cloudflare-concept-zone-configuration) | [`zone-dns-settings`](#rule-zone-dns-settings) |
| `cloudflare_zone_dnssec` | `resource` | [`zone-configuration`](#cloudflare-concept-zone-configuration) | [`zone-dnssec`](#rule-zone-dnssec) |
| `cloudflare_zone_hold` | `resource` | [`zone-configuration`](#cloudflare-concept-zone-configuration) | [`zone-hold`](#rule-zone-hold) |
| `cloudflare_zone_lockdown` | `resource` | [`edge-security-configuration`](#cloudflare-concept-edge-security-configuration) | [`zone-lockdown`](#rule-zone-lockdown) |
| `cloudflare_zone_setting` | `resource` | [`zone-configuration`](#cloudflare-concept-zone-configuration) | [`zone-setting`](#rule-zone-setting) |
| `cloudflare_zone` | `resource` | [`dns-zone`](#cloudflare-concept-dns-zone) | [`zone`](#rule-zone) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="cloudflare-concept-access-application"><code>cloudflare.concept.access-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L1-L3">Source</a></dt>
<dd>

An application or infrastructure destination protected by Cloudflare Access.

</dd>
<dd>

Used by [`access-application`](#rule-access-application).

</dd>
</div>

<div>
<dt id="cloudflare-concept-account"><code>cloudflare.concept.account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare account as a tenancy and ownership boundary.

</dd>
<dd>

Used by [`account`](#rule-account), [`account-dns-settings`](#rule-account-dns-settings).

</dd>
</div>

<div>
<dt id="cloudflare-concept-account-configuration"><code>cloudflare.concept.account-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L15-L17">Source</a></dt>
<dd>

Configuration applied to a Cloudflare account boundary.

</dd>
<dd>

Used by [`account-dns-settings`](#rule-account-dns-settings).

</dd>
</div>

<div>
<dt id="cloudflare-concept-ai-controls-endpoint"><code>cloudflare.concept.ai-controls-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L16-L18">Source</a></dt>
<dd>

An MCP server or portal governed through Cloudflare AI Controls.

</dd>
<dd>

Used by [`access-ai-controls-mcp-portal`](#rule-access-ai-controls-mcp-portal), [`access-ai-controls-mcp-server`](#rule-access-ai-controls-mcp-server).

</dd>
</div>

<div>
<dt id="cloudflare-concept-ai-gateway"><code>cloudflare.concept.ai-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/ai-ml/ai-platform.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare AI Gateway controlling and observing AI inference traffic.

</dd>
<dd>

Used by [`ai-gateway`](#rule-ai-gateway), [`ai-gateway-dynamic-routing`](#rule-ai-gateway-dynamic-routing).

</dd>
</div>

<div>
<dt id="cloudflare-concept-ai-gateway-routing"><code>cloudflare.concept.ai-gateway-routing</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/ai-ml/ai-platform.rf.hcl#L5-L7">Source</a></dt>
<dd>

Dynamic routing configuration contributing to a Cloudflare AI Gateway.

</dd>
<dd>

Used by [`ai-gateway-dynamic-routing`](#rule-ai-gateway-dynamic-routing).

</dd>
</div>

<div>
<dt id="cloudflare-concept-cloudflare-tunnel"><code>cloudflare.concept.cloudflare-tunnel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Tunnel logical link from private resources to the Cloudflare network.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`cloudflare-tunnel`](#rule-cloudflare-tunnel)
- [`cloudflare-tunnel-config`](#rule-cloudflare-tunnel-config)
- [`cloudflare-tunnel-hostname-route`](#rule-cloudflare-tunnel-hostname-route)
- [`cloudflare-tunnel-route`](#rule-cloudflare-tunnel-route)
- [`connectivity-directory-service`](#rule-connectivity-directory-service)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-connectivity-service"><code>cloudflare.concept.connectivity-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L10-L12">Source</a></dt>
<dd>

A service published through Cloudflare Connectivity Directory.

</dd>
<dd>

Used by [`connectivity-directory-service`](#rule-connectivity-directory-service), [`hyperdrive-config`](#rule-hyperdrive-config).

</dd>
</div>

<div>
<dt id="cloudflare-concept-custom-hostname"><code>cloudflare.concept.custom-hostname</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L14-L16">Source</a></dt>
<dd>

A customer hostname onboarded through Cloudflare for SaaS.

</dd>
<dd>

Used by [`custom-hostname`](#rule-custom-hostname).

</dd>
</div>

<div>
<dt id="cloudflare-concept-data-loss-prevention-configuration"><code>cloudflare.concept.data-loss-prevention-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L1-L3">Source</a></dt>
<dd>

Cloudflare One Data Loss Prevention profile, dataset, integration, or service configuration.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`dlp-custom-profile`](#rule-dlp-custom-profile)
- [`dlp-dataset`](#rule-dlp-dataset)
- [`dlp-integration-entry`](#rule-dlp-integration-entry)
- [`dlp-predefined-profile`](#rule-dlp-predefined-profile)
- [`dlp-settings`](#rule-dlp-settings)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-device-posture-configuration"><code>cloudflare.concept.device-posture-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L1-L3">Source</a></dt>
<dd>

Cloudflare One device profile, posture, managed-network, deployment, or subnet configuration.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`device-custom-profile`](#rule-device-custom-profile)
- [`device-default-profile`](#rule-device-default-profile)
- [`device-deployment-group`](#rule-device-deployment-group)
- [`device-ip-profile`](#rule-device-ip-profile)
- [`device-managed-network`](#rule-device-managed-network)
- [`device-posture-integration`](#rule-device-posture-integration)
- [`device-posture-rule`](#rule-device-posture-rule)
- [`device-settings`](#rule-device-settings)
- [`device-subnet`](#rule-device-subnet)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-dns-record-detail"><code>cloudflare.concept.dns-record-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L5-L7">Source</a></dt>
<dd>

A DNS record contributing to a Cloudflare zone without independent architecture identity.

</dd>
<dd>

Used by [`dns-record`](#rule-dns-record).

</dd>
</div>

<div>
<dt id="cloudflare-concept-dns-transfer-configuration"><code>cloudflare.concept.dns-transfer-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L34-L36">Source</a></dt>
<dd>

Secondary DNS transfer, ACL, or TSIG configuration.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`dns-transfer-acl`](#rule-dns-transfer-acl)
- [`dns-transfer-incoming`](#rule-dns-transfer-incoming)
- [`dns-transfer-outgoing`](#rule-dns-transfer-outgoing)
- [`dns-transfer-tsig`](#rule-dns-transfer-tsig)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-dns-transfer-peer"><code>cloudflare.concept.dns-transfer-peer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L30-L32">Source</a></dt>
<dd>

An authoritative DNS peer participating in secondary zone transfers.

</dd>
<dd>

Used by [`dns-transfer-incoming`](#rule-dns-transfer-incoming), [`dns-transfer-outgoing`](#rule-dns-transfer-outgoing), [`dns-transfer-peer`](#rule-dns-transfer-peer).

</dd>
</div>

<div>
<dt id="cloudflare-concept-dns-view"><code>cloudflare.concept.dns-view</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L26-L28">Source</a></dt>
<dd>

A Cloudflare internal DNS view grouping zones for split-horizon resolution.

</dd>
<dd>

Used by [`account-dns-internal-view`](#rule-account-dns-internal-view).

</dd>
</div>

<div>
<dt id="cloudflare-concept-dns-zone"><code>cloudflare.concept.dns-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed DNS namespace containing resource records.

</dd>
<dd>


<details>
<summary>Used by 78 Rules</summary>

- [`account-dns-internal-view`](#rule-account-dns-internal-view)
- [`api-shield`](#rule-api-shield)
- [`api-shield-discovery-operation`](#rule-api-shield-discovery-operation)
- [`api-shield-operation`](#rule-api-shield-operation)
- [`api-shield-operation-schema-validation`](#rule-api-shield-operation-schema-validation)
- [`api-shield-schema`](#rule-api-shield-schema)
- [`api-shield-schema-validation`](#rule-api-shield-schema-validation)
- [`argo-smart-routing`](#rule-argo-smart-routing)
- [`argo-tiered-caching`](#rule-argo-tiered-caching)
- [`authenticated-origin-pulls`](#rule-authenticated-origin-pulls)
- [`authenticated-origin-pulls-certificate`](#rule-authenticated-origin-pulls-certificate)
- [`authenticated-origin-pulls-hostname-certificate`](#rule-authenticated-origin-pulls-hostname-certificate)
- [`authenticated-origin-pulls-settings`](#rule-authenticated-origin-pulls-settings)
- [`bot-management`](#rule-bot-management)
- [`certificate-authority-hostname-associations`](#rule-certificate-authority-hostname-associations)
- [`certificate-pack`](#rule-certificate-pack)
- [`certificate-transparency-alerting`](#rule-certificate-transparency-alerting)
- [`client-certificate`](#rule-client-certificate)
- [`cloud-connector-rules`](#rule-cloud-connector-rules)
- [`content-scanning`](#rule-content-scanning)
- [`content-scanning-expression`](#rule-content-scanning-expression)
- [`custom-csr`](#rule-custom-csr)
- [`custom-hostname`](#rule-custom-hostname)
- [`custom-hostname-fallback-origin`](#rule-custom-hostname-fallback-origin)
- [`custom-origin-trust-store`](#rule-custom-origin-trust-store)
- [`custom-ssl`](#rule-custom-ssl)
- [`dns-record`](#rule-dns-record)
- [`dns-transfer-incoming`](#rule-dns-transfer-incoming)
- [`dns-transfer-outgoing`](#rule-dns-transfer-outgoing)
- [`email-routing-catch-all`](#rule-email-routing-catch-all)
- [`email-routing-rule`](#rule-email-routing-rule)
- [`email-routing-settings`](#rule-email-routing-settings)
- [`firewall-rule`](#rule-firewall-rule)
- [`google-tag-gateway`](#rule-google-tag-gateway)
- [`hostname-tls-setting`](#rule-hostname-tls-setting)
- [`keyless-certificate`](#rule-keyless-certificate)
- [`load-balancer`](#rule-load-balancer)
- [`managed-transforms`](#rule-managed-transforms)
- [`origin-cloud-region`](#rule-origin-cloud-region)
- [`origin-tls-compliance-modes`](#rule-origin-tls-compliance-modes)
- [`page-rule`](#rule-page-rule)
- [`page-shield-policy`](#rule-page-shield-policy)
- [`precursor`](#rule-precursor)
- [`proxied-dns-record`](#rule-proxied-dns-record)
- [`r2-custom-domain`](#rule-r2-custom-domain)
- [`rate-limit`](#rule-rate-limit)
- [`regional-hostname`](#rule-regional-hostname)
- [`regional-tiered-cache`](#rule-regional-tiered-cache)
- [`ruleset`](#rule-ruleset)
- [`schema-validation-operation-settings`](#rule-schema-validation-operation-settings)
- [`schema-validation-schemas`](#rule-schema-validation-schemas)
- [`schema-validation-settings`](#rule-schema-validation-settings)
- [`snippet`](#rule-snippet)
- [`snippet-rules`](#rule-snippet-rules)
- [`snippets`](#rule-snippets)
- [`spectrum-application`](#rule-spectrum-application)
- [`tiered-cache`](#rule-tiered-cache)
- [`token-validation-config`](#rule-token-validation-config)
- [`total-tls`](#rule-total-tls)
- [`universal-ssl-setting`](#rule-universal-ssl-setting)
- [`url-normalization-settings`](#rule-url-normalization-settings)
- [`user-agent-blocking-rule`](#rule-user-agent-blocking-rule)
- [`waiting-room`](#rule-waiting-room)
- [`waiting-room-event`](#rule-waiting-room-event)
- [`waiting-room-rules`](#rule-waiting-room-rules)
- [`waiting-room-settings`](#rule-waiting-room-settings)
- [`web3-hostname`](#rule-web3-hostname)
- [`workers-custom-domain`](#rule-workers-custom-domain)
- [`workers-route`](#rule-workers-route)
- [`zone`](#rule-zone)
- [`zone-auto-origin-tls-kex`](#rule-zone-auto-origin-tls-kex)
- [`zone-cache-reserve`](#rule-zone-cache-reserve)
- [`zone-cache-variants`](#rule-zone-cache-variants)
- [`zone-dns-settings`](#rule-zone-dns-settings)
- [`zone-dnssec`](#rule-zone-dnssec)
- [`zone-hold`](#rule-zone-hold)
- [`zone-lockdown`](#rule-zone-lockdown)
- [`zone-setting`](#rule-zone-setting)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-edge-delivery-configuration"><code>cloudflare.concept.edge-delivery-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L1-L3">Source</a></dt>
<dd>

Cache, routing, transformation, or delivery configuration applied at the Cloudflare edge.

</dd>
<dd>


<details>
<summary>Used by 14 Rules</summary>

- [`argo-smart-routing`](#rule-argo-smart-routing)
- [`argo-tiered-caching`](#rule-argo-tiered-caching)
- [`google-tag-gateway`](#rule-google-tag-gateway)
- [`managed-transforms`](#rule-managed-transforms)
- [`origin-cloud-region`](#rule-origin-cloud-region)
- [`page-rule`](#rule-page-rule)
- [`regional-tiered-cache`](#rule-regional-tiered-cache)
- [`snippet`](#rule-snippet)
- [`snippet-rules`](#rule-snippet-rules)
- [`snippets`](#rule-snippets)
- [`tiered-cache`](#rule-tiered-cache)
- [`url-normalization-settings`](#rule-url-normalization-settings)
- [`zone-cache-reserve`](#rule-zone-cache-reserve)
- [`zone-cache-variants`](#rule-zone-cache-variants)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-edge-route"><code>cloudflare.concept.edge-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare proxied hostname routing edge traffic to an application endpoint.

</dd>
<dd>

Used by [`proxied-dns-record`](#rule-proxied-dns-record), [`regional-hostname`](#rule-regional-hostname), [`workers-custom-domain`](#rule-workers-custom-domain).

</dd>
</div>

<div>
<dt id="cloudflare-concept-edge-security-configuration"><code>cloudflare.concept.edge-security-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L1-L3">Source</a></dt>
<dd>

WAF, API, bot, content, credential, or certificate protection applied at the Cloudflare edge.

</dd>
<dd>


<details>
<summary>Used by 20 Rules</summary>

- [`api-shield`](#rule-api-shield)
- [`api-shield-discovery-operation`](#rule-api-shield-discovery-operation)
- [`api-shield-operation`](#rule-api-shield-operation)
- [`api-shield-operation-schema-validation`](#rule-api-shield-operation-schema-validation)
- [`api-shield-schema`](#rule-api-shield-schema)
- [`api-shield-schema-validation`](#rule-api-shield-schema-validation)
- [`bot-management`](#rule-bot-management)
- [`content-scanning`](#rule-content-scanning)
- [`content-scanning-expression`](#rule-content-scanning-expression)
- [`firewall-rule`](#rule-firewall-rule)
- [`page-shield-policy`](#rule-page-shield-policy)
- [`precursor`](#rule-precursor)
- [`rate-limit`](#rule-rate-limit)
- [`ruleset`](#rule-ruleset)
- [`schema-validation-operation-settings`](#rule-schema-validation-operation-settings)
- [`schema-validation-schemas`](#rule-schema-validation-schemas)
- [`schema-validation-settings`](#rule-schema-validation-settings)
- [`token-validation-config`](#rule-token-validation-config)
- [`user-agent-blocking-rule`](#rule-user-agent-blocking-rule)
- [`zone-lockdown`](#rule-zone-lockdown)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-email-routing-configuration"><code>cloudflare.concept.email-routing-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L9-L11">Source</a></dt>
<dd>

Cloudflare Email Routing configuration for a zone.

</dd>
<dd>

Used by [`email-routing-catch-all`](#rule-email-routing-catch-all), [`email-routing-rule`](#rule-email-routing-rule), [`email-routing-settings`](#rule-email-routing-settings).

</dd>
</div>

<div>
<dt id="cloudflare-concept-email-security-configuration"><code>cloudflare.concept.email-security-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L17-L19">Source</a></dt>
<dd>

Trusted-domain, sender-blocking, or impersonation configuration for Cloudflare Email Security.

</dd>
<dd>

Used by [`email-security-block-sender`](#rule-email-security-block-sender), [`email-security-impersonation-registry`](#rule-email-security-impersonation-registry), [`email-security-trusted-domains`](#rule-email-security-trusted-domains).

</dd>
</div>

<div>
<dt id="cloudflare-concept-feature-flag"><code>cloudflare.concept.feature-flag</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L11-L13">Source</a></dt>
<dd>

A feature flag owned by a feature-flag application.

</dd>
<dd>

Used by [`flagship-flag`](#rule-flagship-flag).

</dd>
</div>

<div>
<dt id="cloudflare-concept-feature-flag-application"><code>cloudflare.concept.feature-flag-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L7-L9">Source</a></dt>
<dd>

A Cloudflare feature-flag application.

</dd>
<dd>

Used by [`flagship-app`](#rule-flagship-app), [`flagship-flag`](#rule-flagship-flag).

</dd>
</div>

<div>
<dt id="cloudflare-concept-gateway-configuration"><code>cloudflare.concept.gateway-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L20-L22">Source</a></dt>
<dd>

Logging, inspection, or risk-integration configuration for Cloudflare Gateway.

</dd>
<dd>

Used by [`gateway-logging`](#rule-gateway-logging), [`gateway-settings`](#rule-gateway-settings), [`risk-scoring-integration`](#rule-risk-scoring-integration).

</dd>
</div>

<div>
<dt id="cloudflare-concept-hyperdrive-configuration"><code>cloudflare.concept.hyperdrive-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/databases/d1-hyperdrive.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Hyperdrive database accelerator and connection pool.

</dd>
<dd>

Used by [`hyperdrive-config`](#rule-hyperdrive-config).

</dd>
</div>

<div>
<dt id="cloudflare-concept-identity-group"><code>cloudflare.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="cloudflare-concept-identity-provider"><code>cloudflare.concept.identity-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L7-L9">Source</a></dt>
<dd>

An identity provider integrated with Cloudflare Zero Trust.

</dd>
<dd>

Used by [`access-identity-provider`](#rule-access-identity-provider), [`sso-connector`](#rule-sso-connector).

</dd>
</div>

<div>
<dt id="cloudflare-concept-load-balancer"><code>cloudflare.concept.load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L9-L11">Source</a></dt>
<dd>

A load-balancing service composed from routing infrastructure.

</dd>
<dd>

Used by [`load-balancer`](#rule-load-balancer).

</dd>
</div>

<div>
<dt id="cloudflare-concept-load-balancer-monitoring"><code>cloudflare.concept.load-balancer-monitoring</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L5-L7">Source</a></dt>
<dd>

Health monitoring configuration supporting Cloudflare Load Balancing.

</dd>
<dd>

Used by [`healthcheck`](#rule-healthcheck), [`load-balancer-monitor`](#rule-load-balancer-monitor), [`load-balancer-monitor-group`](#rule-load-balancer-monitor-group).

</dd>
</div>

<div>
<dt id="cloudflare-concept-magic-transit-site"><code>cloudflare.concept.magic-transit-site</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Magic Transit or Cloudflare WAN network site.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`magic-transit-cf1-site`](#rule-magic-transit-cf1-site)
- [`magic-transit-site`](#rule-magic-transit-site)
- [`magic-transit-site-acl`](#rule-magic-transit-site-acl)
- [`magic-transit-site-lan`](#rule-magic-transit-site-lan)
- [`magic-transit-site-wan`](#rule-magic-transit-site-wan)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-managed-secret"><code>cloudflare.concept.managed-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L13-L15">Source</a></dt>
<dd>

A managed secret identity whose sensitive value stays outside architecture output.

</dd>
<dd>

Used by [`secrets-store-secret`](#rule-secrets-store-secret).

</dd>
</div>

<div>
<dt id="cloudflare-concept-message-queue"><code>cloudflare.concept.message-queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L17-L19">Source</a></dt>
<dd>

A managed queue buffering work or messages for asynchronous consumers.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`queue`](#rule-queue)
- [`queue-consumer`](#rule-queue-consumer)
- [`r2-bucket-event-notification`](#rule-r2-bucket-event-notification)
- [`worker-version`](#rule-worker-version)
- [`workers-script`](#rule-workers-script)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-network-monitor"><code>cloudflare.concept.network-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L7-L9">Source</a></dt>
<dd>

A Cloudflare Network Monitoring configuration.

</dd>
<dd>

Used by [`dex-test`](#rule-dex-test), [`network-monitoring`](#rule-network-monitoring).

</dd>
</div>

<div>
<dt id="cloudflare-concept-network-route-configuration"><code>cloudflare.concept.network-route-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L7-L9">Source</a></dt>
<dd>

A LAN, WAN, ACL, route, or prefix configuration supporting Cloudflare WAN.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`cloud-connector-rules`](#rule-cloud-connector-rules)
- [`magic-transit-site-acl`](#rule-magic-transit-site-acl)
- [`magic-transit-site-lan`](#rule-magic-transit-site-lan)
- [`magic-transit-site-wan`](#rule-magic-transit-site-wan)
- [`magic-wan-static-route`](#rule-magic-wan-static-route)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-observability-configuration"><code>cloudflare.concept.observability-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L3-L5">Source</a></dt>
<dd>

A rule or test supporting Cloudflare observability.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`dex-rule`](#rule-dex-rule)
- [`logpull-retention`](#rule-logpull-retention)
- [`network-monitoring-rule`](#rule-network-monitoring-rule)
- [`notification-policy`](#rule-notification-policy)
- [`notification-webhook`](#rule-notification-webhook)
- [`web-analytics-rule`](#rule-web-analytics-rule)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-origin-pool"><code>cloudflare.concept.origin-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Load Balancing pool grouping origin endpoints.

</dd>
<dd>

Used by [`load-balancer`](#rule-load-balancer), [`load-balancer-pool`](#rule-load-balancer-pool).

</dd>
</div>

<div>
<dt id="cloudflare-concept-pages-domain"><code>cloudflare.concept.pages-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/pages-workflows.rf.hcl#L5-L7">Source</a></dt>
<dd>

A custom domain serving a Cloudflare Pages project.

</dd>
<dd>

Used by [`pages-domain`](#rule-pages-domain).

</dd>
</div>

<div>
<dt id="cloudflare-concept-pages-project"><code>cloudflare.concept.pages-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/pages-workflows.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Pages application project.

</dd>
<dd>

Used by [`pages-domain`](#rule-pages-domain), [`pages-project`](#rule-pages-project).

</dd>
</div>

<div>
<dt id="cloudflare-concept-queue-consumer-binding"><code>cloudflare.concept.queue-consumer-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/messaging-eventing/queues.rf.hcl#L1-L3">Source</a></dt>
<dd>

A consumer binding connecting a Cloudflare Queue to a Worker.

</dd>
<dd>

Used by [`queue-consumer`](#rule-queue-consumer).

</dd>
</div>

<div>
<dt id="cloudflare-concept-r2-configuration"><code>cloudflare.concept.r2-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L5-L7">Source</a></dt>
<dd>

Lifecycle, access, event, migration, or domain configuration contributing to an R2 bucket.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`r2-bucket-cors`](#rule-r2-bucket-cors)
- [`r2-bucket-event-notification`](#rule-r2-bucket-event-notification)
- [`r2-bucket-lifecycle`](#rule-r2-bucket-lifecycle)
- [`r2-bucket-lock`](#rule-r2-bucket-lock)
- [`r2-bucket-sippy`](#rule-r2-bucket-sippy)
- [`r2-custom-domain`](#rule-r2-custom-domain)
- [`r2-managed-domain`](#rule-r2-managed-domain)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-r2-data-catalog"><code>cloudflare.concept.r2-data-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare R2 Data Catalog for tabular data.

</dd>
<dd>

Used by [`r2-data-catalog`](#rule-r2-data-catalog).

</dd>
</div>

<div>
<dt id="cloudflare-concept-saas-fallback-origin"><code>cloudflare.concept.saas-fallback-origin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L18-L20">Source</a></dt>
<dd>

A default origin for Cloudflare for SaaS custom hostnames.

</dd>
<dd>

Used by [`custom-hostname-fallback-origin`](#rule-custom-hostname-fallback-origin).

</dd>
</div>

<div>
<dt id="cloudflare-concept-secrets-store"><code>cloudflare.concept.secrets-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/identity-iam/identities-secrets.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Secrets Store boundary.

</dd>
<dd>

Used by [`secrets-store`](#rule-secrets-store), [`secrets-store-secret`](#rule-secrets-store-secret).

</dd>
</div>

<div>
<dt id="cloudflare-concept-serverless-function"><code>cloudflare.concept.serverless-function</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L21-L23">Source</a></dt>
<dd>

A managed event-driven function runtime.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`access-application`](#rule-access-application)
- [`queue-consumer`](#rule-queue-consumer)
- [`worker`](#rule-worker)
- [`worker-version`](#rule-worker-version)
- [`workers-cron-trigger`](#rule-workers-cron-trigger)
- [`workers-custom-domain`](#rule-workers-custom-domain)
- [`workers-deployment`](#rule-workers-deployment)
- [`workers-route`](#rule-workers-route)
- [`workers-script`](#rule-workers-script)
- [`workers-script-subdomain`](#rule-workers-script-subdomain)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-spectrum-application"><code>cloudflare.concept.spectrum-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloudflare Spectrum TCP or UDP application.

</dd>
<dd>

Used by [`spectrum-application`](#rule-spectrum-application).

</dd>
</div>

<div>
<dt id="cloudflare-concept-tls-configuration"><code>cloudflare.concept.tls-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L1-L3">Source</a></dt>
<dd>

TLS, certificate, trust-store, or authenticated-origin configuration at the Cloudflare edge.

</dd>
<dd>


<details>
<summary>Used by 19 Rules</summary>

- [`authenticated-origin-pulls`](#rule-authenticated-origin-pulls)
- [`authenticated-origin-pulls-certificate`](#rule-authenticated-origin-pulls-certificate)
- [`authenticated-origin-pulls-hostname-certificate`](#rule-authenticated-origin-pulls-hostname-certificate)
- [`authenticated-origin-pulls-settings`](#rule-authenticated-origin-pulls-settings)
- [`certificate-authority-hostname-associations`](#rule-certificate-authority-hostname-associations)
- [`certificate-pack`](#rule-certificate-pack)
- [`certificate-transparency-alerting`](#rule-certificate-transparency-alerting)
- [`client-certificate`](#rule-client-certificate)
- [`custom-csr`](#rule-custom-csr)
- [`custom-origin-trust-store`](#rule-custom-origin-trust-store)
- [`custom-ssl`](#rule-custom-ssl)
- [`hostname-tls-setting`](#rule-hostname-tls-setting)
- [`keyless-certificate`](#rule-keyless-certificate)
- [`mtls-certificate`](#rule-mtls-certificate)
- [`origin-ca-certificate`](#rule-origin-ca-certificate)
- [`origin-tls-compliance-modes`](#rule-origin-tls-compliance-modes)
- [`total-tls`](#rule-total-tls)
- [`universal-ssl-setting`](#rule-universal-ssl-setting)
- [`zone-auto-origin-tls-kex`](#rule-zone-auto-origin-tls-kex)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-tunnel-configuration"><code>cloudflare.concept.tunnel-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L6-L8">Source</a></dt>
<dd>

Ingress, private route, hostname route, or connector configuration supporting a Cloudflare Tunnel.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`cloudflare-tunnel-config`](#rule-cloudflare-tunnel-config)
- [`cloudflare-tunnel-hostname-route`](#rule-cloudflare-tunnel-hostname-route)
- [`cloudflare-tunnel-route`](#rule-cloudflare-tunnel-route)
- [`warp-connector-config`](#rule-warp-connector-config)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-waiting-room"><code>cloudflare.concept.waiting-room</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Cloudflare Waiting Room controlling application admission.

</dd>
<dd>

Used by [`waiting-room`](#rule-waiting-room), [`waiting-room-event`](#rule-waiting-room-event), [`waiting-room-rules`](#rule-waiting-room-rules).

</dd>
</div>

<div>
<dt id="cloudflare-concept-waiting-room-configuration"><code>cloudflare.concept.waiting-room-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L13-L15">Source</a></dt>
<dd>

An event, bypass rule, or setting supporting a Cloudflare Waiting Room.

</dd>
<dd>

Used by [`waiting-room-event`](#rule-waiting-room-event), [`waiting-room-rules`](#rule-waiting-room-rules), [`waiting-room-settings`](#rule-waiting-room-settings).

</dd>
</div>

<div>
<dt id="cloudflare-concept-warp-connector"><code>cloudflare.concept.warp-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L14-L16">Source</a></dt>
<dd>

A Cloudflare WARP Connector joining a private network to Cloudflare.

</dd>
<dd>

Used by [`warp-connector`](#rule-warp-connector), [`warp-connector-config`](#rule-warp-connector-config).

</dd>
</div>

<div>
<dt id="cloudflare-concept-web3-hostname"><code>cloudflare.concept.web3-hostname</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L22-L24">Source</a></dt>
<dd>

A Cloudflare Web3 gateway hostname.

</dd>
<dd>

Used by [`web3-hostname`](#rule-web3-hostname).

</dd>
</div>

<div>
<dt id="cloudflare-concept-worker-deployment"><code>cloudflare.concept.worker-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L5-L7">Source</a></dt>
<dd>

The active version rollout of a Cloudflare Worker.

</dd>
<dd>

Used by [`workers-deployment`](#rule-workers-deployment).

</dd>
</div>

<div>
<dt id="cloudflare-concept-worker-route"><code>cloudflare.concept.worker-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L9-L11">Source</a></dt>
<dd>

A route, custom domain, trigger, or subdomain exposing a Cloudflare Worker.

</dd>
<dd>

Used by [`workers-cron-trigger`](#rule-workers-cron-trigger), [`workers-route`](#rule-workers-route), [`workers-script-subdomain`](#rule-workers-script-subdomain).

</dd>
</div>

<div>
<dt id="cloudflare-concept-worker-version"><code>cloudflare.concept.worker-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L1-L3">Source</a></dt>
<dd>

An immutable version and resource bindings of a Cloudflare Worker.

</dd>
<dd>

Used by [`worker-version`](#rule-worker-version).

</dd>
</div>

<div>
<dt id="cloudflare-concept-workers-kv-entry"><code>cloudflare.concept.workers-kv-entry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L17-L19">Source</a></dt>
<dd>

A Workers KV entry contributing to its namespace.

</dd>
<dd>

Used by [`workers-kv`](#rule-workers-kv).

</dd>
</div>

<div>
<dt id="cloudflare-concept-workers-kv-namespace"><code>cloudflare.concept.workers-kv-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L13-L15">Source</a></dt>
<dd>

A Cloudflare Workers KV namespace.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`worker-version`](#rule-worker-version)
- [`workers-kv`](#rule-workers-kv)
- [`workers-kv-namespace`](#rule-workers-kv-namespace)
- [`workers-script`](#rule-workers-script)

</details>

</dd>
</div>

<div>
<dt id="cloudflare-concept-workflow"><code>cloudflare.concept.workflow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L25-L27">Source</a></dt>
<dd>

A managed workflow coordinating steps and service calls.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="cloudflare-concept-zone-configuration"><code>cloudflare.concept.zone-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L9-L11">Source</a></dt>
<dd>

Configuration contributing to a Cloudflare zone.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`zone-dns-settings`](#rule-zone-dns-settings)
- [`zone-dnssec`](#rule-zone-dnssec)
- [`zone-hold`](#rule-zone-hold)
- [`zone-setting`](#rule-zone-setting)

</details>

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="cloudflare-context-ownership"><code>cloudflare.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/vocabulary.rf.hcl#L29-L31">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>


<details>
<summary>Used by 12 Rules</summary>

- [`custom-hostname`](#rule-custom-hostname)
- [`custom-hostname-fallback-origin`](#rule-custom-hostname-fallback-origin)
- [`load-balancer`](#rule-load-balancer)
- [`proxied-dns-record`](#rule-proxied-dns-record)
- [`r2-custom-domain`](#rule-r2-custom-domain)
- [`regional-hostname`](#rule-regional-hostname)
- [`secrets-store-secret`](#rule-secrets-store-secret)
- [`spectrum-application`](#rule-spectrum-application)
- [`waiting-room`](#rule-waiting-room)
- [`web3-hostname`](#rule-web3-hostname)
- [`workers-custom-domain`](#rule-workers-custom-domain)
- [`workers-route`](#rule-workers-route)

</details>

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="cloudflare-relation-catalogs"><code>cloudflare.relation.catalogs</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L221-L234">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`r2-data-catalog`](#rule-r2-data-catalog).

</dd>
</div>

<div>
<dt id="cloudflare-relation-connects-through"><code>cloudflare.relation.connects-through</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/databases/d1-hyperdrive.rf.hcl#L44-L54">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`hyperdrive-config`](#rule-hyperdrive-config).

</dd>
</div>

<div>
<dt id="cloudflare-relation-connects-to"><code>cloudflare.relation.connects-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/databases/d1-hyperdrive.rf.hcl#L29-L42">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`hyperdrive-config`](#rule-hyperdrive-config).

</dd>
</div>

<div>
<dt id="cloudflare-relation-includes-zone"><code>cloudflare.relation.includes-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L278-L291">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`account-dns-internal-view`](#rule-account-dns-internal-view).

</dd>
</div>

<div>
<dt id="cloudflare-relation-protects"><code>cloudflare.relation.protects</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L31-L41">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`access-application`](#rule-access-application).

</dd>
</div>

<div>
<dt id="cloudflare-relation-publishes-to"><code>cloudflare.relation.publishes-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L68-L78">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`workers-script`](#rule-workers-script).

</dd>
</div>

<div>
<dt id="cloudflare-relation-routes-to"><code>cloudflare.relation.routes-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L317-L327">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`workers-custom-domain`](#rule-workers-custom-domain).

</dd>
</div>

<div>
<dt id="cloudflare-relation-uses"><code>cloudflare.relation.uses</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L38-L51">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`workers-script`](#rule-workers-script).

</dd>
</div>

<div>
<dt id="cloudflare-relation-uses-origin-pool"><code>cloudflare.relation.uses-origin-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L41-L51">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`load-balancer`](#rule-load-balancer).

</dd>
</div>

<div>
<dt id="cloudflare-relation-uses-tunnel"><code>cloudflare.relation.uses-tunnel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L119-L129">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`connectivity-directory-service`](#rule-connectivity-directory-service).

</dd>
</div>

</dl>

## RF Vocabulary used

- [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database)
- [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container)
- [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity)
- [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network)
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network)

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>cloudflare.rule.account-dns-internal-view</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L271-L292">Source</a></summary>

<div id="rule-account-dns-internal-view"></div>

Matches `resource` instances of `cloudflare_account_dns_settings_internal_view`.

**Classification:** [`cloudflare.concept.dns-view`](#cloudflare-concept-dns-view).

**Relations**

- [`cloudflare.relation.includes-zone`](#cloudflare-relation-includes-zone): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zones`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.zones`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.account-dns-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L75-L96">Source</a></summary>

<div id="rule-account-dns-settings"></div>

Matches `resource` instances of `cloudflare_account_dns_settings`.

**Classification:** [`cloudflare.concept.account-configuration`](#cloudflare-concept-account-configuration).

**Contributions**

- targets [`cloudflare.concept.account`](#cloudflare-concept-account) through `source.account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L19-L34">Source</a></summary>

<div id="rule-account"></div>

Matches `resource` instances of `cloudflare_account`.

**Classification:** [`cloudflare.concept.account`](#cloudflare-concept-account).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.ai-gateway-dynamic-routing</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/ai-ml/ai-platform.rf.hcl#L28-L46">Source</a></summary>

<div id="rule-ai-gateway-dynamic-routing"></div>

Matches `resource` instances of `cloudflare_ai_gateway_dynamic_routing`.

**Classification:** [`cloudflare.concept.ai-gateway-routing`](#cloudflare-concept-ai-gateway-routing).

**Contributions**

- targets [`cloudflare.concept.ai-gateway`](#cloudflare-concept-ai-gateway) through `source.gateway_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.gateway_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.ai-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/ai-ml/ai-platform.rf.hcl#L11-L26">Source</a></summary>

<div id="rule-ai-gateway"></div>

Matches `resource` instances of `cloudflare_ai_gateway`.

**Classification:** [`cloudflare.concept.ai-gateway`](#cloudflare-concept-ai-gateway).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield-discovery-operation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L216-L237">Source</a></summary>

<div id="rule-api-shield-discovery-operation"></div>

Matches `resource` instances of `cloudflare_api_shield_discovery_operation`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield-operation-schema-validation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L262-L283">Source</a></summary>

<div id="rule-api-shield-operation-schema-validation"></div>

Matches `resource` instances of `cloudflare_api_shield_operation_schema_validation_settings`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield-operation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L239-L260">Source</a></summary>

<div id="rule-api-shield-operation"></div>

Matches `resource` instances of `cloudflare_api_shield_operation`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield-schema-validation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L308-L329">Source</a></summary>

<div id="rule-api-shield-schema-validation"></div>

Matches `resource` instances of `cloudflare_api_shield_schema_validation_settings`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield-schema</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L285-L306">Source</a></summary>

<div id="rule-api-shield-schema"></div>

Matches `resource` instances of `cloudflare_api_shield_schema`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.api-shield</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L76-L97">Source</a></summary>

<div id="rule-api-shield"></div>

Matches `resource` instances of `cloudflare_api_shield`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.argo-smart-routing</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L5-L26">Source</a></summary>

<div id="rule-argo-smart-routing"></div>

Matches `resource` instances of `cloudflare_argo_smart_routing`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.argo-tiered-caching</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L28-L49">Source</a></summary>

<div id="rule-argo-tiered-caching"></div>

Matches `resource` instances of `cloudflare_argo_tiered_caching`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.authenticated-origin-pulls-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L28-L49">Source</a></summary>

<div id="rule-authenticated-origin-pulls-certificate"></div>

Matches `resource` instances of `cloudflare_authenticated_origin_pulls_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.authenticated-origin-pulls-hostname-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L51-L72">Source</a></summary>

<div id="rule-authenticated-origin-pulls-hostname-certificate"></div>

Matches `resource` instances of `cloudflare_authenticated_origin_pulls_hostname_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.authenticated-origin-pulls-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L74-L95">Source</a></summary>

<div id="rule-authenticated-origin-pulls-settings"></div>

Matches `resource` instances of `cloudflare_authenticated_origin_pulls_settings`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.authenticated-origin-pulls</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L5-L26">Source</a></summary>

<div id="rule-authenticated-origin-pulls"></div>

Matches `resource` instances of `cloudflare_authenticated_origin_pulls`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.bot-management</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L99-L120">Source</a></summary>

<div id="rule-bot-management"></div>

Matches `resource` instances of `cloudflare_bot_management`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.certificate-authority-hostname-associations</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L97-L118">Source</a></summary>

<div id="rule-certificate-authority-hostname-associations"></div>

Matches `resource` instances of `cloudflare_certificate_authorities_hostname_associations`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.certificate-pack</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L120-L141">Source</a></summary>

<div id="rule-certificate-pack"></div>

Matches `resource` instances of `cloudflare_certificate_pack`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.client-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L143-L164">Source</a></summary>

<div id="rule-client-certificate"></div>

Matches `resource` instances of `cloudflare_client_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.cloud-connector-rules</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L122-L143">Source</a></summary>

<div id="rule-cloud-connector-rules"></div>

Matches `resource` instances of `cloudflare_cloud_connector_rules`.

**Classification:** [`cloudflare.concept.network-route-configuration`](#cloudflare-concept-network-route-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.connectivity-directory-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L103-L142">Source</a></summary>

<div id="rule-connectivity-directory-service"></div>

Matches `resource` instances of `cloudflare_connectivity_directory_service`.

**Classification:** [`cloudflare.concept.connectivity-service`](#cloudflare-concept-connectivity-service).

**Relations**

- [`cloudflare.relation.uses-tunnel`](#cloudflare-relation-uses-tunnel): targets [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) through `source.host.network.tunnel_id`.
- [`cloudflare.relation.uses-tunnel`](#cloudflare-relation-uses-tunnel): targets [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) through `source.host.resolver_network.tunnel_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.host.network.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.host.resolver_network.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.content-scanning-expression</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L400-L421">Source</a></summary>

<div id="rule-content-scanning-expression"></div>

Matches `resource` instances of `cloudflare_content_scanning_expression`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.content-scanning</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L145-L166">Source</a></summary>

<div id="rule-content-scanning"></div>

Matches `resource` instances of `cloudflare_content_scanning`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.certificate-transparency-alerting</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L166-L187">Source</a></summary>

<div id="rule-certificate-transparency-alerting"></div>

Matches `resource` instances of `cloudflare_ct_alerting`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.custom-csr</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L189-L210">Source</a></summary>

<div id="rule-custom-csr"></div>

Matches `resource` instances of `cloudflare_custom_csr`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.custom-hostname-fallback-origin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L222-L245">Source</a></summary>

<div id="rule-custom-hostname-fallback-origin"></div>

Matches `resource` instances of `cloudflare_custom_hostname_fallback_origin`.

**Classification:** [`cloudflare.concept.saas-fallback-origin`](#cloudflare-concept-saas-fallback-origin).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.custom-hostname</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L198-L220">Source</a></summary>

<div id="rule-custom-hostname"></div>

Matches `resource` instances of `cloudflare_custom_hostname`.

**Classification:** [`cloudflare.concept.custom-hostname`](#cloudflare-concept-custom-hostname).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.custom-origin-trust-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L212-L233">Source</a></summary>

<div id="rule-custom-origin-trust-store"></div>

Matches `resource` instances of `cloudflare_custom_origin_trust_store`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.custom-ssl</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L235-L256">Source</a></summary>

<div id="rule-custom-ssl"></div>

Matches `resource` instances of `cloudflare_custom_ssl`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.d1-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/databases/d1-hyperdrive.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-d1-database"></div>

Matches `resource` instances of `cloudflare_d1_database`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.dns-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L81-L103">Source</a></summary>

<div id="rule-dns-record"></div>

Matches `resource` instances of `cloudflare_dns_record`.

**Classification:** [`cloudflare.concept.dns-record-detail`](#cloudflare-concept-dns-record-detail).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.proxied != true
```

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.proxied-dns-record</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L55-L79">Source</a></summary>

<div id="rule-proxied-dns-record"></div>

Matches `resource` instances of `cloudflare_dns_record`.

**Classification:** [`cloudflare.concept.edge-route`](#cloudflare-concept-edge-route).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.proxied == true
```

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.dns-transfer-acl</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L405-L411">Source</a></summary>

<div id="rule-dns-transfer-acl"></div>

Matches `resource` instances of `cloudflare_dns_zone_transfers_acl`.

**Classification:** [`cloudflare.concept.dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dns-transfer-incoming</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L335-L368">Source</a></summary>

<div id="rule-dns-transfer-incoming"></div>

Matches `resource` instances of `cloudflare_dns_zone_transfers_incoming`.

**Classification:** [`cloudflare.concept.dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.
- targets [`cloudflare.concept.dns-transfer-peer`](#cloudflare-concept-dns-transfer-peer) through `source.peers`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.peers`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.dns-transfer-outgoing</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L370-L403">Source</a></summary>

<div id="rule-dns-transfer-outgoing"></div>

Matches `resource` instances of `cloudflare_dns_zone_transfers_outgoing`.

**Classification:** [`cloudflare.concept.dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.
- targets [`cloudflare.concept.dns-transfer-peer`](#cloudflare-concept-dns-transfer-peer) through `source.peers`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.peers`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.dns-transfer-peer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L318-L333">Source</a></summary>

<div id="rule-dns-transfer-peer"></div>

Matches `resource` instances of `cloudflare_dns_zone_transfers_peer`.

**Classification:** [`cloudflare.concept.dns-transfer-peer`](#cloudflare-concept-dns-transfer-peer).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.dns-transfer-tsig</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L413-L419">Source</a></summary>

<div id="rule-dns-transfer-tsig"></div>

Matches `resource` instances of `cloudflare_dns_zone_transfers_tsig`.

**Classification:** [`cloudflare.concept.dns-transfer-configuration`](#cloudflare-concept-dns-transfer-configuration).

</details>

<details>
<summary><code>cloudflare.rule.email-routing-catch-all</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L125-L146">Source</a></summary>

<div id="rule-email-routing-catch-all"></div>

Matches `resource` instances of `cloudflare_email_routing_catch_all`.

**Classification:** [`cloudflare.concept.email-routing-configuration`](#cloudflare-concept-email-routing-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.email-routing-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L102-L123">Source</a></summary>

<div id="rule-email-routing-rule"></div>

Matches `resource` instances of `cloudflare_email_routing_rule`.

**Classification:** [`cloudflare.concept.email-routing-configuration`](#cloudflare-concept-email-routing-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.email-routing-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L79-L100">Source</a></summary>

<div id="rule-email-routing-settings"></div>

Matches `resource` instances of `cloudflare_email_routing_settings`.

**Classification:** [`cloudflare.concept.email-routing-configuration`](#cloudflare-concept-email-routing-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.email-security-block-sender</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L241-L247">Source</a></summary>

<div id="rule-email-security-block-sender"></div>

Matches `resource` instances of `cloudflare_email_security_block_sender`.

**Classification:** [`cloudflare.concept.email-security-configuration`](#cloudflare-concept-email-security-configuration).

</details>

<details>
<summary><code>cloudflare.rule.email-security-impersonation-registry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L249-L255">Source</a></summary>

<div id="rule-email-security-impersonation-registry"></div>

Matches `resource` instances of `cloudflare_email_security_impersonation_registry`.

**Classification:** [`cloudflare.concept.email-security-configuration`](#cloudflare-concept-email-security-configuration).

</details>

<details>
<summary><code>cloudflare.rule.email-security-trusted-domains</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L257-L263">Source</a></summary>

<div id="rule-email-security-trusted-domains"></div>

Matches `resource` instances of `cloudflare_email_security_trusted_domains`.

**Classification:** [`cloudflare.concept.email-security-configuration`](#cloudflare-concept-email-security-configuration).

</details>

<details>
<summary><code>cloudflare.rule.firewall-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L30-L51">Source</a></summary>

<div id="rule-firewall-rule"></div>

Matches `resource` instances of `cloudflare_firewall_rule`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.flagship-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L38-L53">Source</a></summary>

<div id="rule-flagship-app"></div>

Matches `resource` instances of `cloudflare_flagship_app`.

**Classification:** [`cloudflare.concept.feature-flag-application`](#cloudflare-concept-feature-flag-application).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.flagship-flag</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/governance-management/accounts-sharing.rf.hcl#L55-L73">Source</a></summary>

<div id="rule-flagship-flag"></div>

Matches `resource` instances of `cloudflare_flagship_flag`.

**Classification:** [`cloudflare.concept.feature-flag`](#cloudflare-concept-feature-flag).

**Contributions**

- targets [`cloudflare.concept.feature-flag-application`](#cloudflare-concept-feature-flag-application) through `source.app_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.app_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.google-tag-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L212-L233">Source</a></summary>

<div id="rule-google-tag-gateway"></div>

Matches `resource` instances of `cloudflare_google_tag_gateway`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.healthcheck</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L99-L105">Source</a></summary>

<div id="rule-healthcheck"></div>

Matches `resource` instances of `cloudflare_healthcheck`.

**Classification:** [`cloudflare.concept.load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring).

</details>

<details>
<summary><code>cloudflare.rule.hostname-tls-setting</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L258-L279">Source</a></summary>

<div id="rule-hostname-tls-setting"></div>

Matches `resource` instances of `cloudflare_hostname_tls_setting`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.hyperdrive-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/databases/d1-hyperdrive.rf.hcl#L22-L55">Source</a></summary>

<div id="rule-hyperdrive-config"></div>

Matches `resource` instances of `cloudflare_hyperdrive_config`.

**Classification:** [`cloudflare.concept.hyperdrive-configuration`](#cloudflare-concept-hyperdrive-configuration).

**Relations**

- [`cloudflare.relation.connects-to`](#cloudflare-relation-connects-to): targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.origin.host`.
- [`cloudflare.relation.connects-through`](#cloudflare-relation-connects-through): targets [`cloudflare.concept.connectivity-service`](#cloudflare-concept-connectivity-service) through `source.origin.service_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.origin.host`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.origin.service_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.keyless-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L281-L302">Source</a></summary>

<div id="rule-keyless-certificate"></div>

Matches `resource` instances of `cloudflare_keyless_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.load-balancer-monitor-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L91-L97">Source</a></summary>

<div id="rule-load-balancer-monitor-group"></div>

Matches `resource` instances of `cloudflare_load_balancer_monitor_group`.

**Classification:** [`cloudflare.concept.load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring).

</details>

<details>
<summary><code>cloudflare.rule.load-balancer-monitor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L84-L90">Source</a></summary>

<div id="rule-load-balancer-monitor"></div>

Matches `resource` instances of `cloudflare_load_balancer_monitor`.

**Classification:** [`cloudflare.concept.load-balancer-monitoring`](#cloudflare-concept-load-balancer-monitoring).

</details>

<details>
<summary><code>cloudflare.rule.load-balancer-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L66-L82">Source</a></summary>

<div id="rule-load-balancer-pool"></div>

Matches `resource` instances of `cloudflare_load_balancer_pool`.

**Classification:** [`cloudflare.concept.origin-pool`](#cloudflare-concept-origin-pool).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/load-balancing/load-balancing.rf.hcl#L9-L64">Source</a></summary>

<div id="rule-load-balancer"></div>

Matches `resource` instances of `cloudflare_load_balancer`.

**Classification:** [`cloudflare.concept.load-balancer`](#cloudflare-concept-load-balancer).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

**Relations**

- [`cloudflare.relation.uses-origin-pool`](#cloudflare-relation-uses-origin-pool): targets [`cloudflare.concept.origin-pool`](#cloudflare-concept-origin-pool) through `source.default_pools`.
- [`cloudflare.relation.uses-origin-pool`](#cloudflare-relation-uses-origin-pool): targets [`cloudflare.concept.origin-pool`](#cloudflare-concept-origin-pool) through `source.fallback_pool`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.default_pools`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.fallback_pool`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.logpull-retention</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L69-L75">Source</a></summary>

<div id="rule-logpull-retention"></div>

Matches `resource` instances of `cloudflare_logpull_retention`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.network-monitoring</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-network-monitoring"></div>

Matches `resource` instances of `cloudflare_magic_network_monitoring_configuration`.

**Classification:** [`cloudflare.concept.network-monitor`](#cloudflare-concept-network-monitor).

</details>

<details>
<summary><code>cloudflare.rule.network-monitoring-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-network-monitoring-rule"></div>

Matches `resource` instances of `cloudflare_magic_network_monitoring_rule`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.magic-transit-cf1-site</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L30-L45">Source</a></summary>

<div id="rule-magic-transit-cf1-site"></div>

Matches `resource` instances of `cloudflare_magic_transit_cf1_site`.

**Classification:** [`cloudflare.concept.magic-transit-site`](#cloudflare-concept-magic-transit-site).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.magic-transit-site-acl</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L90-L109">Source</a></summary>

<div id="rule-magic-transit-site-acl"></div>

Matches `resource` instances of `cloudflare_magic_transit_site_acl`.

**Classification:** [`cloudflare.concept.network-route-configuration`](#cloudflare-concept-network-route-configuration).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`cloudflare.concept.magic-transit-site`](#cloudflare-concept-magic-transit-site) through `source.site_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.site_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.magic-transit-site-lan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L48-L67">Source</a></summary>

<div id="rule-magic-transit-site-lan"></div>

Matches `resource` instances of `cloudflare_magic_transit_site_lan`.

**Classification:** [`cloudflare.concept.network-route-configuration`](#cloudflare-concept-network-route-configuration).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`cloudflare.concept.magic-transit-site`](#cloudflare-concept-magic-transit-site) through `source.site_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.site_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.magic-transit-site-wan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L69-L88">Source</a></summary>

<div id="rule-magic-transit-site-wan"></div>

Matches `resource` instances of `cloudflare_magic_transit_site_wan`.

**Classification:** [`cloudflare.concept.network-route-configuration`](#cloudflare-concept-network-route-configuration).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`cloudflare.concept.magic-transit-site`](#cloudflare-concept-magic-transit-site) through `source.site_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.site_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.magic-transit-site</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L13-L28">Source</a></summary>

<div id="rule-magic-transit-site"></div>

Matches `resource` instances of `cloudflare_magic_transit_site`.

**Classification:** [`cloudflare.concept.magic-transit-site`](#cloudflare-concept-magic-transit-site).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.magic-wan-static-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-wan.rf.hcl#L112-L118">Source</a></summary>

<div id="rule-magic-wan-static-route"></div>

Matches `resource` instances of `cloudflare_magic_wan_static_route`.

**Classification:** [`cloudflare.concept.network-route-configuration`](#cloudflare-concept-network-route-configuration).

</details>

<details>
<summary><code>cloudflare.rule.managed-transforms</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L143-L164">Source</a></summary>

<div id="rule-managed-transforms"></div>

Matches `resource` instances of `cloudflare_managed_transforms`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.mtls-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L304-L310">Source</a></summary>

<div id="rule-mtls-certificate"></div>

Matches `resource` instances of `cloudflare_mtls_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

</details>

<details>
<summary><code>cloudflare.rule.notification-webhook</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L45-L51">Source</a></summary>

<div id="rule-notification-webhook"></div>

Matches `resource` instances of `cloudflare_notification_policy_webhooks`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.notification-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-notification-policy"></div>

Matches `resource` instances of `cloudflare_notification_policy`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.oauth-client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/identity-iam/identities-secrets.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-oauth-client"></div>

Matches `resource` instances of `cloudflare_oauth_client`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

</details>

<details>
<summary><code>cloudflare.rule.origin-ca-certificate</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L312-L318">Source</a></summary>

<div id="rule-origin-ca-certificate"></div>

Matches `resource` instances of `cloudflare_origin_ca_certificate`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

</details>

<details>
<summary><code>cloudflare.rule.origin-cloud-region</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L235-L256">Source</a></summary>

<div id="rule-origin-cloud-region"></div>

Matches `resource` instances of `cloudflare_origin_cloud_region`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.origin-tls-compliance-modes</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L320-L341">Source</a></summary>

<div id="rule-origin-tls-compliance-modes"></div>

Matches `resource` instances of `cloudflare_origin_tls_compliance_modes`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.page-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L189-L210">Source</a></summary>

<div id="rule-page-rule"></div>

Matches `resource` instances of `cloudflare_page_rule`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.page-shield-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L122-L143">Source</a></summary>

<div id="rule-page-shield-policy"></div>

Matches `resource` instances of `cloudflare_page_shield_policy`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.pages-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/pages-workflows.rf.hcl#L29-L47">Source</a></summary>

<div id="rule-pages-domain"></div>

Matches `resource` instances of `cloudflare_pages_domain`.

**Classification:** [`cloudflare.concept.pages-domain`](#cloudflare-concept-pages-domain).

**Contributions**

- targets [`cloudflare.concept.pages-project`](#cloudflare-concept-pages-project) through `source.project_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.project_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.pages-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/pages-workflows.rf.hcl#L12-L27">Source</a></summary>

<div id="rule-pages-project"></div>

Matches `resource` instances of `cloudflare_pages_project`.

**Classification:** [`cloudflare.concept.pages-project`](#cloudflare-concept-pages-project).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.precursor</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L193-L214">Source</a></summary>

<div id="rule-precursor"></div>

Matches `resource` instances of `cloudflare_precursor`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.queue-consumer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/messaging-eventing/queues.rf.hcl#L22-L52">Source</a></summary>

<div id="rule-queue-consumer"></div>

Matches `resource` instances of `cloudflare_queue_consumer`.

**Classification:** [`cloudflare.concept.queue-consumer-binding`](#cloudflare-concept-queue-consumer-binding).

**Contributions**

- targets [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue) through `source.queue_id`.
- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.script_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.queue_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.script_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/messaging-eventing/queues.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-queue"></div>

Matches `resource` instances of `cloudflare_queue`.

**Classification:** [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "queue_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "queue_name"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket-cors</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L26-L47">Source</a></summary>

<div id="rule-r2-bucket-cors"></div>

Matches `resource` instances of `cloudflare_r2_bucket_cors`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket-event-notification</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L117-L150">Source</a></summary>

<div id="rule-r2-bucket-event-notification"></div>

Matches `resource` instances of `cloudflare_r2_bucket_event_notification`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.
- targets [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue) through `source.queue_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.queue_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket-lifecycle</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L48-L69">Source</a></summary>

<div id="rule-r2-bucket-lifecycle"></div>

Matches `resource` instances of `cloudflare_r2_bucket_lifecycle`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket-lock</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L71-L92">Source</a></summary>

<div id="rule-r2-bucket-lock"></div>

Matches `resource` instances of `cloudflare_r2_bucket_lock`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket-sippy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L94-L115">Source</a></summary>

<div id="rule-r2-bucket-sippy"></div>

Matches `resource` instances of `cloudflare_r2_bucket_sippy`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-r2-bucket"></div>

Matches `resource` instances of `cloudflare_r2_bucket`.

**Classification:** [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-custom-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L152-L189">Source</a></summary>

<div id="rule-r2-custom-domain"></div>

Matches `resource` instances of `cloudflare_r2_custom_domain`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-data-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L214-L235">Source</a></summary>

<div id="rule-r2-data-catalog"></div>

Matches `resource` instances of `cloudflare_r2_data_catalog`.

**Classification:** [`cloudflare.concept.r2-data-catalog`](#cloudflare-concept-r2-data-catalog).

**Relations**

- [`cloudflare.relation.catalogs`](#cloudflare-relation-catalogs): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.r2-managed-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/storage/r2.rf.hcl#L191-L212">Source</a></summary>

<div id="rule-r2-managed-domain"></div>

Matches `resource` instances of `cloudflare_r2_managed_domain`.

**Classification:** [`cloudflare.concept.r2-configuration`](#cloudflare-concept-r2-configuration).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.rate-limit</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L53-L74">Source</a></summary>

<div id="rule-rate-limit"></div>

Matches `resource` instances of `cloudflare_rate_limit`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.regional-hostname</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L294-L316">Source</a></summary>

<div id="rule-regional-hostname"></div>

Matches `resource` instances of `cloudflare_regional_hostname`.

**Classification:** [`cloudflare.concept.edge-route`](#cloudflare-concept-edge-route).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.regional-tiered-cache</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L74-L95">Source</a></summary>

<div id="rule-regional-tiered-cache"></div>

Matches `resource` instances of `cloudflare_regional_tiered_cache`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.ruleset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L7-L28">Source</a></summary>

<div id="rule-ruleset"></div>

Matches `resource` instances of `cloudflare_ruleset`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.schema-validation-operation-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L331-L352">Source</a></summary>

<div id="rule-schema-validation-operation-settings"></div>

Matches `resource` instances of `cloudflare_schema_validation_operation_settings`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.schema-validation-schemas</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L354-L375">Source</a></summary>

<div id="rule-schema-validation-schemas"></div>

Matches `resource` instances of `cloudflare_schema_validation_schemas`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.schema-validation-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L377-L398">Source</a></summary>

<div id="rule-schema-validation-settings"></div>

Matches `resource` instances of `cloudflare_schema_validation_settings`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.secrets-store-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/identity-iam/identities-secrets.rf.hcl#L39-L58">Source</a></summary>

<div id="rule-secrets-store-secret"></div>

Matches `resource` instances of `cloudflare_secrets_store_secret`.

**Classification:** [`cloudflare.concept.managed-secret`](#cloudflare-concept-managed-secret).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.secrets-store`](#cloudflare-concept-secrets-store) through `source.store_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.store_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.secrets-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/identity-iam/identities-secrets.rf.hcl#L22-L37">Source</a></summary>

<div id="rule-secrets-store"></div>

Matches `resource` instances of `cloudflare_secrets_store`.

**Classification:** [`cloudflare.concept.secrets-store`](#cloudflare-concept-secrets-store).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.snippet-rules</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L304-L325">Source</a></summary>

<div id="rule-snippet-rules"></div>

Matches `resource` instances of `cloudflare_snippet_rules`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.snippet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L258-L279">Source</a></summary>

<div id="rule-snippet"></div>

Matches `resource` instances of `cloudflare_snippet`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.snippets</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L281-L302">Source</a></summary>

<div id="rule-snippets"></div>

Matches `resource` instances of `cloudflare_snippets`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.spectrum-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L21-L44">Source</a></summary>

<div id="rule-spectrum-application"></div>

Matches `resource` instances of `cloudflare_spectrum_application`.

**Classification:** [`cloudflare.concept.spectrum-application`](#cloudflare-concept-spectrum-application).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.sso-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/identity-iam/identities-secrets.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-sso-connector"></div>

Matches `resource` instances of `cloudflare_sso_connector`.

**Classification:** [`cloudflare.concept.identity-provider`](#cloudflare-concept-identity-provider).

</details>

<details>
<summary><code>cloudflare.rule.tiered-cache</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L51-L72">Source</a></summary>

<div id="rule-tiered-cache"></div>

Matches `resource` instances of `cloudflare_tiered_cache`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.token-validation-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L168-L189">Source</a></summary>

<div id="rule-token-validation-config"></div>

Matches `resource` instances of `cloudflare_token_validation_config`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.total-tls</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L343-L364">Source</a></summary>

<div id="rule-total-tls"></div>

Matches `resource` instances of `cloudflare_total_tls`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.universal-ssl-setting</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L366-L387">Source</a></summary>

<div id="rule-universal-ssl-setting"></div>

Matches `resource` instances of `cloudflare_universal_ssl_setting`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.url-normalization-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L166-L187">Source</a></summary>

<div id="rule-url-normalization-settings"></div>

Matches `resource` instances of `cloudflare_url_normalization_settings`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.user-agent-blocking-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L423-L444">Source</a></summary>

<div id="rule-user-agent-blocking-rule"></div>

Matches `resource` instances of `cloudflare_user_agent_blocking_rule`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.waiting-room-event</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L148-L181">Source</a></summary>

<div id="rule-waiting-room-event"></div>

Matches `resource` instances of `cloudflare_waiting_room_event`.

**Classification:** [`cloudflare.concept.waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration).

**Contributions**

- targets [`cloudflare.concept.waiting-room`](#cloudflare-concept-waiting-room) through `source.waiting_room_id`.
- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.waiting_room_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.waiting-room-rules</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L183-L216">Source</a></summary>

<div id="rule-waiting-room-rules"></div>

Matches `resource` instances of `cloudflare_waiting_room_rules`.

**Classification:** [`cloudflare.concept.waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration).

**Contributions**

- targets [`cloudflare.concept.waiting-room`](#cloudflare-concept-waiting-room) through `source.waiting_room_id`.
- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.waiting_room_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.waiting-room-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L218-L239">Source</a></summary>

<div id="rule-waiting-room-settings"></div>

Matches `resource` instances of `cloudflare_waiting_room_settings`.

**Classification:** [`cloudflare.concept.waiting-room-configuration`](#cloudflare-concept-waiting-room-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.waiting-room</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/edge-applications/edge-services.rf.hcl#L46-L77">Source</a></summary>

<div id="rule-waiting-room"></div>

Matches `resource` instances of `cloudflare_waiting_room`.

**Classification:** [`cloudflare.concept.waiting-room`](#cloudflare-concept-waiting-room).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.web-analytics-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-web-analytics-rule"></div>

Matches `resource` instances of `cloudflare_web_analytics_rule`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.web3-hostname</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L247-L269">Source</a></summary>

<div id="rule-web3-hostname"></div>

Matches `resource` instances of `cloudflare_web3_hostname`.

**Classification:** [`cloudflare.concept.web3-hostname`](#cloudflare-concept-web3-hostname).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.worker-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L164-L236">Source</a></summary>

<div id="rule-worker-version"></div>

Matches `resource` instances of `cloudflare_worker_version`.

**Classification:** [`cloudflare.concept.worker-version`](#cloudflare-concept-worker-version).

**Contributions**

- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.worker_id`.
- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bindings[0].bucket_name`.
- targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.bindings[1].database_id`.
- targets [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue) through `source.bindings[2].queue_name`.
- targets [`cloudflare.concept.workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace) through `source.bindings[3].namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.worker_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.bindings[0].bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.bindings[1].database_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.bindings[2].queue_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.queue_name`
- `match.strategy`: `"exact"`

**Contribution through `source.bindings[3].namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.worker</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L147-L162">Source</a></summary>

<div id="rule-worker"></div>

Matches `resource` instances of `cloudflare_worker`.

**Classification:** [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-cron-trigger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L350-L368">Source</a></summary>

<div id="rule-workers-cron-trigger"></div>

Matches `resource` instances of `cloudflare_workers_cron_trigger`.

**Classification:** [`cloudflare.concept.worker-route`](#cloudflare-concept-worker-route).

**Contributions**

- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.script_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.script_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-custom-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L294-L328">Source</a></summary>

<div id="rule-workers-custom-domain"></div>

Matches `resource` instances of `cloudflare_workers_custom_domain`.

**Classification:** [`cloudflare.concept.edge-route`](#cloudflare-concept-edge-route).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

**Relations**

- [`cloudflare.relation.routes-to`](#cloudflare-relation-routes-to): targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.service`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.service`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L238-L256">Source</a></summary>

<div id="rule-workers-deployment"></div>

Matches `resource` instances of `cloudflare_workers_deployment`.

**Classification:** [`cloudflare.concept.worker-deployment`](#cloudflare-concept-worker-deployment).

**Contributions**

- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.script_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.script_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-kv-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L371-L386">Source</a></summary>

<div id="rule-workers-kv-namespace"></div>

Matches `resource` instances of `cloudflare_workers_kv_namespace`.

**Classification:** [`cloudflare.concept.workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-kv</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L388-L406">Source</a></summary>

<div id="rule-workers-kv"></div>

Matches `resource` instances of `cloudflare_workers_kv`.

**Classification:** [`cloudflare.concept.workers-kv-entry`](#cloudflare-concept-workers-kv-entry).

**Contributions**

- targets [`cloudflare.concept.workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace) through `source.namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L258-L292">Source</a></summary>

<div id="rule-workers-route"></div>

Matches `resource` instances of `cloudflare_workers_route`.

**Classification:** [`cloudflare.concept.worker-route`](#cloudflare-concept-worker-route).

**Contexts**

- [`cloudflare.context.ownership`](#cloudflare-context-ownership): targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

**Contributions**

- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.script`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.script`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Context through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-script-subdomain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L330-L348">Source</a></summary>

<div id="rule-workers-script-subdomain"></div>

Matches `resource` instances of `cloudflare_workers_script_subdomain`.

**Classification:** [`cloudflare.concept.worker-route`](#cloudflare-concept-worker-route).

**Contributions**

- targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.script_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.script_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.workers-script</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/serverless/workers.rf.hcl#L22-L145">Source</a></summary>

<div id="rule-workers-script"></div>

Matches `resource` instances of `cloudflare_workers_script`.

**Classification:** [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function).

**Relations**

- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bindings[0].bucket_name`.
- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.bindings[1].database_id`.
- [`cloudflare.relation.publishes-to`](#cloudflare-relation-publishes-to): targets [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue) through `source.bindings[2].queue_name`.
- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`cloudflare.concept.workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace) through `source.bindings[3].namespace_id`.
- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bindings[4].bucket_name`.
- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.bindings[5].database_id`.
- [`cloudflare.relation.publishes-to`](#cloudflare-relation-publishes-to): targets [`cloudflare.concept.message-queue`](#cloudflare-concept-message-queue) through `source.bindings[6].queue_name`.
- [`cloudflare.relation.uses`](#cloudflare-relation-uses): targets [`cloudflare.concept.workers-kv-namespace`](#cloudflare-concept-workers-kv-namespace) through `source.bindings[7].namespace_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "script_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "script_name"]`

**Relation through `source.bindings[0].bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[1].database_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[2].queue_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.queue_name`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[3].namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[4].bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[5].database_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[6].queue_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.queue_name`
- `match.strategy`: `"exact"`

**Relation through `source.bindings[7].namespace_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.access-ai-controls-mcp-portal</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L111-L117">Source</a></summary>

<div id="rule-access-ai-controls-mcp-portal"></div>

Matches `resource` instances of `cloudflare_zero_trust_access_ai_controls_mcp_portal`.

**Classification:** [`cloudflare.concept.ai-controls-endpoint`](#cloudflare-concept-ai-controls-endpoint).

</details>

<details>
<summary><code>cloudflare.rule.access-ai-controls-mcp-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L103-L109">Source</a></summary>

<div id="rule-access-ai-controls-mcp-server"></div>

Matches `resource` instances of `cloudflare_zero_trust_access_ai_controls_mcp_server`.

**Classification:** [`cloudflare.concept.ai-controls-endpoint`](#cloudflare-concept-ai-controls-endpoint).

</details>

<details>
<summary><code>cloudflare.rule.access-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L24-L78">Source</a></summary>

<div id="rule-access-application"></div>

Matches `resource` instances of `cloudflare_zero_trust_access_application`.

**Classification:** [`cloudflare.concept.access-application`](#cloudflare-concept-access-application).

**Relations**

- [`cloudflare.relation.protects`](#cloudflare-relation-protects): targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.destinations[0].worker_id`.
- [`cloudflare.relation.protects`](#cloudflare-relation-protects): targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.destinations[1].worker_id`.
- [`cloudflare.relation.protects`](#cloudflare-relation-protects): targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.destinations[2].worker_id`.
- [`cloudflare.relation.protects`](#cloudflare-relation-protects): targets [`cloudflare.concept.serverless-function`](#cloudflare-concept-serverless-function) through `source.destinations[3].worker_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.destinations[0].worker_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.destinations[1].worker_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.destinations[2].worker_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.destinations[3].worker_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.access-identity-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L82-L88">Source</a></summary>

<div id="rule-access-identity-provider"></div>

Matches `resource` instances of `cloudflare_zero_trust_access_identity_provider`.

**Classification:** [`cloudflare.concept.identity-provider`](#cloudflare-concept-identity-provider).

</details>

<details>
<summary><code>cloudflare.rule.access-service-token</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L90-L96">Source</a></summary>

<div id="rule-access-service-token"></div>

Matches `resource` instances of `cloudflare_zero_trust_access_service_token`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

</details>

<details>
<summary><code>cloudflare.rule.device-custom-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-device-custom-profile"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_custom_profile`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-default-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-device-default-profile"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_default_profile`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-deployment-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-device-deployment-group"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_deployment_groups`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-ip-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-device-ip-profile"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_ip_profile`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-managed-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-device-managed-network"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_managed_networks`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-posture-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L45-L51">Source</a></summary>

<div id="rule-device-posture-integration"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_posture_integration`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-posture-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L53-L59">Source</a></summary>

<div id="rule-device-posture-rule"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_posture_rule`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L61-L67">Source</a></summary>

<div id="rule-device-settings"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_settings`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.device-subnet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/device-posture.rf.hcl#L69-L75">Source</a></summary>

<div id="rule-device-subnet"></div>

Matches `resource` instances of `cloudflare_zero_trust_device_subnet`.

**Classification:** [`cloudflare.concept.device-posture-configuration`](#cloudflare-concept-device-posture-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dex-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L61-L67">Source</a></summary>

<div id="rule-dex-rule"></div>

Matches `resource` instances of `cloudflare_zero_trust_dex_rule`.

**Classification:** [`cloudflare.concept.observability-configuration`](#cloudflare-concept-observability-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dex-test</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/observability/observability.rf.hcl#L53-L59">Source</a></summary>

<div id="rule-dex-test"></div>

Matches `resource` instances of `cloudflare_zero_trust_dex_test`.

**Classification:** [`cloudflare.concept.network-monitor`](#cloudflare-concept-network-monitor).

</details>

<details>
<summary><code>cloudflare.rule.dlp-custom-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-dlp-custom-profile"></div>

Matches `resource` instances of `cloudflare_zero_trust_dlp_custom_profile`.

**Classification:** [`cloudflare.concept.data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dlp-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-dlp-dataset"></div>

Matches `resource` instances of `cloudflare_zero_trust_dlp_dataset`.

**Classification:** [`cloudflare.concept.data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dlp-integration-entry</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-dlp-integration-entry"></div>

Matches `resource` instances of `cloudflare_zero_trust_dlp_integration_entry`.

**Classification:** [`cloudflare.concept.data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dlp-predefined-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-dlp-predefined-profile"></div>

Matches `resource` instances of `cloudflare_zero_trust_dlp_predefined_profile`.

**Classification:** [`cloudflare.concept.data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration).

</details>

<details>
<summary><code>cloudflare.rule.dlp-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/data-loss-prevention.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-dlp-settings"></div>

Matches `resource` instances of `cloudflare_zero_trust_dlp_settings`.

**Classification:** [`cloudflare.concept.data-loss-prevention-configuration`](#cloudflare-concept-data-loss-prevention-configuration).

</details>

<details>
<summary><code>cloudflare.rule.gateway-logging</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L127-L133">Source</a></summary>

<div id="rule-gateway-logging"></div>

Matches `resource` instances of `cloudflare_zero_trust_gateway_logging`.

**Classification:** [`cloudflare.concept.gateway-configuration`](#cloudflare-concept-gateway-configuration).

</details>

<details>
<summary><code>cloudflare.rule.gateway-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L119-L125">Source</a></summary>

<div id="rule-gateway-settings"></div>

Matches `resource` instances of `cloudflare_zero_trust_gateway_settings`.

**Classification:** [`cloudflare.concept.gateway-configuration`](#cloudflare-concept-gateway-configuration).

</details>

<details>
<summary><code>cloudflare.rule.cloudflare-tunnel-hostname-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L83-L101">Source</a></summary>

<div id="rule-cloudflare-tunnel-hostname-route"></div>

Matches `resource` instances of `cloudflare_zero_trust_network_hostname_route`.

**Classification:** [`cloudflare.concept.tunnel-configuration`](#cloudflare-concept-tunnel-configuration).

**Contributions**

- targets [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) through `source.tunnel_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.risk-scoring-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/access.rf.hcl#L135-L141">Source</a></summary>

<div id="rule-risk-scoring-integration"></div>

Matches `resource` instances of `cloudflare_zero_trust_risk_scoring_integration`.

**Classification:** [`cloudflare.concept.gateway-configuration`](#cloudflare-concept-gateway-configuration).

</details>

<details>
<summary><code>cloudflare.rule.cloudflare-tunnel-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L35-L53">Source</a></summary>

<div id="rule-cloudflare-tunnel-config"></div>

Matches `resource` instances of `cloudflare_zero_trust_tunnel_cloudflared_config`.

**Classification:** [`cloudflare.concept.tunnel-configuration`](#cloudflare-concept-tunnel-configuration).

**Contributions**

- targets [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) through `source.tunnel_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.cloudflare-tunnel-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L54-L80">Source</a></summary>

<div id="rule-cloudflare-tunnel-route"></div>

Matches `resource` instances of `cloudflare_zero_trust_tunnel_cloudflared_route`.

**Classification:** [`cloudflare.concept.tunnel-configuration`](#cloudflare-concept-tunnel-configuration).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

**Contributions**

- targets [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel) through `source.tunnel_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.cloudflare-tunnel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L18-L33">Source</a></summary>

<div id="rule-cloudflare-tunnel"></div>

Matches `resource` instances of `cloudflare_zero_trust_tunnel_cloudflared`.

**Classification:** [`cloudflare.concept.cloudflare-tunnel`](#cloudflare-concept-cloudflare-tunnel).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.warp-connector-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L161-L179">Source</a></summary>

<div id="rule-warp-connector-config"></div>

Matches `resource` instances of `cloudflare_zero_trust_tunnel_warp_connector_config`.

**Classification:** [`cloudflare.concept.tunnel-configuration`](#cloudflare-concept-tunnel-configuration).

**Contributions**

- targets [`cloudflare.concept.warp-connector`](#cloudflare-concept-warp-connector) through `source.tunnel_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.tunnel_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.warp-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/network/cloudflare-tunnel.rf.hcl#L144-L159">Source</a></summary>

<div id="rule-warp-connector"></div>

Matches `resource` instances of `cloudflare_zero_trust_tunnel_warp_connector`.

**Classification:** [`cloudflare.concept.warp-connector`](#cloudflare-concept-warp-connector).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-auto-origin-tls-kex</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/tls-certificates.rf.hcl#L389-L410">Source</a></summary>

<div id="rule-zone-auto-origin-tls-kex"></div>

Matches `resource` instances of `cloudflare_zone_auto_origin_tls_kex`.

**Classification:** [`cloudflare.concept.tls-configuration`](#cloudflare-concept-tls-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-cache-reserve</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L97-L118">Source</a></summary>

<div id="rule-zone-cache-reserve"></div>

Matches `resource` instances of `cloudflare_zone_cache_reserve`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-cache-variants</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/edge-delivery.rf.hcl#L120-L141">Source</a></summary>

<div id="rule-zone-cache-variants"></div>

Matches `resource` instances of `cloudflare_zone_cache_variants`.

**Classification:** [`cloudflare.concept.edge-delivery-configuration`](#cloudflare-concept-edge-delivery-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-dns-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L151-L172">Source</a></summary>

<div id="rule-zone-dns-settings"></div>

Matches `resource` instances of `cloudflare_zone_dns_settings`.

**Classification:** [`cloudflare.concept.zone-configuration`](#cloudflare-concept-zone-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-dnssec</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L105-L126">Source</a></summary>

<div id="rule-zone-dnssec"></div>

Matches `resource` instances of `cloudflare_zone_dnssec`.

**Classification:** [`cloudflare.concept.zone-configuration`](#cloudflare-concept-zone-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-hold</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L174-L195">Source</a></summary>

<div id="rule-zone-hold"></div>

Matches `resource` instances of `cloudflare_zone_hold`.

**Classification:** [`cloudflare.concept.zone-configuration`](#cloudflare-concept-zone-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-lockdown</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/security/application-security.rf.hcl#L446-L467">Source</a></summary>

<div id="rule-zone-lockdown"></div>

Matches `resource` instances of `cloudflare_zone_lockdown`.

**Classification:** [`cloudflare.concept.edge-security-configuration`](#cloudflare-concept-edge-security-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone-setting</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L128-L149">Source</a></summary>

<div id="rule-zone-setting"></div>

Matches `resource` instances of `cloudflare_zone_setting`.

**Classification:** [`cloudflare.concept.zone-configuration`](#cloudflare-concept-zone-configuration).

**Contributions**

- targets [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone) through `source.zone_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.zone_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>cloudflare.rule.zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/cloudflare/dns-cdn/zones-dns.rf.hcl#L38-L53">Source</a></summary>

<div id="rule-zone"></div>

Matches `resource` instances of `cloudflare_zone`.

**Classification:** [`cloudflare.concept.dns-zone`](#cloudflare-concept-dns-zone).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>
