Reference
consul Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/consul:= 2.23.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
consul.concept.access-control-configurationSource-
A binding or attachment supporting a Consul identity boundary.
-
Used by
acl-binding-rule,namespace-policy-attachment,namespace-role-attachment. consul.concept.acl-auth-methodSource-
A Consul authentication boundary that verifies an external workload identity.
-
Used by
acl-auth-method,acl-auth-method-lookup,acl-binding-rule. consul.concept.admin-partitionSource-
A Consul Enterprise administrative and communication boundary.
-
Used by
admin-partition,namespace. consul.concept.api-gatewaySource-
A managed gateway that exposes and governs APIs.
-
Used by
config-entry-api-gateway-json,config-entry-api-gateway-json-lookup. consul.concept.cluster-peeringSource-
A Consul cluster peering connection for exported service discovery and mesh traffic.
consul.concept.consul-serviceSource-
A service registered or selected in the Consul catalog.
-
Used by 14 Rules
agent-servicecatalog-service-lookupconfig-entry-service-defaultsconfig-entry-service-intentionsconfig-entry-service-resolverconfig-entry-service-routerconfig-entry-service-splitterconfig-entry-v2-exported-servicesconfig-entry-v2-exported-services-lookupintentionprepared-queryserviceservice-health-lookupservice-lookup
consul.concept.discovery-chain-configurationSource-
A resolver, router, splitter, or prepared-query detail for service discovery.
-
Used by 10 Rules
config-entry-service-resolverconfig-entry-service-resolver-jsonconfig-entry-service-resolver-json-lookupconfig-entry-service-routerconfig-entry-service-router-jsonconfig-entry-service-router-json-lookupconfig-entry-service-splitterconfig-entry-service-splitter-jsonconfig-entry-service-splitter-json-lookupprepared-query
consul.concept.gateway-configurationSource-
A route or certificate configuration supporting a Consul API gateway.
-
Used by 8 Rules
consul.concept.ingress-gatewaySource-
A deprecated Consul gateway admitting traffic into the service mesh.
-
Used by
config-entry-ingress-gateway-json,config-entry-ingress-gateway-json-lookup. consul.concept.jwt-providerSource-
A JWT validation boundary used by Consul service mesh intentions.
-
Used by
config-entry-jwt-provider-json,config-entry-jwt-provider-json-lookup. consul.concept.mesh-security-configurationSource-
An authorization detail protecting service mesh traffic without proving traffic flow.
consul.concept.operations-configurationSource-
An operational or health setting that owns no independent topology.
consul.concept.sameness-groupSource-
A Consul group of partitions or peers with equivalent service instances.
consul.concept.service-exportSource-
A service export detail for peers, partitions, or sameness groups.
consul.concept.service-meshSource-
A Consul service mesh traffic-control and identity boundary.
-
Used by
config-entry-mesh-json,config-entry-mesh-json-lookup. consul.concept.service-networking-configurationSource-
A mesh-wide or service-specific proxy configuration.
consul.concept.terminating-gatewaySource-
A Consul gateway connecting mesh services to services outside the mesh.
-
Used by
config-entry-terminating-gateway-json,config-entry-terminating-gateway-json-lookup.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
consul.rule.acl-auth-method-lookup Source
Matches data instances of consul_acl_auth_method.
Classification: consul.concept.acl-auth-method.
Contexts
consul.context.ownership: targetsconsul.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.namematch.strategy:"exact"
consul.rule.acl-auth-method Source
Matches resource instances of consul_acl_auth_method.
Classification: consul.concept.acl-auth-method.
Contexts
consul.context.ownership: targetsconsul.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
consul.rule.acl-binding-rule Source
Matches resource instances of consul_acl_binding_rule.
Classification: consul.concept.access-control-configuration.
Contributions
- targets
consul.concept.acl-auth-methodthroughsource.auth_method.
Conditions, identity and resolution
Contribution through source.auth_method
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.admin-partition Source
Matches resource instances of consul_admin_partition.
Classification: consul.concept.admin-partition.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.agent-service Source
Matches resource instances of consul_agent_service.
Classification: consul.concept.consul-service.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.autopilot-config Source
Matches resource instances of consul_autopilot_config.
Classification: consul.concept.operations-configuration.
consul.rule.catalog-service-lookup Source
Matches data instances of consul_catalog_service.
Classification: consul.concept.consul-service.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.config-entry-service-defaults Source
Matches resource instances of consul_config_entry_service_defaults.
Classification: consul.concept.service-networking-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-service-intentions Source
Matches resource instances of consul_config_entry_service_intentions.
Classification: consul.concept.mesh-security-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-service-resolver Source
Matches resource instances of consul_config_entry_service_resolver.
Classification: consul.concept.discovery-chain-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-service-router Source
Matches resource instances of consul_config_entry_service_router.
Classification: consul.concept.discovery-chain-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-service-splitter Source
Matches resource instances of consul_config_entry_service_splitter.
Classification: consul.concept.discovery-chain-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-v2-exported-services-lookup Source
Matches data instances of consul_config_entry_v2_exported_services.
Classification: consul.concept.service-export.
Contributions
- targets
consul.concept.consul-servicethroughsource.services. - targets
consul.concept.cluster-peeringthroughsource.peer_consumers. - targets
consul.concept.sameness-groupthroughsource.sameness_group_consumers.
Conditions, identity and resolution
Contribution through source.services
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
Contribution through source.peer_consumers
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.peer_namematch.strategy:"exact"
Contribution through source.sameness_group_consumers
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-v2-exported-services Source
Matches resource instances of consul_config_entry_v2_exported_services.
Classification: consul.concept.service-export.
Contributions
- targets
consul.concept.consul-servicethroughsource.services. - targets
consul.concept.cluster-peeringthroughsource.peer_consumers. - targets
consul.concept.sameness-groupthroughsource.sameness_group_consumers.
Conditions, identity and resolution
Contribution through source.services
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Contribution through source.peer_consumers
on_null:"absent"on_empty:"absent"match.by:target.peer_namematch.strategy:"exact"
Contribution through source.sameness_group_consumers
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.config-entry-api-gateway-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.api-gateway.
Conditions, identity and resolution
Condition
source.kind == "api-gateway"consul.rule.config-entry-control-plane-request-limit-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.operations-configuration.
Conditions, identity and resolution
Condition
source.kind == "control-plane-request-limit"consul.rule.config-entry-exported-services-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.service-export.
Conditions, identity and resolution
Condition
source.kind == "exported-services"consul.rule.config-entry-file-system-certificate-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "file-system-certificate"consul.rule.config-entry-http-route-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "http-route"consul.rule.config-entry-ingress-gateway-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.ingress-gateway.
Conditions, identity and resolution
Condition
source.kind == "ingress-gateway"consul.rule.config-entry-inline-certificate-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "inline-certificate"consul.rule.config-entry-jwt-provider-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.jwt-provider.
Conditions, identity and resolution
Condition
source.kind == "jwt-provider"consul.rule.config-entry-mesh-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.service-mesh.
Conditions, identity and resolution
Condition
source.kind == "mesh"consul.rule.config-entry-proxy-defaults-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.service-networking-configuration.
Conditions, identity and resolution
Condition
source.kind == "proxy-defaults"consul.rule.config-entry-sameness-group-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.sameness-group.
Conditions, identity and resolution
Condition
source.kind == "sameness-group"Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.config-entry-service-defaults-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.service-networking-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-defaults"consul.rule.config-entry-service-intentions-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.mesh-security-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-intentions"consul.rule.config-entry-service-resolver-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-resolver"consul.rule.config-entry-service-router-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-router"consul.rule.config-entry-service-splitter-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-splitter"consul.rule.config-entry-tcp-route-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "tcp-route"consul.rule.config-entry-terminating-gateway-json-lookup Source
Matches data instances of consul_config_entry.
Classification: consul.concept.terminating-gateway.
Conditions, identity and resolution
Condition
source.kind == "terminating-gateway"consul.rule.config-entry-api-gateway-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.api-gateway.
Conditions, identity and resolution
Condition
source.kind == "api-gateway"consul.rule.config-entry-control-plane-request-limit-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.operations-configuration.
Conditions, identity and resolution
Condition
source.kind == "control-plane-request-limit"consul.rule.config-entry-exported-services-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.service-export.
Conditions, identity and resolution
Condition
source.kind == "exported-services"consul.rule.config-entry-file-system-certificate-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "file-system-certificate"consul.rule.config-entry-http-route-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "http-route"consul.rule.config-entry-ingress-gateway-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.ingress-gateway.
Conditions, identity and resolution
Condition
source.kind == "ingress-gateway"consul.rule.config-entry-inline-certificate-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "inline-certificate"consul.rule.config-entry-jwt-provider-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.jwt-provider.
Conditions, identity and resolution
Condition
source.kind == "jwt-provider"consul.rule.config-entry-mesh-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.service-mesh.
Conditions, identity and resolution
Condition
source.kind == "mesh"consul.rule.config-entry-proxy-defaults-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.service-networking-configuration.
Conditions, identity and resolution
Condition
source.kind == "proxy-defaults"consul.rule.config-entry-sameness-group-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.sameness-group.
Conditions, identity and resolution
Condition
source.kind == "sameness-group"Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.config-entry-service-defaults-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.service-networking-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-defaults"consul.rule.config-entry-service-intentions-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.mesh-security-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-intentions"consul.rule.config-entry-service-resolver-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-resolver"consul.rule.config-entry-service-router-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-router"consul.rule.config-entry-service-splitter-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.discovery-chain-configuration.
Conditions, identity and resolution
Condition
source.kind == "service-splitter"consul.rule.config-entry-tcp-route-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.gateway-configuration.
Conditions, identity and resolution
Condition
source.kind == "tcp-route"consul.rule.config-entry-terminating-gateway-json Source
Matches resource instances of consul_config_entry.
Classification: consul.concept.terminating-gateway.
Conditions, identity and resolution
Condition
source.kind == "terminating-gateway"consul.rule.intention Source
Matches resource instances of consul_intention.
Classification: consul.concept.mesh-security-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.source_name. - targets
consul.concept.consul-servicethroughsource.destination_name.
Conditions, identity and resolution
Contribution through source.source_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Contribution through source.destination_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.namespace-policy-attachment Source
Matches resource instances of consul_namespace_policy_attachment.
Classification: consul.concept.access-control-configuration.
Contributions
- targets
consul.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Contribution through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
consul.rule.namespace-role-attachment Source
Matches resource instances of consul_namespace_role_attachment.
Classification: consul.concept.access-control-configuration.
Contributions
- targets
consul.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Contribution through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
consul.rule.namespace Source
Matches resource instances of consul_namespace.
Classification: consul.concept.namespace.
Contexts
consul.context.ownership: targetsconsul.concept.admin-partitionthroughsource.partition.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.partition
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.node Source
Matches resource instances of consul_node.
Classification: consul.concept.consul-node.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.peering-lookup Source
Matches data instances of consul_peering.
Classification: consul.concept.cluster-peering.
Conditions, identity and resolution
Identity
attributes:["id", "peer_name"]scope:"provider"
Endpoint
attributes:["id", "peer_name"]
consul.rule.peering Source
Matches resource instances of consul_peering.
Classification: consul.concept.cluster-peering.
Conditions, identity and resolution
Identity
attributes:["id", "peer_name"]scope:"provider"
Endpoint
attributes:["id", "peer_name"]
consul.rule.prepared-query Source
Matches resource instances of consul_prepared_query.
Classification: consul.concept.discovery-chain-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.service.
Conditions, identity and resolution
Contribution through source.service
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
consul.rule.service-health-lookup Source
Matches data instances of consul_service_health.
Classification: consul.concept.operations-configuration.
Contributions
- targets
consul.concept.consul-servicethroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
consul.rule.service-lookup Source
Matches data instances of consul_service.
Classification: consul.concept.consul-service.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
consul.rule.service Source
Matches resource instances of consul_service.
Classification: consul.concept.consul-service.
Contexts
rf.context.runtime: targetsconsul.concept.consul-nodethroughsource.node.consul.context.ownership: targetsconsul.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.node
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"