Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/consul: = 2.23.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
consul_acl_auth_methoddataacl-auth-methodacl-auth-method-lookup
consul_acl_auth_methodresourceacl-auth-methodacl-auth-method
consul_acl_binding_ruleresourceaccess-control-configurationacl-binding-rule
consul_admin_partitionresourceadmin-partitionadmin-partition
consul_agent_serviceresourceconsul-serviceagent-service
consul_autopilot_configresourceoperations-configurationautopilot-config
consul_catalog_servicedataconsul-servicecatalog-service-lookup
consul_config_entry_service_defaultsresourceservice-networking-configurationconfig-entry-service-defaults
consul_config_entry_service_intentionsresourcemesh-security-configurationconfig-entry-service-intentions
consul_config_entry_service_resolverresourcediscovery-chain-configurationconfig-entry-service-resolver
consul_config_entry_service_routerresourcediscovery-chain-configurationconfig-entry-service-router
consul_config_entry_service_splitterresourcediscovery-chain-configurationconfig-entry-service-splitter
consul_config_entry_v2_exported_servicesdataservice-exportconfig-entry-v2-exported-services-lookup
consul_config_entry_v2_exported_servicesresourceservice-exportconfig-entry-v2-exported-services
consul_config_entrydataapi-gateway
operations-configuration
service-export
gateway-configuration
ingress-gateway
jwt-provider
service-mesh
service-networking-configuration
sameness-group
mesh-security-configuration
discovery-chain-configuration
terminating-gateway
config-entry-api-gateway-json-lookup (conditional)
config-entry-control-plane-request-limit-json-lookup (conditional)
config-entry-exported-services-json-lookup (conditional)
config-entry-file-system-certificate-json-lookup (conditional)
config-entry-http-route-json-lookup (conditional)
config-entry-ingress-gateway-json-lookup (conditional)
config-entry-inline-certificate-json-lookup (conditional)
config-entry-jwt-provider-json-lookup (conditional)
config-entry-mesh-json-lookup (conditional)
config-entry-proxy-defaults-json-lookup (conditional)
config-entry-sameness-group-json-lookup (conditional)
config-entry-service-defaults-json-lookup (conditional)
config-entry-service-intentions-json-lookup (conditional)
config-entry-service-resolver-json-lookup (conditional)
config-entry-service-router-json-lookup (conditional)
config-entry-service-splitter-json-lookup (conditional)
config-entry-tcp-route-json-lookup (conditional)
config-entry-terminating-gateway-json-lookup (conditional)
consul_config_entryresourceapi-gateway
operations-configuration
service-export
gateway-configuration
ingress-gateway
jwt-provider
service-mesh
service-networking-configuration
sameness-group
mesh-security-configuration
discovery-chain-configuration
terminating-gateway
config-entry-api-gateway-json (conditional)
config-entry-control-plane-request-limit-json (conditional)
config-entry-exported-services-json (conditional)
config-entry-file-system-certificate-json (conditional)
config-entry-http-route-json (conditional)
config-entry-ingress-gateway-json (conditional)
config-entry-inline-certificate-json (conditional)
config-entry-jwt-provider-json (conditional)
config-entry-mesh-json (conditional)
config-entry-proxy-defaults-json (conditional)
config-entry-sameness-group-json (conditional)
config-entry-service-defaults-json (conditional)
config-entry-service-intentions-json (conditional)
config-entry-service-resolver-json (conditional)
config-entry-service-router-json (conditional)
config-entry-service-splitter-json (conditional)
config-entry-tcp-route-json (conditional)
config-entry-terminating-gateway-json (conditional)
consul_intentionresourcemesh-security-configurationintention
consul_namespace_policy_attachmentresourceaccess-control-configurationnamespace-policy-attachment
consul_namespace_role_attachmentresourceaccess-control-configurationnamespace-role-attachment
consul_namespaceresourcenamespacenamespace
consul_noderesourceconsul-nodenode
consul_peeringdatacluster-peeringpeering-lookup
consul_peeringresourcecluster-peeringpeering
consul_prepared_queryresourcediscovery-chain-configurationprepared-query
consul_service_healthdataoperations-configurationservice-health-lookup
consul_servicedataconsul-serviceservice-lookup
consul_serviceresourceconsul-serviceservice

Local vocabulary

Concepts

consul.concept.access-control-configuration Source

A binding or attachment supporting a Consul identity boundary.

Used by acl-binding-rule, namespace-policy-attachment, namespace-role-attachment.

consul.concept.acl-auth-method Source

A Consul authentication boundary that verifies an external workload identity.

Used by acl-auth-method, acl-auth-method-lookup, acl-binding-rule.

consul.concept.admin-partition Source

A Consul Enterprise administrative and communication boundary.

Used by admin-partition, namespace.

consul.concept.api-gateway Source

A managed gateway that exposes and governs APIs.

Used by config-entry-api-gateway-json, config-entry-api-gateway-json-lookup.

consul.concept.cluster-peering Source

A Consul cluster peering connection for exported service discovery and mesh traffic.

Used by 4 Rules
consul.concept.consul-node Source

A node registered in the Consul service catalog.

Used by node, service.

consul.concept.ingress-gateway Source

A deprecated Consul gateway admitting traffic into the service mesh.

Used by config-entry-ingress-gateway-json, config-entry-ingress-gateway-json-lookup.

consul.concept.jwt-provider Source

A JWT validation boundary used by Consul service mesh intentions.

Used by config-entry-jwt-provider-json, config-entry-jwt-provider-json-lookup.

consul.concept.mesh-security-configuration Source

An authorization detail protecting service mesh traffic without proving traffic flow.

Used by 4 Rules
consul.concept.namespace Source

A Consul Enterprise tenant boundary within an admin partition.

Used by 6 Rules
consul.concept.operations-configuration Source

An operational or health setting that owns no independent topology.

Used by 4 Rules
consul.concept.sameness-group Source

A Consul group of partitions or peers with equivalent service instances.

Used by 4 Rules
consul.concept.service-export Source

A service export detail for peers, partitions, or sameness groups.

Used by 4 Rules
consul.concept.service-mesh Source

A Consul service mesh traffic-control and identity boundary.

Used by config-entry-mesh-json, config-entry-mesh-json-lookup.

consul.concept.service-networking-configuration Source

A mesh-wide or service-specific proxy configuration.

Used by 5 Rules
consul.concept.terminating-gateway Source

A Consul gateway connecting mesh services to services outside the mesh.

Used by config-entry-terminating-gateway-json, config-entry-terminating-gateway-json-lookup.

Contexts

consul.context.ownership Source

Administrative or lifecycle ownership.

Used by 4 Rules

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

consul.rule.acl-auth-method-lookup Source

Matches data instances of consul_acl_auth_method.

Classification: consul.concept.acl-auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.acl-auth-method Source

Matches resource instances of consul_acl_auth_method.

Classification: consul.concept.acl-auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.acl-binding-rule Source

Matches resource instances of consul_acl_binding_rule.

Classification: consul.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.auth_method

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.admin-partition Source

Matches resource instances of consul_admin_partition.

Classification: consul.concept.admin-partition.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.agent-service Source

Matches resource instances of consul_agent_service.

Classification: consul.concept.consul-service.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.autopilot-config Source

Matches resource instances of consul_autopilot_config.

Classification: consul.concept.operations-configuration.

consul.rule.catalog-service-lookup Source

Matches data instances of consul_catalog_service.

Classification: consul.concept.consul-service.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.config-entry-service-defaults Source

Matches resource instances of consul_config_entry_service_defaults.

Classification: consul.concept.service-networking-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-service-intentions Source

Matches resource instances of consul_config_entry_service_intentions.

Classification: consul.concept.mesh-security-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-service-resolver Source

Matches resource instances of consul_config_entry_service_resolver.

Classification: consul.concept.discovery-chain-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-service-router Source

Matches resource instances of consul_config_entry_service_router.

Classification: consul.concept.discovery-chain-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-service-splitter Source

Matches resource instances of consul_config_entry_service_splitter.

Classification: consul.concept.discovery-chain-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-v2-exported-services-lookup Source

Matches data instances of consul_config_entry_v2_exported_services.

Classification: consul.concept.service-export.

Contributions

Conditions, identity and resolution

Contribution through source.services

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.peer_consumers

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.peer_name
  • match.strategy: "exact"

Contribution through source.sameness_group_consumers

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-v2-exported-services Source

Matches resource instances of consul_config_entry_v2_exported_services.

Classification: consul.concept.service-export.

Contributions

Conditions, identity and resolution

Contribution through source.services

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.peer_consumers

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.peer_name
  • match.strategy: "exact"

Contribution through source.sameness_group_consumers

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.config-entry-api-gateway-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.api-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "api-gateway"
consul.rule.config-entry-control-plane-request-limit-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.operations-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "control-plane-request-limit"
consul.rule.config-entry-exported-services-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.service-export.

Conditions, identity and resolution

Condition

RF
source.kind == "exported-services"
consul.rule.config-entry-file-system-certificate-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "file-system-certificate"
consul.rule.config-entry-http-route-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "http-route"
consul.rule.config-entry-ingress-gateway-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.ingress-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "ingress-gateway"
consul.rule.config-entry-inline-certificate-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "inline-certificate"
consul.rule.config-entry-jwt-provider-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.jwt-provider.

Conditions, identity and resolution

Condition

RF
source.kind == "jwt-provider"
consul.rule.config-entry-mesh-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.service-mesh.

Conditions, identity and resolution

Condition

RF
source.kind == "mesh"
consul.rule.config-entry-proxy-defaults-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.service-networking-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "proxy-defaults"
consul.rule.config-entry-sameness-group-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.sameness-group.

Conditions, identity and resolution

Condition

RF
source.kind == "sameness-group"

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.config-entry-service-defaults-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.service-networking-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-defaults"
consul.rule.config-entry-service-intentions-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.mesh-security-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-intentions"
consul.rule.config-entry-service-resolver-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-resolver"
consul.rule.config-entry-service-router-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-router"
consul.rule.config-entry-service-splitter-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-splitter"
consul.rule.config-entry-tcp-route-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "tcp-route"
consul.rule.config-entry-terminating-gateway-json-lookup Source

Matches data instances of consul_config_entry.

Classification: consul.concept.terminating-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "terminating-gateway"
consul.rule.config-entry-api-gateway-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.api-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "api-gateway"
consul.rule.config-entry-control-plane-request-limit-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.operations-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "control-plane-request-limit"
consul.rule.config-entry-exported-services-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.service-export.

Conditions, identity and resolution

Condition

RF
source.kind == "exported-services"
consul.rule.config-entry-file-system-certificate-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "file-system-certificate"
consul.rule.config-entry-http-route-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "http-route"
consul.rule.config-entry-ingress-gateway-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.ingress-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "ingress-gateway"
consul.rule.config-entry-inline-certificate-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "inline-certificate"
consul.rule.config-entry-jwt-provider-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.jwt-provider.

Conditions, identity and resolution

Condition

RF
source.kind == "jwt-provider"
consul.rule.config-entry-mesh-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.service-mesh.

Conditions, identity and resolution

Condition

RF
source.kind == "mesh"
consul.rule.config-entry-proxy-defaults-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.service-networking-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "proxy-defaults"
consul.rule.config-entry-sameness-group-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.sameness-group.

Conditions, identity and resolution

Condition

RF
source.kind == "sameness-group"

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.config-entry-service-defaults-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.service-networking-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-defaults"
consul.rule.config-entry-service-intentions-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.mesh-security-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-intentions"
consul.rule.config-entry-service-resolver-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-resolver"
consul.rule.config-entry-service-router-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-router"
consul.rule.config-entry-service-splitter-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.discovery-chain-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "service-splitter"
consul.rule.config-entry-tcp-route-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.gateway-configuration.

Conditions, identity and resolution

Condition

RF
source.kind == "tcp-route"
consul.rule.config-entry-terminating-gateway-json Source

Matches resource instances of consul_config_entry.

Classification: consul.concept.terminating-gateway.

Conditions, identity and resolution

Condition

RF
source.kind == "terminating-gateway"
consul.rule.intention Source

Matches resource instances of consul_intention.

Classification: consul.concept.mesh-security-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.source_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.destination_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.namespace-policy-attachment Source

Matches resource instances of consul_namespace_policy_attachment.

Classification: consul.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.namespace-role-attachment Source

Matches resource instances of consul_namespace_role_attachment.

Classification: consul.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.namespace Source

Matches resource instances of consul_namespace.

Classification: consul.concept.namespace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.partition

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.node Source

Matches resource instances of consul_node.

Classification: consul.concept.consul-node.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.peering-lookup Source

Matches data instances of consul_peering.

Classification: consul.concept.cluster-peering.

Conditions, identity and resolution

Identity

  • attributes: ["id", "peer_name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "peer_name"]
consul.rule.peering Source

Matches resource instances of consul_peering.

Classification: consul.concept.cluster-peering.

Conditions, identity and resolution

Identity

  • attributes: ["id", "peer_name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "peer_name"]
consul.rule.prepared-query Source

Matches resource instances of consul_prepared_query.

Classification: consul.concept.discovery-chain-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.service

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.service-health-lookup Source

Matches data instances of consul_service_health.

Classification: consul.concept.operations-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"
consul.rule.service-lookup Source

Matches data instances of consul_service.

Classification: consul.concept.consul-service.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
consul.rule.service Source

Matches resource instances of consul_service.

Classification: consul.concept.consul-service.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.node

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"