Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/google: = 8.0.0.
  • hashicorp/google-beta: = 8.0.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
google_alloydb_clusterresourcemanaged-databasealloydb-cluster
google_alloydb_instanceresourcealloydb-instancealloydb-instance
google_api_gateway_gatewayresourceapi-gatewayapi-gateway
google_app_engine_flexible_app_versionresourceapp-engine-service-versionapp-engine-flexible-service-version
google_app_engine_standard_app_versionresourceapp-engine-service-versionapp-engine-standard-service-version
google_backup_dr_backup_planresourcebackup-planbackup-dr-backup-plan
google_backup_dr_backup_vaultresourcebackup-vaultbackup-dr-backup-vault
google_biglake_catalogresourcebiglake-catalogbiglake-catalog
google_biglake_databaseresourcebiglake-databasebiglake-database
google_biglake_hive_catalogresourcebiglake-catalogbiglake-hive-catalog
google_biglake_hive_databaseresourcebiglake-databasebiglake-hive-database
google_biglake_hive_tableresourcebiglake-tablebiglake-hive-table
google_biglake_iceberg_catalogresourcebiglake-catalogbiglake-iceberg-catalog
google_biglake_iceberg_namespaceresourcebiglake-databasebiglake-iceberg-namespace
google_biglake_iceberg_tableresourcebiglake-tablebiglake-iceberg-table
google_biglake_tableresourcebiglake-tablebiglake-table
google_bigquery_analytics_hub_data_exchange_subscriptionresourceanalytics-hub-subscriptionanalytics-hub-data-exchange-subscription
google_bigquery_analytics_hub_listing_subscriptionresourceanalytics-hub-subscriptionanalytics-hub-listing-subscription
google_bigquery_dataset_accessresourceaccess-bindingbigquery-dataset-access
google_bigquery_datasetresourcebigquery-datasetbigquery-dataset
google_bigquery_table_iam_memberresourceaccess-bindingbigquery-table-iam-member
google_bigquery_tableresourcebigquery-tablebigquery-table
google_bigtable_instanceresourcemanaged-databasebigtable-instance
google_bigtable_tableresourcebigtable-tablebigtable-table
google_ces_app_root_agent_associationresourcecx-agent-studio-configurationcx-agent-studio-root-agent-association
google_ces_app_versionresourcecx-agent-studio-configurationcx-agent-studio-app-version
google_ces_deploymentresourcecx-agent-studio-configurationcx-agent-studio-deployment
google_ces_evaluationresourcecx-agent-studio-configurationcx-agent-studio-evaluation
google_ces_exampleresourcecx-agent-studio-configurationcx-agent-studio-example
google_ces_guardrailresourcecx-agent-studio-configurationcx-agent-studio-guardrail
google_ces_security_settingsresourcecx-agent-studio-configurationcx-agent-studio-security-settings
google_ces_toolresourcecx-agent-studio-configurationcx-agent-studio-tool
google_ces_toolsetresourcecx-agent-studio-configurationcx-agent-studio-toolset
google_cloud_asset_folder_feedresourcecloud-asset-feedcloud-asset-folder-feed
google_cloud_asset_organization_feedresourcecloud-asset-feedcloud-asset-organization-feed
google_cloud_asset_project_feedresourcecloud-asset-feedcloud-asset-project-feed
google_cloud_identity_group_membershipresourcecloud-identity-group-membershipcloud-identity-group-membership
google_cloud_identity_groupresourceidentity-groupcloud-identity-group
google_cloud_ids_endpointresourcecloud-ids-endpointcloud-ids-endpoint
google_cloud_run_serviceresourcecloud-run-servicecloud-run-service-v1
google_cloud_run_v2_jobresourcecloud-run-jobcloud-run-job
google_cloud_run_v2_serviceresourcecloud-run-servicecloud-run-service
google_cloud_run_v2_worker_poolresourcecloud-run-servicecloud-run-worker-pool
google_cloud_security_compliance_cloud_controlresourcecompliance-manager-configurationcompliance-manager-cloud-control
google_cloud_security_compliance_framework_deploymentresourcecompliance-manager-configurationcompliance-manager-framework-deployment
google_cloudbuildv2_connectionresourcesource-connectioncloud-build-v2-connection
google_cloudbuildv2_repositoryresourcesource-repositorycloud-build-v2-repository
google_cloudfunctions_functionresourceserverless-functioncloud-run-function
google_cloudfunctions2_functionresourceserverless-functioncloud-run-function-v2
google_colab_runtime_templateresourcecolab-enterprise-configurationcolab-enterprise-runtime-template
google_colab_scheduleresourcecolab-enterprise-configurationcolab-enterprise-schedule
google_compute_backend_bucketresourcecloud-cdn-servicecloud-cdn-backend-bucket (conditional)
google_compute_diskresourceblock-storage-volumepersistent-disk
google_compute_firewall_policy_ruleresourcefirewall-policy-rulehierarchical-firewall-policy-rule
google_compute_firewall_policyresourcefirewall-policyhierarchical-firewall-policy
google_compute_firewallresourcevpc-firewall-rulevpc-firewall-rule
google_compute_forwarding_ruleresourceprivate-endpoint
load-balancer
private-service-connect-endpoint (conditional)
regional-load-balancer (conditional)
google_compute_global_addressresourceallocated-network-rangeprivate-services-access-range (conditional)
google_compute_global_forwarding_ruleresourceload-balancerapplication-load-balancer
google_compute_ha_vpn_gatewayresourcevpn-gatewayha-vpn-gateway
google_compute_instance_from_machine_imageresourcecompute-instancecompute-instance-from-machine-image
google_compute_instance_from_templateresourcecompute-instancecompute-instance-from-template
google_compute_instance_group_managerresourcecompute-instance-groupzonal-managed-instance-group
google_compute_instance_groupresourcecompute-instance-groupunmanaged-instance-group
google_compute_instanceresourcecompute-instancecompute-engine-instance
google_compute_network_firewall_policy_ruleresourcefirewall-policy-rulenetwork-firewall-policy-rule
google_compute_network_firewall_policyresourcefirewall-policynetwork-firewall-policy
google_compute_network_peeringresourcenetwork-peeringvpc-network-peering
google_compute_networkresourcevirtual-networkvpc-network
google_compute_region_diskresourceblock-storage-volumeregional-persistent-disk
google_compute_region_instance_group_managerresourcecompute-instance-groupregional-managed-instance-group
google_compute_router_natresourcemanaged-natcloud-nat
google_compute_routerresourcecloud-routercloud-router
google_compute_security_policy_ruleresourcecloud-armor-security-rulecloud-armor-security-rule
google_compute_security_policyresourcecloud-armor-security-policycloud-armor-security-policy
google_compute_subnetworkresourcesubnetvpc-subnetwork
google_compute_vpn_gatewayresourcevpn-gatewayclassic-vpn-gateway
google_container_attached_clusterresourcekubernetes-clustergke-attached-cluster
google_container_aws_clusterresourcekubernetes-clustergke-aws-cluster
google_container_aws_node_poolresourcekubernetes-node-poolgke-aws-node-pool
google_container_azure_clusterresourcekubernetes-clustergke-azure-cluster
google_container_azure_node_poolresourcekubernetes-node-poolgke-azure-node-pool
google_container_clusterresourcekubernetes-clustergke-cluster
google_container_node_poolresourcekubernetes-node-poolgke-node-pool
google_data_loss_prevention_deidentify_templateresourcesensitive-data-protection-templatesensitive-data-protection-deidentify-template
google_data_loss_prevention_discovery_configresourcesensitive-data-protection-scansensitive-data-protection-discovery
google_data_loss_prevention_inspect_templateresourcesensitive-data-protection-templatesensitive-data-protection-inspect-template
google_data_loss_prevention_job_triggerresourcesensitive-data-protection-scansensitive-data-protection-job-trigger
google_data_loss_prevention_stored_info_typeresourcesensitive-data-protection-templatesensitive-data-protection-stored-info-type
google_database_migration_service_connection_profileresourcedatabase-migration-connectiondatabase-migration-connection-profile
google_database_migration_service_private_connectionresourcedatabase-migration-connectiondatabase-migration-private-connection
google_dataflow_flex_template_jobresourcedataflow-jobdataflow-flex-template-job
google_dataflow_jobresourcedataflow-jobdataflow-job
google_dataplex_assetresourcedataplex-assetdataplex-asset
google_dataplex_data_assetresourcedataplex-assetdataplex-data-asset
google_dataplex_lakeresourcedataplex-lakedataplex-lake
google_dataplex_zoneresourcedataplex-zonedataplex-zone
google_developer_connect_connectionresourcesource-connectiondeveloper-connect-connection
google_developer_connect_git_repository_linkresourcesource-repositorydeveloper-connect-repository-link
google_dialogflow_agentresourceconversational-agentdialogflow-agent
google_dialogflow_cx_agentresourceconversational-agentdialogflow-cx-agent
google_discovery_engine_chat_engineresourcediscovery-enginediscovery-engine-chat-engine
google_discovery_engine_recommendation_engineresourcediscovery-enginediscovery-engine-recommendation-engine
google_discovery_engine_search_engineresourcediscovery-enginediscovery-engine-search-engine
google_dns_managed_zoneresourcedns-zonecloud-dns-managed-zone
google_dns_record_setresourcecloud-dns-record-setcloud-dns-record-set
google_edgecontainer_clusterresourcekubernetes-clusteredge-container-cluster
google_edgecontainer_node_poolresourcekubernetes-node-pooledge-container-node-pool
google_edgenetwork_networkresourcevirtual-networkedge-network
google_edgenetwork_subnetresourcesubnetedge-network-subnet
google_endpoints_serviceresourceapi-gatewaycloud-endpoints-service
google_filestore_instanceresourcemanaged-file-storagefilestore-instance
google_firebase_database_instanceresourcemanaged-databasefirebase-realtime-database
google_firestore_databaseresourcemanaged-databasefirestore-database
google_gke_backup_backup_channelresourcegke-backup-channelgke-backup-channel
google_gke_backup_backup_planresourcebackup-plangke-backup-plan
google_gke_backup_restore_channelresourcegke-backup-channelgke-restore-channel
google_gkeonprem_bare_metal_admin_clusterresourcekubernetes-clusterbare-metal-gdc-admin-cluster
google_gkeonprem_bare_metal_clusterresourcekubernetes-clusterbare-metal-gdc-cluster
google_gkeonprem_bare_metal_node_poolresourcekubernetes-node-poolbare-metal-gdc-node-pool
google_gkeonprem_vmware_admin_clusterresourcekubernetes-clustervmware-gdc-admin-cluster
google_gkeonprem_vmware_clusterresourcekubernetes-clustervmware-gdc-cluster
google_gkeonprem_vmware_node_poolresourcekubernetes-node-poolvmware-gdc-node-pool
google_healthcare_consent_storeresourcehealthcare-storehealthcare-consent-store
google_healthcare_datasetresourcehealthcare-datasethealthcare-dataset
google_healthcare_dicom_storeresourcehealthcare-storehealthcare-dicom-store
google_healthcare_fhir_storeresourcehealthcare-storehealthcare-fhir-store
google_healthcare_hl7_v2_storeresourcehealthcare-storehealthcare-hl7v2-store
google_kms_crypto_key_versionresourcecloud-kms-key-versioncloud-kms-key-version
google_kms_crypto_keyresourceencryption-keycloud-kms-key
google_kms_key_ringresourcecloud-kms-key-ringcloud-kms-key-ring
google_logging_billing_account_bucket_configresourcecloud-logging-bucketcloud-logging-billing-account-bucket
google_logging_billing_account_sinkresourcecloud-logging-sinkcloud-logging-billing-account-sink
google_logging_folder_bucket_configresourcecloud-logging-bucketcloud-logging-folder-bucket
google_logging_folder_sinkresourcecloud-logging-sinkcloud-logging-folder-sink
google_logging_organization_bucket_configresourcecloud-logging-bucketcloud-logging-organization-bucket
google_logging_organization_sinkresourcecloud-logging-sinkcloud-logging-organization-sink
google_logging_project_bucket_configresourcecloud-logging-bucketcloud-logging-project-bucket
google_logging_project_sinkresourcecloud-logging-sinkcloud-logging-project-sink
google_lustre_instanceresourcemanaged-file-storagemanaged-lustre-instance
google_managed_kafka_topicresourcemessage-topicmanaged-kafka-topic
google_memcache_instanceresourcemanaged-cachememorystore-memcached-instance
google_memorystore_instanceresourcemanaged-cachememorystore-instance
google_migration_center_assets_export_jobresourcemigration-center-assessmentmigration-center-assets-export-job
google_migration_center_groupresourcemigration-center-assessmentmigration-center-group
google_migration_center_import_data_fileresourcemigration-center-assessmentmigration-center-import-data-file
google_migration_center_import_jobresourcemigration-center-assessmentmigration-center-import-job
google_migration_center_preference_setresourcemigration-center-assessmentmigration-center-preference-set
google_migration_center_report_configresourcemigration-center-assessmentmigration-center-report-config
google_migration_center_reportresourcemigration-center-assessmentmigration-center-report
google_migration_center_settingsresourcemigration-center-assessmentmigration-center-settings
google_monitoring_alert_policyresourcecloud-monitoring-alerting-policycloud-monitoring-alerting-policy
google_monitoring_serviceresourcecloud-monitoring-servicecloud-monitoring-service
google_monitoring_sloresourcecloud-monitoring-slocloud-monitoring-slo
google_netapp_storage_poolresourcenetapp-storage-poolnetapp-storage-pool
google_netapp_volumeresourcemanaged-file-storagenetapp-volume
google_network_connectivity_hubresourcenetwork-connectivity-center-hubnetwork-connectivity-center-hub
google_network_connectivity_spokeresourcenetwork-connectivity-center-spokenetwork-connectivity-center-spoke
google_network_services_edge_cache_serviceresourcecloud-cdn-servicemedia-cdn-service
google_network_services_grpc_routeresourcenetwork-services-routenetwork-services-grpc-route
google_network_services_http_routeresourcenetwork-services-routenetwork-services-http-route
google_network_services_multicast_consumer_associationresourcemulticast-configurationmulticast-consumer-association
google_network_services_multicast_domain_activationresourcemulticast-configurationmulticast-domain-activation
google_network_services_multicast_group_consumer_activationresourcemulticast-configurationmulticast-group-consumer-activation
google_network_services_multicast_group_producer_activationresourcemulticast-configurationmulticast-group-producer-activation
google_network_services_multicast_group_range_activationresourcemulticast-configurationmulticast-group-range-activation
google_network_services_multicast_group_rangeresourcemulticast-configurationmulticast-group-range
google_network_services_multicast_producer_associationresourcemulticast-configurationmulticast-producer-association
google_network_services_tcp_routeresourcenetwork-services-routenetwork-services-tcp-route
google_network_services_tls_routeresourcenetwork-services-routenetwork-services-tls-route
google_oracle_database_autonomous_databaseresourcemanaged-databaseoracle-autonomous-database
google_oracle_database_odb_networkresourcevirtual-networkoracle-odb-network
google_oracle_database_odb_subnetresourcesubnetoracle-odb-subnet
google_os_config_guest_policiesresourcevm-manager-policyvm-manager-guest-policy
google_os_config_os_policy_assignmentresourcevm-manager-policyvm-manager-os-policy-assignment
google_os_config_patch_deploymentresourcevm-manager-policyvm-manager-patch-deployment
google_os_config_v2_policy_orchestrator_for_folderresourcevm-manager-policyvm-manager-folder-policy-orchestrator
google_os_config_v2_policy_orchestrator_for_organizationresourcevm-manager-policyvm-manager-organization-policy-orchestrator
google_os_config_v2_policy_orchestratorresourcevm-manager-policyvm-manager-policy-orchestrator
google_parallelstore_instanceresourcemanaged-file-storageparallelstore-instance
google_privateca_ca_poolresourceprivate-ca-poolprivate-ca-pool
google_privateca_certificate_authorityresourceprivate-certificate-authorityprivate-certificate-authority
google_project_iam_bindingresourceservice-identity-bindingproject-iam-binding
google_project_iam_memberresourceservice-identity-bindingproject-iam-member
google_project_iam_policyresourceservice-identity-bindingproject-iam-policy
google_projectresourcegoogle-cloud-projectgoogle-cloud-project
google_pubsub_lite_subscriptionresourcemessage-subscriptionpubsub-lite-subscription
google_pubsub_lite_topicresourcemessage-topicpubsub-lite-topic
google_pubsub_subscriptionresourcemessage-subscriptionpubsub-subscription
google_pubsub_topicresourcemessage-topicpubsub-topic
google_redis_clusterresourcemanaged-cachememorystore-redis-cluster
google_redis_instanceresourcemanaged-cachememorystore-redis-instance
google_secret_manager_regional_secret_versionresourcesecret-manager-secret-versionsecret-manager-regional-secret-version
google_secret_manager_regional_secretresourcemanaged-secretsecret-manager-regional-secret
google_secret_manager_secret_versionresourcesecret-manager-secret-versionsecret-manager-secret-version
google_secret_manager_secretresourcemanaged-secretsecret-manager-secret
google_secure_source_manager_repositoryresourcesource-repositorysecure-source-manager-repository
google_service_account_keyresourceservice-credentialservice-account-key
google_service_accountresourceservice-identityiam-service-account
google_service_networking_connectionresourceservice-networking-detailservice-networking-connection
google_sourcerepo_repositoryresourcesource-repositorycloud-source-repository
google_spanner_databaseresourcespanner-databasespanner-database
google_spanner_instanceresourcemanaged-databasespanner-instance
google_sql_database_instanceresourcemanaged-databasecloud-sql-instance
google_storage_bucket_iam_memberresourceaccess-bindingcloud-storage-bucket-iam-member
google_storage_bucketresourceobject-storage-containercloud-storage-bucket
google_tpu_v2_vmresourcecompute-instancetpu-vm
google_vector_search_indexresourcevertex-ai-vector-indexvector-search-index
google_vertex_ai_endpoint_with_model_garden_deploymentresourceai-inference-endpointvertex-ai-model-garden-endpoint
google_vertex_ai_endpointresourceai-inference-endpointvertex-ai-endpoint
google_vertex_ai_feature_online_storeresourcevertex-ai-feature-storevertex-ai-feature-online-store
google_vertex_ai_featurestoreresourcevertex-ai-feature-storevertex-ai-feature-store
google_vertex_ai_indexresourcevertex-ai-vector-indexvertex-ai-vector-index
google_vmwareengine_networkresourcevirtual-networkvmware-engine-network
google_vmwareengine_subnetresourcesubnetvmware-engine-subnet
google_vpc_access_connectorresourceserverless-vpc-access-connectorserverless-vpc-access-connector

Local vocabulary

Concepts

google.concept.access-binding Source

An access-control declaration attached to a data resource.

Used by bigquery-dataset-access, bigquery-table-iam-member, cloud-storage-bucket-iam-member.

google.concept.ai-inference-endpoint Source

A managed endpoint that serves model inference requests.

Used by vertex-ai-endpoint, vertex-ai-model-garden-endpoint.

google.concept.allocated-network-range Source

An allocated address range used by private service networking.

Used by private-services-access-range.

google.concept.alloydb-instance Source

A database instance contributing compute capacity to an AlloyDB cluster.

Used by alloydb-instance.

google.concept.analytics-hub-subscription Source

An Analytics Hub subscription to a data exchange or listing.

Used by analytics-hub-data-exchange-subscription, analytics-hub-listing-subscription.

google.concept.api-gateway Source

A managed gateway that exposes and governs APIs.

Used by api-gateway, cloud-endpoints-service.

google.concept.app-engine-service-version Source

A deployed App Engine standard or flexible service version.

Used by app-engine-flexible-service-version, app-engine-standard-service-version.

google.concept.backup-plan Source

A managed policy scheduling and retaining backups.

Used by backup-dr-backup-plan, gke-backup-plan.

google.concept.backup-vault Source

A managed vault storing protected recovery data.

Used by backup-dr-backup-plan, backup-dr-backup-vault.

google.concept.biglake-catalog Source

A BigLake catalog organizing lakehouse metadata.

Used by biglake-catalog, biglake-hive-catalog, biglake-iceberg-catalog.

google.concept.biglake-database Source

A database namespace in a BigLake catalog.

Used by biglake-database, biglake-hive-database, biglake-iceberg-namespace.

google.concept.biglake-table Source

A table registered in BigLake.

Used by biglake-hive-table, biglake-iceberg-table, biglake-table.

google.concept.bigquery-dataset Source

A BigQuery dataset that organizes tables and their access boundary.

Used by bigquery-dataset, bigquery-dataset-access, bigquery-table.

google.concept.bigquery-table Source

A table managed inside a BigQuery dataset.

Used by bigquery-table, bigquery-table-iam-member.

google.concept.bigtable-table Source

A table belonging to a Bigtable instance.

Used by bigtable-table.

google.concept.block-storage-volume Source

A durable block-storage volume attachable to compute workloads.

Used by persistent-disk, regional-persistent-disk.

google.concept.cloud-armor-security-policy Source

A Cloud Armor security policy protecting load-balanced applications.

Used by cloud-armor-security-policy, cloud-armor-security-rule.

google.concept.cloud-armor-security-rule Source

A rule contributing traffic controls to a Cloud Armor security policy.

Used by cloud-armor-security-rule.

google.concept.cloud-asset-feed Source

A Cloud Asset Inventory feed publishing asset changes to a destination.

Used by cloud-asset-folder-feed, cloud-asset-organization-feed, cloud-asset-project-feed.

google.concept.cloud-cdn-service Source

A Cloud CDN or Media CDN edge delivery service.

Used by cloud-cdn-backend-bucket, media-cdn-service.

google.concept.cloud-dns-record-set Source

A DNS record set managed inside a Cloud DNS managed zone.

Used by cloud-dns-record-set.

google.concept.cloud-identity-group-membership Source

A membership contributing a principal to a Cloud Identity group.

Used by cloud-identity-group-membership.

google.concept.cloud-ids-endpoint Source

A Cloud IDS endpoint inspecting traffic in a VPC network.

Used by cloud-ids-endpoint.

google.concept.cloud-kms-key-ring Source

A Cloud KMS key ring organizing keys in one Google Cloud location.

Used by cloud-kms-key, cloud-kms-key-ring.

google.concept.cloud-kms-key-version Source

A cryptographic key version belonging to a Cloud KMS key.

Used by cloud-kms-key-version.

google.concept.cloud-logging-bucket Source

A Cloud Logging bucket retaining log entries.

Used by 4 Rules
google.concept.cloud-logging-sink Source

A Cloud Logging sink routing selected log entries to a destination.

Used by 4 Rules
google.concept.cloud-monitoring-alerting-policy Source

A Cloud Monitoring alerting policy defining conditions and notification behavior.

Used by cloud-monitoring-alerting-policy.

google.concept.cloud-monitoring-service Source

A Cloud Monitoring service used as the target of service-level objectives.

Used by cloud-monitoring-service, cloud-monitoring-slo.

google.concept.cloud-monitoring-slo Source

A service-level objective contributing reliability intent to a monitored service.

Used by cloud-monitoring-slo.

google.concept.cloud-router Source

A Cloud Router exchanging dynamic routes for a VPC network.

Used by cloud-nat, cloud-router.

google.concept.cloud-run-job Source

A Cloud Run job that runs tasks to completion.

Used by cloud-run-job.

google.concept.cloud-run-service Source

A Cloud Run service that handles requests or events on managed container instances.

Used by 4 Rules
google.concept.colab-enterprise-configuration Source

A runtime template or schedule configuring Colab Enterprise execution.

Used by colab-enterprise-runtime-template, colab-enterprise-schedule.

google.concept.compliance-manager-configuration Source

A cloud control or deployment configuring a Compliance Manager framework.

Used by compliance-manager-cloud-control, compliance-manager-framework-deployment.

google.concept.compute-instance Source

A provisioned compute instance running a workload.

Used by 4 Rules
google.concept.compute-instance-group Source

A managed or unmanaged Compute Engine instance group.

Used by regional-managed-instance-group, unmanaged-instance-group, zonal-managed-instance-group.

google.concept.conversational-agent Source

A Dialogflow conversational agent.

Used by dialogflow-agent, dialogflow-cx-agent.

google.concept.cx-agent-studio-configuration Source

A version, deployment, tool, guardrail, or other configuration supporting a CX Agent Studio application.

Used by 9 Rules
google.concept.database-migration-connection Source

A source, destination, or private connection used by Database Migration Service.

Used by database-migration-connection-profile, database-migration-private-connection.

google.concept.dataflow-job Source

A Dataflow batch or streaming job.

Used by dataflow-flex-template-job, dataflow-job.

google.concept.dataplex-asset Source

A data asset governed through Dataplex.

Used by dataplex-asset, dataplex-data-asset.

google.concept.dataplex-lake Source

A Dataplex lake organizing governed data domains.

Used by dataplex-lake, dataplex-zone.

google.concept.dataplex-zone Source

A Dataplex zone organizing assets within a lake.

Used by dataplex-zone.

google.concept.dedicated-interconnect Source

A dedicated private connection between an external network and a cloud provider.

No Rule in this Dialect uses this definition.

google.concept.discovery-engine Source

A Discovery Engine search, recommendation, or conversational engine.

Used by discovery-engine-chat-engine, discovery-engine-recommendation-engine, discovery-engine-search-engine.

google.concept.dns-zone Source

A managed DNS namespace containing resource records.

Used by cloud-dns-managed-zone, cloud-dns-record-set.

google.concept.encryption-key Source

A managed key used for cryptographic operations.

Used by cloud-kms-key, cloud-kms-key-version.

google.concept.firewall-policy Source

A Google Cloud hierarchical or network firewall policy.

Used by 4 Rules
google.concept.firewall-policy-rule Source

A rule contributing controls to a Google Cloud firewall policy.

Used by hierarchical-firewall-policy-rule, network-firewall-policy-rule.

google.concept.gke-backup-channel Source

A Backup for GKE channel connecting backup or restore operations across projects.

Used by gke-backup-channel, gke-restore-channel.

google.concept.healthcare-dataset Source

A Cloud Healthcare API dataset containing healthcare data stores.

Used by 5 Rules
google.concept.healthcare-store Source

A FHIR, DICOM, HL7v2, or consent store in a Cloud Healthcare API dataset.

Used by 4 Rules
google.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by cloud-identity-group, cloud-identity-group-membership.

google.concept.kubernetes-node-pool Source

A node pool contributing compute capacity to a Kubernetes cluster.

Used by 6 Rules
google.concept.load-balancer Source

A load-balancing service composed from routing infrastructure.

Used by application-load-balancer, regional-load-balancer.

google.concept.managed-cache Source

A managed in-memory cache service.

Used by 4 Rules
google.concept.managed-file-storage Source

A managed shared file-storage service.

Used by 4 Rules
google.concept.managed-nat Source

A managed network address translation service.

Used by cloud-nat.

google.concept.managed-secret Source

A managed secret identity whose sensitive value stays outside architecture output.

Used by 4 Rules
google.concept.message-queue Source

A managed queue buffering work or messages for asynchronous consumers.

No Rule in this Dialect uses this definition.

google.concept.message-subscription Source

A durable subscription consuming messages from a topic.

Used by pubsub-lite-subscription, pubsub-subscription.

google.concept.message-topic Source

A messaging topic receiving messages from publishers.

Used by 4 Rules
google.concept.migration-center-assessment Source

An import, grouping, preference, report, or settings resource supporting migration assessment.

Used by 8 Rules
google.concept.multicast-configuration Source

An activation, group range, or network association configuring Cloud Multicast.

Used by 7 Rules
google.concept.netapp-storage-pool Source

A NetApp Volumes storage pool providing capacity to volumes.

Used by netapp-storage-pool, netapp-volume.

google.concept.network-connectivity-center-hub Source

A Network Connectivity Center hub coordinating connectivity through spokes.

Used by network-connectivity-center-hub, network-connectivity-center-spoke.

google.concept.network-connectivity-center-spoke Source

A spoke attaching a network resource to a Network Connectivity Center hub.

Used by network-connectivity-center-spoke.

google.concept.network-peering Source

A direct private connectivity agreement between virtual networks.

Used by vpc-network-peering.

google.concept.network-services-route Source

An HTTP, gRPC, TCP, or TLS route contributing traffic policy.

Used by 4 Rules
google.concept.private-ca-pool Source

A Certificate Authority Service pool containing certificate authorities.

Used by private-ca-pool, private-certificate-authority.

google.concept.private-certificate-authority Source

A managed private certificate authority.

Used by private-certificate-authority.

google.concept.private-endpoint Source

A private endpoint exposing a service inside a virtual network.

Used by private-service-connect-endpoint.

google.concept.secret-manager-secret-version Source

A version attached to a Secret Manager secret without exposing its secret data.

Used by secret-manager-regional-secret-version, secret-manager-secret-version.

google.concept.sensitive-data-protection-scan Source

A Sensitive Data Protection discovery or inspection job configuration.

Used by sensitive-data-protection-discovery, sensitive-data-protection-job-trigger.

google.concept.sensitive-data-protection-template Source

A reusable inspection, de-identification, or stored information type configuration.

Used by sensitive-data-protection-deidentify-template, sensitive-data-protection-inspect-template, sensitive-data-protection-stored-info-type.

google.concept.serverless-function Source

A managed event-driven function runtime.

Used by cloud-run-function, cloud-run-function-v2.

google.concept.serverless-vpc-access-connector Source

A Serverless VPC Access connector bridging serverless workloads to a VPC network.

Used by cloud-run-service, serverless-vpc-access-connector.

google.concept.service-credential Source

A credential issued for a service identity.

Used by service-account-key.

google.concept.service-identity-binding Source

An access-control binding that contributes to a service identity.

Used by project-iam-binding, project-iam-member, project-iam-policy.

google.concept.service-networking-detail Source

A provider networking detail used to establish private service access.

Used by service-networking-connection.

google.concept.source-connection Source

A managed connection from Google Cloud developer services to a source host.

Used by cloud-build-v2-connection, developer-connect-connection.

google.concept.source-repository Source

A source-code repository hosted or connected through Google Cloud developer services.

Used by 4 Rules
google.concept.spanner-database Source

A database belonging to a Spanner instance.

Used by spanner-database.

google.concept.vertex-ai-feature-store Source

A Vertex AI feature store or online feature store.

Used by vertex-ai-feature-online-store, vertex-ai-feature-store.

google.concept.vertex-ai-vector-index Source

A Vertex AI vector index.

Used by vector-search-index, vertex-ai-vector-index.

google.concept.vm-manager-policy Source

A VM Manager policy orchestrating guest configuration or operating system maintenance.

Used by 6 Rules
google.concept.vpc-firewall-rule Source

A Google Cloud VPC firewall rule controlling network traffic.

Used by vpc-firewall-rule.

google.concept.vpn-connection Source

A virtual private network connection between network endpoints.

No Rule in this Dialect uses this definition.

google.concept.vpn-gateway Source

A managed gateway terminating virtual private network connections.

Used by classic-vpn-gateway, ha-vpn-gateway.

google.concept.workflow Source

A managed workflow coordinating steps and service calls.

No Rule in this Dialect uses this definition.

Contexts

Relations

google.relation.delivers-to Source

Introduced by a labeled emission. Used by pubsub-subscription.

google.relation.routes-to Source

Introduced by a labeled emission. Used by cloud-run-service.

google.relation.runs-as Source

Introduced by a labeled emission. Used by cloud-run-service.

google.relation.stores-in Source

Introduced by a labeled emission. Used by backup-dr-backup-plan.

google.relation.subscribes-to Source

Introduced by a labeled emission. Used by pubsub-subscription.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

google.rule.alloydb-cluster Source

Matches resource instances of google_alloydb_cluster.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.alloydb-instance Source

Matches resource instances of google_alloydb_instance.

Classification: google.concept.alloydb-instance.

Contributions

Conditions, identity and resolution

Contribution through source.cluster

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
google.rule.api-gateway Source

Matches resource instances of google_api_gateway_gateway.

Classification: google.concept.api-gateway.

google.rule.app-engine-flexible-service-version Source

Matches resource instances of google_app_engine_flexible_app_version.

Classification: google.concept.app-engine-service-version.

google.rule.app-engine-standard-service-version Source

Matches resource instances of google_app_engine_standard_app_version.

Classification: google.concept.app-engine-service-version.

google.rule.backup-dr-backup-plan Source

Matches resource instances of google_backup_dr_backup_plan.

Classification: google.concept.backup-plan.

Relations

Conditions, identity and resolution

Relation through source.backup_vault

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.backup-dr-backup-vault Source

Matches resource instances of google_backup_dr_backup_vault.

Classification: google.concept.backup-vault.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.biglake-catalog Source

Matches resource instances of google_biglake_catalog.

Classification: google.concept.biglake-catalog.

google.rule.biglake-database Source

Matches resource instances of google_biglake_database.

Classification: google.concept.biglake-database.

google.rule.biglake-hive-catalog Source

Matches resource instances of google_biglake_hive_catalog.

Classification: google.concept.biglake-catalog.

google.rule.biglake-hive-database Source

Matches resource instances of google_biglake_hive_database.

Classification: google.concept.biglake-database.

google.rule.biglake-hive-table Source

Matches resource instances of google_biglake_hive_table.

Classification: google.concept.biglake-table.

google.rule.biglake-iceberg-catalog Source

Matches resource instances of google_biglake_iceberg_catalog.

Classification: google.concept.biglake-catalog.

google.rule.biglake-iceberg-namespace Source

Matches resource instances of google_biglake_iceberg_namespace.

Classification: google.concept.biglake-database.

google.rule.biglake-iceberg-table Source

Matches resource instances of google_biglake_iceberg_table.

Classification: google.concept.biglake-table.

google.rule.biglake-table Source

Matches resource instances of google_biglake_table.

Classification: google.concept.biglake-table.

google.rule.analytics-hub-data-exchange-subscription Source

Matches resource instances of google_bigquery_analytics_hub_data_exchange_subscription.

Classification: google.concept.analytics-hub-subscription.

google.rule.analytics-hub-listing-subscription Source

Matches resource instances of google_bigquery_analytics_hub_listing_subscription.

Classification: google.concept.analytics-hub-subscription.

google.rule.bigquery-dataset-access Source

Matches resource instances of google_bigquery_dataset_access.

Classification: google.concept.access-binding.

Contributions

Conditions, identity and resolution

Contribution through source.dataset_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.dataset_id
  • match.strategy: "exact"
google.rule.bigquery-dataset Source

Matches resource instances of google_bigquery_dataset.

Classification: google.concept.bigquery-dataset.

Conditions, identity and resolution

Identity

  • attributes: ["dataset_id"]
  • scope: "provider"

Endpoint

  • attributes: ["dataset_id", "id", "self_link"]
google.rule.bigquery-table-iam-member Source

Matches resource instances of google_bigquery_table_iam_member.

Classification: google.concept.access-binding.

Contributions

Conditions, identity and resolution

Contribution through source.table_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.table_id
  • match.strategy: "last-segment"
google.rule.bigquery-table Source

Matches resource instances of google_bigquery_table.

Classification: google.concept.bigquery-table.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["table_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "table_id"]

Context through source.dataset_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.dataset_id
  • match.strategy: "exact"
google.rule.bigtable-instance Source

Matches resource instances of google_bigtable_instance.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.bigtable-table Source

Matches resource instances of google_bigtable_table.

Classification: google.concept.bigtable-table.

Contributions

Conditions, identity and resolution

Contribution through source.instance_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
google.rule.cx-agent-studio-root-agent-association Source

Matches resource instances of google_ces_app_root_agent_association.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-app-version Source

Matches resource instances of google_ces_app_version.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-deployment Source

Matches resource instances of google_ces_deployment.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-evaluation Source

Matches resource instances of google_ces_evaluation.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-example Source

Matches resource instances of google_ces_example.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-guardrail Source

Matches resource instances of google_ces_guardrail.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-security-settings Source

Matches resource instances of google_ces_security_settings.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-tool Source

Matches resource instances of google_ces_tool.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cx-agent-studio-toolset Source

Matches resource instances of google_ces_toolset.

Classification: google.concept.cx-agent-studio-configuration.

google.rule.cloud-asset-folder-feed Source

Matches resource instances of google_cloud_asset_folder_feed.

Classification: google.concept.cloud-asset-feed.

google.rule.cloud-asset-organization-feed Source

Matches resource instances of google_cloud_asset_organization_feed.

Classification: google.concept.cloud-asset-feed.

google.rule.cloud-asset-project-feed Source

Matches resource instances of google_cloud_asset_project_feed.

Classification: google.concept.cloud-asset-feed.

google.rule.cloud-identity-group-membership Source

Matches resource instances of google_cloud_identity_group_membership.

Classification: google.concept.cloud-identity-group-membership.

Contributions

Conditions, identity and resolution

Contribution through source.group

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
google.rule.cloud-identity-group Source

Matches resource instances of google_cloud_identity_group.

Classification: google.concept.identity-group.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.cloud-ids-endpoint Source

Matches resource instances of google_cloud_ids_endpoint.

Classification: google.concept.cloud-ids-endpoint.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.cloud-run-service-v1 Source

Matches resource instances of google_cloud_run_service.

Classification: google.concept.cloud-run-service.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-run-job Source

Matches resource instances of google_cloud_run_v2_job.

Classification: google.concept.cloud-run-job.

Contexts

Conditions, identity and resolution

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-run-service Source

Matches resource instances of google_cloud_run_v2_service.

Classification: google.concept.cloud-run-service.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "uri"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "uri"]

Context through source.template[0].vpc_access[0].network_interfaces[0].network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.template[0].vpc_access[0].network_interfaces[0].subnetwork

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"

Relation through source.template[0].vpc_access[0].connector

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.template[0].service_account

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
google.rule.cloud-run-worker-pool Source

Matches resource instances of google_cloud_run_v2_worker_pool.

Classification: google.concept.cloud-run-service.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.compliance-manager-cloud-control Source

Matches resource instances of google_cloud_security_compliance_cloud_control.

Classification: google.concept.compliance-manager-configuration.

google.rule.compliance-manager-framework-deployment Source

Matches resource instances of google_cloud_security_compliance_framework_deployment.

Classification: google.concept.compliance-manager-configuration.

google.rule.cloud-build-v2-connection Source

Matches resource instances of google_cloudbuildv2_connection.

Classification: google.concept.source-connection.

google.rule.cloud-build-v2-repository Source

Matches resource instances of google_cloudbuildv2_repository.

Classification: google.concept.source-repository.

google.rule.cloud-run-function Source

Matches resource instances of google_cloudfunctions_function.

Classification: google.concept.serverless-function.

google.rule.cloud-run-function-v2 Source

Matches resource instances of google_cloudfunctions2_function.

Classification: google.concept.serverless-function.

google.rule.colab-enterprise-runtime-template Source

Matches resource instances of google_colab_runtime_template.

Classification: google.concept.colab-enterprise-configuration.

google.rule.colab-enterprise-schedule Source

Matches resource instances of google_colab_schedule.

Classification: google.concept.colab-enterprise-configuration.

google.rule.cloud-cdn-backend-bucket Source

Matches resource instances of google_compute_backend_bucket.

Classification: google.concept.cloud-cdn-service.

Conditions, identity and resolution

Condition

RF
source.enable_cdn == true
google.rule.persistent-disk Source

Matches resource instances of google_compute_disk.

Classification: google.concept.block-storage-volume.

google.rule.hierarchical-firewall-policy-rule Source

Matches resource instances of google_compute_firewall_policy_rule.

Classification: google.concept.firewall-policy-rule.

Contributions

Conditions, identity and resolution

Contribution through source.firewall_policy

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.id, target.name, target.self_link]
  • match.strategy: "exact"
google.rule.hierarchical-firewall-policy Source

Matches resource instances of google_compute_firewall_policy.

Classification: google.concept.firewall-policy.

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]
google.rule.vpc-firewall-rule Source

Matches resource instances of google_compute_firewall.

Classification: google.concept.vpc-firewall-rule.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.private-service-connect-endpoint Source

Matches resource instances of google_compute_forwarding_rule.

Classification: google.concept.private-endpoint.

Contexts

Conditions, identity and resolution

Condition

RF
source.load_balancing_scheme == ""

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.subnetwork

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.regional-load-balancer Source

Matches resource instances of google_compute_forwarding_rule.

Classification: google.concept.load-balancer.

Conditions, identity and resolution

Condition

RF
source.load_balancing_scheme != ""
google.rule.private-services-access-range Source

Matches resource instances of google_compute_global_address.

Classification: google.concept.allocated-network-range.

Contributions

Conditions, identity and resolution

Condition

RF
source.purpose == "VPC_PEERING" && source.address_type == "INTERNAL"

Contribution through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.application-load-balancer Source

Matches resource instances of google_compute_global_forwarding_rule.

Classification: google.concept.load-balancer.

Composition members, in declared order

  1. target-https-proxy matches "google_compute_target_https_proxy" ("resource"), through source.target.
  2. url-map matches "google_compute_url_map" ("resource"), through member.target-https-proxy.url_map. Depends on target-https-proxy.
  3. backend-service matches "google_compute_backend_service" ("resource"), through member.url-map.default_service. Depends on url-map.
google.rule.ha-vpn-gateway Source

Matches resource instances of google_compute_ha_vpn_gateway.

Classification: google.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.compute-instance-from-machine-image Source

Matches resource instances of google_compute_instance_from_machine_image.

Classification: google.concept.compute-instance.

google.rule.compute-instance-from-template Source

Matches resource instances of google_compute_instance_from_template.

Classification: google.concept.compute-instance.

google.rule.zonal-managed-instance-group Source

Matches resource instances of google_compute_instance_group_manager.

Classification: google.concept.compute-instance-group.

google.rule.unmanaged-instance-group Source

Matches resource instances of google_compute_instance_group.

Classification: google.concept.compute-instance-group.

google.rule.compute-engine-instance Source

Matches resource instances of google_compute_instance.

Classification: google.concept.compute-instance.

google.rule.network-firewall-policy-rule Source

Matches resource instances of google_compute_network_firewall_policy_rule.

Classification: google.concept.firewall-policy-rule.

Contributions

Conditions, identity and resolution

Contribution through source.firewall_policy

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id, target.self_link]
  • match.strategy: "exact"
google.rule.network-firewall-policy Source

Matches resource instances of google_compute_network_firewall_policy.

Classification: google.concept.firewall-policy.

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]
google.rule.vpc-network-peering Source

Matches resource instances of google_compute_network_peering.

Classification: google.concept.network-peering.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.peer_network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.vpc-network Source

Matches resource instances of google_compute_network.

Classification: rf.concept.virtual-network.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.regional-persistent-disk Source

Matches resource instances of google_compute_region_disk.

Classification: google.concept.block-storage-volume.

google.rule.regional-managed-instance-group Source

Matches resource instances of google_compute_region_instance_group_manager.

Classification: google.concept.compute-instance-group.

google.rule.cloud-nat Source

Matches resource instances of google_compute_router_nat.

Classification: google.concept.managed-nat.

Contexts

Conditions, identity and resolution

Context through source.router

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id, target.self_link]
  • match.strategy: "exact"
google.rule.cloud-router Source

Matches resource instances of google_compute_router.

Classification: google.concept.cloud-router.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-armor-security-rule Source

Matches resource instances of google_compute_security_policy_rule.

Classification: google.concept.cloud-armor-security-rule.

Contributions

Conditions, identity and resolution

Contribution through source.security_policy

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id, target.self_link]
  • match.strategy: "exact"
google.rule.cloud-armor-security-policy Source

Matches resource instances of google_compute_security_policy.

Classification: google.concept.cloud-armor-security-policy.

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]
google.rule.vpc-subnetwork Source

Matches resource instances of google_compute_subnetwork.

Classification: rf.concept.subnet.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "self_link", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link", "name"]

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.classic-vpn-gateway Source

Matches resource instances of google_compute_vpn_gateway.

Classification: google.concept.vpn-gateway.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.gke-attached-cluster Source

Matches resource instances of google_container_attached_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.gke-aws-cluster Source

Matches resource instances of google_container_aws_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.gke-aws-node-pool Source

Matches resource instances of google_container_aws_node_pool.

Classification: google.concept.kubernetes-node-pool.

google.rule.gke-azure-cluster Source

Matches resource instances of google_container_azure_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.gke-azure-node-pool Source

Matches resource instances of google_container_azure_node_pool.

Classification: google.concept.kubernetes-node-pool.

google.rule.gke-cluster Source

Matches resource instances of google_container_cluster.

Classification: rf.concept.kubernetes-cluster.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name", "self_link", "endpoint"]

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.subnetwork

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.gke-node-pool Source

Matches resource instances of google_container_node_pool.

Classification: google.concept.kubernetes-node-pool.

Contributions

Conditions, identity and resolution

Contribution through source.cluster

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.name, target.id, target.self_link]
  • match.strategy: "exact"
google.rule.sensitive-data-protection-deidentify-template Source

Matches resource instances of google_data_loss_prevention_deidentify_template.

Classification: google.concept.sensitive-data-protection-template.

google.rule.sensitive-data-protection-discovery Source

Matches resource instances of google_data_loss_prevention_discovery_config.

Classification: google.concept.sensitive-data-protection-scan.

google.rule.sensitive-data-protection-inspect-template Source

Matches resource instances of google_data_loss_prevention_inspect_template.

Classification: google.concept.sensitive-data-protection-template.

google.rule.sensitive-data-protection-job-trigger Source

Matches resource instances of google_data_loss_prevention_job_trigger.

Classification: google.concept.sensitive-data-protection-scan.

google.rule.sensitive-data-protection-stored-info-type Source

Matches resource instances of google_data_loss_prevention_stored_info_type.

Classification: google.concept.sensitive-data-protection-template.

google.rule.database-migration-connection-profile Source

Matches resource instances of google_database_migration_service_connection_profile.

Classification: google.concept.database-migration-connection.

google.rule.database-migration-private-connection Source

Matches resource instances of google_database_migration_service_private_connection.

Classification: google.concept.database-migration-connection.

google.rule.dataflow-flex-template-job Source

Matches resource instances of google_dataflow_flex_template_job.

Classification: google.concept.dataflow-job.

google.rule.dataflow-job Source

Matches resource instances of google_dataflow_job.

Classification: google.concept.dataflow-job.

google.rule.dataplex-asset Source

Matches resource instances of google_dataplex_asset.

Classification: google.concept.dataplex-asset.

google.rule.dataplex-data-asset Source

Matches resource instances of google_dataplex_data_asset.

Classification: google.concept.dataplex-asset.

google.rule.dataplex-lake Source

Matches resource instances of google_dataplex_lake.

Classification: google.concept.dataplex-lake.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.dataplex-zone Source

Matches resource instances of google_dataplex_zone.

Classification: google.concept.dataplex-zone.

Contexts

Conditions, identity and resolution

Context through source.lake

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id]
  • match.strategy: "exact"
google.rule.developer-connect-connection Source

Matches resource instances of google_developer_connect_connection.

Classification: google.concept.source-connection.

google.rule.developer-connect-repository-link Source

Matches resource instances of google_developer_connect_git_repository_link.

Classification: google.concept.source-repository.

google.rule.dialogflow-agent Source

Matches resource instances of google_dialogflow_agent.

Classification: google.concept.conversational-agent.

google.rule.dialogflow-cx-agent Source

Matches resource instances of google_dialogflow_cx_agent.

Classification: google.concept.conversational-agent.

google.rule.discovery-engine-chat-engine Source

Matches resource instances of google_discovery_engine_chat_engine.

Classification: google.concept.discovery-engine.

google.rule.discovery-engine-recommendation-engine Source

Matches resource instances of google_discovery_engine_recommendation_engine.

Classification: google.concept.discovery-engine.

google.rule.discovery-engine-search-engine Source

Matches resource instances of google_discovery_engine_search_engine.

Classification: google.concept.discovery-engine.

google.rule.cloud-dns-managed-zone Source

Matches resource instances of google_dns_managed_zone.

Classification: google.concept.dns-zone.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.cloud-dns-record-set Source

Matches resource instances of google_dns_record_set.

Classification: google.concept.cloud-dns-record-set.

Contributions

Conditions, identity and resolution

Contribution through source.managed_zone

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
google.rule.edge-container-cluster Source

Matches resource instances of google_edgecontainer_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.edge-container-node-pool Source

Matches resource instances of google_edgecontainer_node_pool.

Classification: google.concept.kubernetes-node-pool.

google.rule.edge-network Source

Matches resource instances of google_edgenetwork_network.

Classification: rf.concept.virtual-network.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.edge-network-subnet Source

Matches resource instances of google_edgenetwork_subnet.

Classification: rf.concept.subnet.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.cloud-endpoints-service Source

Matches resource instances of google_endpoints_service.

Classification: google.concept.api-gateway.

google.rule.filestore-instance Source

Matches resource instances of google_filestore_instance.

Classification: google.concept.managed-file-storage.

google.rule.firebase-realtime-database Source

Matches resource instances of google_firebase_database_instance.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.firestore-database Source

Matches resource instances of google_firestore_database.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.gke-backup-channel Source

Matches resource instances of google_gke_backup_backup_channel.

Classification: google.concept.gke-backup-channel.

google.rule.gke-backup-plan Source

Matches resource instances of google_gke_backup_backup_plan.

Classification: google.concept.backup-plan.

google.rule.gke-restore-channel Source

Matches resource instances of google_gke_backup_restore_channel.

Classification: google.concept.gke-backup-channel.

google.rule.bare-metal-gdc-admin-cluster Source

Matches resource instances of google_gkeonprem_bare_metal_admin_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.bare-metal-gdc-cluster Source

Matches resource instances of google_gkeonprem_bare_metal_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.bare-metal-gdc-node-pool Source

Matches resource instances of google_gkeonprem_bare_metal_node_pool.

Classification: google.concept.kubernetes-node-pool.

google.rule.vmware-gdc-admin-cluster Source

Matches resource instances of google_gkeonprem_vmware_admin_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.vmware-gdc-cluster Source

Matches resource instances of google_gkeonprem_vmware_cluster.

Classification: rf.concept.kubernetes-cluster.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.vmware-gdc-node-pool Source

Matches resource instances of google_gkeonprem_vmware_node_pool.

Classification: google.concept.kubernetes-node-pool.

google.rule.healthcare-consent-store Source

Matches resource instances of google_healthcare_consent_store.

Classification: google.concept.healthcare-store.

Contexts

Conditions, identity and resolution

Context through source.dataset

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.healthcare-dataset Source

Matches resource instances of google_healthcare_dataset.

Classification: google.concept.healthcare-dataset.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link"]
google.rule.healthcare-dicom-store Source

Matches resource instances of google_healthcare_dicom_store.

Classification: google.concept.healthcare-store.

Contexts

Conditions, identity and resolution

Context through source.dataset

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.healthcare-fhir-store Source

Matches resource instances of google_healthcare_fhir_store.

Classification: google.concept.healthcare-store.

Contexts

Conditions, identity and resolution

Context through source.dataset

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.healthcare-hl7v2-store Source

Matches resource instances of google_healthcare_hl7_v2_store.

Classification: google.concept.healthcare-store.

Contexts

Conditions, identity and resolution

Context through source.dataset

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.cloud-kms-key-version Source

Matches resource instances of google_kms_crypto_key_version.

Classification: google.concept.cloud-kms-key-version.

Contributions

Conditions, identity and resolution

Contribution through source.crypto_key

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.cloud-kms-key Source

Matches resource instances of google_kms_crypto_key.

Classification: google.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.key_ring

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.cloud-kms-key-ring Source

Matches resource instances of google_kms_key_ring.

Classification: google.concept.cloud-kms-key-ring.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.cloud-logging-billing-account-bucket Source

Matches resource instances of google_logging_billing_account_bucket_config.

Classification: google.concept.cloud-logging-bucket.

google.rule.cloud-logging-billing-account-sink Source

Matches resource instances of google_logging_billing_account_sink.

Classification: google.concept.cloud-logging-sink.

google.rule.cloud-logging-folder-bucket Source

Matches resource instances of google_logging_folder_bucket_config.

Classification: google.concept.cloud-logging-bucket.

google.rule.cloud-logging-folder-sink Source

Matches resource instances of google_logging_folder_sink.

Classification: google.concept.cloud-logging-sink.

google.rule.cloud-logging-organization-bucket Source

Matches resource instances of google_logging_organization_bucket_config.

Classification: google.concept.cloud-logging-bucket.

google.rule.cloud-logging-organization-sink Source

Matches resource instances of google_logging_organization_sink.

Classification: google.concept.cloud-logging-sink.

google.rule.cloud-logging-project-bucket Source

Matches resource instances of google_logging_project_bucket_config.

Classification: google.concept.cloud-logging-bucket.

google.rule.cloud-logging-project-sink Source

Matches resource instances of google_logging_project_sink.

Classification: google.concept.cloud-logging-sink.

google.rule.managed-lustre-instance Source

Matches resource instances of google_lustre_instance.

Classification: google.concept.managed-file-storage.

google.rule.managed-kafka-topic Source

Matches resource instances of google_managed_kafka_topic.

Classification: google.concept.message-topic.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.memorystore-memcached-instance Source

Matches resource instances of google_memcache_instance.

Classification: google.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.authorized_network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.memorystore-instance Source

Matches resource instances of google_memorystore_instance.

Classification: google.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.migration-center-assets-export-job Source

Matches resource instances of google_migration_center_assets_export_job.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-group Source

Matches resource instances of google_migration_center_group.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-import-data-file Source

Matches resource instances of google_migration_center_import_data_file.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-import-job Source

Matches resource instances of google_migration_center_import_job.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-preference-set Source

Matches resource instances of google_migration_center_preference_set.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-report-config Source

Matches resource instances of google_migration_center_report_config.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-report Source

Matches resource instances of google_migration_center_report.

Classification: google.concept.migration-center-assessment.

google.rule.migration-center-settings Source

Matches resource instances of google_migration_center_settings.

Classification: google.concept.migration-center-assessment.

google.rule.cloud-monitoring-alerting-policy Source

Matches resource instances of google_monitoring_alert_policy.

Classification: google.concept.cloud-monitoring-alerting-policy.

Contexts

Conditions, identity and resolution

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-monitoring-service Source

Matches resource instances of google_monitoring_service.

Classification: google.concept.cloud-monitoring-service.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name", "service_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name", "service_id"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-monitoring-slo Source

Matches resource instances of google_monitoring_slo.

Classification: google.concept.cloud-monitoring-slo.

Contexts

Contributions

Conditions, identity and resolution

Contribution through source.service

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.service_id, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.netapp-storage-pool Source

Matches resource instances of google_netapp_storage_pool.

Classification: google.concept.netapp-storage-pool.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.netapp-volume Source

Matches resource instances of google_netapp_volume.

Classification: google.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.storage_pool

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id]
  • match.strategy: "exact"
google.rule.network-connectivity-center-hub Source

Matches resource instances of google_network_connectivity_hub.

Classification: google.concept.network-connectivity-center-hub.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.network-connectivity-center-spoke Source

Matches resource instances of google_network_connectivity_spoke.

Classification: google.concept.network-connectivity-center-spoke.

Contributions

Conditions, identity and resolution

Contribution through source.hub

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.media-cdn-service Source

Matches resource instances of google_network_services_edge_cache_service.

Classification: google.concept.cloud-cdn-service.

google.rule.network-services-grpc-route Source

Matches resource instances of google_network_services_grpc_route.

Classification: google.concept.network-services-route.

google.rule.network-services-http-route Source

Matches resource instances of google_network_services_http_route.

Classification: google.concept.network-services-route.

google.rule.multicast-consumer-association Source

Matches resource instances of google_network_services_multicast_consumer_association.

Classification: google.concept.multicast-configuration.

google.rule.multicast-domain-activation Source

Matches resource instances of google_network_services_multicast_domain_activation.

Classification: google.concept.multicast-configuration.

google.rule.multicast-group-consumer-activation Source

Matches resource instances of google_network_services_multicast_group_consumer_activation.

Classification: google.concept.multicast-configuration.

google.rule.multicast-group-producer-activation Source

Matches resource instances of google_network_services_multicast_group_producer_activation.

Classification: google.concept.multicast-configuration.

google.rule.multicast-group-range-activation Source

Matches resource instances of google_network_services_multicast_group_range_activation.

Classification: google.concept.multicast-configuration.

google.rule.multicast-group-range Source

Matches resource instances of google_network_services_multicast_group_range.

Classification: google.concept.multicast-configuration.

google.rule.multicast-producer-association Source

Matches resource instances of google_network_services_multicast_producer_association.

Classification: google.concept.multicast-configuration.

google.rule.network-services-tcp-route Source

Matches resource instances of google_network_services_tcp_route.

Classification: google.concept.network-services-route.

google.rule.network-services-tls-route Source

Matches resource instances of google_network_services_tls_route.

Classification: google.concept.network-services-route.

google.rule.oracle-autonomous-database Source

Matches resource instances of google_oracle_database_autonomous_database.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.oracle-odb-network Source

Matches resource instances of google_oracle_database_odb_network.

Classification: rf.concept.virtual-network.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.oracle-odb-subnet Source

Matches resource instances of google_oracle_database_odb_subnet.

Classification: rf.concept.subnet.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.vm-manager-guest-policy Source

Matches resource instances of google_os_config_guest_policies.

Classification: google.concept.vm-manager-policy.

google.rule.vm-manager-os-policy-assignment Source

Matches resource instances of google_os_config_os_policy_assignment.

Classification: google.concept.vm-manager-policy.

google.rule.vm-manager-patch-deployment Source

Matches resource instances of google_os_config_patch_deployment.

Classification: google.concept.vm-manager-policy.

google.rule.vm-manager-folder-policy-orchestrator Source

Matches resource instances of google_os_config_v2_policy_orchestrator_for_folder.

Classification: google.concept.vm-manager-policy.

google.rule.vm-manager-organization-policy-orchestrator Source

Matches resource instances of google_os_config_v2_policy_orchestrator_for_organization.

Classification: google.concept.vm-manager-policy.

google.rule.vm-manager-policy-orchestrator Source

Matches resource instances of google_os_config_v2_policy_orchestrator.

Classification: google.concept.vm-manager-policy.

google.rule.parallelstore-instance Source

Matches resource instances of google_parallelstore_instance.

Classification: google.concept.managed-file-storage.

Contexts

Conditions, identity and resolution

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.private-ca-pool Source

Matches resource instances of google_privateca_ca_pool.

Classification: google.concept.private-ca-pool.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.private-certificate-authority Source

Matches resource instances of google_privateca_certificate_authority.

Classification: google.concept.private-certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.pool

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.name, target.id]
  • match.strategy: "exact"
google.rule.project-iam-binding Source

Matches resource instances of google_project_iam_binding.

Classification: google.concept.service-identity-binding.

Contributions

Conditions, identity and resolution

Contribution through source.members

  • on_null: "absent"
  • on_empty: "absent"
  • prefix: "serviceAccount:"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
google.rule.project-iam-member Source

Matches resource instances of google_project_iam_member.

Classification: google.concept.service-identity-binding.

Contributions

Conditions, identity and resolution

Contribution through source.member

  • on_null: "absent"
  • on_empty: "absent"
  • prefix: "serviceAccount:"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
google.rule.project-iam-policy Source

Matches resource instances of google_project_iam_policy.

Classification: google.concept.service-identity-binding.

google.rule.google-cloud-project Source

Matches resource instances of google_project.

Classification: google.concept.google-cloud-project.

Conditions, identity and resolution

Identity

  • attributes: ["project_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "project_id"]
google.rule.pubsub-lite-subscription Source

Matches resource instances of google_pubsub_lite_subscription.

Classification: google.concept.message-subscription.

google.rule.pubsub-lite-topic Source

Matches resource instances of google_pubsub_lite_topic.

Classification: google.concept.message-topic.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.pubsub-subscription Source

Matches resource instances of google_pubsub_subscription.

Classification: google.concept.message-subscription.

Contexts

Relations

Conditions, identity and resolution

Relation through source.topic

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.id, target.name]
  • match.strategy: "exact"

Relation through source.push_config[0].push_endpoint

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.uri
  • match.strategy: "exact"

Relation through source.dead_letter_policy[0].dead_letter_topic

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: [target.id, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.pubsub-topic Source

Matches resource instances of google_pubsub_topic.

Classification: google.concept.message-topic.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.memorystore-redis-cluster Source

Matches resource instances of google_redis_cluster.

Classification: google.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.memorystore-redis-instance Source

Matches resource instances of google_redis_instance.

Classification: google.concept.managed-cache.

Contexts

Conditions, identity and resolution

Context through source.authorized_network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.secret-manager-regional-secret-version Source

Matches resource instances of google_secret_manager_regional_secret_version.

Classification: google.concept.secret-manager-secret-version.

Contributions

Conditions, identity and resolution

Contribution through source.secret

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.secret-manager-regional-secret Source

Matches resource instances of google_secret_manager_regional_secret.

Classification: google.concept.managed-secret.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.secret-manager-secret-version Source

Matches resource instances of google_secret_manager_secret_version.

Classification: google.concept.secret-manager-secret-version.

Contributions

Conditions, identity and resolution

Contribution through source.secret

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
google.rule.secret-manager-secret Source

Matches resource instances of google_secret_manager_secret.

Classification: google.concept.managed-secret.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.secure-source-manager-repository Source

Matches resource instances of google_secure_source_manager_repository.

Classification: google.concept.source-repository.

google.rule.service-account-key Source

Matches resource instances of google_service_account_key.

Classification: google.concept.service-credential.

Contributions

Conditions, identity and resolution

Contribution through source.service_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.email]
  • match.strategy: "exact"
google.rule.iam-service-account Source

Matches resource instances of google_service_account.

Classification: rf.concept.service-identity.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["email", "id"]
  • scope: "global"

Endpoint

  • attributes: ["email", "id", "member", "name"]

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.service-networking-connection Source

Matches resource instances of google_service_networking_connection.

Classification: google.concept.service-networking-detail.

Contributions

Conditions, identity and resolution

Contribution through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"
google.rule.cloud-source-repository Source

Matches resource instances of google_sourcerepo_repository.

Classification: google.concept.source-repository.

google.rule.spanner-database Source

Matches resource instances of google_spanner_database.

Classification: google.concept.spanner-database.

Contributions

Conditions, identity and resolution

Contribution through source.instance

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.name, target.id]
  • match.strategy: "exact"
google.rule.spanner-instance Source

Matches resource instances of google_spanner_instance.

Classification: rf.concept.managed-database.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
google.rule.cloud-sql-instance Source

Matches resource instances of google_sql_database_instance.

Classification: rf.concept.managed-database.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name", "self_link"]

Context through source.settings[0].ip_configuration[0].private_network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"
google.rule.cloud-storage-bucket-iam-member Source

Matches resource instances of google_storage_bucket_iam_member.

Classification: google.concept.access-binding.

Contributions

Conditions, identity and resolution

Contribution through source.bucket

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "last-segment"
google.rule.cloud-storage-bucket Source

Matches resource instances of google_storage_bucket.

Classification: rf.concept.object-storage-container.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name", "self_link"]
google.rule.tpu-vm Source

Matches resource instances of google_tpu_v2_vm.

Classification: google.concept.compute-instance.

google.rule.vector-search-index Source

Matches resource instances of google_vector_search_index.

Classification: google.concept.vertex-ai-vector-index.

google.rule.vertex-ai-model-garden-endpoint Source

Matches resource instances of google_vertex_ai_endpoint_with_model_garden_deployment.

Classification: google.concept.ai-inference-endpoint.

google.rule.vertex-ai-endpoint Source

Matches resource instances of google_vertex_ai_endpoint.

Classification: google.concept.ai-inference-endpoint.

google.rule.vertex-ai-feature-online-store Source

Matches resource instances of google_vertex_ai_feature_online_store.

Classification: google.concept.vertex-ai-feature-store.

google.rule.vertex-ai-feature-store Source

Matches resource instances of google_vertex_ai_featurestore.

Classification: google.concept.vertex-ai-feature-store.

google.rule.vertex-ai-vector-index Source

Matches resource instances of google_vertex_ai_index.

Classification: google.concept.vertex-ai-vector-index.

google.rule.vmware-engine-network Source

Matches resource instances of google_vmwareengine_network.

Classification: rf.concept.virtual-network.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.vmware-engine-subnet Source

Matches resource instances of google_vmwareengine_subnet.

Classification: rf.concept.subnet.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
google.rule.serverless-vpc-access-connector Source

Matches resource instances of google_vpc_access_connector.

Classification: google.concept.serverless-vpc-access-connector.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "self_link"]

Context through source.network

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.id, target.self_link, target.name]
  • match.strategy: "exact"

Context through source.subnet[0].name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: [target.name, target.id, target.self_link]
  • match.strategy: "exact"

Context through source.project

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.project_id
  • match.strategy: "exact"