Reference
google Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/google:= 8.0.0.hashicorp/google-beta:= 8.0.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
google.concept.access-bindingSource-
An access-control declaration attached to a data resource.
-
Used by
bigquery-dataset-access,bigquery-table-iam-member,cloud-storage-bucket-iam-member. google.concept.ai-inference-endpointSource-
A managed endpoint that serves model inference requests.
-
Used by
vertex-ai-endpoint,vertex-ai-model-garden-endpoint. google.concept.allocated-network-rangeSource-
An allocated address range used by private service networking.
-
Used by
private-services-access-range. google.concept.alloydb-instanceSource-
A database instance contributing compute capacity to an AlloyDB cluster.
-
Used by
alloydb-instance. google.concept.analytics-hub-subscriptionSource-
An Analytics Hub subscription to a data exchange or listing.
-
Used by
analytics-hub-data-exchange-subscription,analytics-hub-listing-subscription. google.concept.api-gatewaySource-
A managed gateway that exposes and governs APIs.
-
Used by
api-gateway,cloud-endpoints-service. google.concept.app-engine-service-versionSource-
A deployed App Engine standard or flexible service version.
-
Used by
app-engine-flexible-service-version,app-engine-standard-service-version. google.concept.backup-planSource-
A managed policy scheduling and retaining backups.
-
Used by
backup-dr-backup-plan,gke-backup-plan. google.concept.backup-vaultSource-
A managed vault storing protected recovery data.
-
Used by
backup-dr-backup-plan,backup-dr-backup-vault. google.concept.biglake-catalogSource-
A BigLake catalog organizing lakehouse metadata.
-
Used by
biglake-catalog,biglake-hive-catalog,biglake-iceberg-catalog. google.concept.biglake-databaseSource-
A database namespace in a BigLake catalog.
-
Used by
biglake-database,biglake-hive-database,biglake-iceberg-namespace. google.concept.biglake-tableSource-
A table registered in BigLake.
-
Used by
biglake-hive-table,biglake-iceberg-table,biglake-table. google.concept.bigquery-datasetSource-
A BigQuery dataset that organizes tables and their access boundary.
-
Used by
bigquery-dataset,bigquery-dataset-access,bigquery-table. google.concept.bigquery-tableSource-
A table managed inside a BigQuery dataset.
-
Used by
bigquery-table,bigquery-table-iam-member. google.concept.bigtable-tableSource-
A table belonging to a Bigtable instance.
-
Used by
bigtable-table. google.concept.block-storage-volumeSource-
A durable block-storage volume attachable to compute workloads.
-
Used by
persistent-disk,regional-persistent-disk. google.concept.cloud-armor-security-policySource-
A Cloud Armor security policy protecting load-balanced applications.
-
Used by
cloud-armor-security-policy,cloud-armor-security-rule. google.concept.cloud-armor-security-ruleSource-
A rule contributing traffic controls to a Cloud Armor security policy.
-
Used by
cloud-armor-security-rule. google.concept.cloud-asset-feedSource-
A Cloud Asset Inventory feed publishing asset changes to a destination.
-
Used by
cloud-asset-folder-feed,cloud-asset-organization-feed,cloud-asset-project-feed. google.concept.cloud-cdn-serviceSource-
A Cloud CDN or Media CDN edge delivery service.
-
Used by
cloud-cdn-backend-bucket,media-cdn-service. google.concept.cloud-dns-record-setSource-
A DNS record set managed inside a Cloud DNS managed zone.
-
Used by
cloud-dns-record-set. google.concept.cloud-identity-group-membershipSource-
A membership contributing a principal to a Cloud Identity group.
-
Used by
cloud-identity-group-membership. google.concept.cloud-ids-endpointSource-
A Cloud IDS endpoint inspecting traffic in a VPC network.
-
Used by
cloud-ids-endpoint. google.concept.cloud-kms-key-ringSource-
A Cloud KMS key ring organizing keys in one Google Cloud location.
-
Used by
cloud-kms-key,cloud-kms-key-ring. google.concept.cloud-kms-key-versionSource-
A cryptographic key version belonging to a Cloud KMS key.
-
Used by
cloud-kms-key-version. google.concept.cloud-logging-sinkSource-
A Cloud Logging sink routing selected log entries to a destination.
google.concept.cloud-monitoring-alerting-policySource-
A Cloud Monitoring alerting policy defining conditions and notification behavior.
-
Used by
cloud-monitoring-alerting-policy. google.concept.cloud-monitoring-serviceSource-
A Cloud Monitoring service used as the target of service-level objectives.
-
Used by
cloud-monitoring-service,cloud-monitoring-slo. google.concept.cloud-monitoring-sloSource-
A service-level objective contributing reliability intent to a monitored service.
-
Used by
cloud-monitoring-slo. google.concept.cloud-routerSource-
A Cloud Router exchanging dynamic routes for a VPC network.
-
Used by
cloud-nat,cloud-router. google.concept.cloud-run-jobSource-
A Cloud Run job that runs tasks to completion.
-
Used by
cloud-run-job. google.concept.cloud-run-serviceSource-
A Cloud Run service that handles requests or events on managed container instances.
google.concept.colab-enterprise-configurationSource-
A runtime template or schedule configuring Colab Enterprise execution.
-
Used by
colab-enterprise-runtime-template,colab-enterprise-schedule. google.concept.compliance-manager-configurationSource-
A cloud control or deployment configuring a Compliance Manager framework.
-
Used by
compliance-manager-cloud-control,compliance-manager-framework-deployment. google.concept.compute-instance-groupSource-
A managed or unmanaged Compute Engine instance group.
-
Used by
regional-managed-instance-group,unmanaged-instance-group,zonal-managed-instance-group. google.concept.conversational-agentSource-
A Dialogflow conversational agent.
-
Used by
dialogflow-agent,dialogflow-cx-agent. google.concept.cx-agent-studio-configurationSource-
A version, deployment, tool, guardrail, or other configuration supporting a CX Agent Studio application.
google.concept.database-migration-connectionSource-
A source, destination, or private connection used by Database Migration Service.
-
Used by
database-migration-connection-profile,database-migration-private-connection. google.concept.dataflow-jobSource-
A Dataflow batch or streaming job.
-
Used by
dataflow-flex-template-job,dataflow-job. google.concept.dataplex-assetSource-
A data asset governed through Dataplex.
-
Used by
dataplex-asset,dataplex-data-asset. google.concept.dataplex-lakeSource-
A Dataplex lake organizing governed data domains.
-
Used by
dataplex-lake,dataplex-zone. google.concept.dataplex-zoneSource-
A Dataplex zone organizing assets within a lake.
-
Used by
dataplex-zone. google.concept.dedicated-interconnectSource-
A dedicated private connection between an external network and a cloud provider.
-
No Rule in this Dialect uses this definition.
google.concept.discovery-engineSource-
A Discovery Engine search, recommendation, or conversational engine.
-
Used by
discovery-engine-chat-engine,discovery-engine-recommendation-engine,discovery-engine-search-engine. google.concept.dns-zoneSource-
A managed DNS namespace containing resource records.
-
Used by
cloud-dns-managed-zone,cloud-dns-record-set. google.concept.encryption-keySource-
A managed key used for cryptographic operations.
-
Used by
cloud-kms-key,cloud-kms-key-version. google.concept.firewall-policy-ruleSource-
A rule contributing controls to a Google Cloud firewall policy.
-
Used by
hierarchical-firewall-policy-rule,network-firewall-policy-rule. google.concept.gke-backup-channelSource-
A Backup for GKE channel connecting backup or restore operations across projects.
-
Used by
gke-backup-channel,gke-restore-channel. google.concept.google-cloud-projectSource-
A Google Cloud project serving as a resource and billing boundary.
-
Used by 24 Rules
cloud-monitoring-alerting-policycloud-monitoring-servicecloud-monitoring-slocloud-routercloud-run-jobcloud-run-servicecloud-run-service-v1cloud-run-worker-poolcloud-sql-instancegke-clustergoogle-cloud-projectiam-service-accountmemorystore-instancememorystore-memcached-instancememorystore-redis-clustermemorystore-redis-instancepubsub-subscriptionpubsub-topicsecret-manager-regional-secretsecret-manager-secretserverless-vpc-access-connectorvpc-firewall-rulevpc-networkvpc-subnetwork
google.concept.healthcare-datasetSource-
A Cloud Healthcare API dataset containing healthcare data stores.
google.concept.healthcare-storeSource-
A FHIR, DICOM, HL7v2, or consent store in a Cloud Healthcare API dataset.
google.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by
cloud-identity-group,cloud-identity-group-membership. google.concept.kubernetes-node-poolSource-
A node pool contributing compute capacity to a Kubernetes cluster.
google.concept.managed-secretSource-
A managed secret identity whose sensitive value stays outside architecture output.
google.concept.message-queueSource-
A managed queue buffering work or messages for asynchronous consumers.
-
No Rule in this Dialect uses this definition.
google.concept.message-subscriptionSource-
A durable subscription consuming messages from a topic.
-
Used by
pubsub-lite-subscription,pubsub-subscription. google.concept.message-topicSource-
A messaging topic receiving messages from publishers.
-
Used by 4 Rules
google.concept.migration-center-assessmentSource-
An import, grouping, preference, report, or settings resource supporting migration assessment.
google.concept.multicast-configurationSource-
An activation, group range, or network association configuring Cloud Multicast.
google.concept.netapp-storage-poolSource-
A NetApp Volumes storage pool providing capacity to volumes.
-
Used by
netapp-storage-pool,netapp-volume. google.concept.network-connectivity-center-hubSource-
A Network Connectivity Center hub coordinating connectivity through spokes.
-
Used by
network-connectivity-center-hub,network-connectivity-center-spoke. google.concept.network-connectivity-center-spokeSource-
A spoke attaching a network resource to a Network Connectivity Center hub.
-
Used by
network-connectivity-center-spoke. google.concept.network-peeringSource-
A direct private connectivity agreement between virtual networks.
-
Used by
vpc-network-peering. google.concept.network-services-routeSource-
An HTTP, gRPC, TCP, or TLS route contributing traffic policy.
google.concept.private-ca-poolSource-
A Certificate Authority Service pool containing certificate authorities.
-
Used by
private-ca-pool,private-certificate-authority. -
A managed private certificate authority.
-
Used by
private-certificate-authority. google.concept.private-endpointSource-
A private endpoint exposing a service inside a virtual network.
-
Used by
private-service-connect-endpoint. google.concept.secret-manager-secret-versionSource-
A version attached to a Secret Manager secret without exposing its secret data.
-
Used by
secret-manager-regional-secret-version,secret-manager-secret-version. google.concept.sensitive-data-protection-scanSource-
A Sensitive Data Protection discovery or inspection job configuration.
-
Used by
sensitive-data-protection-discovery,sensitive-data-protection-job-trigger. google.concept.sensitive-data-protection-templateSource-
A reusable inspection, de-identification, or stored information type configuration.
-
Used by
sensitive-data-protection-deidentify-template,sensitive-data-protection-inspect-template,sensitive-data-protection-stored-info-type. google.concept.serverless-functionSource-
A managed event-driven function runtime.
-
Used by
cloud-run-function,cloud-run-function-v2. google.concept.serverless-vpc-access-connectorSource-
A Serverless VPC Access connector bridging serverless workloads to a VPC network.
google.concept.service-credentialSource-
A credential issued for a service identity.
-
Used by
service-account-key. google.concept.service-identity-bindingSource-
An access-control binding that contributes to a service identity.
-
Used by
project-iam-binding,project-iam-member,project-iam-policy. google.concept.service-networking-detailSource-
A provider networking detail used to establish private service access.
-
Used by
service-networking-connection. google.concept.source-connectionSource-
A managed connection from Google Cloud developer services to a source host.
-
Used by
cloud-build-v2-connection,developer-connect-connection. google.concept.source-repositorySource-
A source-code repository hosted or connected through Google Cloud developer services.
google.concept.spanner-databaseSource-
A database belonging to a Spanner instance.
-
Used by
spanner-database. google.concept.vertex-ai-feature-storeSource-
A Vertex AI feature store or online feature store.
-
Used by
vertex-ai-feature-online-store,vertex-ai-feature-store. google.concept.vertex-ai-vector-indexSource-
A Vertex AI vector index.
-
Used by
vector-search-index,vertex-ai-vector-index. google.concept.vm-manager-policySource-
A VM Manager policy orchestrating guest configuration or operating system maintenance.
google.concept.vpc-firewall-ruleSource-
A Google Cloud VPC firewall rule controlling network traffic.
-
Used by
vpc-firewall-rule. google.concept.vpn-connectionSource-
A virtual private network connection between network endpoints.
-
No Rule in this Dialect uses this definition.
google.concept.vpn-gatewaySource-
A managed gateway terminating virtual private network connections.
-
Used by
classic-vpn-gateway,ha-vpn-gateway. google.concept.workflowSource-
A managed workflow coordinating steps and service calls.
-
No Rule in this Dialect uses this definition.
google.context.ownershipSource-
Administrative or lifecycle ownership.
-
Used by 33 Rules
bigquery-tablecloud-kms-keycloud-monitoring-alerting-policycloud-monitoring-servicecloud-monitoring-slocloud-natcloud-routercloud-run-jobcloud-run-servicecloud-run-service-v1cloud-run-worker-poolcloud-sql-instancedataplex-zonegke-clusterhealthcare-consent-storehealthcare-dicom-storehealthcare-fhir-storehealthcare-hl7v2-storeiam-service-accountmemorystore-instancememorystore-memcached-instancememorystore-redis-clustermemorystore-redis-instancenetapp-volumeprivate-certificate-authoritypubsub-subscriptionpubsub-topicsecret-manager-regional-secretsecret-manager-secretserverless-vpc-access-connectorvpc-firewall-rulevpc-networkvpc-subnetwork
google.relation.delivers-toSource-
Introduced by a labeled emission. Used by
pubsub-subscription. google.relation.routes-toSource-
Introduced by a labeled emission. Used by
cloud-run-service. google.relation.runs-asSource-
Introduced by a labeled emission. Used by
cloud-run-service. google.relation.stores-inSource-
Introduced by a labeled emission. Used by
backup-dr-backup-plan. google.relation.subscribes-toSource-
Introduced by a labeled emission. Used by
pubsub-subscription.
rf.concept.kubernetes-clusterrf.concept.managed-databaserf.concept.object-storage-containerrf.concept.service-identityrf.concept.subnetrf.concept.virtual-networkrf.context.network
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
google.rule.alloydb-cluster Source
Matches resource instances of google_alloydb_cluster.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.alloydb-instance Source
Matches resource instances of google_alloydb_instance.
Classification: google.concept.alloydb-instance.
Contributions
- targets
rf.concept.managed-databasethroughsource.cluster.
Conditions, identity and resolution
Contribution through source.cluster
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
google.rule.api-gateway Source
Matches resource instances of google_api_gateway_gateway.
Classification: google.concept.api-gateway.
google.rule.app-engine-flexible-service-version Source
Matches resource instances of google_app_engine_flexible_app_version.
Classification: google.concept.app-engine-service-version.
google.rule.app-engine-standard-service-version Source
Matches resource instances of google_app_engine_standard_app_version.
Classification: google.concept.app-engine-service-version.
google.rule.backup-dr-backup-plan Source
Matches resource instances of google_backup_dr_backup_plan.
Classification: google.concept.backup-plan.
Relations
google.relation.stores-in: targetsgoogle.concept.backup-vaultthroughsource.backup_vault.
Conditions, identity and resolution
Relation through source.backup_vault
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.backup-dr-backup-vault Source
Matches resource instances of google_backup_dr_backup_vault.
Classification: google.concept.backup-vault.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.biglake-catalog Source
Matches resource instances of google_biglake_catalog.
Classification: google.concept.biglake-catalog.
google.rule.biglake-database Source
Matches resource instances of google_biglake_database.
Classification: google.concept.biglake-database.
google.rule.biglake-hive-catalog Source
Matches resource instances of google_biglake_hive_catalog.
Classification: google.concept.biglake-catalog.
google.rule.biglake-hive-database Source
Matches resource instances of google_biglake_hive_database.
Classification: google.concept.biglake-database.
google.rule.biglake-hive-table Source
Matches resource instances of google_biglake_hive_table.
Classification: google.concept.biglake-table.
google.rule.biglake-iceberg-catalog Source
Matches resource instances of google_biglake_iceberg_catalog.
Classification: google.concept.biglake-catalog.
google.rule.biglake-iceberg-namespace Source
Matches resource instances of google_biglake_iceberg_namespace.
Classification: google.concept.biglake-database.
google.rule.biglake-iceberg-table Source
Matches resource instances of google_biglake_iceberg_table.
Classification: google.concept.biglake-table.
google.rule.biglake-table Source
Matches resource instances of google_biglake_table.
Classification: google.concept.biglake-table.
google.rule.analytics-hub-data-exchange-subscription Source
Matches resource instances of google_bigquery_analytics_hub_data_exchange_subscription.
Classification: google.concept.analytics-hub-subscription.
google.rule.analytics-hub-listing-subscription Source
Matches resource instances of google_bigquery_analytics_hub_listing_subscription.
Classification: google.concept.analytics-hub-subscription.
google.rule.bigquery-dataset-access Source
Matches resource instances of google_bigquery_dataset_access.
Classification: google.concept.access-binding.
Contributions
- targets
google.concept.bigquery-datasetthroughsource.dataset_id.
Conditions, identity and resolution
Contribution through source.dataset_id
on_null:"absent"on_empty:"absent"match.by:target.dataset_idmatch.strategy:"exact"
google.rule.bigquery-dataset Source
Matches resource instances of google_bigquery_dataset.
Classification: google.concept.bigquery-dataset.
Conditions, identity and resolution
Identity
attributes:["dataset_id"]scope:"provider"
Endpoint
attributes:["dataset_id", "id", "self_link"]
google.rule.bigquery-table-iam-member Source
Matches resource instances of google_bigquery_table_iam_member.
Classification: google.concept.access-binding.
Contributions
- targets
google.concept.bigquery-tablethroughsource.table_id.
Conditions, identity and resolution
Contribution through source.table_id
on_null:"absent"on_empty:"absent"match.by:target.table_idmatch.strategy:"last-segment"
google.rule.bigquery-table Source
Matches resource instances of google_bigquery_table.
Classification: google.concept.bigquery-table.
Contexts
google.context.ownership: targetsgoogle.concept.bigquery-datasetthroughsource.dataset_id.
Conditions, identity and resolution
Identity
attributes:["table_id"]scope:"provider"
Endpoint
attributes:["id", "self_link", "table_id"]
Context through source.dataset_id
on_null:"absent"on_empty:"absent"match.by:target.dataset_idmatch.strategy:"exact"
google.rule.bigtable-instance Source
Matches resource instances of google_bigtable_instance.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.bigtable-table Source
Matches resource instances of google_bigtable_table.
Classification: google.concept.bigtable-table.
Contributions
- targets
rf.concept.managed-databasethroughsource.instance_name.
Conditions, identity and resolution
Contribution through source.instance_name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
google.rule.cx-agent-studio-root-agent-association Source
Matches resource instances of google_ces_app_root_agent_association.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-app-version Source
Matches resource instances of google_ces_app_version.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-deployment Source
Matches resource instances of google_ces_deployment.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-evaluation Source
Matches resource instances of google_ces_evaluation.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-example Source
Matches resource instances of google_ces_example.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-guardrail Source
Matches resource instances of google_ces_guardrail.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-security-settings Source
Matches resource instances of google_ces_security_settings.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-tool Source
Matches resource instances of google_ces_tool.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cx-agent-studio-toolset Source
Matches resource instances of google_ces_toolset.
Classification: google.concept.cx-agent-studio-configuration.
google.rule.cloud-asset-folder-feed Source
Matches resource instances of google_cloud_asset_folder_feed.
Classification: google.concept.cloud-asset-feed.
google.rule.cloud-asset-organization-feed Source
Matches resource instances of google_cloud_asset_organization_feed.
Classification: google.concept.cloud-asset-feed.
google.rule.cloud-asset-project-feed Source
Matches resource instances of google_cloud_asset_project_feed.
Classification: google.concept.cloud-asset-feed.
google.rule.cloud-identity-group-membership Source
Matches resource instances of google_cloud_identity_group_membership.
Classification: google.concept.cloud-identity-group-membership.
Contributions
- targets
google.concept.identity-groupthroughsource.group.
Conditions, identity and resolution
Contribution through source.group
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
google.rule.cloud-identity-group Source
Matches resource instances of google_cloud_identity_group.
Classification: google.concept.identity-group.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.cloud-ids-endpoint Source
Matches resource instances of google_cloud_ids_endpoint.
Classification: google.concept.cloud-ids-endpoint.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.cloud-run-service-v1 Source
Matches resource instances of google_cloud_run_service.
Classification: google.concept.cloud-run-service.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-run-job Source
Matches resource instances of google_cloud_run_v2_job.
Classification: google.concept.cloud-run-job.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-run-service Source
Matches resource instances of google_cloud_run_v2_service.
Classification: google.concept.cloud-run-service.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.template[0].vpc_access[0].network_interfaces[0].network.rf.context.network: targetsrf.concept.subnetthroughsource.template[0].vpc_access[0].network_interfaces[0].subnetwork.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Relations
google.relation.routes-to: targetsgoogle.concept.serverless-vpc-access-connectorthroughsource.template[0].vpc_access[0].connector.google.relation.runs-as: targetsrf.concept.service-identitythroughsource.template[0].service_account.
Conditions, identity and resolution
Identity
attributes:["id", "uri"]scope:"provider"
Endpoint
attributes:["id", "uri"]
Context through source.template[0].vpc_access[0].network_interfaces[0].network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.template[0].vpc_access[0].network_interfaces[0].subnetwork
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
Relation through source.template[0].vpc_access[0].connector
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.template[0].service_account
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
google.rule.cloud-run-worker-pool Source
Matches resource instances of google_cloud_run_v2_worker_pool.
Classification: google.concept.cloud-run-service.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.compliance-manager-cloud-control Source
Matches resource instances of google_cloud_security_compliance_cloud_control.
Classification: google.concept.compliance-manager-configuration.
google.rule.compliance-manager-framework-deployment Source
Matches resource instances of google_cloud_security_compliance_framework_deployment.
Classification: google.concept.compliance-manager-configuration.
google.rule.cloud-build-v2-connection Source
Matches resource instances of google_cloudbuildv2_connection.
Classification: google.concept.source-connection.
google.rule.cloud-build-v2-repository Source
Matches resource instances of google_cloudbuildv2_repository.
Classification: google.concept.source-repository.
google.rule.cloud-run-function Source
Matches resource instances of google_cloudfunctions_function.
Classification: google.concept.serverless-function.
google.rule.cloud-run-function-v2 Source
Matches resource instances of google_cloudfunctions2_function.
Classification: google.concept.serverless-function.
google.rule.colab-enterprise-runtime-template Source
Matches resource instances of google_colab_runtime_template.
Classification: google.concept.colab-enterprise-configuration.
google.rule.colab-enterprise-schedule Source
Matches resource instances of google_colab_schedule.
Classification: google.concept.colab-enterprise-configuration.
google.rule.cloud-cdn-backend-bucket Source
Matches resource instances of google_compute_backend_bucket.
Classification: google.concept.cloud-cdn-service.
Conditions, identity and resolution
Condition
source.enable_cdn == truegoogle.rule.persistent-disk Source
Matches resource instances of google_compute_disk.
Classification: google.concept.block-storage-volume.
google.rule.hierarchical-firewall-policy-rule Source
Matches resource instances of google_compute_firewall_policy_rule.
Classification: google.concept.firewall-policy-rule.
Contributions
- targets
google.concept.firewall-policythroughsource.firewall_policy.
Conditions, identity and resolution
Contribution through source.firewall_policy
on_null:"absent"on_empty:"absent"match.by:[target.id, target.name, target.self_link]match.strategy:"exact"
google.rule.hierarchical-firewall-policy Source
Matches resource instances of google_compute_firewall_policy.
Classification: google.concept.firewall-policy.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
google.rule.vpc-firewall-rule Source
Matches resource instances of google_compute_firewall.
Classification: google.concept.vpc-firewall-rule.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.private-service-connect-endpoint Source
Matches resource instances of google_compute_forwarding_rule.
Classification: google.concept.private-endpoint.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.rf.context.network: targetsrf.concept.subnetthroughsource.subnetwork.
Conditions, identity and resolution
Condition
source.load_balancing_scheme == ""Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.subnetwork
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.regional-load-balancer Source
Matches resource instances of google_compute_forwarding_rule.
Classification: google.concept.load-balancer.
Conditions, identity and resolution
Condition
source.load_balancing_scheme != ""google.rule.private-services-access-range Source
Matches resource instances of google_compute_global_address.
Classification: google.concept.allocated-network-range.
Contributions
- targets
rf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Condition
source.purpose == "VPC_PEERING" && source.address_type == "INTERNAL"Contribution through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.application-load-balancer Source
Matches resource instances of google_compute_global_forwarding_rule.
Classification: google.concept.load-balancer.
Composition members, in declared order
target-https-proxymatches"google_compute_target_https_proxy"("resource"), throughsource.target.url-mapmatches"google_compute_url_map"("resource"), throughmember.target-https-proxy.url_map. Depends ontarget-https-proxy.backend-servicematches"google_compute_backend_service"("resource"), throughmember.url-map.default_service. Depends onurl-map.
google.rule.ha-vpn-gateway Source
Matches resource instances of google_compute_ha_vpn_gateway.
Classification: google.concept.vpn-gateway.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.compute-instance-from-machine-image Source
Matches resource instances of google_compute_instance_from_machine_image.
Classification: google.concept.compute-instance.
google.rule.compute-instance-from-template Source
Matches resource instances of google_compute_instance_from_template.
Classification: google.concept.compute-instance.
google.rule.zonal-managed-instance-group Source
Matches resource instances of google_compute_instance_group_manager.
Classification: google.concept.compute-instance-group.
google.rule.unmanaged-instance-group Source
Matches resource instances of google_compute_instance_group.
Classification: google.concept.compute-instance-group.
google.rule.compute-engine-instance Source
Matches resource instances of google_compute_instance.
Classification: google.concept.compute-instance.
google.rule.network-firewall-policy-rule Source
Matches resource instances of google_compute_network_firewall_policy_rule.
Classification: google.concept.firewall-policy-rule.
Contributions
- targets
google.concept.firewall-policythroughsource.firewall_policy.
Conditions, identity and resolution
Contribution through source.firewall_policy
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id, target.self_link]match.strategy:"exact"
google.rule.network-firewall-policy Source
Matches resource instances of google_compute_network_firewall_policy.
Classification: google.concept.firewall-policy.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
google.rule.vpc-network-peering Source
Matches resource instances of google_compute_network_peering.
Classification: google.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.rf.context.network: targetsrf.concept.virtual-networkthroughsource.peer_network.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.peer_network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.vpc-network Source
Matches resource instances of google_compute_network.
Classification: rf.concept.virtual-network.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.regional-persistent-disk Source
Matches resource instances of google_compute_region_disk.
Classification: google.concept.block-storage-volume.
google.rule.regional-managed-instance-group Source
Matches resource instances of google_compute_region_instance_group_manager.
Classification: google.concept.compute-instance-group.
google.rule.cloud-nat Source
Matches resource instances of google_compute_router_nat.
Classification: google.concept.managed-nat.
Contexts
google.context.ownership: targetsgoogle.concept.cloud-routerthroughsource.router.
Conditions, identity and resolution
Context through source.router
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id, target.self_link]match.strategy:"exact"
google.rule.cloud-router Source
Matches resource instances of google_compute_router.
Classification: google.concept.cloud-router.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-armor-security-rule Source
Matches resource instances of google_compute_security_policy_rule.
Classification: google.concept.cloud-armor-security-rule.
Contributions
- targets
google.concept.cloud-armor-security-policythroughsource.security_policy.
Conditions, identity and resolution
Contribution through source.security_policy
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id, target.self_link]match.strategy:"exact"
google.rule.cloud-armor-security-policy Source
Matches resource instances of google_compute_security_policy.
Classification: google.concept.cloud-armor-security-policy.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
google.rule.vpc-subnetwork Source
Matches resource instances of google_compute_subnetwork.
Classification: rf.concept.subnet.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id", "self_link", "name"]scope:"provider"
Endpoint
attributes:["id", "self_link", "name"]
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.classic-vpn-gateway Source
Matches resource instances of google_compute_vpn_gateway.
Classification: google.concept.vpn-gateway.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.gke-attached-cluster Source
Matches resource instances of google_container_attached_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.gke-aws-cluster Source
Matches resource instances of google_container_aws_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.gke-aws-node-pool Source
Matches resource instances of google_container_aws_node_pool.
Classification: google.concept.kubernetes-node-pool.
google.rule.gke-azure-cluster Source
Matches resource instances of google_container_azure_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.gke-azure-node-pool Source
Matches resource instances of google_container_azure_node_pool.
Classification: google.concept.kubernetes-node-pool.
google.rule.gke-cluster Source
Matches resource instances of google_container_cluster.
Classification: rf.concept.kubernetes-cluster.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.rf.context.network: targetsrf.concept.subnetthroughsource.subnetwork.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name", "self_link", "endpoint"]
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.subnetwork
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.gke-node-pool Source
Matches resource instances of google_container_node_pool.
Classification: google.concept.kubernetes-node-pool.
Contributions
- targets
rf.concept.kubernetes-clusterthroughsource.cluster.
Conditions, identity and resolution
Contribution through source.cluster
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.name, target.id, target.self_link]match.strategy:"exact"
google.rule.sensitive-data-protection-deidentify-template Source
Matches resource instances of google_data_loss_prevention_deidentify_template.
Classification: google.concept.sensitive-data-protection-template.
google.rule.sensitive-data-protection-discovery Source
Matches resource instances of google_data_loss_prevention_discovery_config.
Classification: google.concept.sensitive-data-protection-scan.
google.rule.sensitive-data-protection-inspect-template Source
Matches resource instances of google_data_loss_prevention_inspect_template.
Classification: google.concept.sensitive-data-protection-template.
google.rule.sensitive-data-protection-job-trigger Source
Matches resource instances of google_data_loss_prevention_job_trigger.
Classification: google.concept.sensitive-data-protection-scan.
google.rule.sensitive-data-protection-stored-info-type Source
Matches resource instances of google_data_loss_prevention_stored_info_type.
Classification: google.concept.sensitive-data-protection-template.
google.rule.database-migration-connection-profile Source
Matches resource instances of google_database_migration_service_connection_profile.
Classification: google.concept.database-migration-connection.
google.rule.database-migration-private-connection Source
Matches resource instances of google_database_migration_service_private_connection.
Classification: google.concept.database-migration-connection.
google.rule.dataflow-flex-template-job Source
Matches resource instances of google_dataflow_flex_template_job.
Classification: google.concept.dataflow-job.
google.rule.dataflow-job Source
Matches resource instances of google_dataflow_job.
Classification: google.concept.dataflow-job.
google.rule.dataplex-asset Source
Matches resource instances of google_dataplex_asset.
Classification: google.concept.dataplex-asset.
google.rule.dataplex-data-asset Source
Matches resource instances of google_dataplex_data_asset.
Classification: google.concept.dataplex-asset.
google.rule.dataplex-lake Source
Matches resource instances of google_dataplex_lake.
Classification: google.concept.dataplex-lake.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.dataplex-zone Source
Matches resource instances of google_dataplex_zone.
Classification: google.concept.dataplex-zone.
Contexts
google.context.ownership: targetsgoogle.concept.dataplex-lakethroughsource.lake.
Conditions, identity and resolution
Context through source.lake
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id]match.strategy:"exact"
google.rule.developer-connect-connection Source
Matches resource instances of google_developer_connect_connection.
Classification: google.concept.source-connection.
google.rule.developer-connect-repository-link Source
Matches resource instances of google_developer_connect_git_repository_link.
Classification: google.concept.source-repository.
google.rule.dialogflow-agent Source
Matches resource instances of google_dialogflow_agent.
Classification: google.concept.conversational-agent.
google.rule.dialogflow-cx-agent Source
Matches resource instances of google_dialogflow_cx_agent.
Classification: google.concept.conversational-agent.
google.rule.discovery-engine-chat-engine Source
Matches resource instances of google_discovery_engine_chat_engine.
Classification: google.concept.discovery-engine.
google.rule.discovery-engine-recommendation-engine Source
Matches resource instances of google_discovery_engine_recommendation_engine.
Classification: google.concept.discovery-engine.
google.rule.discovery-engine-search-engine Source
Matches resource instances of google_discovery_engine_search_engine.
Classification: google.concept.discovery-engine.
google.rule.cloud-dns-managed-zone Source
Matches resource instances of google_dns_managed_zone.
Classification: google.concept.dns-zone.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.cloud-dns-record-set Source
Matches resource instances of google_dns_record_set.
Classification: google.concept.cloud-dns-record-set.
Contributions
- targets
google.concept.dns-zonethroughsource.managed_zone.
Conditions, identity and resolution
Contribution through source.managed_zone
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
google.rule.edge-container-cluster Source
Matches resource instances of google_edgecontainer_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.edge-container-node-pool Source
Matches resource instances of google_edgecontainer_node_pool.
Classification: google.concept.kubernetes-node-pool.
google.rule.edge-network Source
Matches resource instances of google_edgenetwork_network.
Classification: rf.concept.virtual-network.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.edge-network-subnet Source
Matches resource instances of google_edgenetwork_subnet.
Classification: rf.concept.subnet.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.cloud-endpoints-service Source
Matches resource instances of google_endpoints_service.
Classification: google.concept.api-gateway.
google.rule.filestore-instance Source
Matches resource instances of google_filestore_instance.
Classification: google.concept.managed-file-storage.
google.rule.firebase-realtime-database Source
Matches resource instances of google_firebase_database_instance.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.firestore-database Source
Matches resource instances of google_firestore_database.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.gke-backup-channel Source
Matches resource instances of google_gke_backup_backup_channel.
Classification: google.concept.gke-backup-channel.
google.rule.gke-backup-plan Source
Matches resource instances of google_gke_backup_backup_plan.
Classification: google.concept.backup-plan.
google.rule.gke-restore-channel Source
Matches resource instances of google_gke_backup_restore_channel.
Classification: google.concept.gke-backup-channel.
google.rule.bare-metal-gdc-admin-cluster Source
Matches resource instances of google_gkeonprem_bare_metal_admin_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.bare-metal-gdc-cluster Source
Matches resource instances of google_gkeonprem_bare_metal_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.bare-metal-gdc-node-pool Source
Matches resource instances of google_gkeonprem_bare_metal_node_pool.
Classification: google.concept.kubernetes-node-pool.
google.rule.vmware-gdc-admin-cluster Source
Matches resource instances of google_gkeonprem_vmware_admin_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.vmware-gdc-cluster Source
Matches resource instances of google_gkeonprem_vmware_cluster.
Classification: rf.concept.kubernetes-cluster.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.vmware-gdc-node-pool Source
Matches resource instances of google_gkeonprem_vmware_node_pool.
Classification: google.concept.kubernetes-node-pool.
google.rule.healthcare-consent-store Source
Matches resource instances of google_healthcare_consent_store.
Classification: google.concept.healthcare-store.
Contexts
google.context.ownership: targetsgoogle.concept.healthcare-datasetthroughsource.dataset.
Conditions, identity and resolution
Context through source.dataset
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.healthcare-dataset Source
Matches resource instances of google_healthcare_dataset.
Classification: google.concept.healthcare-dataset.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id", "self_link"]
google.rule.healthcare-dicom-store Source
Matches resource instances of google_healthcare_dicom_store.
Classification: google.concept.healthcare-store.
Contexts
google.context.ownership: targetsgoogle.concept.healthcare-datasetthroughsource.dataset.
Conditions, identity and resolution
Context through source.dataset
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.healthcare-fhir-store Source
Matches resource instances of google_healthcare_fhir_store.
Classification: google.concept.healthcare-store.
Contexts
google.context.ownership: targetsgoogle.concept.healthcare-datasetthroughsource.dataset.
Conditions, identity and resolution
Context through source.dataset
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.healthcare-hl7v2-store Source
Matches resource instances of google_healthcare_hl7_v2_store.
Classification: google.concept.healthcare-store.
Contexts
google.context.ownership: targetsgoogle.concept.healthcare-datasetthroughsource.dataset.
Conditions, identity and resolution
Context through source.dataset
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.cloud-kms-key-version Source
Matches resource instances of google_kms_crypto_key_version.
Classification: google.concept.cloud-kms-key-version.
Contributions
- targets
google.concept.encryption-keythroughsource.crypto_key.
Conditions, identity and resolution
Contribution through source.crypto_key
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
google.rule.cloud-kms-key Source
Matches resource instances of google_kms_crypto_key.
Classification: google.concept.encryption-key.
Contexts
google.context.ownership: targetsgoogle.concept.cloud-kms-key-ringthroughsource.key_ring.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.key_ring
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.cloud-kms-key-ring Source
Matches resource instances of google_kms_key_ring.
Classification: google.concept.cloud-kms-key-ring.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.cloud-logging-billing-account-bucket Source
Matches resource instances of google_logging_billing_account_bucket_config.
Classification: google.concept.cloud-logging-bucket.
google.rule.cloud-logging-billing-account-sink Source
Matches resource instances of google_logging_billing_account_sink.
Classification: google.concept.cloud-logging-sink.
google.rule.cloud-logging-folder-bucket Source
Matches resource instances of google_logging_folder_bucket_config.
Classification: google.concept.cloud-logging-bucket.
google.rule.cloud-logging-folder-sink Source
Matches resource instances of google_logging_folder_sink.
Classification: google.concept.cloud-logging-sink.
google.rule.cloud-logging-organization-bucket Source
Matches resource instances of google_logging_organization_bucket_config.
Classification: google.concept.cloud-logging-bucket.
google.rule.cloud-logging-organization-sink Source
Matches resource instances of google_logging_organization_sink.
Classification: google.concept.cloud-logging-sink.
google.rule.cloud-logging-project-bucket Source
Matches resource instances of google_logging_project_bucket_config.
Classification: google.concept.cloud-logging-bucket.
google.rule.cloud-logging-project-sink Source
Matches resource instances of google_logging_project_sink.
Classification: google.concept.cloud-logging-sink.
google.rule.managed-lustre-instance Source
Matches resource instances of google_lustre_instance.
Classification: google.concept.managed-file-storage.
google.rule.managed-kafka-topic Source
Matches resource instances of google_managed_kafka_topic.
Classification: google.concept.message-topic.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.memorystore-memcached-instance Source
Matches resource instances of google_memcache_instance.
Classification: google.concept.managed-cache.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.authorized_network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.authorized_network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.memorystore-instance Source
Matches resource instances of google_memorystore_instance.
Classification: google.concept.managed-cache.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.migration-center-assets-export-job Source
Matches resource instances of google_migration_center_assets_export_job.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-group Source
Matches resource instances of google_migration_center_group.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-import-data-file Source
Matches resource instances of google_migration_center_import_data_file.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-import-job Source
Matches resource instances of google_migration_center_import_job.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-preference-set Source
Matches resource instances of google_migration_center_preference_set.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-report-config Source
Matches resource instances of google_migration_center_report_config.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-report Source
Matches resource instances of google_migration_center_report.
Classification: google.concept.migration-center-assessment.
google.rule.migration-center-settings Source
Matches resource instances of google_migration_center_settings.
Classification: google.concept.migration-center-assessment.
google.rule.cloud-monitoring-alerting-policy Source
Matches resource instances of google_monitoring_alert_policy.
Classification: google.concept.cloud-monitoring-alerting-policy.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-monitoring-service Source
Matches resource instances of google_monitoring_service.
Classification: google.concept.cloud-monitoring-service.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["name", "service_id"]scope:"provider"
Endpoint
attributes:["id", "name", "service_id"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-monitoring-slo Source
Matches resource instances of google_monitoring_slo.
Classification: google.concept.cloud-monitoring-slo.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Contributions
- targets
google.concept.cloud-monitoring-servicethroughsource.service.
Conditions, identity and resolution
Contribution through source.service
on_null:"absent"on_empty:"absent"match.by:[target.service_id, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.netapp-storage-pool Source
Matches resource instances of google_netapp_storage_pool.
Classification: google.concept.netapp-storage-pool.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.netapp-volume Source
Matches resource instances of google_netapp_volume.
Classification: google.concept.managed-file-storage.
Contexts
google.context.ownership: targetsgoogle.concept.netapp-storage-poolthroughsource.storage_pool.
Conditions, identity and resolution
Context through source.storage_pool
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id]match.strategy:"exact"
google.rule.network-connectivity-center-hub Source
Matches resource instances of google_network_connectivity_hub.
Classification: google.concept.network-connectivity-center-hub.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.network-connectivity-center-spoke Source
Matches resource instances of google_network_connectivity_spoke.
Classification: google.concept.network-connectivity-center-spoke.
Contributions
- targets
google.concept.network-connectivity-center-hubthroughsource.hub.
Conditions, identity and resolution
Contribution through source.hub
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.media-cdn-service Source
Matches resource instances of google_network_services_edge_cache_service.
Classification: google.concept.cloud-cdn-service.
google.rule.network-services-grpc-route Source
Matches resource instances of google_network_services_grpc_route.
Classification: google.concept.network-services-route.
google.rule.network-services-http-route Source
Matches resource instances of google_network_services_http_route.
Classification: google.concept.network-services-route.
google.rule.multicast-consumer-association Source
Matches resource instances of google_network_services_multicast_consumer_association.
Classification: google.concept.multicast-configuration.
google.rule.multicast-domain-activation Source
Matches resource instances of google_network_services_multicast_domain_activation.
Classification: google.concept.multicast-configuration.
google.rule.multicast-group-consumer-activation Source
Matches resource instances of google_network_services_multicast_group_consumer_activation.
Classification: google.concept.multicast-configuration.
google.rule.multicast-group-producer-activation Source
Matches resource instances of google_network_services_multicast_group_producer_activation.
Classification: google.concept.multicast-configuration.
google.rule.multicast-group-range-activation Source
Matches resource instances of google_network_services_multicast_group_range_activation.
Classification: google.concept.multicast-configuration.
google.rule.multicast-group-range Source
Matches resource instances of google_network_services_multicast_group_range.
Classification: google.concept.multicast-configuration.
google.rule.multicast-producer-association Source
Matches resource instances of google_network_services_multicast_producer_association.
Classification: google.concept.multicast-configuration.
google.rule.network-services-tcp-route Source
Matches resource instances of google_network_services_tcp_route.
Classification: google.concept.network-services-route.
google.rule.network-services-tls-route Source
Matches resource instances of google_network_services_tls_route.
Classification: google.concept.network-services-route.
google.rule.oracle-autonomous-database Source
Matches resource instances of google_oracle_database_autonomous_database.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.oracle-odb-network Source
Matches resource instances of google_oracle_database_odb_network.
Classification: rf.concept.virtual-network.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.oracle-odb-subnet Source
Matches resource instances of google_oracle_database_odb_subnet.
Classification: rf.concept.subnet.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.vm-manager-guest-policy Source
Matches resource instances of google_os_config_guest_policies.
Classification: google.concept.vm-manager-policy.
google.rule.vm-manager-os-policy-assignment Source
Matches resource instances of google_os_config_os_policy_assignment.
Classification: google.concept.vm-manager-policy.
google.rule.vm-manager-patch-deployment Source
Matches resource instances of google_os_config_patch_deployment.
Classification: google.concept.vm-manager-policy.
google.rule.vm-manager-folder-policy-orchestrator Source
Matches resource instances of google_os_config_v2_policy_orchestrator_for_folder.
Classification: google.concept.vm-manager-policy.
google.rule.vm-manager-organization-policy-orchestrator Source
Matches resource instances of google_os_config_v2_policy_orchestrator_for_organization.
Classification: google.concept.vm-manager-policy.
google.rule.vm-manager-policy-orchestrator Source
Matches resource instances of google_os_config_v2_policy_orchestrator.
Classification: google.concept.vm-manager-policy.
google.rule.parallelstore-instance Source
Matches resource instances of google_parallelstore_instance.
Classification: google.concept.managed-file-storage.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.private-ca-pool Source
Matches resource instances of google_privateca_ca_pool.
Classification: google.concept.private-ca-pool.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.private-certificate-authority Source
Matches resource instances of google_privateca_certificate_authority.
Classification: google.concept.private-certificate-authority.
Contexts
google.context.ownership: targetsgoogle.concept.private-ca-poolthroughsource.pool.
Conditions, identity and resolution
Context through source.pool
on_null:"absent"on_empty:"absent"match.by:[target.name, target.id]match.strategy:"exact"
google.rule.project-iam-binding Source
Matches resource instances of google_project_iam_binding.
Classification: google.concept.service-identity-binding.
Contributions
- targets
rf.concept.service-identitythroughsource.members.
Conditions, identity and resolution
Contribution through source.members
on_null:"absent"on_empty:"absent"prefix:"serviceAccount:"external:"allow"match.by:target.emailmatch.strategy:"exact"
google.rule.project-iam-member Source
Matches resource instances of google_project_iam_member.
Classification: google.concept.service-identity-binding.
Contributions
- targets
rf.concept.service-identitythroughsource.member.
Conditions, identity and resolution
Contribution through source.member
on_null:"absent"on_empty:"absent"prefix:"serviceAccount:"external:"allow"match.by:target.emailmatch.strategy:"exact"
google.rule.project-iam-policy Source
Matches resource instances of google_project_iam_policy.
Classification: google.concept.service-identity-binding.
google.rule.google-cloud-project Source
Matches resource instances of google_project.
Classification: google.concept.google-cloud-project.
Conditions, identity and resolution
Identity
attributes:["project_id"]scope:"provider"
Endpoint
attributes:["id", "project_id"]
google.rule.pubsub-lite-subscription Source
Matches resource instances of google_pubsub_lite_subscription.
Classification: google.concept.message-subscription.
google.rule.pubsub-lite-topic Source
Matches resource instances of google_pubsub_lite_topic.
Classification: google.concept.message-topic.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.pubsub-subscription Source
Matches resource instances of google_pubsub_subscription.
Classification: google.concept.message-subscription.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Relations
google.relation.subscribes-to: targetsgoogle.concept.message-topicthroughsource.topic.google.relation.delivers-to: targetsgoogle.concept.cloud-run-servicethroughsource.push_config[0].push_endpoint.google.relation.delivers-to: targetsgoogle.concept.message-topicthroughsource.dead_letter_policy[0].dead_letter_topic.
Conditions, identity and resolution
Relation through source.topic
on_null:"absent"on_empty:"absent"match.by:[target.id, target.name]match.strategy:"exact"
Relation through source.push_config[0].push_endpoint
on_null:"absent"on_empty:"absent"match.by:target.urimatch.strategy:"exact"
Relation through source.dead_letter_policy[0].dead_letter_topic
on_null:"absent"on_empty:"absent"match.by:[target.id, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.pubsub-topic Source
Matches resource instances of google_pubsub_topic.
Classification: google.concept.message-topic.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.memorystore-redis-cluster Source
Matches resource instances of google_redis_cluster.
Classification: google.concept.managed-cache.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.memorystore-redis-instance Source
Matches resource instances of google_redis_instance.
Classification: google.concept.managed-cache.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.authorized_network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Context through source.authorized_network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.secret-manager-regional-secret-version Source
Matches resource instances of google_secret_manager_regional_secret_version.
Classification: google.concept.secret-manager-secret-version.
Contributions
- targets
google.concept.managed-secretthroughsource.secret.
Conditions, identity and resolution
Contribution through source.secret
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.secret-manager-regional-secret Source
Matches resource instances of google_secret_manager_regional_secret.
Classification: google.concept.managed-secret.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.secret-manager-secret-version Source
Matches resource instances of google_secret_manager_secret_version.
Classification: google.concept.secret-manager-secret-version.
Contributions
- targets
google.concept.managed-secretthroughsource.secret.
Conditions, identity and resolution
Contribution through source.secret
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
google.rule.secret-manager-secret Source
Matches resource instances of google_secret_manager_secret.
Classification: google.concept.managed-secret.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.secure-source-manager-repository Source
Matches resource instances of google_secure_source_manager_repository.
Classification: google.concept.source-repository.
google.rule.service-account-key Source
Matches resource instances of google_service_account_key.
Classification: google.concept.service-credential.
Contributions
- targets
rf.concept.service-identitythroughsource.service_account_id.
Conditions, identity and resolution
Contribution through source.service_account_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.email]match.strategy:"exact"
google.rule.iam-service-account Source
Matches resource instances of google_service_account.
Classification: rf.concept.service-identity.
Contexts
google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["email", "id"]scope:"global"
Endpoint
attributes:["email", "id", "member", "name"]
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.service-networking-connection Source
Matches resource instances of google_service_networking_connection.
Classification: google.concept.service-networking-detail.
Contributions
- targets
rf.concept.virtual-networkthroughsource.network.
Conditions, identity and resolution
Contribution through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
google.rule.cloud-source-repository Source
Matches resource instances of google_sourcerepo_repository.
Classification: google.concept.source-repository.
google.rule.spanner-database Source
Matches resource instances of google_spanner_database.
Classification: google.concept.spanner-database.
Contributions
- targets
rf.concept.managed-databasethroughsource.instance.
Conditions, identity and resolution
Contribution through source.instance
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.name, target.id]match.strategy:"exact"
google.rule.spanner-instance Source
Matches resource instances of google_spanner_instance.
Classification: rf.concept.managed-database.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
google.rule.cloud-sql-instance Source
Matches resource instances of google_sql_database_instance.
Classification: rf.concept.managed-database.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.settings[0].ip_configuration[0].private_network.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name", "self_link"]
Context through source.settings[0].ip_configuration[0].private_network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"
google.rule.cloud-storage-bucket-iam-member Source
Matches resource instances of google_storage_bucket_iam_member.
Classification: google.concept.access-binding.
Contributions
- targets
rf.concept.object-storage-containerthroughsource.bucket.
Conditions, identity and resolution
Contribution through source.bucket
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"last-segment"
google.rule.cloud-storage-bucket Source
Matches resource instances of google_storage_bucket.
Classification: rf.concept.object-storage-container.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name", "self_link"]
google.rule.tpu-vm Source
Matches resource instances of google_tpu_v2_vm.
Classification: google.concept.compute-instance.
google.rule.vector-search-index Source
Matches resource instances of google_vector_search_index.
Classification: google.concept.vertex-ai-vector-index.
google.rule.vertex-ai-model-garden-endpoint Source
Matches resource instances of google_vertex_ai_endpoint_with_model_garden_deployment.
Classification: google.concept.ai-inference-endpoint.
google.rule.vertex-ai-endpoint Source
Matches resource instances of google_vertex_ai_endpoint.
Classification: google.concept.ai-inference-endpoint.
google.rule.vertex-ai-feature-online-store Source
Matches resource instances of google_vertex_ai_feature_online_store.
Classification: google.concept.vertex-ai-feature-store.
google.rule.vertex-ai-feature-store Source
Matches resource instances of google_vertex_ai_featurestore.
Classification: google.concept.vertex-ai-feature-store.
google.rule.vertex-ai-vector-index Source
Matches resource instances of google_vertex_ai_index.
Classification: google.concept.vertex-ai-vector-index.
google.rule.vmware-engine-network Source
Matches resource instances of google_vmwareengine_network.
Classification: rf.concept.virtual-network.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.vmware-engine-subnet Source
Matches resource instances of google_vmwareengine_subnet.
Classification: rf.concept.subnet.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
google.rule.serverless-vpc-access-connector Source
Matches resource instances of google_vpc_access_connector.
Classification: google.concept.serverless-vpc-access-connector.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.network.rf.context.network: targetsrf.concept.subnetthroughsource.subnet[0].name.google.context.ownership: targetsgoogle.concept.google-cloud-projectthroughsource.project.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id", "self_link"]
Context through source.network
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.id, target.self_link, target.name]match.strategy:"exact"
Context through source.subnet[0].name
on_null:"absent"on_empty:"absent"external:"allow"match.by:[target.name, target.id, target.self_link]match.strategy:"exact"
Context through source.project
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.project_idmatch.strategy:"exact"