# google Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `hashicorp/google`: `= 8.0.0`.
- `hashicorp/google-beta`: `= 8.0.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `google_alloydb_cluster` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`alloydb-cluster`](#rule-alloydb-cluster) |
| `google_alloydb_instance` | `resource` | [`alloydb-instance`](#google-concept-alloydb-instance) | [`alloydb-instance`](#rule-alloydb-instance) |
| `google_api_gateway_gateway` | `resource` | [`api-gateway`](#google-concept-api-gateway) | [`api-gateway`](#rule-api-gateway) |
| `google_app_engine_flexible_app_version` | `resource` | [`app-engine-service-version`](#google-concept-app-engine-service-version) | [`app-engine-flexible-service-version`](#rule-app-engine-flexible-service-version) |
| `google_app_engine_standard_app_version` | `resource` | [`app-engine-service-version`](#google-concept-app-engine-service-version) | [`app-engine-standard-service-version`](#rule-app-engine-standard-service-version) |
| `google_backup_dr_backup_plan` | `resource` | [`backup-plan`](#google-concept-backup-plan) | [`backup-dr-backup-plan`](#rule-backup-dr-backup-plan) |
| `google_backup_dr_backup_vault` | `resource` | [`backup-vault`](#google-concept-backup-vault) | [`backup-dr-backup-vault`](#rule-backup-dr-backup-vault) |
| `google_biglake_catalog` | `resource` | [`biglake-catalog`](#google-concept-biglake-catalog) | [`biglake-catalog`](#rule-biglake-catalog) |
| `google_biglake_database` | `resource` | [`biglake-database`](#google-concept-biglake-database) | [`biglake-database`](#rule-biglake-database) |
| `google_biglake_hive_catalog` | `resource` | [`biglake-catalog`](#google-concept-biglake-catalog) | [`biglake-hive-catalog`](#rule-biglake-hive-catalog) |
| `google_biglake_hive_database` | `resource` | [`biglake-database`](#google-concept-biglake-database) | [`biglake-hive-database`](#rule-biglake-hive-database) |
| `google_biglake_hive_table` | `resource` | [`biglake-table`](#google-concept-biglake-table) | [`biglake-hive-table`](#rule-biglake-hive-table) |
| `google_biglake_iceberg_catalog` | `resource` | [`biglake-catalog`](#google-concept-biglake-catalog) | [`biglake-iceberg-catalog`](#rule-biglake-iceberg-catalog) |
| `google_biglake_iceberg_namespace` | `resource` | [`biglake-database`](#google-concept-biglake-database) | [`biglake-iceberg-namespace`](#rule-biglake-iceberg-namespace) |
| `google_biglake_iceberg_table` | `resource` | [`biglake-table`](#google-concept-biglake-table) | [`biglake-iceberg-table`](#rule-biglake-iceberg-table) |
| `google_biglake_table` | `resource` | [`biglake-table`](#google-concept-biglake-table) | [`biglake-table`](#rule-biglake-table) |
| `google_bigquery_analytics_hub_data_exchange_subscription` | `resource` | [`analytics-hub-subscription`](#google-concept-analytics-hub-subscription) | [`analytics-hub-data-exchange-subscription`](#rule-analytics-hub-data-exchange-subscription) |
| `google_bigquery_analytics_hub_listing_subscription` | `resource` | [`analytics-hub-subscription`](#google-concept-analytics-hub-subscription) | [`analytics-hub-listing-subscription`](#rule-analytics-hub-listing-subscription) |
| `google_bigquery_dataset_access` | `resource` | [`access-binding`](#google-concept-access-binding) | [`bigquery-dataset-access`](#rule-bigquery-dataset-access) |
| `google_bigquery_dataset` | `resource` | [`bigquery-dataset`](#google-concept-bigquery-dataset) | [`bigquery-dataset`](#rule-bigquery-dataset) |
| `google_bigquery_table_iam_member` | `resource` | [`access-binding`](#google-concept-access-binding) | [`bigquery-table-iam-member`](#rule-bigquery-table-iam-member) |
| `google_bigquery_table` | `resource` | [`bigquery-table`](#google-concept-bigquery-table) | [`bigquery-table`](#rule-bigquery-table) |
| `google_bigtable_instance` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`bigtable-instance`](#rule-bigtable-instance) |
| `google_bigtable_table` | `resource` | [`bigtable-table`](#google-concept-bigtable-table) | [`bigtable-table`](#rule-bigtable-table) |
| `google_ces_app_root_agent_association` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-root-agent-association`](#rule-cx-agent-studio-root-agent-association) |
| `google_ces_app_version` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-app-version`](#rule-cx-agent-studio-app-version) |
| `google_ces_deployment` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-deployment`](#rule-cx-agent-studio-deployment) |
| `google_ces_evaluation` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-evaluation`](#rule-cx-agent-studio-evaluation) |
| `google_ces_example` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-example`](#rule-cx-agent-studio-example) |
| `google_ces_guardrail` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-guardrail`](#rule-cx-agent-studio-guardrail) |
| `google_ces_security_settings` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-security-settings`](#rule-cx-agent-studio-security-settings) |
| `google_ces_tool` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-tool`](#rule-cx-agent-studio-tool) |
| `google_ces_toolset` | `resource` | [`cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration) | [`cx-agent-studio-toolset`](#rule-cx-agent-studio-toolset) |
| `google_cloud_asset_folder_feed` | `resource` | [`cloud-asset-feed`](#google-concept-cloud-asset-feed) | [`cloud-asset-folder-feed`](#rule-cloud-asset-folder-feed) |
| `google_cloud_asset_organization_feed` | `resource` | [`cloud-asset-feed`](#google-concept-cloud-asset-feed) | [`cloud-asset-organization-feed`](#rule-cloud-asset-organization-feed) |
| `google_cloud_asset_project_feed` | `resource` | [`cloud-asset-feed`](#google-concept-cloud-asset-feed) | [`cloud-asset-project-feed`](#rule-cloud-asset-project-feed) |
| `google_cloud_identity_group_membership` | `resource` | [`cloud-identity-group-membership`](#google-concept-cloud-identity-group-membership) | [`cloud-identity-group-membership`](#rule-cloud-identity-group-membership) |
| `google_cloud_identity_group` | `resource` | [`identity-group`](#google-concept-identity-group) | [`cloud-identity-group`](#rule-cloud-identity-group) |
| `google_cloud_ids_endpoint` | `resource` | [`cloud-ids-endpoint`](#google-concept-cloud-ids-endpoint) | [`cloud-ids-endpoint`](#rule-cloud-ids-endpoint) |
| `google_cloud_run_service` | `resource` | [`cloud-run-service`](#google-concept-cloud-run-service) | [`cloud-run-service-v1`](#rule-cloud-run-service-v1) |
| `google_cloud_run_v2_job` | `resource` | [`cloud-run-job`](#google-concept-cloud-run-job) | [`cloud-run-job`](#rule-cloud-run-job) |
| `google_cloud_run_v2_service` | `resource` | [`cloud-run-service`](#google-concept-cloud-run-service) | [`cloud-run-service`](#rule-cloud-run-service) |
| `google_cloud_run_v2_worker_pool` | `resource` | [`cloud-run-service`](#google-concept-cloud-run-service) | [`cloud-run-worker-pool`](#rule-cloud-run-worker-pool) |
| `google_cloud_security_compliance_cloud_control` | `resource` | [`compliance-manager-configuration`](#google-concept-compliance-manager-configuration) | [`compliance-manager-cloud-control`](#rule-compliance-manager-cloud-control) |
| `google_cloud_security_compliance_framework_deployment` | `resource` | [`compliance-manager-configuration`](#google-concept-compliance-manager-configuration) | [`compliance-manager-framework-deployment`](#rule-compliance-manager-framework-deployment) |
| `google_cloudbuildv2_connection` | `resource` | [`source-connection`](#google-concept-source-connection) | [`cloud-build-v2-connection`](#rule-cloud-build-v2-connection) |
| `google_cloudbuildv2_repository` | `resource` | [`source-repository`](#google-concept-source-repository) | [`cloud-build-v2-repository`](#rule-cloud-build-v2-repository) |
| `google_cloudfunctions_function` | `resource` | [`serverless-function`](#google-concept-serverless-function) | [`cloud-run-function`](#rule-cloud-run-function) |
| `google_cloudfunctions2_function` | `resource` | [`serverless-function`](#google-concept-serverless-function) | [`cloud-run-function-v2`](#rule-cloud-run-function-v2) |
| `google_colab_runtime_template` | `resource` | [`colab-enterprise-configuration`](#google-concept-colab-enterprise-configuration) | [`colab-enterprise-runtime-template`](#rule-colab-enterprise-runtime-template) |
| `google_colab_schedule` | `resource` | [`colab-enterprise-configuration`](#google-concept-colab-enterprise-configuration) | [`colab-enterprise-schedule`](#rule-colab-enterprise-schedule) |
| `google_compute_backend_bucket` | `resource` | [`cloud-cdn-service`](#google-concept-cloud-cdn-service) | [`cloud-cdn-backend-bucket`](#rule-cloud-cdn-backend-bucket) (conditional) |
| `google_compute_disk` | `resource` | [`block-storage-volume`](#google-concept-block-storage-volume) | [`persistent-disk`](#rule-persistent-disk) |
| `google_compute_firewall_policy_rule` | `resource` | [`firewall-policy-rule`](#google-concept-firewall-policy-rule) | [`hierarchical-firewall-policy-rule`](#rule-hierarchical-firewall-policy-rule) |
| `google_compute_firewall_policy` | `resource` | [`firewall-policy`](#google-concept-firewall-policy) | [`hierarchical-firewall-policy`](#rule-hierarchical-firewall-policy) |
| `google_compute_firewall` | `resource` | [`vpc-firewall-rule`](#google-concept-vpc-firewall-rule) | [`vpc-firewall-rule`](#rule-vpc-firewall-rule) |
| `google_compute_forwarding_rule` | `resource` | [`private-endpoint`](#google-concept-private-endpoint)<br>[`load-balancer`](#google-concept-load-balancer) | [`private-service-connect-endpoint`](#rule-private-service-connect-endpoint) (conditional)<br>[`regional-load-balancer`](#rule-regional-load-balancer) (conditional) |
| `google_compute_global_address` | `resource` | [`allocated-network-range`](#google-concept-allocated-network-range) | [`private-services-access-range`](#rule-private-services-access-range) (conditional) |
| `google_compute_global_forwarding_rule` | `resource` | [`load-balancer`](#google-concept-load-balancer) | [`application-load-balancer`](#rule-application-load-balancer) |
| `google_compute_ha_vpn_gateway` | `resource` | [`vpn-gateway`](#google-concept-vpn-gateway) | [`ha-vpn-gateway`](#rule-ha-vpn-gateway) |
| `google_compute_instance_from_machine_image` | `resource` | [`compute-instance`](#google-concept-compute-instance) | [`compute-instance-from-machine-image`](#rule-compute-instance-from-machine-image) |
| `google_compute_instance_from_template` | `resource` | [`compute-instance`](#google-concept-compute-instance) | [`compute-instance-from-template`](#rule-compute-instance-from-template) |
| `google_compute_instance_group_manager` | `resource` | [`compute-instance-group`](#google-concept-compute-instance-group) | [`zonal-managed-instance-group`](#rule-zonal-managed-instance-group) |
| `google_compute_instance_group` | `resource` | [`compute-instance-group`](#google-concept-compute-instance-group) | [`unmanaged-instance-group`](#rule-unmanaged-instance-group) |
| `google_compute_instance` | `resource` | [`compute-instance`](#google-concept-compute-instance) | [`compute-engine-instance`](#rule-compute-engine-instance) |
| `google_compute_network_firewall_policy_rule` | `resource` | [`firewall-policy-rule`](#google-concept-firewall-policy-rule) | [`network-firewall-policy-rule`](#rule-network-firewall-policy-rule) |
| `google_compute_network_firewall_policy` | `resource` | [`firewall-policy`](#google-concept-firewall-policy) | [`network-firewall-policy`](#rule-network-firewall-policy) |
| `google_compute_network_peering` | `resource` | [`network-peering`](#google-concept-network-peering) | [`vpc-network-peering`](#rule-vpc-network-peering) |
| `google_compute_network` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`vpc-network`](#rule-vpc-network) |
| `google_compute_region_disk` | `resource` | [`block-storage-volume`](#google-concept-block-storage-volume) | [`regional-persistent-disk`](#rule-regional-persistent-disk) |
| `google_compute_region_instance_group_manager` | `resource` | [`compute-instance-group`](#google-concept-compute-instance-group) | [`regional-managed-instance-group`](#rule-regional-managed-instance-group) |
| `google_compute_router_nat` | `resource` | [`managed-nat`](#google-concept-managed-nat) | [`cloud-nat`](#rule-cloud-nat) |
| `google_compute_router` | `resource` | [`cloud-router`](#google-concept-cloud-router) | [`cloud-router`](#rule-cloud-router) |
| `google_compute_security_policy_rule` | `resource` | [`cloud-armor-security-rule`](#google-concept-cloud-armor-security-rule) | [`cloud-armor-security-rule`](#rule-cloud-armor-security-rule) |
| `google_compute_security_policy` | `resource` | [`cloud-armor-security-policy`](#google-concept-cloud-armor-security-policy) | [`cloud-armor-security-policy`](#rule-cloud-armor-security-policy) |
| `google_compute_subnetwork` | `resource` | [`subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) | [`vpc-subnetwork`](#rule-vpc-subnetwork) |
| `google_compute_vpn_gateway` | `resource` | [`vpn-gateway`](#google-concept-vpn-gateway) | [`classic-vpn-gateway`](#rule-classic-vpn-gateway) |
| `google_container_attached_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`gke-attached-cluster`](#rule-gke-attached-cluster) |
| `google_container_aws_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`gke-aws-cluster`](#rule-gke-aws-cluster) |
| `google_container_aws_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`gke-aws-node-pool`](#rule-gke-aws-node-pool) |
| `google_container_azure_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`gke-azure-cluster`](#rule-gke-azure-cluster) |
| `google_container_azure_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`gke-azure-node-pool`](#rule-gke-azure-node-pool) |
| `google_container_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`gke-cluster`](#rule-gke-cluster) |
| `google_container_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`gke-node-pool`](#rule-gke-node-pool) |
| `google_data_loss_prevention_deidentify_template` | `resource` | [`sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template) | [`sensitive-data-protection-deidentify-template`](#rule-sensitive-data-protection-deidentify-template) |
| `google_data_loss_prevention_discovery_config` | `resource` | [`sensitive-data-protection-scan`](#google-concept-sensitive-data-protection-scan) | [`sensitive-data-protection-discovery`](#rule-sensitive-data-protection-discovery) |
| `google_data_loss_prevention_inspect_template` | `resource` | [`sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template) | [`sensitive-data-protection-inspect-template`](#rule-sensitive-data-protection-inspect-template) |
| `google_data_loss_prevention_job_trigger` | `resource` | [`sensitive-data-protection-scan`](#google-concept-sensitive-data-protection-scan) | [`sensitive-data-protection-job-trigger`](#rule-sensitive-data-protection-job-trigger) |
| `google_data_loss_prevention_stored_info_type` | `resource` | [`sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template) | [`sensitive-data-protection-stored-info-type`](#rule-sensitive-data-protection-stored-info-type) |
| `google_database_migration_service_connection_profile` | `resource` | [`database-migration-connection`](#google-concept-database-migration-connection) | [`database-migration-connection-profile`](#rule-database-migration-connection-profile) |
| `google_database_migration_service_private_connection` | `resource` | [`database-migration-connection`](#google-concept-database-migration-connection) | [`database-migration-private-connection`](#rule-database-migration-private-connection) |
| `google_dataflow_flex_template_job` | `resource` | [`dataflow-job`](#google-concept-dataflow-job) | [`dataflow-flex-template-job`](#rule-dataflow-flex-template-job) |
| `google_dataflow_job` | `resource` | [`dataflow-job`](#google-concept-dataflow-job) | [`dataflow-job`](#rule-dataflow-job) |
| `google_dataplex_asset` | `resource` | [`dataplex-asset`](#google-concept-dataplex-asset) | [`dataplex-asset`](#rule-dataplex-asset) |
| `google_dataplex_data_asset` | `resource` | [`dataplex-asset`](#google-concept-dataplex-asset) | [`dataplex-data-asset`](#rule-dataplex-data-asset) |
| `google_dataplex_lake` | `resource` | [`dataplex-lake`](#google-concept-dataplex-lake) | [`dataplex-lake`](#rule-dataplex-lake) |
| `google_dataplex_zone` | `resource` | [`dataplex-zone`](#google-concept-dataplex-zone) | [`dataplex-zone`](#rule-dataplex-zone) |
| `google_developer_connect_connection` | `resource` | [`source-connection`](#google-concept-source-connection) | [`developer-connect-connection`](#rule-developer-connect-connection) |
| `google_developer_connect_git_repository_link` | `resource` | [`source-repository`](#google-concept-source-repository) | [`developer-connect-repository-link`](#rule-developer-connect-repository-link) |
| `google_dialogflow_agent` | `resource` | [`conversational-agent`](#google-concept-conversational-agent) | [`dialogflow-agent`](#rule-dialogflow-agent) |
| `google_dialogflow_cx_agent` | `resource` | [`conversational-agent`](#google-concept-conversational-agent) | [`dialogflow-cx-agent`](#rule-dialogflow-cx-agent) |
| `google_discovery_engine_chat_engine` | `resource` | [`discovery-engine`](#google-concept-discovery-engine) | [`discovery-engine-chat-engine`](#rule-discovery-engine-chat-engine) |
| `google_discovery_engine_recommendation_engine` | `resource` | [`discovery-engine`](#google-concept-discovery-engine) | [`discovery-engine-recommendation-engine`](#rule-discovery-engine-recommendation-engine) |
| `google_discovery_engine_search_engine` | `resource` | [`discovery-engine`](#google-concept-discovery-engine) | [`discovery-engine-search-engine`](#rule-discovery-engine-search-engine) |
| `google_dns_managed_zone` | `resource` | [`dns-zone`](#google-concept-dns-zone) | [`cloud-dns-managed-zone`](#rule-cloud-dns-managed-zone) |
| `google_dns_record_set` | `resource` | [`cloud-dns-record-set`](#google-concept-cloud-dns-record-set) | [`cloud-dns-record-set`](#rule-cloud-dns-record-set) |
| `google_edgecontainer_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`edge-container-cluster`](#rule-edge-container-cluster) |
| `google_edgecontainer_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`edge-container-node-pool`](#rule-edge-container-node-pool) |
| `google_edgenetwork_network` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`edge-network`](#rule-edge-network) |
| `google_edgenetwork_subnet` | `resource` | [`subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) | [`edge-network-subnet`](#rule-edge-network-subnet) |
| `google_endpoints_service` | `resource` | [`api-gateway`](#google-concept-api-gateway) | [`cloud-endpoints-service`](#rule-cloud-endpoints-service) |
| `google_filestore_instance` | `resource` | [`managed-file-storage`](#google-concept-managed-file-storage) | [`filestore-instance`](#rule-filestore-instance) |
| `google_firebase_database_instance` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`firebase-realtime-database`](#rule-firebase-realtime-database) |
| `google_firestore_database` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`firestore-database`](#rule-firestore-database) |
| `google_gke_backup_backup_channel` | `resource` | [`gke-backup-channel`](#google-concept-gke-backup-channel) | [`gke-backup-channel`](#rule-gke-backup-channel) |
| `google_gke_backup_backup_plan` | `resource` | [`backup-plan`](#google-concept-backup-plan) | [`gke-backup-plan`](#rule-gke-backup-plan) |
| `google_gke_backup_restore_channel` | `resource` | [`gke-backup-channel`](#google-concept-gke-backup-channel) | [`gke-restore-channel`](#rule-gke-restore-channel) |
| `google_gkeonprem_bare_metal_admin_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`bare-metal-gdc-admin-cluster`](#rule-bare-metal-gdc-admin-cluster) |
| `google_gkeonprem_bare_metal_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`bare-metal-gdc-cluster`](#rule-bare-metal-gdc-cluster) |
| `google_gkeonprem_bare_metal_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`bare-metal-gdc-node-pool`](#rule-bare-metal-gdc-node-pool) |
| `google_gkeonprem_vmware_admin_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`vmware-gdc-admin-cluster`](#rule-vmware-gdc-admin-cluster) |
| `google_gkeonprem_vmware_cluster` | `resource` | [`kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) | [`vmware-gdc-cluster`](#rule-vmware-gdc-cluster) |
| `google_gkeonprem_vmware_node_pool` | `resource` | [`kubernetes-node-pool`](#google-concept-kubernetes-node-pool) | [`vmware-gdc-node-pool`](#rule-vmware-gdc-node-pool) |
| `google_healthcare_consent_store` | `resource` | [`healthcare-store`](#google-concept-healthcare-store) | [`healthcare-consent-store`](#rule-healthcare-consent-store) |
| `google_healthcare_dataset` | `resource` | [`healthcare-dataset`](#google-concept-healthcare-dataset) | [`healthcare-dataset`](#rule-healthcare-dataset) |
| `google_healthcare_dicom_store` | `resource` | [`healthcare-store`](#google-concept-healthcare-store) | [`healthcare-dicom-store`](#rule-healthcare-dicom-store) |
| `google_healthcare_fhir_store` | `resource` | [`healthcare-store`](#google-concept-healthcare-store) | [`healthcare-fhir-store`](#rule-healthcare-fhir-store) |
| `google_healthcare_hl7_v2_store` | `resource` | [`healthcare-store`](#google-concept-healthcare-store) | [`healthcare-hl7v2-store`](#rule-healthcare-hl7v2-store) |
| `google_kms_crypto_key_version` | `resource` | [`cloud-kms-key-version`](#google-concept-cloud-kms-key-version) | [`cloud-kms-key-version`](#rule-cloud-kms-key-version) |
| `google_kms_crypto_key` | `resource` | [`encryption-key`](#google-concept-encryption-key) | [`cloud-kms-key`](#rule-cloud-kms-key) |
| `google_kms_key_ring` | `resource` | [`cloud-kms-key-ring`](#google-concept-cloud-kms-key-ring) | [`cloud-kms-key-ring`](#rule-cloud-kms-key-ring) |
| `google_logging_billing_account_bucket_config` | `resource` | [`cloud-logging-bucket`](#google-concept-cloud-logging-bucket) | [`cloud-logging-billing-account-bucket`](#rule-cloud-logging-billing-account-bucket) |
| `google_logging_billing_account_sink` | `resource` | [`cloud-logging-sink`](#google-concept-cloud-logging-sink) | [`cloud-logging-billing-account-sink`](#rule-cloud-logging-billing-account-sink) |
| `google_logging_folder_bucket_config` | `resource` | [`cloud-logging-bucket`](#google-concept-cloud-logging-bucket) | [`cloud-logging-folder-bucket`](#rule-cloud-logging-folder-bucket) |
| `google_logging_folder_sink` | `resource` | [`cloud-logging-sink`](#google-concept-cloud-logging-sink) | [`cloud-logging-folder-sink`](#rule-cloud-logging-folder-sink) |
| `google_logging_organization_bucket_config` | `resource` | [`cloud-logging-bucket`](#google-concept-cloud-logging-bucket) | [`cloud-logging-organization-bucket`](#rule-cloud-logging-organization-bucket) |
| `google_logging_organization_sink` | `resource` | [`cloud-logging-sink`](#google-concept-cloud-logging-sink) | [`cloud-logging-organization-sink`](#rule-cloud-logging-organization-sink) |
| `google_logging_project_bucket_config` | `resource` | [`cloud-logging-bucket`](#google-concept-cloud-logging-bucket) | [`cloud-logging-project-bucket`](#rule-cloud-logging-project-bucket) |
| `google_logging_project_sink` | `resource` | [`cloud-logging-sink`](#google-concept-cloud-logging-sink) | [`cloud-logging-project-sink`](#rule-cloud-logging-project-sink) |
| `google_lustre_instance` | `resource` | [`managed-file-storage`](#google-concept-managed-file-storage) | [`managed-lustre-instance`](#rule-managed-lustre-instance) |
| `google_managed_kafka_topic` | `resource` | [`message-topic`](#google-concept-message-topic) | [`managed-kafka-topic`](#rule-managed-kafka-topic) |
| `google_memcache_instance` | `resource` | [`managed-cache`](#google-concept-managed-cache) | [`memorystore-memcached-instance`](#rule-memorystore-memcached-instance) |
| `google_memorystore_instance` | `resource` | [`managed-cache`](#google-concept-managed-cache) | [`memorystore-instance`](#rule-memorystore-instance) |
| `google_migration_center_assets_export_job` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-assets-export-job`](#rule-migration-center-assets-export-job) |
| `google_migration_center_group` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-group`](#rule-migration-center-group) |
| `google_migration_center_import_data_file` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-import-data-file`](#rule-migration-center-import-data-file) |
| `google_migration_center_import_job` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-import-job`](#rule-migration-center-import-job) |
| `google_migration_center_preference_set` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-preference-set`](#rule-migration-center-preference-set) |
| `google_migration_center_report_config` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-report-config`](#rule-migration-center-report-config) |
| `google_migration_center_report` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-report`](#rule-migration-center-report) |
| `google_migration_center_settings` | `resource` | [`migration-center-assessment`](#google-concept-migration-center-assessment) | [`migration-center-settings`](#rule-migration-center-settings) |
| `google_monitoring_alert_policy` | `resource` | [`cloud-monitoring-alerting-policy`](#google-concept-cloud-monitoring-alerting-policy) | [`cloud-monitoring-alerting-policy`](#rule-cloud-monitoring-alerting-policy) |
| `google_monitoring_service` | `resource` | [`cloud-monitoring-service`](#google-concept-cloud-monitoring-service) | [`cloud-monitoring-service`](#rule-cloud-monitoring-service) |
| `google_monitoring_slo` | `resource` | [`cloud-monitoring-slo`](#google-concept-cloud-monitoring-slo) | [`cloud-monitoring-slo`](#rule-cloud-monitoring-slo) |
| `google_netapp_storage_pool` | `resource` | [`netapp-storage-pool`](#google-concept-netapp-storage-pool) | [`netapp-storage-pool`](#rule-netapp-storage-pool) |
| `google_netapp_volume` | `resource` | [`managed-file-storage`](#google-concept-managed-file-storage) | [`netapp-volume`](#rule-netapp-volume) |
| `google_network_connectivity_hub` | `resource` | [`network-connectivity-center-hub`](#google-concept-network-connectivity-center-hub) | [`network-connectivity-center-hub`](#rule-network-connectivity-center-hub) |
| `google_network_connectivity_spoke` | `resource` | [`network-connectivity-center-spoke`](#google-concept-network-connectivity-center-spoke) | [`network-connectivity-center-spoke`](#rule-network-connectivity-center-spoke) |
| `google_network_services_edge_cache_service` | `resource` | [`cloud-cdn-service`](#google-concept-cloud-cdn-service) | [`media-cdn-service`](#rule-media-cdn-service) |
| `google_network_services_grpc_route` | `resource` | [`network-services-route`](#google-concept-network-services-route) | [`network-services-grpc-route`](#rule-network-services-grpc-route) |
| `google_network_services_http_route` | `resource` | [`network-services-route`](#google-concept-network-services-route) | [`network-services-http-route`](#rule-network-services-http-route) |
| `google_network_services_multicast_consumer_association` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-consumer-association`](#rule-multicast-consumer-association) |
| `google_network_services_multicast_domain_activation` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-domain-activation`](#rule-multicast-domain-activation) |
| `google_network_services_multicast_group_consumer_activation` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-group-consumer-activation`](#rule-multicast-group-consumer-activation) |
| `google_network_services_multicast_group_producer_activation` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-group-producer-activation`](#rule-multicast-group-producer-activation) |
| `google_network_services_multicast_group_range_activation` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-group-range-activation`](#rule-multicast-group-range-activation) |
| `google_network_services_multicast_group_range` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-group-range`](#rule-multicast-group-range) |
| `google_network_services_multicast_producer_association` | `resource` | [`multicast-configuration`](#google-concept-multicast-configuration) | [`multicast-producer-association`](#rule-multicast-producer-association) |
| `google_network_services_tcp_route` | `resource` | [`network-services-route`](#google-concept-network-services-route) | [`network-services-tcp-route`](#rule-network-services-tcp-route) |
| `google_network_services_tls_route` | `resource` | [`network-services-route`](#google-concept-network-services-route) | [`network-services-tls-route`](#rule-network-services-tls-route) |
| `google_oracle_database_autonomous_database` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`oracle-autonomous-database`](#rule-oracle-autonomous-database) |
| `google_oracle_database_odb_network` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`oracle-odb-network`](#rule-oracle-odb-network) |
| `google_oracle_database_odb_subnet` | `resource` | [`subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) | [`oracle-odb-subnet`](#rule-oracle-odb-subnet) |
| `google_os_config_guest_policies` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-guest-policy`](#rule-vm-manager-guest-policy) |
| `google_os_config_os_policy_assignment` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-os-policy-assignment`](#rule-vm-manager-os-policy-assignment) |
| `google_os_config_patch_deployment` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-patch-deployment`](#rule-vm-manager-patch-deployment) |
| `google_os_config_v2_policy_orchestrator_for_folder` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-folder-policy-orchestrator`](#rule-vm-manager-folder-policy-orchestrator) |
| `google_os_config_v2_policy_orchestrator_for_organization` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-organization-policy-orchestrator`](#rule-vm-manager-organization-policy-orchestrator) |
| `google_os_config_v2_policy_orchestrator` | `resource` | [`vm-manager-policy`](#google-concept-vm-manager-policy) | [`vm-manager-policy-orchestrator`](#rule-vm-manager-policy-orchestrator) |
| `google_parallelstore_instance` | `resource` | [`managed-file-storage`](#google-concept-managed-file-storage) | [`parallelstore-instance`](#rule-parallelstore-instance) |
| `google_privateca_ca_pool` | `resource` | [`private-ca-pool`](#google-concept-private-ca-pool) | [`private-ca-pool`](#rule-private-ca-pool) |
| `google_privateca_certificate_authority` | `resource` | [`private-certificate-authority`](#google-concept-private-certificate-authority) | [`private-certificate-authority`](#rule-private-certificate-authority) |
| `google_project_iam_binding` | `resource` | [`service-identity-binding`](#google-concept-service-identity-binding) | [`project-iam-binding`](#rule-project-iam-binding) |
| `google_project_iam_member` | `resource` | [`service-identity-binding`](#google-concept-service-identity-binding) | [`project-iam-member`](#rule-project-iam-member) |
| `google_project_iam_policy` | `resource` | [`service-identity-binding`](#google-concept-service-identity-binding) | [`project-iam-policy`](#rule-project-iam-policy) |
| `google_project` | `resource` | [`google-cloud-project`](#google-concept-google-cloud-project) | [`google-cloud-project`](#rule-google-cloud-project) |
| `google_pubsub_lite_subscription` | `resource` | [`message-subscription`](#google-concept-message-subscription) | [`pubsub-lite-subscription`](#rule-pubsub-lite-subscription) |
| `google_pubsub_lite_topic` | `resource` | [`message-topic`](#google-concept-message-topic) | [`pubsub-lite-topic`](#rule-pubsub-lite-topic) |
| `google_pubsub_subscription` | `resource` | [`message-subscription`](#google-concept-message-subscription) | [`pubsub-subscription`](#rule-pubsub-subscription) |
| `google_pubsub_topic` | `resource` | [`message-topic`](#google-concept-message-topic) | [`pubsub-topic`](#rule-pubsub-topic) |
| `google_redis_cluster` | `resource` | [`managed-cache`](#google-concept-managed-cache) | [`memorystore-redis-cluster`](#rule-memorystore-redis-cluster) |
| `google_redis_instance` | `resource` | [`managed-cache`](#google-concept-managed-cache) | [`memorystore-redis-instance`](#rule-memorystore-redis-instance) |
| `google_secret_manager_regional_secret_version` | `resource` | [`secret-manager-secret-version`](#google-concept-secret-manager-secret-version) | [`secret-manager-regional-secret-version`](#rule-secret-manager-regional-secret-version) |
| `google_secret_manager_regional_secret` | `resource` | [`managed-secret`](#google-concept-managed-secret) | [`secret-manager-regional-secret`](#rule-secret-manager-regional-secret) |
| `google_secret_manager_secret_version` | `resource` | [`secret-manager-secret-version`](#google-concept-secret-manager-secret-version) | [`secret-manager-secret-version`](#rule-secret-manager-secret-version) |
| `google_secret_manager_secret` | `resource` | [`managed-secret`](#google-concept-managed-secret) | [`secret-manager-secret`](#rule-secret-manager-secret) |
| `google_secure_source_manager_repository` | `resource` | [`source-repository`](#google-concept-source-repository) | [`secure-source-manager-repository`](#rule-secure-source-manager-repository) |
| `google_service_account_key` | `resource` | [`service-credential`](#google-concept-service-credential) | [`service-account-key`](#rule-service-account-key) |
| `google_service_account` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`iam-service-account`](#rule-iam-service-account) |
| `google_service_networking_connection` | `resource` | [`service-networking-detail`](#google-concept-service-networking-detail) | [`service-networking-connection`](#rule-service-networking-connection) |
| `google_sourcerepo_repository` | `resource` | [`source-repository`](#google-concept-source-repository) | [`cloud-source-repository`](#rule-cloud-source-repository) |
| `google_spanner_database` | `resource` | [`spanner-database`](#google-concept-spanner-database) | [`spanner-database`](#rule-spanner-database) |
| `google_spanner_instance` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`spanner-instance`](#rule-spanner-instance) |
| `google_sql_database_instance` | `resource` | [`managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) | [`cloud-sql-instance`](#rule-cloud-sql-instance) |
| `google_storage_bucket_iam_member` | `resource` | [`access-binding`](#google-concept-access-binding) | [`cloud-storage-bucket-iam-member`](#rule-cloud-storage-bucket-iam-member) |
| `google_storage_bucket` | `resource` | [`object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) | [`cloud-storage-bucket`](#rule-cloud-storage-bucket) |
| `google_tpu_v2_vm` | `resource` | [`compute-instance`](#google-concept-compute-instance) | [`tpu-vm`](#rule-tpu-vm) |
| `google_vector_search_index` | `resource` | [`vertex-ai-vector-index`](#google-concept-vertex-ai-vector-index) | [`vector-search-index`](#rule-vector-search-index) |
| `google_vertex_ai_endpoint_with_model_garden_deployment` | `resource` | [`ai-inference-endpoint`](#google-concept-ai-inference-endpoint) | [`vertex-ai-model-garden-endpoint`](#rule-vertex-ai-model-garden-endpoint) |
| `google_vertex_ai_endpoint` | `resource` | [`ai-inference-endpoint`](#google-concept-ai-inference-endpoint) | [`vertex-ai-endpoint`](#rule-vertex-ai-endpoint) |
| `google_vertex_ai_feature_online_store` | `resource` | [`vertex-ai-feature-store`](#google-concept-vertex-ai-feature-store) | [`vertex-ai-feature-online-store`](#rule-vertex-ai-feature-online-store) |
| `google_vertex_ai_featurestore` | `resource` | [`vertex-ai-feature-store`](#google-concept-vertex-ai-feature-store) | [`vertex-ai-feature-store`](#rule-vertex-ai-feature-store) |
| `google_vertex_ai_index` | `resource` | [`vertex-ai-vector-index`](#google-concept-vertex-ai-vector-index) | [`vertex-ai-vector-index`](#rule-vertex-ai-vector-index) |
| `google_vmwareengine_network` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`vmware-engine-network`](#rule-vmware-engine-network) |
| `google_vmwareengine_subnet` | `resource` | [`subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) | [`vmware-engine-subnet`](#rule-vmware-engine-subnet) |
| `google_vpc_access_connector` | `resource` | [`serverless-vpc-access-connector`](#google-concept-serverless-vpc-access-connector) | [`serverless-vpc-access-connector`](#rule-serverless-vpc-access-connector) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="google-concept-access-binding"><code>google.concept.access-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/access-control.rf.hcl#L1-L3">Source</a></dt>
<dd>

An access-control declaration attached to a data resource.

</dd>
<dd>

Used by [`bigquery-dataset-access`](#rule-bigquery-dataset-access), [`bigquery-table-iam-member`](#rule-bigquery-table-iam-member), [`cloud-storage-bucket-iam-member`](#rule-cloud-storage-bucket-iam-member).

</dd>
</div>

<div>
<dt id="google-concept-ai-inference-endpoint"><code>google.concept.ai-inference-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed endpoint that serves model inference requests.

</dd>
<dd>

Used by [`vertex-ai-endpoint`](#rule-vertex-ai-endpoint), [`vertex-ai-model-garden-endpoint`](#rule-vertex-ai-model-garden-endpoint).

</dd>
</div>

<div>
<dt id="google-concept-allocated-network-range"><code>google.concept.allocated-network-range</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

An allocated address range used by private service networking.

</dd>
<dd>

Used by [`private-services-access-range`](#rule-private-services-access-range).

</dd>
</div>

<div>
<dt id="google-concept-alloydb-instance"><code>google.concept.alloydb-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/alloydb.rf.hcl#L1-L3">Source</a></dt>
<dd>

A database instance contributing compute capacity to an AlloyDB cluster.

</dd>
<dd>

Used by [`alloydb-instance`](#rule-alloydb-instance).

</dd>
</div>

<div>
<dt id="google-concept-analytics-hub-subscription"><code>google.concept.analytics-hub-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/analytics-hub.rf.hcl#L3-L5">Source</a></dt>
<dd>

An Analytics Hub subscription to a data exchange or listing.

</dd>
<dd>

Used by [`analytics-hub-data-exchange-subscription`](#rule-analytics-hub-data-exchange-subscription), [`analytics-hub-listing-subscription`](#rule-analytics-hub-listing-subscription).

</dd>
</div>

<div>
<dt id="google-concept-api-gateway"><code>google.concept.api-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L9-L11">Source</a></dt>
<dd>

A managed gateway that exposes and governs APIs.

</dd>
<dd>

Used by [`api-gateway`](#rule-api-gateway), [`cloud-endpoints-service`](#rule-cloud-endpoints-service).

</dd>
</div>

<div>
<dt id="google-concept-app-engine-service-version"><code>google.concept.app-engine-service-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/app-engine.rf.hcl#L2-L4">Source</a></dt>
<dd>

A deployed App Engine standard or flexible service version.

</dd>
<dd>

Used by [`app-engine-flexible-service-version`](#rule-app-engine-flexible-service-version), [`app-engine-standard-service-version`](#rule-app-engine-standard-service-version).

</dd>
</div>

<div>
<dt id="google-concept-backup-plan"><code>google.concept.backup-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L13-L15">Source</a></dt>
<dd>

A managed policy scheduling and retaining backups.

</dd>
<dd>

Used by [`backup-dr-backup-plan`](#rule-backup-dr-backup-plan), [`gke-backup-plan`](#rule-gke-backup-plan).

</dd>
</div>

<div>
<dt id="google-concept-backup-vault"><code>google.concept.backup-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L17-L19">Source</a></dt>
<dd>

A managed vault storing protected recovery data.

</dd>
<dd>

Used by [`backup-dr-backup-plan`](#rule-backup-dr-backup-plan), [`backup-dr-backup-vault`](#rule-backup-dr-backup-vault).

</dd>
</div>

<div>
<dt id="google-concept-biglake-catalog"><code>google.concept.biglake-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L1-L3">Source</a></dt>
<dd>

A BigLake catalog organizing lakehouse metadata.

</dd>
<dd>

Used by [`biglake-catalog`](#rule-biglake-catalog), [`biglake-hive-catalog`](#rule-biglake-hive-catalog), [`biglake-iceberg-catalog`](#rule-biglake-iceberg-catalog).

</dd>
</div>

<div>
<dt id="google-concept-biglake-database"><code>google.concept.biglake-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L5-L7">Source</a></dt>
<dd>

A database namespace in a BigLake catalog.

</dd>
<dd>

Used by [`biglake-database`](#rule-biglake-database), [`biglake-hive-database`](#rule-biglake-hive-database), [`biglake-iceberg-namespace`](#rule-biglake-iceberg-namespace).

</dd>
</div>

<div>
<dt id="google-concept-biglake-table"><code>google.concept.biglake-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L9-L11">Source</a></dt>
<dd>

A table registered in BigLake.

</dd>
<dd>

Used by [`biglake-hive-table`](#rule-biglake-hive-table), [`biglake-iceberg-table`](#rule-biglake-iceberg-table), [`biglake-table`](#rule-biglake-table).

</dd>
</div>

<div>
<dt id="google-concept-bigquery-dataset"><code>google.concept.bigquery-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L1-L3">Source</a></dt>
<dd>

A BigQuery dataset that organizes tables and their access boundary.

</dd>
<dd>

Used by [`bigquery-dataset`](#rule-bigquery-dataset), [`bigquery-dataset-access`](#rule-bigquery-dataset-access), [`bigquery-table`](#rule-bigquery-table).

</dd>
</div>

<div>
<dt id="google-concept-bigquery-table"><code>google.concept.bigquery-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L5-L7">Source</a></dt>
<dd>

A table managed inside a BigQuery dataset.

</dd>
<dd>

Used by [`bigquery-table`](#rule-bigquery-table), [`bigquery-table-iam-member`](#rule-bigquery-table-iam-member).

</dd>
</div>

<div>
<dt id="google-concept-bigtable-table"><code>google.concept.bigtable-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/bigtable.rf.hcl#L1-L3">Source</a></dt>
<dd>

A table belonging to a Bigtable instance.

</dd>
<dd>

Used by [`bigtable-table`](#rule-bigtable-table).

</dd>
</div>

<div>
<dt id="google-concept-block-storage-volume"><code>google.concept.block-storage-volume</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L21-L23">Source</a></dt>
<dd>

A durable block-storage volume attachable to compute workloads.

</dd>
<dd>

Used by [`persistent-disk`](#rule-persistent-disk), [`regional-persistent-disk`](#rule-regional-persistent-disk).

</dd>
</div>

<div>
<dt id="google-concept-cloud-armor-security-policy"><code>google.concept.cloud-armor-security-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-armor.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Armor security policy protecting load-balanced applications.

</dd>
<dd>

Used by [`cloud-armor-security-policy`](#rule-cloud-armor-security-policy), [`cloud-armor-security-rule`](#rule-cloud-armor-security-rule).

</dd>
</div>

<div>
<dt id="google-concept-cloud-armor-security-rule"><code>google.concept.cloud-armor-security-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-armor.rf.hcl#L5-L7">Source</a></dt>
<dd>

A rule contributing traffic controls to a Cloud Armor security policy.

</dd>
<dd>

Used by [`cloud-armor-security-rule`](#rule-cloud-armor-security-rule).

</dd>
</div>

<div>
<dt id="google-concept-cloud-asset-feed"><code>google.concept.cloud-asset-feed</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/cloud-asset-inventory.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Asset Inventory feed publishing asset changes to a destination.

</dd>
<dd>

Used by [`cloud-asset-folder-feed`](#rule-cloud-asset-folder-feed), [`cloud-asset-organization-feed`](#rule-cloud-asset-organization-feed), [`cloud-asset-project-feed`](#rule-cloud-asset-project-feed).

</dd>
</div>

<div>
<dt id="google-concept-cloud-cdn-service"><code>google.concept.cloud-cdn-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-cdn.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud CDN or Media CDN edge delivery service.

</dd>
<dd>

Used by [`cloud-cdn-backend-bucket`](#rule-cloud-cdn-backend-bucket), [`media-cdn-service`](#rule-media-cdn-service).

</dd>
</div>

<div>
<dt id="google-concept-cloud-dns-record-set"><code>google.concept.cloud-dns-record-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-dns.rf.hcl#L1-L3">Source</a></dt>
<dd>

A DNS record set managed inside a Cloud DNS managed zone.

</dd>
<dd>

Used by [`cloud-dns-record-set`](#rule-cloud-dns-record-set).

</dd>
</div>

<div>
<dt id="google-concept-cloud-identity-group-membership"><code>google.concept.cloud-identity-group-membership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/cloud-identity.rf.hcl#L1-L3">Source</a></dt>
<dd>

A membership contributing a principal to a Cloud Identity group.

</dd>
<dd>

Used by [`cloud-identity-group-membership`](#rule-cloud-identity-group-membership).

</dd>
</div>

<div>
<dt id="google-concept-cloud-ids-endpoint"><code>google.concept.cloud-ids-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-ids.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud IDS endpoint inspecting traffic in a VPC network.

</dd>
<dd>

Used by [`cloud-ids-endpoint`](#rule-cloud-ids-endpoint).

</dd>
</div>

<div>
<dt id="google-concept-cloud-kms-key-ring"><code>google.concept.cloud-kms-key-ring</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-kms.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud KMS key ring organizing keys in one Google Cloud location.

</dd>
<dd>

Used by [`cloud-kms-key`](#rule-cloud-kms-key), [`cloud-kms-key-ring`](#rule-cloud-kms-key-ring).

</dd>
</div>

<div>
<dt id="google-concept-cloud-kms-key-version"><code>google.concept.cloud-kms-key-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-kms.rf.hcl#L5-L7">Source</a></dt>
<dd>

A cryptographic key version belonging to a Cloud KMS key.

</dd>
<dd>

Used by [`cloud-kms-key-version`](#rule-cloud-kms-key-version).

</dd>
</div>

<div>
<dt id="google-concept-cloud-logging-bucket"><code>google.concept.cloud-logging-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Cloud Logging bucket retaining log entries.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`cloud-logging-billing-account-bucket`](#rule-cloud-logging-billing-account-bucket)
- [`cloud-logging-folder-bucket`](#rule-cloud-logging-folder-bucket)
- [`cloud-logging-organization-bucket`](#rule-cloud-logging-organization-bucket)
- [`cloud-logging-project-bucket`](#rule-cloud-logging-project-bucket)

</details>

</dd>
</div>

<div>
<dt id="google-concept-cloud-logging-sink"><code>google.concept.cloud-logging-sink</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Logging sink routing selected log entries to a destination.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`cloud-logging-billing-account-sink`](#rule-cloud-logging-billing-account-sink)
- [`cloud-logging-folder-sink`](#rule-cloud-logging-folder-sink)
- [`cloud-logging-organization-sink`](#rule-cloud-logging-organization-sink)
- [`cloud-logging-project-sink`](#rule-cloud-logging-project-sink)

</details>

</dd>
</div>

<div>
<dt id="google-concept-cloud-monitoring-alerting-policy"><code>google.concept.cloud-monitoring-alerting-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Monitoring alerting policy defining conditions and notification behavior.

</dd>
<dd>

Used by [`cloud-monitoring-alerting-policy`](#rule-cloud-monitoring-alerting-policy).

</dd>
</div>

<div>
<dt id="google-concept-cloud-monitoring-service"><code>google.concept.cloud-monitoring-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Cloud Monitoring service used as the target of service-level objectives.

</dd>
<dd>

Used by [`cloud-monitoring-service`](#rule-cloud-monitoring-service), [`cloud-monitoring-slo`](#rule-cloud-monitoring-slo).

</dd>
</div>

<div>
<dt id="google-concept-cloud-monitoring-slo"><code>google.concept.cloud-monitoring-slo</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L9-L11">Source</a></dt>
<dd>

A service-level objective contributing reliability intent to a monitored service.

</dd>
<dd>

Used by [`cloud-monitoring-slo`](#rule-cloud-monitoring-slo).

</dd>
</div>

<div>
<dt id="google-concept-cloud-router"><code>google.concept.cloud-router</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-router.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Router exchanging dynamic routes for a VPC network.

</dd>
<dd>

Used by [`cloud-nat`](#rule-cloud-nat), [`cloud-router`](#rule-cloud-router).

</dd>
</div>

<div>
<dt id="google-concept-cloud-run-job"><code>google.concept.cloud-run-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Cloud Run job that runs tasks to completion.

</dd>
<dd>

Used by [`cloud-run-job`](#rule-cloud-run-job).

</dd>
</div>

<div>
<dt id="google-concept-cloud-run-service"><code>google.concept.cloud-run-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Run service that handles requests or events on managed container instances.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`cloud-run-service`](#rule-cloud-run-service)
- [`cloud-run-service-v1`](#rule-cloud-run-service-v1)
- [`cloud-run-worker-pool`](#rule-cloud-run-worker-pool)
- [`pubsub-subscription`](#rule-pubsub-subscription)

</details>

</dd>
</div>

<div>
<dt id="google-concept-colab-enterprise-configuration"><code>google.concept.colab-enterprise-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/colab-enterprise.rf.hcl#L2-L4">Source</a></dt>
<dd>

A runtime template or schedule configuring Colab Enterprise execution.

</dd>
<dd>

Used by [`colab-enterprise-runtime-template`](#rule-colab-enterprise-runtime-template), [`colab-enterprise-schedule`](#rule-colab-enterprise-schedule).

</dd>
</div>

<div>
<dt id="google-concept-compliance-manager-configuration"><code>google.concept.compliance-manager-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/compliance-manager.rf.hcl#L2-L4">Source</a></dt>
<dd>

A cloud control or deployment configuring a Compliance Manager framework.

</dd>
<dd>

Used by [`compliance-manager-cloud-control`](#rule-compliance-manager-cloud-control), [`compliance-manager-framework-deployment`](#rule-compliance-manager-framework-deployment).

</dd>
</div>

<div>
<dt id="google-concept-compute-instance"><code>google.concept.compute-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L25-L27">Source</a></dt>
<dd>

A provisioned compute instance running a workload.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`compute-engine-instance`](#rule-compute-engine-instance)
- [`compute-instance-from-machine-image`](#rule-compute-instance-from-machine-image)
- [`compute-instance-from-template`](#rule-compute-instance-from-template)
- [`tpu-vm`](#rule-tpu-vm)

</details>

</dd>
</div>

<div>
<dt id="google-concept-compute-instance-group"><code>google.concept.compute-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed or unmanaged Compute Engine instance group.

</dd>
<dd>

Used by [`regional-managed-instance-group`](#rule-regional-managed-instance-group), [`unmanaged-instance-group`](#rule-unmanaged-instance-group), [`zonal-managed-instance-group`](#rule-zonal-managed-instance-group).

</dd>
</div>

<div>
<dt id="google-concept-conversational-agent"><code>google.concept.conversational-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/dialogflow.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Dialogflow conversational agent.

</dd>
<dd>

Used by [`dialogflow-agent`](#rule-dialogflow-agent), [`dialogflow-cx-agent`](#rule-dialogflow-cx-agent).

</dd>
</div>

<div>
<dt id="google-concept-cx-agent-studio-configuration"><code>google.concept.cx-agent-studio-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L3-L5">Source</a></dt>
<dd>

A version, deployment, tool, guardrail, or other configuration supporting a CX Agent Studio application.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`cx-agent-studio-app-version`](#rule-cx-agent-studio-app-version)
- [`cx-agent-studio-deployment`](#rule-cx-agent-studio-deployment)
- [`cx-agent-studio-evaluation`](#rule-cx-agent-studio-evaluation)
- [`cx-agent-studio-example`](#rule-cx-agent-studio-example)
- [`cx-agent-studio-guardrail`](#rule-cx-agent-studio-guardrail)
- [`cx-agent-studio-root-agent-association`](#rule-cx-agent-studio-root-agent-association)
- [`cx-agent-studio-security-settings`](#rule-cx-agent-studio-security-settings)
- [`cx-agent-studio-tool`](#rule-cx-agent-studio-tool)
- [`cx-agent-studio-toolset`](#rule-cx-agent-studio-toolset)

</details>

</dd>
</div>

<div>
<dt id="google-concept-database-migration-connection"><code>google.concept.database-migration-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/database-migration.rf.hcl#L2-L4">Source</a></dt>
<dd>

A source, destination, or private connection used by Database Migration Service.

</dd>
<dd>

Used by [`database-migration-connection-profile`](#rule-database-migration-connection-profile), [`database-migration-private-connection`](#rule-database-migration-private-connection).

</dd>
</div>

<div>
<dt id="google-concept-dataflow-job"><code>google.concept.dataflow-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataflow.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Dataflow batch or streaming job.

</dd>
<dd>

Used by [`dataflow-flex-template-job`](#rule-dataflow-flex-template-job), [`dataflow-job`](#rule-dataflow-job).

</dd>
</div>

<div>
<dt id="google-concept-dataplex-asset"><code>google.concept.dataplex-asset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L9-L11">Source</a></dt>
<dd>

A data asset governed through Dataplex.

</dd>
<dd>

Used by [`dataplex-asset`](#rule-dataplex-asset), [`dataplex-data-asset`](#rule-dataplex-data-asset).

</dd>
</div>

<div>
<dt id="google-concept-dataplex-lake"><code>google.concept.dataplex-lake</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Dataplex lake organizing governed data domains.

</dd>
<dd>

Used by [`dataplex-lake`](#rule-dataplex-lake), [`dataplex-zone`](#rule-dataplex-zone).

</dd>
</div>

<div>
<dt id="google-concept-dataplex-zone"><code>google.concept.dataplex-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Dataplex zone organizing assets within a lake.

</dd>
<dd>

Used by [`dataplex-zone`](#rule-dataplex-zone).

</dd>
</div>

<div>
<dt id="google-concept-dedicated-interconnect"><code>google.concept.dedicated-interconnect</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L29-L31">Source</a></dt>
<dd>

A dedicated private connection between an external network and a cloud provider.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="google-concept-discovery-engine"><code>google.concept.discovery-engine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/discovery-engine.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Discovery Engine search, recommendation, or conversational engine.

</dd>
<dd>

Used by [`discovery-engine-chat-engine`](#rule-discovery-engine-chat-engine), [`discovery-engine-recommendation-engine`](#rule-discovery-engine-recommendation-engine), [`discovery-engine-search-engine`](#rule-discovery-engine-search-engine).

</dd>
</div>

<div>
<dt id="google-concept-dns-zone"><code>google.concept.dns-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L33-L35">Source</a></dt>
<dd>

A managed DNS namespace containing resource records.

</dd>
<dd>

Used by [`cloud-dns-managed-zone`](#rule-cloud-dns-managed-zone), [`cloud-dns-record-set`](#rule-cloud-dns-record-set).

</dd>
</div>

<div>
<dt id="google-concept-encryption-key"><code>google.concept.encryption-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L37-L39">Source</a></dt>
<dd>

A managed key used for cryptographic operations.

</dd>
<dd>

Used by [`cloud-kms-key`](#rule-cloud-kms-key), [`cloud-kms-key-version`](#rule-cloud-kms-key-version).

</dd>
</div>

<div>
<dt id="google-concept-firewall-policy"><code>google.concept.firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Google Cloud hierarchical or network firewall policy.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`hierarchical-firewall-policy`](#rule-hierarchical-firewall-policy)
- [`hierarchical-firewall-policy-rule`](#rule-hierarchical-firewall-policy-rule)
- [`network-firewall-policy`](#rule-network-firewall-policy)
- [`network-firewall-policy-rule`](#rule-network-firewall-policy-rule)

</details>

</dd>
</div>

<div>
<dt id="google-concept-firewall-policy-rule"><code>google.concept.firewall-policy-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L9-L11">Source</a></dt>
<dd>

A rule contributing controls to a Google Cloud firewall policy.

</dd>
<dd>

Used by [`hierarchical-firewall-policy-rule`](#rule-hierarchical-firewall-policy-rule), [`network-firewall-policy-rule`](#rule-network-firewall-policy-rule).

</dd>
</div>

<div>
<dt id="google-concept-gke-backup-channel"><code>google.concept.gke-backup-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/gke-backup.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Backup for GKE channel connecting backup or restore operations across projects.

</dd>
<dd>

Used by [`gke-backup-channel`](#rule-gke-backup-channel), [`gke-restore-channel`](#rule-gke-restore-channel).

</dd>
</div>

<div>
<dt id="google-concept-google-cloud-project"><code>google.concept.google-cloud-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/resource-hierarchy.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Google Cloud project serving as a resource and billing boundary.

</dd>
<dd>


<details>
<summary>Used by 24 Rules</summary>

- [`cloud-monitoring-alerting-policy`](#rule-cloud-monitoring-alerting-policy)
- [`cloud-monitoring-service`](#rule-cloud-monitoring-service)
- [`cloud-monitoring-slo`](#rule-cloud-monitoring-slo)
- [`cloud-router`](#rule-cloud-router)
- [`cloud-run-job`](#rule-cloud-run-job)
- [`cloud-run-service`](#rule-cloud-run-service)
- [`cloud-run-service-v1`](#rule-cloud-run-service-v1)
- [`cloud-run-worker-pool`](#rule-cloud-run-worker-pool)
- [`cloud-sql-instance`](#rule-cloud-sql-instance)
- [`gke-cluster`](#rule-gke-cluster)
- [`google-cloud-project`](#rule-google-cloud-project)
- [`iam-service-account`](#rule-iam-service-account)
- [`memorystore-instance`](#rule-memorystore-instance)
- [`memorystore-memcached-instance`](#rule-memorystore-memcached-instance)
- [`memorystore-redis-cluster`](#rule-memorystore-redis-cluster)
- [`memorystore-redis-instance`](#rule-memorystore-redis-instance)
- [`pubsub-subscription`](#rule-pubsub-subscription)
- [`pubsub-topic`](#rule-pubsub-topic)
- [`secret-manager-regional-secret`](#rule-secret-manager-regional-secret)
- [`secret-manager-secret`](#rule-secret-manager-secret)
- [`serverless-vpc-access-connector`](#rule-serverless-vpc-access-connector)
- [`vpc-firewall-rule`](#rule-vpc-firewall-rule)
- [`vpc-network`](#rule-vpc-network)
- [`vpc-subnetwork`](#rule-vpc-subnetwork)

</details>

</dd>
</div>

<div>
<dt id="google-concept-healthcare-dataset"><code>google.concept.healthcare-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Cloud Healthcare API dataset containing healthcare data stores.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`healthcare-consent-store`](#rule-healthcare-consent-store)
- [`healthcare-dataset`](#rule-healthcare-dataset)
- [`healthcare-dicom-store`](#rule-healthcare-dicom-store)
- [`healthcare-fhir-store`](#rule-healthcare-fhir-store)
- [`healthcare-hl7v2-store`](#rule-healthcare-hl7v2-store)

</details>

</dd>
</div>

<div>
<dt id="google-concept-healthcare-store"><code>google.concept.healthcare-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L5-L7">Source</a></dt>
<dd>

A FHIR, DICOM, HL7v2, or consent store in a Cloud Healthcare API dataset.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`healthcare-consent-store`](#rule-healthcare-consent-store)
- [`healthcare-dicom-store`](#rule-healthcare-dicom-store)
- [`healthcare-fhir-store`](#rule-healthcare-fhir-store)
- [`healthcare-hl7v2-store`](#rule-healthcare-hl7v2-store)

</details>

</dd>
</div>

<div>
<dt id="google-concept-identity-group"><code>google.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L41-L43">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>

Used by [`cloud-identity-group`](#rule-cloud-identity-group), [`cloud-identity-group-membership`](#rule-cloud-identity-group-membership).

</dd>
</div>

<div>
<dt id="google-concept-kubernetes-node-pool"><code>google.concept.kubernetes-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L45-L47">Source</a></dt>
<dd>

A node pool contributing compute capacity to a Kubernetes cluster.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`bare-metal-gdc-node-pool`](#rule-bare-metal-gdc-node-pool)
- [`edge-container-node-pool`](#rule-edge-container-node-pool)
- [`gke-aws-node-pool`](#rule-gke-aws-node-pool)
- [`gke-azure-node-pool`](#rule-gke-azure-node-pool)
- [`gke-node-pool`](#rule-gke-node-pool)
- [`vmware-gdc-node-pool`](#rule-vmware-gdc-node-pool)

</details>

</dd>
</div>

<div>
<dt id="google-concept-load-balancer"><code>google.concept.load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L49-L51">Source</a></dt>
<dd>

A load-balancing service composed from routing infrastructure.

</dd>
<dd>

Used by [`application-load-balancer`](#rule-application-load-balancer), [`regional-load-balancer`](#rule-regional-load-balancer).

</dd>
</div>

<div>
<dt id="google-concept-managed-cache"><code>google.concept.managed-cache</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L53-L55">Source</a></dt>
<dd>

A managed in-memory cache service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`memorystore-instance`](#rule-memorystore-instance)
- [`memorystore-memcached-instance`](#rule-memorystore-memcached-instance)
- [`memorystore-redis-cluster`](#rule-memorystore-redis-cluster)
- [`memorystore-redis-instance`](#rule-memorystore-redis-instance)

</details>

</dd>
</div>

<div>
<dt id="google-concept-managed-file-storage"><code>google.concept.managed-file-storage</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L57-L59">Source</a></dt>
<dd>

A managed shared file-storage service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`filestore-instance`](#rule-filestore-instance)
- [`managed-lustre-instance`](#rule-managed-lustre-instance)
- [`netapp-volume`](#rule-netapp-volume)
- [`parallelstore-instance`](#rule-parallelstore-instance)

</details>

</dd>
</div>

<div>
<dt id="google-concept-managed-nat"><code>google.concept.managed-nat</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L61-L63">Source</a></dt>
<dd>

A managed network address translation service.

</dd>
<dd>

Used by [`cloud-nat`](#rule-cloud-nat).

</dd>
</div>

<div>
<dt id="google-concept-managed-secret"><code>google.concept.managed-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L65-L67">Source</a></dt>
<dd>

A managed secret identity whose sensitive value stays outside architecture output.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`secret-manager-regional-secret`](#rule-secret-manager-regional-secret)
- [`secret-manager-regional-secret-version`](#rule-secret-manager-regional-secret-version)
- [`secret-manager-secret`](#rule-secret-manager-secret)
- [`secret-manager-secret-version`](#rule-secret-manager-secret-version)

</details>

</dd>
</div>

<div>
<dt id="google-concept-message-queue"><code>google.concept.message-queue</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L69-L71">Source</a></dt>
<dd>

A managed queue buffering work or messages for asynchronous consumers.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="google-concept-message-subscription"><code>google.concept.message-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L73-L75">Source</a></dt>
<dd>

A durable subscription consuming messages from a topic.

</dd>
<dd>

Used by [`pubsub-lite-subscription`](#rule-pubsub-lite-subscription), [`pubsub-subscription`](#rule-pubsub-subscription).

</dd>
</div>

<div>
<dt id="google-concept-message-topic"><code>google.concept.message-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L77-L79">Source</a></dt>
<dd>

A messaging topic receiving messages from publishers.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`managed-kafka-topic`](#rule-managed-kafka-topic)
- [`pubsub-lite-topic`](#rule-pubsub-lite-topic)
- [`pubsub-subscription`](#rule-pubsub-subscription)
- [`pubsub-topic`](#rule-pubsub-topic)

</details>

</dd>
</div>

<div>
<dt id="google-concept-migration-center-assessment"><code>google.concept.migration-center-assessment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L3-L5">Source</a></dt>
<dd>

An import, grouping, preference, report, or settings resource supporting migration assessment.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`migration-center-assets-export-job`](#rule-migration-center-assets-export-job)
- [`migration-center-group`](#rule-migration-center-group)
- [`migration-center-import-data-file`](#rule-migration-center-import-data-file)
- [`migration-center-import-job`](#rule-migration-center-import-job)
- [`migration-center-preference-set`](#rule-migration-center-preference-set)
- [`migration-center-report`](#rule-migration-center-report)
- [`migration-center-report-config`](#rule-migration-center-report-config)
- [`migration-center-settings`](#rule-migration-center-settings)

</details>

</dd>
</div>

<div>
<dt id="google-concept-multicast-configuration"><code>google.concept.multicast-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L3-L5">Source</a></dt>
<dd>

An activation, group range, or network association configuring Cloud Multicast.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`multicast-consumer-association`](#rule-multicast-consumer-association)
- [`multicast-domain-activation`](#rule-multicast-domain-activation)
- [`multicast-group-consumer-activation`](#rule-multicast-group-consumer-activation)
- [`multicast-group-producer-activation`](#rule-multicast-group-producer-activation)
- [`multicast-group-range`](#rule-multicast-group-range)
- [`multicast-group-range-activation`](#rule-multicast-group-range-activation)
- [`multicast-producer-association`](#rule-multicast-producer-association)

</details>

</dd>
</div>

<div>
<dt id="google-concept-netapp-storage-pool"><code>google.concept.netapp-storage-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L1-L3">Source</a></dt>
<dd>

A NetApp Volumes storage pool providing capacity to volumes.

</dd>
<dd>

Used by [`netapp-storage-pool`](#rule-netapp-storage-pool), [`netapp-volume`](#rule-netapp-volume).

</dd>
</div>

<div>
<dt id="google-concept-network-connectivity-center-hub"><code>google.concept.network-connectivity-center-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/network-connectivity-center.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Network Connectivity Center hub coordinating connectivity through spokes.

</dd>
<dd>

Used by [`network-connectivity-center-hub`](#rule-network-connectivity-center-hub), [`network-connectivity-center-spoke`](#rule-network-connectivity-center-spoke).

</dd>
</div>

<div>
<dt id="google-concept-network-connectivity-center-spoke"><code>google.concept.network-connectivity-center-spoke</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/network-connectivity-center.rf.hcl#L5-L7">Source</a></dt>
<dd>

A spoke attaching a network resource to a Network Connectivity Center hub.

</dd>
<dd>

Used by [`network-connectivity-center-spoke`](#rule-network-connectivity-center-spoke).

</dd>
</div>

<div>
<dt id="google-concept-network-peering"><code>google.concept.network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L81-L83">Source</a></dt>
<dd>

A direct private connectivity agreement between virtual networks.

</dd>
<dd>

Used by [`vpc-network-peering`](#rule-vpc-network-peering).

</dd>
</div>

<div>
<dt id="google-concept-network-services-route"><code>google.concept.network-services-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/service-mesh.rf.hcl#L3-L5">Source</a></dt>
<dd>

An HTTP, gRPC, TCP, or TLS route contributing traffic policy.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`network-services-grpc-route`](#rule-network-services-grpc-route)
- [`network-services-http-route`](#rule-network-services-http-route)
- [`network-services-tcp-route`](#rule-network-services-tcp-route)
- [`network-services-tls-route`](#rule-network-services-tls-route)

</details>

</dd>
</div>

<div>
<dt id="google-concept-private-ca-pool"><code>google.concept.private-ca-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/private-ca.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Certificate Authority Service pool containing certificate authorities.

</dd>
<dd>

Used by [`private-ca-pool`](#rule-private-ca-pool), [`private-certificate-authority`](#rule-private-certificate-authority).

</dd>
</div>

<div>
<dt id="google-concept-private-certificate-authority"><code>google.concept.private-certificate-authority</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/private-ca.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed private certificate authority.

</dd>
<dd>

Used by [`private-certificate-authority`](#rule-private-certificate-authority).

</dd>
</div>

<div>
<dt id="google-concept-private-endpoint"><code>google.concept.private-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L85-L87">Source</a></dt>
<dd>

A private endpoint exposing a service inside a virtual network.

</dd>
<dd>

Used by [`private-service-connect-endpoint`](#rule-private-service-connect-endpoint).

</dd>
</div>

<div>
<dt id="google-concept-secret-manager-secret-version"><code>google.concept.secret-manager-secret-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/secret-manager.rf.hcl#L1-L3">Source</a></dt>
<dd>

A version attached to a Secret Manager secret without exposing its secret data.

</dd>
<dd>

Used by [`secret-manager-regional-secret-version`](#rule-secret-manager-regional-secret-version), [`secret-manager-secret-version`](#rule-secret-manager-secret-version).

</dd>
</div>

<div>
<dt id="google-concept-sensitive-data-protection-scan"><code>google.concept.sensitive-data-protection-scan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Sensitive Data Protection discovery or inspection job configuration.

</dd>
<dd>

Used by [`sensitive-data-protection-discovery`](#rule-sensitive-data-protection-discovery), [`sensitive-data-protection-job-trigger`](#rule-sensitive-data-protection-job-trigger).

</dd>
</div>

<div>
<dt id="google-concept-sensitive-data-protection-template"><code>google.concept.sensitive-data-protection-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L5-L7">Source</a></dt>
<dd>

A reusable inspection, de-identification, or stored information type configuration.

</dd>
<dd>

Used by [`sensitive-data-protection-deidentify-template`](#rule-sensitive-data-protection-deidentify-template), [`sensitive-data-protection-inspect-template`](#rule-sensitive-data-protection-inspect-template), [`sensitive-data-protection-stored-info-type`](#rule-sensitive-data-protection-stored-info-type).

</dd>
</div>

<div>
<dt id="google-concept-serverless-function"><code>google.concept.serverless-function</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L89-L91">Source</a></dt>
<dd>

A managed event-driven function runtime.

</dd>
<dd>

Used by [`cloud-run-function`](#rule-cloud-run-function), [`cloud-run-function-v2`](#rule-cloud-run-function-v2).

</dd>
</div>

<div>
<dt id="google-concept-serverless-vpc-access-connector"><code>google.concept.serverless-vpc-access-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/vpc-access.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Serverless VPC Access connector bridging serverless workloads to a VPC network.

</dd>
<dd>

Used by [`cloud-run-service`](#rule-cloud-run-service), [`serverless-vpc-access-connector`](#rule-serverless-vpc-access-connector).

</dd>
</div>

<div>
<dt id="google-concept-service-credential"><code>google.concept.service-credential</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/service-accounts.rf.hcl#L1-L3">Source</a></dt>
<dd>

A credential issued for a service identity.

</dd>
<dd>

Used by [`service-account-key`](#rule-service-account-key).

</dd>
</div>

<div>
<dt id="google-concept-service-identity-binding"><code>google.concept.service-identity-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L93-L95">Source</a></dt>
<dd>

An access-control binding that contributes to a service identity.

</dd>
<dd>

Used by [`project-iam-binding`](#rule-project-iam-binding), [`project-iam-member`](#rule-project-iam-member), [`project-iam-policy`](#rule-project-iam-policy).

</dd>
</div>

<div>
<dt id="google-concept-service-networking-detail"><code>google.concept.service-networking-detail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L97-L99">Source</a></dt>
<dd>

A provider networking detail used to establish private service access.

</dd>
<dd>

Used by [`service-networking-connection`](#rule-service-networking-connection).

</dd>
</div>

<div>
<dt id="google-concept-source-connection"><code>google.concept.source-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed connection from Google Cloud developer services to a source host.

</dd>
<dd>

Used by [`cloud-build-v2-connection`](#rule-cloud-build-v2-connection), [`developer-connect-connection`](#rule-developer-connect-connection).

</dd>
</div>

<div>
<dt id="google-concept-source-repository"><code>google.concept.source-repository</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L1-L3">Source</a></dt>
<dd>

A source-code repository hosted or connected through Google Cloud developer services.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`cloud-build-v2-repository`](#rule-cloud-build-v2-repository)
- [`cloud-source-repository`](#rule-cloud-source-repository)
- [`developer-connect-repository-link`](#rule-developer-connect-repository-link)
- [`secure-source-manager-repository`](#rule-secure-source-manager-repository)

</details>

</dd>
</div>

<div>
<dt id="google-concept-spanner-database"><code>google.concept.spanner-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/spanner.rf.hcl#L1-L3">Source</a></dt>
<dd>

A database belonging to a Spanner instance.

</dd>
<dd>

Used by [`spanner-database`](#rule-spanner-database).

</dd>
</div>

<div>
<dt id="google-concept-vertex-ai-feature-store"><code>google.concept.vertex-ai-feature-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L7-L9">Source</a></dt>
<dd>

A Vertex AI feature store or online feature store.

</dd>
<dd>

Used by [`vertex-ai-feature-online-store`](#rule-vertex-ai-feature-online-store), [`vertex-ai-feature-store`](#rule-vertex-ai-feature-store).

</dd>
</div>

<div>
<dt id="google-concept-vertex-ai-vector-index"><code>google.concept.vertex-ai-vector-index</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L2-L4">Source</a></dt>
<dd>

A Vertex AI vector index.

</dd>
<dd>

Used by [`vector-search-index`](#rule-vector-search-index), [`vertex-ai-vector-index`](#rule-vertex-ai-vector-index).

</dd>
</div>

<div>
<dt id="google-concept-vm-manager-policy"><code>google.concept.vm-manager-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L1-L3">Source</a></dt>
<dd>

A VM Manager policy orchestrating guest configuration or operating system maintenance.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`vm-manager-folder-policy-orchestrator`](#rule-vm-manager-folder-policy-orchestrator)
- [`vm-manager-guest-policy`](#rule-vm-manager-guest-policy)
- [`vm-manager-organization-policy-orchestrator`](#rule-vm-manager-organization-policy-orchestrator)
- [`vm-manager-os-policy-assignment`](#rule-vm-manager-os-policy-assignment)
- [`vm-manager-patch-deployment`](#rule-vm-manager-patch-deployment)
- [`vm-manager-policy-orchestrator`](#rule-vm-manager-policy-orchestrator)

</details>

</dd>
</div>

<div>
<dt id="google-concept-vpc-firewall-rule"><code>google.concept.vpc-firewall-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Google Cloud VPC firewall rule controlling network traffic.

</dd>
<dd>

Used by [`vpc-firewall-rule`](#rule-vpc-firewall-rule).

</dd>
</div>

<div>
<dt id="google-concept-vpn-connection"><code>google.concept.vpn-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L101-L103">Source</a></dt>
<dd>

A virtual private network connection between network endpoints.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

<div>
<dt id="google-concept-vpn-gateway"><code>google.concept.vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L105-L107">Source</a></dt>
<dd>

A managed gateway terminating virtual private network connections.

</dd>
<dd>

Used by [`classic-vpn-gateway`](#rule-classic-vpn-gateway), [`ha-vpn-gateway`](#rule-ha-vpn-gateway).

</dd>
</div>

<div>
<dt id="google-concept-workflow"><code>google.concept.workflow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L109-L111">Source</a></dt>
<dd>

A managed workflow coordinating steps and service calls.

</dd>
<dd>

No Rule in this Dialect uses this definition.

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="google-context-ownership"><code>google.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/vocabulary.rf.hcl#L113-L115">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>


<details>
<summary>Used by 33 Rules</summary>

- [`bigquery-table`](#rule-bigquery-table)
- [`cloud-kms-key`](#rule-cloud-kms-key)
- [`cloud-monitoring-alerting-policy`](#rule-cloud-monitoring-alerting-policy)
- [`cloud-monitoring-service`](#rule-cloud-monitoring-service)
- [`cloud-monitoring-slo`](#rule-cloud-monitoring-slo)
- [`cloud-nat`](#rule-cloud-nat)
- [`cloud-router`](#rule-cloud-router)
- [`cloud-run-job`](#rule-cloud-run-job)
- [`cloud-run-service`](#rule-cloud-run-service)
- [`cloud-run-service-v1`](#rule-cloud-run-service-v1)
- [`cloud-run-worker-pool`](#rule-cloud-run-worker-pool)
- [`cloud-sql-instance`](#rule-cloud-sql-instance)
- [`dataplex-zone`](#rule-dataplex-zone)
- [`gke-cluster`](#rule-gke-cluster)
- [`healthcare-consent-store`](#rule-healthcare-consent-store)
- [`healthcare-dicom-store`](#rule-healthcare-dicom-store)
- [`healthcare-fhir-store`](#rule-healthcare-fhir-store)
- [`healthcare-hl7v2-store`](#rule-healthcare-hl7v2-store)
- [`iam-service-account`](#rule-iam-service-account)
- [`memorystore-instance`](#rule-memorystore-instance)
- [`memorystore-memcached-instance`](#rule-memorystore-memcached-instance)
- [`memorystore-redis-cluster`](#rule-memorystore-redis-cluster)
- [`memorystore-redis-instance`](#rule-memorystore-redis-instance)
- [`netapp-volume`](#rule-netapp-volume)
- [`private-certificate-authority`](#rule-private-certificate-authority)
- [`pubsub-subscription`](#rule-pubsub-subscription)
- [`pubsub-topic`](#rule-pubsub-topic)
- [`secret-manager-regional-secret`](#rule-secret-manager-regional-secret)
- [`secret-manager-secret`](#rule-secret-manager-secret)
- [`serverless-vpc-access-connector`](#rule-serverless-vpc-access-connector)
- [`vpc-firewall-rule`](#rule-vpc-firewall-rule)
- [`vpc-network`](#rule-vpc-network)
- [`vpc-subnetwork`](#rule-vpc-subnetwork)

</details>

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="google-relation-delivers-to"><code>google.relation.delivers-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L53-L63">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`pubsub-subscription`](#rule-pubsub-subscription).

</dd>
</div>

<div>
<dt id="google-relation-routes-to"><code>google.relation.routes-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L73-L83">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`cloud-run-service`](#rule-cloud-run-service).

</dd>
</div>

<div>
<dt id="google-relation-runs-as"><code>google.relation.runs-as</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L85-L98">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`cloud-run-service`](#rule-cloud-run-service).

</dd>
</div>

<div>
<dt id="google-relation-stores-in"><code>google.relation.stores-in</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/backup-dr.rf.hcl#L25-L35">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`backup-dr-backup-plan`](#rule-backup-dr-backup-plan).

</dd>
</div>

<div>
<dt id="google-relation-subscribes-to"><code>google.relation.subscribes-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L41-L51">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`pubsub-subscription`](#rule-pubsub-subscription).

</dd>
</div>

</dl>

## RF Vocabulary used

- [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster)
- [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database)
- [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container)
- [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity)
- [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet)
- [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network)
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network)

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>google.rule.alloydb-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/alloydb.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-alloydb-cluster"></div>

Matches `resource` instances of `google_alloydb_cluster`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.alloydb-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/alloydb.rf.hcl#L22-L43">Source</a></summary>

<div id="rule-alloydb-instance"></div>

Matches `resource` instances of `google_alloydb_instance`.

**Classification:** [`google.concept.alloydb-instance`](#google-concept-alloydb-instance).

**Contributions**

- targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.cluster`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.cluster`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.api-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/api-gateway.rf.hcl#L1-L7">Source</a></summary>

<div id="rule-api-gateway"></div>

Matches `resource` instances of `google_api_gateway_gateway`.

**Classification:** [`google.concept.api-gateway`](#google-concept-api-gateway).

</details>

<details>
<summary><code>google.rule.app-engine-flexible-service-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/app-engine.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-app-engine-flexible-service-version"></div>

Matches `resource` instances of `google_app_engine_flexible_app_version`.

**Classification:** [`google.concept.app-engine-service-version`](#google-concept-app-engine-service-version).

</details>

<details>
<summary><code>google.rule.app-engine-standard-service-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/app-engine.rf.hcl#L7-L13">Source</a></summary>

<div id="rule-app-engine-standard-service-version"></div>

Matches `resource` instances of `google_app_engine_standard_app_version`.

**Classification:** [`google.concept.app-engine-service-version`](#google-concept-app-engine-service-version).

</details>

<details>
<summary><code>google.rule.backup-dr-backup-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/backup-dr.rf.hcl#L18-L36">Source</a></summary>

<div id="rule-backup-dr-backup-plan"></div>

Matches `resource` instances of `google_backup_dr_backup_plan`.

**Classification:** [`google.concept.backup-plan`](#google-concept-backup-plan).

**Relations**

- [`google.relation.stores-in`](#google-relation-stores-in): targets [`google.concept.backup-vault`](#google-concept-backup-vault) through `source.backup_vault`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.backup_vault`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.backup-dr-backup-vault</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/backup-dr.rf.hcl#L1-L16">Source</a></summary>

<div id="rule-backup-dr-backup-vault"></div>

Matches `resource` instances of `google_backup_dr_backup_vault`.

**Classification:** [`google.concept.backup-vault`](#google-concept-backup-vault).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.biglake-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-biglake-catalog"></div>

Matches `resource` instances of `google_biglake_catalog`.

**Classification:** [`google.concept.biglake-catalog`](#google-concept-biglake-catalog).

</details>

<details>
<summary><code>google.rule.biglake-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-biglake-database"></div>

Matches `resource` instances of `google_biglake_database`.

**Classification:** [`google.concept.biglake-database`](#google-concept-biglake-database).

</details>

<details>
<summary><code>google.rule.biglake-hive-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-biglake-hive-catalog"></div>

Matches `resource` instances of `google_biglake_hive_catalog`.

**Classification:** [`google.concept.biglake-catalog`](#google-concept-biglake-catalog).

</details>

<details>
<summary><code>google.rule.biglake-hive-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L45-L51">Source</a></summary>

<div id="rule-biglake-hive-database"></div>

Matches `resource` instances of `google_biglake_hive_database`.

**Classification:** [`google.concept.biglake-database`](#google-concept-biglake-database).

</details>

<details>
<summary><code>google.rule.biglake-hive-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L53-L59">Source</a></summary>

<div id="rule-biglake-hive-table"></div>

Matches `resource` instances of `google_biglake_hive_table`.

**Classification:** [`google.concept.biglake-table`](#google-concept-biglake-table).

</details>

<details>
<summary><code>google.rule.biglake-iceberg-catalog</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L61-L67">Source</a></summary>

<div id="rule-biglake-iceberg-catalog"></div>

Matches `resource` instances of `google_biglake_iceberg_catalog`.

**Classification:** [`google.concept.biglake-catalog`](#google-concept-biglake-catalog).

</details>

<details>
<summary><code>google.rule.biglake-iceberg-namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L69-L75">Source</a></summary>

<div id="rule-biglake-iceberg-namespace"></div>

Matches `resource` instances of `google_biglake_iceberg_namespace`.

**Classification:** [`google.concept.biglake-database`](#google-concept-biglake-database).

</details>

<details>
<summary><code>google.rule.biglake-iceberg-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L77-L83">Source</a></summary>

<div id="rule-biglake-iceberg-table"></div>

Matches `resource` instances of `google_biglake_iceberg_table`.

**Classification:** [`google.concept.biglake-table`](#google-concept-biglake-table).

</details>

<details>
<summary><code>google.rule.biglake-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/biglake.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-biglake-table"></div>

Matches `resource` instances of `google_biglake_table`.

**Classification:** [`google.concept.biglake-table`](#google-concept-biglake-table).

</details>

<details>
<summary><code>google.rule.analytics-hub-data-exchange-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/analytics-hub.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-analytics-hub-data-exchange-subscription"></div>

Matches `resource` instances of `google_bigquery_analytics_hub_data_exchange_subscription`.

**Classification:** [`google.concept.analytics-hub-subscription`](#google-concept-analytics-hub-subscription).

</details>

<details>
<summary><code>google.rule.analytics-hub-listing-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/analytics-hub.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-analytics-hub-listing-subscription"></div>

Matches `resource` instances of `google_bigquery_analytics_hub_listing_subscription`.

**Classification:** [`google.concept.analytics-hub-subscription`](#google-concept-analytics-hub-subscription).

</details>

<details>
<summary><code>google.rule.bigquery-dataset-access</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L56-L74">Source</a></summary>

<div id="rule-bigquery-dataset-access"></div>

Matches `resource` instances of `google_bigquery_dataset_access`.

**Classification:** [`google.concept.access-binding`](#google-concept-access-binding).

**Contributions**

- targets [`google.concept.bigquery-dataset`](#google-concept-bigquery-dataset) through `source.dataset_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.dataset_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.dataset_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.bigquery-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-bigquery-dataset"></div>

Matches `resource` instances of `google_bigquery_dataset`.

**Classification:** [`google.concept.bigquery-dataset`](#google-concept-bigquery-dataset).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["dataset_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["dataset_id", "id", "self_link"]`

</details>

</details>

<details>
<summary><code>google.rule.bigquery-table-iam-member</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L76-L94">Source</a></summary>

<div id="rule-bigquery-table-iam-member"></div>

Matches `resource` instances of `google_bigquery_table_iam_member`.

**Classification:** [`google.concept.access-binding`](#google-concept-access-binding).

**Contributions**

- targets [`google.concept.bigquery-table`](#google-concept-bigquery-table) through `source.table_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.table_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.table_id`
- `match.strategy`: `"last-segment"`

</details>

</details>

<details>
<summary><code>google.rule.bigquery-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/bigquery.rf.hcl#L26-L54">Source</a></summary>

<div id="rule-bigquery-table"></div>

Matches `resource` instances of `google_bigquery_table`.

**Classification:** [`google.concept.bigquery-table`](#google-concept-bigquery-table).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.bigquery-dataset`](#google-concept-bigquery-dataset) through `source.dataset_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["table_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "table_id"]`

**Context through `source.dataset_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.dataset_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.bigtable-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/bigtable.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-bigtable-instance"></div>

Matches `resource` instances of `google_bigtable_instance`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.bigtable-table</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/bigtable.rf.hcl#L22-L43">Source</a></summary>

<div id="rule-bigtable-table"></div>

Matches `resource` instances of `google_bigtable_table`.

**Classification:** [`google.concept.bigtable-table`](#google-concept-bigtable-table).

**Contributions**

- targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.instance_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.instance_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cx-agent-studio-root-agent-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-cx-agent-studio-root-agent-association"></div>

Matches `resource` instances of `google_ces_app_root_agent_association`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-app-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-cx-agent-studio-app-version"></div>

Matches `resource` instances of `google_ces_app_version`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-cx-agent-studio-deployment"></div>

Matches `resource` instances of `google_ces_deployment`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-evaluation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L33-L39">Source</a></summary>

<div id="rule-cx-agent-studio-evaluation"></div>

Matches `resource` instances of `google_ces_evaluation`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-example</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L41-L47">Source</a></summary>

<div id="rule-cx-agent-studio-example"></div>

Matches `resource` instances of `google_ces_example`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-guardrail</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L49-L55">Source</a></summary>

<div id="rule-cx-agent-studio-guardrail"></div>

Matches `resource` instances of `google_ces_guardrail`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-security-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L57-L63">Source</a></summary>

<div id="rule-cx-agent-studio-security-settings"></div>

Matches `resource` instances of `google_ces_security_settings`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-tool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L65-L71">Source</a></summary>

<div id="rule-cx-agent-studio-tool"></div>

Matches `resource` instances of `google_ces_tool`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cx-agent-studio-toolset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/cx-agent-studio.rf.hcl#L73-L79">Source</a></summary>

<div id="rule-cx-agent-studio-toolset"></div>

Matches `resource` instances of `google_ces_toolset`.

**Classification:** [`google.concept.cx-agent-studio-configuration`](#google-concept-cx-agent-studio-configuration).

</details>

<details>
<summary><code>google.rule.cloud-asset-folder-feed</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/cloud-asset-inventory.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-cloud-asset-folder-feed"></div>

Matches `resource` instances of `google_cloud_asset_folder_feed`.

**Classification:** [`google.concept.cloud-asset-feed`](#google-concept-cloud-asset-feed).

</details>

<details>
<summary><code>google.rule.cloud-asset-organization-feed</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/cloud-asset-inventory.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-cloud-asset-organization-feed"></div>

Matches `resource` instances of `google_cloud_asset_organization_feed`.

**Classification:** [`google.concept.cloud-asset-feed`](#google-concept-cloud-asset-feed).

</details>

<details>
<summary><code>google.rule.cloud-asset-project-feed</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/cloud-asset-inventory.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-cloud-asset-project-feed"></div>

Matches `resource` instances of `google_cloud_asset_project_feed`.

**Classification:** [`google.concept.cloud-asset-feed`](#google-concept-cloud-asset-feed).

</details>

<details>
<summary><code>google.rule.cloud-identity-group-membership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/cloud-identity.rf.hcl#L22-L40">Source</a></summary>

<div id="rule-cloud-identity-group-membership"></div>

Matches `resource` instances of `google_cloud_identity_group_membership`.

**Classification:** [`google.concept.cloud-identity-group-membership`](#google-concept-cloud-identity-group-membership).

**Contributions**

- targets [`google.concept.identity-group`](#google-concept-identity-group) through `source.group`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.group`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/cloud-identity.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-cloud-identity-group"></div>

Matches `resource` instances of `google_cloud_identity_group`.

**Classification:** [`google.concept.identity-group`](#google-concept-identity-group).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.cloud-ids-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-ids.rf.hcl#L5-L27">Source</a></summary>

<div id="rule-cloud-ids-endpoint"></div>

Matches `resource` instances of `google_cloud_ids_endpoint`.

**Classification:** [`google.concept.cloud-ids-endpoint`](#google-concept-cloud-ids-endpoint).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-run-service-v1</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L125-L156">Source</a></summary>

<div id="rule-cloud-run-service-v1"></div>

Matches `resource` instances of `google_cloud_run_service`.

**Classification:** [`google.concept.cloud-run-service`](#google-concept-cloud-run-service).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-run-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L101-L123">Source</a></summary>

<div id="rule-cloud-run-job"></div>

Matches `resource` instances of `google_cloud_run_v2_job`.

**Classification:** [`google.concept.cloud-run-job`](#google-concept-cloud-run-job).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-run-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L9-L99">Source</a></summary>

<div id="rule-cloud-run-service"></div>

Matches `resource` instances of `google_cloud_run_v2_service`.

**Classification:** [`google.concept.cloud-run-service`](#google-concept-cloud-run-service).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.template[0].vpc_access[0].network_interfaces[0].network`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.template[0].vpc_access[0].network_interfaces[0].subnetwork`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

**Relations**

- [`google.relation.routes-to`](#google-relation-routes-to): targets [`google.concept.serverless-vpc-access-connector`](#google-concept-serverless-vpc-access-connector) through `source.template[0].vpc_access[0].connector`.
- [`google.relation.runs-as`](#google-relation-runs-as): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.template[0].service_account`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "uri"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "uri"]`

**Context through `source.template[0].vpc_access[0].network_interfaces[0].network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.template[0].vpc_access[0].network_interfaces[0].subnetwork`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

**Relation through `source.template[0].vpc_access[0].connector`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.template[0].service_account`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-run-worker-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-run.rf.hcl#L158-L189">Source</a></summary>

<div id="rule-cloud-run-worker-pool"></div>

Matches `resource` instances of `google_cloud_run_v2_worker_pool`.

**Classification:** [`google.concept.cloud-run-service`](#google-concept-cloud-run-service).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.compliance-manager-cloud-control</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/compliance-manager.rf.hcl#L7-L13">Source</a></summary>

<div id="rule-compliance-manager-cloud-control"></div>

Matches `resource` instances of `google_cloud_security_compliance_cloud_control`.

**Classification:** [`google.concept.compliance-manager-configuration`](#google-concept-compliance-manager-configuration).

</details>

<details>
<summary><code>google.rule.compliance-manager-framework-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/compliance-manager.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-compliance-manager-framework-deployment"></div>

Matches `resource` instances of `google_cloud_security_compliance_framework_deployment`.

**Classification:** [`google.concept.compliance-manager-configuration`](#google-concept-compliance-manager-configuration).

</details>

<details>
<summary><code>google.rule.cloud-build-v2-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-cloud-build-v2-connection"></div>

Matches `resource` instances of `google_cloudbuildv2_connection`.

**Classification:** [`google.concept.source-connection`](#google-concept-source-connection).

</details>

<details>
<summary><code>google.rule.cloud-build-v2-repository</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-cloud-build-v2-repository"></div>

Matches `resource` instances of `google_cloudbuildv2_repository`.

**Classification:** [`google.concept.source-repository`](#google-concept-source-repository).

</details>

<details>
<summary><code>google.rule.cloud-run-function</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-functions.rf.hcl#L1-L7">Source</a></summary>

<div id="rule-cloud-run-function"></div>

Matches `resource` instances of `google_cloudfunctions_function`.

**Classification:** [`google.concept.serverless-function`](#google-concept-serverless-function).

</details>

<details>
<summary><code>google.rule.cloud-run-function-v2</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/serverless/cloud-functions.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-cloud-run-function-v2"></div>

Matches `resource` instances of `google_cloudfunctions2_function`.

**Classification:** [`google.concept.serverless-function`](#google-concept-serverless-function).

</details>

<details>
<summary><code>google.rule.colab-enterprise-runtime-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/colab-enterprise.rf.hcl#L7-L13">Source</a></summary>

<div id="rule-colab-enterprise-runtime-template"></div>

Matches `resource` instances of `google_colab_runtime_template`.

**Classification:** [`google.concept.colab-enterprise-configuration`](#google-concept-colab-enterprise-configuration).

</details>

<details>
<summary><code>google.rule.colab-enterprise-schedule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/colab-enterprise.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-colab-enterprise-schedule"></div>

Matches `resource` instances of `google_colab_schedule`.

**Classification:** [`google.concept.colab-enterprise-configuration`](#google-concept-colab-enterprise-configuration).

</details>

<details>
<summary><code>google.rule.cloud-cdn-backend-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-cdn.rf.hcl#L6-L13">Source</a></summary>

<div id="rule-cloud-cdn-backend-bucket"></div>

Matches `resource` instances of `google_compute_backend_bucket`.

**Classification:** [`google.concept.cloud-cdn-service`](#google-concept-cloud-cdn-service).

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.enable_cdn == true
```

</details>

</details>

<details>
<summary><code>google.rule.persistent-disk</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/persistent-disk.rf.hcl#L1-L7">Source</a></summary>

<div id="rule-persistent-disk"></div>

Matches `resource` instances of `google_compute_disk`.

**Classification:** [`google.concept.block-storage-volume`](#google-concept-block-storage-volume).

</details>

<details>
<summary><code>google.rule.hierarchical-firewall-policy-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L70-L88">Source</a></summary>

<div id="rule-hierarchical-firewall-policy-rule"></div>

Matches `resource` instances of `google_compute_firewall_policy_rule`.

**Classification:** [`google.concept.firewall-policy-rule`](#google-concept-firewall-policy-rule).

**Contributions**

- targets [`google.concept.firewall-policy`](#google-concept-firewall-policy) through `source.firewall_policy`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.firewall_policy`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.id, target.name, target.self_link]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.hierarchical-firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L53-L68">Source</a></summary>

<div id="rule-hierarchical-firewall-policy"></div>

Matches `resource` instances of `google_compute_firewall_policy`.

**Classification:** [`google.concept.firewall-policy`](#google-concept-firewall-policy).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.vpc-firewall-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L13-L51">Source</a></summary>

<div id="rule-vpc-firewall-rule"></div>

Matches `resource` instances of `google_compute_firewall`.

**Classification:** [`google.concept.vpc-firewall-rule`](#google-concept-vpc-firewall-rule).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.private-service-connect-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/connectivity.rf.hcl#L112-L151">Source</a></summary>

<div id="rule-private-service-connect-endpoint"></div>

Matches `resource` instances of `google_compute_forwarding_rule`.

**Classification:** [`google.concept.private-endpoint`](#google-concept-private-endpoint).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.subnetwork`.

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.load_balancing_scheme == ""
```

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.subnetwork`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.regional-load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/load-balancing/regional-load-balancer.rf.hcl#L1-L8">Source</a></summary>

<div id="rule-regional-load-balancer"></div>

Matches `resource` instances of `google_compute_forwarding_rule`.

**Classification:** [`google.concept.load-balancer`](#google-concept-load-balancer).

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.load_balancing_scheme != ""
```

</details>

</details>

<details>
<summary><code>google.rule.private-services-access-range</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/private-services-access.rf.hcl#L24-L46">Source</a></summary>

<div id="rule-private-services-access-range"></div>

Matches `resource` instances of `google_compute_global_address`.

**Classification:** [`google.concept.allocated-network-range`](#google-concept-allocated-network-range).

**Contributions**

- targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Condition**

```rf
source.purpose == "VPC_PEERING" && source.address_type == "INTERNAL"
```

**Contribution through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.application-load-balancer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/load-balancing/application-load-balancer.rf.hcl#L1-L33">Source</a></summary>

<div id="rule-application-load-balancer"></div>

Matches `resource` instances of `google_compute_global_forwarding_rule`.

**Classification:** [`google.concept.load-balancer`](#google-concept-load-balancer).

**Composition members, in declared order**

1. **`target-https-proxy`** matches `"google_compute_target_https_proxy"` (`"resource"`), through `source.target`.
2. **`url-map`** matches `"google_compute_url_map"` (`"resource"`), through `member.target-https-proxy.url_map`. Depends on `target-https-proxy`.
3. **`backend-service`** matches `"google_compute_backend_service"` (`"resource"`), through `member.url-map.default_service`. Depends on `url-map`.

</details>

<details>
<summary><code>google.rule.ha-vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/connectivity.rf.hcl#L63-L85">Source</a></summary>

<div id="rule-ha-vpn-gateway"></div>

Matches `resource` instances of `google_compute_ha_vpn_gateway`.

**Classification:** [`google.concept.vpn-gateway`](#google-concept-vpn-gateway).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.compute-instance-from-machine-image</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-compute-instance-from-machine-image"></div>

Matches `resource` instances of `google_compute_instance_from_machine_image`.

**Classification:** [`google.concept.compute-instance`](#google-concept-compute-instance).

</details>

<details>
<summary><code>google.rule.compute-instance-from-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-compute-instance-from-template"></div>

Matches `resource` instances of `google_compute_instance_from_template`.

**Classification:** [`google.concept.compute-instance`](#google-concept-compute-instance).

</details>

<details>
<summary><code>google.rule.zonal-managed-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-zonal-managed-instance-group"></div>

Matches `resource` instances of `google_compute_instance_group_manager`.

**Classification:** [`google.concept.compute-instance-group`](#google-concept-compute-instance-group).

</details>

<details>
<summary><code>google.rule.unmanaged-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-unmanaged-instance-group"></div>

Matches `resource` instances of `google_compute_instance_group`.

**Classification:** [`google.concept.compute-instance-group`](#google-concept-compute-instance-group).

</details>

<details>
<summary><code>google.rule.compute-engine-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/compute-engine.rf.hcl#L1-L7">Source</a></summary>

<div id="rule-compute-engine-instance"></div>

Matches `resource` instances of `google_compute_instance`.

**Classification:** [`google.concept.compute-instance`](#google-concept-compute-instance).

</details>

<details>
<summary><code>google.rule.network-firewall-policy-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L107-L125">Source</a></summary>

<div id="rule-network-firewall-policy-rule"></div>

Matches `resource` instances of `google_compute_network_firewall_policy_rule`.

**Classification:** [`google.concept.firewall-policy-rule`](#google-concept-firewall-policy-rule).

**Contributions**

- targets [`google.concept.firewall-policy`](#google-concept-firewall-policy) through `source.firewall_policy`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.firewall_policy`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id, target.self_link]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.network-firewall-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/firewall.rf.hcl#L90-L105">Source</a></summary>

<div id="rule-network-firewall-policy"></div>

Matches `resource` instances of `google_compute_network_firewall_policy`.

**Classification:** [`google.concept.firewall-policy`](#google-concept-firewall-policy).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.vpc-network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/connectivity.rf.hcl#L2-L40">Source</a></summary>

<div id="rule-vpc-network-peering"></div>

Matches `resource` instances of `google_compute_network_peering`.

**Classification:** [`google.concept.network-peering`](#google-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.peer_network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.peer_network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.vpc-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/vpc.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-vpc-network"></div>

Matches `resource` instances of `google_compute_network`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.regional-persistent-disk</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/persistent-disk.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-regional-persistent-disk"></div>

Matches `resource` instances of `google_compute_region_disk`.

**Classification:** [`google.concept.block-storage-volume`](#google-concept-block-storage-volume).

</details>

<details>
<summary><code>google.rule.regional-managed-instance-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/managed-instance-groups.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-regional-managed-instance-group"></div>

Matches `resource` instances of `google_compute_region_instance_group_manager`.

**Classification:** [`google.concept.compute-instance-group`](#google-concept-compute-instance-group).

</details>

<details>
<summary><code>google.rule.cloud-nat</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/connectivity.rf.hcl#L42-L61">Source</a></summary>

<div id="rule-cloud-nat"></div>

Matches `resource` instances of `google_compute_router_nat`.

**Classification:** [`google.concept.managed-nat`](#google-concept-managed-nat).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.cloud-router`](#google-concept-cloud-router) through `source.router`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.router`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id, target.self_link]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-router</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-router.rf.hcl#L5-L52">Source</a></summary>

<div id="rule-cloud-router"></div>

Matches `resource` instances of `google_compute_router`.

**Classification:** [`google.concept.cloud-router`](#google-concept-cloud-router).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-armor-security-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-armor.rf.hcl#L26-L44">Source</a></summary>

<div id="rule-cloud-armor-security-rule"></div>

Matches `resource` instances of `google_compute_security_policy_rule`.

**Classification:** [`google.concept.cloud-armor-security-rule`](#google-concept-cloud-armor-security-rule).

**Contributions**

- targets [`google.concept.cloud-armor-security-policy`](#google-concept-cloud-armor-security-policy) through `source.security_policy`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.security_policy`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id, target.self_link]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-armor-security-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-armor.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-cloud-armor-security-policy"></div>

Matches `resource` instances of `google_compute_security_policy`.

**Classification:** [`google.concept.cloud-armor-security-policy`](#google-concept-cloud-armor-security-policy).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.vpc-subnetwork</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/vpc.rf.hcl#L34-L81">Source</a></summary>

<div id="rule-vpc-subnetwork"></div>

Matches `resource` instances of `google_compute_subnetwork`.

**Classification:** [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "self_link", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link", "name"]`

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.classic-vpn-gateway</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/connectivity.rf.hcl#L87-L109">Source</a></summary>

<div id="rule-classic-vpn-gateway"></div>

Matches `resource` instances of `google_compute_vpn_gateway`.

**Classification:** [`google.concept.vpn-gateway`](#google-concept-vpn-gateway).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.gke-attached-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L89-L104">Source</a></summary>

<div id="rule-gke-attached-cluster"></div>

Matches `resource` instances of `google_container_attached_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.gke-aws-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L106-L121">Source</a></summary>

<div id="rule-gke-aws-cluster"></div>

Matches `resource` instances of `google_container_aws_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.gke-aws-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L123-L129">Source</a></summary>

<div id="rule-gke-aws-node-pool"></div>

Matches `resource` instances of `google_container_aws_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

</details>

<details>
<summary><code>google.rule.gke-azure-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L131-L146">Source</a></summary>

<div id="rule-gke-azure-cluster"></div>

Matches `resource` instances of `google_container_azure_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.gke-azure-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L148-L154">Source</a></summary>

<div id="rule-gke-azure-node-pool"></div>

Matches `resource` instances of `google_container_azure_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

</details>

<details>
<summary><code>google.rule.gke-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L1-L64">Source</a></summary>

<div id="rule-gke-cluster"></div>

Matches `resource` instances of `google_container_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.subnetwork`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name", "self_link", "endpoint"]`

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.subnetwork`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.gke-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/containers/gke.rf.hcl#L66-L87">Source</a></summary>

<div id="rule-gke-node-pool"></div>

Matches `resource` instances of `google_container_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

**Contributions**

- targets [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) through `source.cluster`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.cluster`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.name, target.id, target.self_link]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.sensitive-data-protection-deidentify-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-sensitive-data-protection-deidentify-template"></div>

Matches `resource` instances of `google_data_loss_prevention_deidentify_template`.

**Classification:** [`google.concept.sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template).

</details>

<details>
<summary><code>google.rule.sensitive-data-protection-discovery</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-sensitive-data-protection-discovery"></div>

Matches `resource` instances of `google_data_loss_prevention_discovery_config`.

**Classification:** [`google.concept.sensitive-data-protection-scan`](#google-concept-sensitive-data-protection-scan).

</details>

<details>
<summary><code>google.rule.sensitive-data-protection-inspect-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L33-L39">Source</a></summary>

<div id="rule-sensitive-data-protection-inspect-template"></div>

Matches `resource` instances of `google_data_loss_prevention_inspect_template`.

**Classification:** [`google.concept.sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template).

</details>

<details>
<summary><code>google.rule.sensitive-data-protection-job-trigger</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-sensitive-data-protection-job-trigger"></div>

Matches `resource` instances of `google_data_loss_prevention_job_trigger`.

**Classification:** [`google.concept.sensitive-data-protection-scan`](#google-concept-sensitive-data-protection-scan).

</details>

<details>
<summary><code>google.rule.sensitive-data-protection-stored-info-type</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/sensitive-data-protection.rf.hcl#L41-L47">Source</a></summary>

<div id="rule-sensitive-data-protection-stored-info-type"></div>

Matches `resource` instances of `google_data_loss_prevention_stored_info_type`.

**Classification:** [`google.concept.sensitive-data-protection-template`](#google-concept-sensitive-data-protection-template).

</details>

<details>
<summary><code>google.rule.database-migration-connection-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/database-migration.rf.hcl#L7-L13">Source</a></summary>

<div id="rule-database-migration-connection-profile"></div>

Matches `resource` instances of `google_database_migration_service_connection_profile`.

**Classification:** [`google.concept.database-migration-connection`](#google-concept-database-migration-connection).

</details>

<details>
<summary><code>google.rule.database-migration-private-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/database-migration.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-database-migration-private-connection"></div>

Matches `resource` instances of `google_database_migration_service_private_connection`.

**Classification:** [`google.concept.database-migration-connection`](#google-concept-database-migration-connection).

</details>

<details>
<summary><code>google.rule.dataflow-flex-template-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataflow.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-dataflow-flex-template-job"></div>

Matches `resource` instances of `google_dataflow_flex_template_job`.

**Classification:** [`google.concept.dataflow-job`](#google-concept-dataflow-job).

</details>

<details>
<summary><code>google.rule.dataflow-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataflow.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-dataflow-job"></div>

Matches `resource` instances of `google_dataflow_job`.

**Classification:** [`google.concept.dataflow-job`](#google-concept-dataflow-job).

</details>

<details>
<summary><code>google.rule.dataplex-asset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L52-L58">Source</a></summary>

<div id="rule-dataplex-asset"></div>

Matches `resource` instances of `google_dataplex_asset`.

**Classification:** [`google.concept.dataplex-asset`](#google-concept-dataplex-asset).

</details>

<details>
<summary><code>google.rule.dataplex-data-asset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L60-L66">Source</a></summary>

<div id="rule-dataplex-data-asset"></div>

Matches `resource` instances of `google_dataplex_data_asset`.

**Classification:** [`google.concept.dataplex-asset`](#google-concept-dataplex-asset).

</details>

<details>
<summary><code>google.rule.dataplex-lake</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L14-L29">Source</a></summary>

<div id="rule-dataplex-lake"></div>

Matches `resource` instances of `google_dataplex_lake`.

**Classification:** [`google.concept.dataplex-lake`](#google-concept-dataplex-lake).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.dataplex-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/dataplex.rf.hcl#L31-L50">Source</a></summary>

<div id="rule-dataplex-zone"></div>

Matches `resource` instances of `google_dataplex_zone`.

**Classification:** [`google.concept.dataplex-zone`](#google-concept-dataplex-zone).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.dataplex-lake`](#google-concept-dataplex-lake) through `source.lake`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.lake`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.developer-connect-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-developer-connect-connection"></div>

Matches `resource` instances of `google_developer_connect_connection`.

**Classification:** [`google.concept.source-connection`](#google-concept-source-connection).

</details>

<details>
<summary><code>google.rule.developer-connect-repository-link</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-developer-connect-repository-link"></div>

Matches `resource` instances of `google_developer_connect_git_repository_link`.

**Classification:** [`google.concept.source-repository`](#google-concept-source-repository).

</details>

<details>
<summary><code>google.rule.dialogflow-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/dialogflow.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-dialogflow-agent"></div>

Matches `resource` instances of `google_dialogflow_agent`.

**Classification:** [`google.concept.conversational-agent`](#google-concept-conversational-agent).

</details>

<details>
<summary><code>google.rule.dialogflow-cx-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/dialogflow.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-dialogflow-cx-agent"></div>

Matches `resource` instances of `google_dialogflow_cx_agent`.

**Classification:** [`google.concept.conversational-agent`](#google-concept-conversational-agent).

</details>

<details>
<summary><code>google.rule.discovery-engine-chat-engine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/discovery-engine.rf.hcl#L16-L22">Source</a></summary>

<div id="rule-discovery-engine-chat-engine"></div>

Matches `resource` instances of `google_discovery_engine_chat_engine`.

**Classification:** [`google.concept.discovery-engine`](#google-concept-discovery-engine).

</details>

<details>
<summary><code>google.rule.discovery-engine-recommendation-engine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/discovery-engine.rf.hcl#L24-L30">Source</a></summary>

<div id="rule-discovery-engine-recommendation-engine"></div>

Matches `resource` instances of `google_discovery_engine_recommendation_engine`.

**Classification:** [`google.concept.discovery-engine`](#google-concept-discovery-engine).

</details>

<details>
<summary><code>google.rule.discovery-engine-search-engine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/discovery-engine.rf.hcl#L8-L14">Source</a></summary>

<div id="rule-discovery-engine-search-engine"></div>

Matches `resource` instances of `google_discovery_engine_search_engine`.

**Classification:** [`google.concept.discovery-engine`](#google-concept-discovery-engine).

</details>

<details>
<summary><code>google.rule.cloud-dns-managed-zone</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-dns.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-cloud-dns-managed-zone"></div>

Matches `resource` instances of `google_dns_managed_zone`.

**Classification:** [`google.concept.dns-zone`](#google-concept-dns-zone).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.cloud-dns-record-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-dns.rf.hcl#L22-L43">Source</a></summary>

<div id="rule-cloud-dns-record-set"></div>

Matches `resource` instances of `google_dns_record_set`.

**Classification:** [`google.concept.cloud-dns-record-set`](#google-concept-cloud-dns-record-set).

**Contributions**

- targets [`google.concept.dns-zone`](#google-concept-dns-zone) through `source.managed_zone`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.managed_zone`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.edge-container-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L3-L18">Source</a></summary>

<div id="rule-edge-container-cluster"></div>

Matches `resource` instances of `google_edgecontainer_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.edge-container-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L20-L26">Source</a></summary>

<div id="rule-edge-container-node-pool"></div>

Matches `resource` instances of `google_edgecontainer_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

</details>

<details>
<summary><code>google.rule.edge-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/edge-network.rf.hcl#L2-L17">Source</a></summary>

<div id="rule-edge-network"></div>

Matches `resource` instances of `google_edgenetwork_network`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.edge-network-subnet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/edge-network.rf.hcl#L19-L34">Source</a></summary>

<div id="rule-edge-network-subnet"></div>

Matches `resource` instances of `google_edgenetwork_subnet`.

**Classification:** [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.cloud-endpoints-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/cloud-endpoints.rf.hcl#L1-L7">Source</a></summary>

<div id="rule-cloud-endpoints-service"></div>

Matches `resource` instances of `google_endpoints_service`.

**Classification:** [`google.concept.api-gateway`](#google-concept-api-gateway).

</details>

<details>
<summary><code>google.rule.filestore-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-filestore-instance"></div>

Matches `resource` instances of `google_filestore_instance`.

**Classification:** [`google.concept.managed-file-storage`](#google-concept-managed-file-storage).

</details>

<details>
<summary><code>google.rule.firebase-realtime-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/firebase.rf.hcl#L2-L17">Source</a></summary>

<div id="rule-firebase-realtime-database"></div>

Matches `resource` instances of `google_firebase_database_instance`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.firestore-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/firestore.rf.hcl#L1-L16">Source</a></summary>

<div id="rule-firestore-database"></div>

Matches `resource` instances of `google_firestore_database`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.gke-backup-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/gke-backup.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-gke-backup-channel"></div>

Matches `resource` instances of `google_gke_backup_backup_channel`.

**Classification:** [`google.concept.gke-backup-channel`](#google-concept-gke-backup-channel).

</details>

<details>
<summary><code>google.rule.gke-backup-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/gke-backup.rf.hcl#L6-L12">Source</a></summary>

<div id="rule-gke-backup-plan"></div>

Matches `resource` instances of `google_gke_backup_backup_plan`.

**Classification:** [`google.concept.backup-plan`](#google-concept-backup-plan).

</details>

<details>
<summary><code>google.rule.gke-restore-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/gke-backup.rf.hcl#L23-L29">Source</a></summary>

<div id="rule-gke-restore-channel"></div>

Matches `resource` instances of `google_gke_backup_restore_channel`.

**Classification:** [`google.concept.gke-backup-channel`](#google-concept-gke-backup-channel).

</details>

<details>
<summary><code>google.rule.bare-metal-gdc-admin-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L45-L60">Source</a></summary>

<div id="rule-bare-metal-gdc-admin-cluster"></div>

Matches `resource` instances of `google_gkeonprem_bare_metal_admin_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.bare-metal-gdc-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L28-L43">Source</a></summary>

<div id="rule-bare-metal-gdc-cluster"></div>

Matches `resource` instances of `google_gkeonprem_bare_metal_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.bare-metal-gdc-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L62-L68">Source</a></summary>

<div id="rule-bare-metal-gdc-node-pool"></div>

Matches `resource` instances of `google_gkeonprem_bare_metal_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

</details>

<details>
<summary><code>google.rule.vmware-gdc-admin-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L87-L102">Source</a></summary>

<div id="rule-vmware-gdc-admin-cluster"></div>

Matches `resource` instances of `google_gkeonprem_vmware_admin_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.vmware-gdc-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L70-L85">Source</a></summary>

<div id="rule-vmware-gdc-cluster"></div>

Matches `resource` instances of `google_gkeonprem_vmware_cluster`.

**Classification:** [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.vmware-gdc-node-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/distributed-cloud.rf.hcl#L104-L110">Source</a></summary>

<div id="rule-vmware-gdc-node-pool"></div>

Matches `resource` instances of `google_gkeonprem_vmware_node_pool`.

**Classification:** [`google.concept.kubernetes-node-pool`](#google-concept-kubernetes-node-pool).

</details>

<details>
<summary><code>google.rule.healthcare-consent-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L90-L109">Source</a></summary>

<div id="rule-healthcare-consent-store"></div>

Matches `resource` instances of `google_healthcare_consent_store`.

**Classification:** [`google.concept.healthcare-store`](#google-concept-healthcare-store).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.healthcare-dataset`](#google-concept-healthcare-dataset) through `source.dataset`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.dataset`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.healthcare-dataset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L10-L25">Source</a></summary>

<div id="rule-healthcare-dataset"></div>

Matches `resource` instances of `google_healthcare_dataset`.

**Classification:** [`google.concept.healthcare-dataset`](#google-concept-healthcare-dataset).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link"]`

</details>

</details>

<details>
<summary><code>google.rule.healthcare-dicom-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L48-L67">Source</a></summary>

<div id="rule-healthcare-dicom-store"></div>

Matches `resource` instances of `google_healthcare_dicom_store`.

**Classification:** [`google.concept.healthcare-store`](#google-concept-healthcare-store).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.healthcare-dataset`](#google-concept-healthcare-dataset) through `source.dataset`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.dataset`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.healthcare-fhir-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L27-L46">Source</a></summary>

<div id="rule-healthcare-fhir-store"></div>

Matches `resource` instances of `google_healthcare_fhir_store`.

**Classification:** [`google.concept.healthcare-store`](#google-concept-healthcare-store).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.healthcare-dataset`](#google-concept-healthcare-dataset) through `source.dataset`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.dataset`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.healthcare-hl7v2-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/api-integration/healthcare-api.rf.hcl#L69-L88">Source</a></summary>

<div id="rule-healthcare-hl7v2-store"></div>

Matches `resource` instances of `google_healthcare_hl7_v2_store`.

**Classification:** [`google.concept.healthcare-store`](#google-concept-healthcare-store).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.healthcare-dataset`](#google-concept-healthcare-dataset) through `source.dataset`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.dataset`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-kms-key-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-kms.rf.hcl#L56-L77">Source</a></summary>

<div id="rule-cloud-kms-key-version"></div>

Matches `resource` instances of `google_kms_crypto_key_version`.

**Classification:** [`google.concept.cloud-kms-key-version`](#google-concept-cloud-kms-key-version).

**Contributions**

- targets [`google.concept.encryption-key`](#google-concept-encryption-key) through `source.crypto_key`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.crypto_key`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-kms-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-kms.rf.hcl#L26-L54">Source</a></summary>

<div id="rule-cloud-kms-key"></div>

Matches `resource` instances of `google_kms_crypto_key`.

**Classification:** [`google.concept.encryption-key`](#google-concept-encryption-key).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.cloud-kms-key-ring`](#google-concept-cloud-kms-key-ring) through `source.key_ring`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.key_ring`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-kms-key-ring</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/cloud-kms.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-cloud-kms-key-ring"></div>

Matches `resource` instances of `google_kms_key_ring`.

**Classification:** [`google.concept.cloud-kms-key-ring`](#google-concept-cloud-kms-key-ring).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.cloud-logging-billing-account-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L66-L72">Source</a></summary>

<div id="rule-cloud-logging-billing-account-bucket"></div>

Matches `resource` instances of `google_logging_billing_account_bucket_config`.

**Classification:** [`google.concept.cloud-logging-bucket`](#google-concept-cloud-logging-bucket).

</details>

<details>
<summary><code>google.rule.cloud-logging-billing-account-sink</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-cloud-logging-billing-account-sink"></div>

Matches `resource` instances of `google_logging_billing_account_sink`.

**Classification:** [`google.concept.cloud-logging-sink`](#google-concept-cloud-logging-sink).

</details>

<details>
<summary><code>google.rule.cloud-logging-folder-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L50-L56">Source</a></summary>

<div id="rule-cloud-logging-folder-bucket"></div>

Matches `resource` instances of `google_logging_folder_bucket_config`.

**Classification:** [`google.concept.cloud-logging-bucket`](#google-concept-cloud-logging-bucket).

</details>

<details>
<summary><code>google.rule.cloud-logging-folder-sink</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L18-L24">Source</a></summary>

<div id="rule-cloud-logging-folder-sink"></div>

Matches `resource` instances of `google_logging_folder_sink`.

**Classification:** [`google.concept.cloud-logging-sink`](#google-concept-cloud-logging-sink).

</details>

<details>
<summary><code>google.rule.cloud-logging-organization-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L58-L64">Source</a></summary>

<div id="rule-cloud-logging-organization-bucket"></div>

Matches `resource` instances of `google_logging_organization_bucket_config`.

**Classification:** [`google.concept.cloud-logging-bucket`](#google-concept-cloud-logging-bucket).

</details>

<details>
<summary><code>google.rule.cloud-logging-organization-sink</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-cloud-logging-organization-sink"></div>

Matches `resource` instances of `google_logging_organization_sink`.

**Classification:** [`google.concept.cloud-logging-sink`](#google-concept-cloud-logging-sink).

</details>

<details>
<summary><code>google.rule.cloud-logging-project-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-cloud-logging-project-bucket"></div>

Matches `resource` instances of `google_logging_project_bucket_config`.

**Classification:** [`google.concept.cloud-logging-bucket`](#google-concept-cloud-logging-bucket).

</details>

<details>
<summary><code>google.rule.cloud-logging-project-sink</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-logging.rf.hcl#L10-L16">Source</a></summary>

<div id="rule-cloud-logging-project-sink"></div>

Matches `resource` instances of `google_logging_project_sink`.

**Classification:** [`google.concept.cloud-logging-sink`](#google-concept-cloud-logging-sink).

</details>

<details>
<summary><code>google.rule.managed-lustre-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L75-L81">Source</a></summary>

<div id="rule-managed-lustre-instance"></div>

Matches `resource` instances of `google_lustre_instance`.

**Classification:** [`google.concept.managed-file-storage`](#google-concept-managed-file-storage).

</details>

<details>
<summary><code>google.rule.managed-kafka-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/managed-kafka.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-managed-kafka-topic"></div>

Matches `resource` instances of `google_managed_kafka_topic`.

**Classification:** [`google.concept.message-topic`](#google-concept-message-topic).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.memorystore-memcached-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/memorystore.rf.hcl#L65-L103">Source</a></summary>

<div id="rule-memorystore-memcached-instance"></div>

Matches `resource` instances of `google_memcache_instance`.

**Classification:** [`google.concept.managed-cache`](#google-concept-managed-cache).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.authorized_network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.authorized_network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.memorystore-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/memorystore.rf.hcl#L105-L127">Source</a></summary>

<div id="rule-memorystore-instance"></div>

Matches `resource` instances of `google_memorystore_instance`.

**Classification:** [`google.concept.managed-cache`](#google-concept-managed-cache).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.migration-center-assets-export-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-migration-center-assets-export-job"></div>

Matches `resource` instances of `google_migration_center_assets_export_job`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-migration-center-group"></div>

Matches `resource` instances of `google_migration_center_group`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-import-data-file</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-migration-center-import-data-file"></div>

Matches `resource` instances of `google_migration_center_import_data_file`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-import-job</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L33-L39">Source</a></summary>

<div id="rule-migration-center-import-job"></div>

Matches `resource` instances of `google_migration_center_import_job`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-preference-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L41-L47">Source</a></summary>

<div id="rule-migration-center-preference-set"></div>

Matches `resource` instances of `google_migration_center_preference_set`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-report-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L57-L63">Source</a></summary>

<div id="rule-migration-center-report-config"></div>

Matches `resource` instances of `google_migration_center_report_config`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-report</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L49-L55">Source</a></summary>

<div id="rule-migration-center-report"></div>

Matches `resource` instances of `google_migration_center_report`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.migration-center-settings</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/migration/migration-center.rf.hcl#L65-L71">Source</a></summary>

<div id="rule-migration-center-settings"></div>

Matches `resource` instances of `google_migration_center_settings`.

**Classification:** [`google.concept.migration-center-assessment`](#google-concept-migration-center-assessment).

</details>

<details>
<summary><code>google.rule.cloud-monitoring-alerting-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L13-L35">Source</a></summary>

<div id="rule-cloud-monitoring-alerting-policy"></div>

Matches `resource` instances of `google_monitoring_alert_policy`.

**Classification:** [`google.concept.cloud-monitoring-alerting-policy`](#google-concept-cloud-monitoring-alerting-policy).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-monitoring-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L37-L68">Source</a></summary>

<div id="rule-cloud-monitoring-service"></div>

Matches `resource` instances of `google_monitoring_service`.

**Classification:** [`google.concept.cloud-monitoring-service`](#google-concept-cloud-monitoring-service).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name", "service_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name", "service_id"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-monitoring-slo</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/cloud-monitoring.rf.hcl#L70-L104">Source</a></summary>

<div id="rule-cloud-monitoring-slo"></div>

Matches `resource` instances of `google_monitoring_slo`.

**Classification:** [`google.concept.cloud-monitoring-slo`](#google-concept-cloud-monitoring-slo).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

**Contributions**

- targets [`google.concept.cloud-monitoring-service`](#google-concept-cloud-monitoring-service) through `source.service`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.service`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.service_id, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.netapp-storage-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L13-L28">Source</a></summary>

<div id="rule-netapp-storage-pool"></div>

Matches `resource` instances of `google_netapp_storage_pool`.

**Classification:** [`google.concept.netapp-storage-pool`](#google-concept-netapp-storage-pool).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.netapp-volume</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L30-L49">Source</a></summary>

<div id="rule-netapp-volume"></div>

Matches `resource` instances of `google_netapp_volume`.

**Classification:** [`google.concept.managed-file-storage`](#google-concept-managed-file-storage).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.netapp-storage-pool`](#google-concept-netapp-storage-pool) through `source.storage_pool`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.storage_pool`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.network-connectivity-center-hub</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/network-connectivity-center.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-network-connectivity-center-hub"></div>

Matches `resource` instances of `google_network_connectivity_hub`.

**Classification:** [`google.concept.network-connectivity-center-hub`](#google-concept-network-connectivity-center-hub).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.network-connectivity-center-spoke</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/network-connectivity-center.rf.hcl#L26-L44">Source</a></summary>

<div id="rule-network-connectivity-center-spoke"></div>

Matches `resource` instances of `google_network_connectivity_spoke`.

**Classification:** [`google.concept.network-connectivity-center-spoke`](#google-concept-network-connectivity-center-spoke).

**Contributions**

- targets [`google.concept.network-connectivity-center-hub`](#google-concept-network-connectivity-center-hub) through `source.hub`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.hub`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.media-cdn-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/dns-cdn/cloud-cdn.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-media-cdn-service"></div>

Matches `resource` instances of `google_network_services_edge_cache_service`.

**Classification:** [`google.concept.cloud-cdn-service`](#google-concept-cloud-cdn-service).

</details>

<details>
<summary><code>google.rule.network-services-grpc-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/service-mesh.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-network-services-grpc-route"></div>

Matches `resource` instances of `google_network_services_grpc_route`.

**Classification:** [`google.concept.network-services-route`](#google-concept-network-services-route).

</details>

<details>
<summary><code>google.rule.network-services-http-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/service-mesh.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-network-services-http-route"></div>

Matches `resource` instances of `google_network_services_http_route`.

**Classification:** [`google.concept.network-services-route`](#google-concept-network-services-route).

</details>

<details>
<summary><code>google.rule.multicast-consumer-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-multicast-consumer-association"></div>

Matches `resource` instances of `google_network_services_multicast_consumer_association`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-domain-activation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-multicast-domain-activation"></div>

Matches `resource` instances of `google_network_services_multicast_domain_activation`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-group-consumer-activation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L49-L55">Source</a></summary>

<div id="rule-multicast-group-consumer-activation"></div>

Matches `resource` instances of `google_network_services_multicast_group_consumer_activation`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-group-producer-activation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L57-L63">Source</a></summary>

<div id="rule-multicast-group-producer-activation"></div>

Matches `resource` instances of `google_network_services_multicast_group_producer_activation`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-group-range-activation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L41-L47">Source</a></summary>

<div id="rule-multicast-group-range-activation"></div>

Matches `resource` instances of `google_network_services_multicast_group_range_activation`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-group-range</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L33-L39">Source</a></summary>

<div id="rule-multicast-group-range"></div>

Matches `resource` instances of `google_network_services_multicast_group_range`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.multicast-producer-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/cloud-multicast.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-multicast-producer-association"></div>

Matches `resource` instances of `google_network_services_multicast_producer_association`.

**Classification:** [`google.concept.multicast-configuration`](#google-concept-multicast-configuration).

</details>

<details>
<summary><code>google.rule.network-services-tcp-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/service-mesh.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-network-services-tcp-route"></div>

Matches `resource` instances of `google_network_services_tcp_route`.

**Classification:** [`google.concept.network-services-route`](#google-concept-network-services-route).

</details>

<details>
<summary><code>google.rule.network-services-tls-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/service-mesh.rf.hcl#L33-L39">Source</a></summary>

<div id="rule-network-services-tls-route"></div>

Matches `resource` instances of `google_network_services_tls_route`.

**Classification:** [`google.concept.network-services-route`](#google-concept-network-services-route).

</details>

<details>
<summary><code>google.rule.oracle-autonomous-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/oracle-database.rf.hcl#L3-L18">Source</a></summary>

<div id="rule-oracle-autonomous-database"></div>

Matches `resource` instances of `google_oracle_database_autonomous_database`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.oracle-odb-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/oracle-database.rf.hcl#L22-L37">Source</a></summary>

<div id="rule-oracle-odb-network"></div>

Matches `resource` instances of `google_oracle_database_odb_network`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.oracle-odb-subnet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/oracle-database.rf.hcl#L39-L54">Source</a></summary>

<div id="rule-oracle-odb-subnet"></div>

Matches `resource` instances of `google_oracle_database_odb_subnet`.

**Classification:** [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.vm-manager-guest-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-vm-manager-guest-policy"></div>

Matches `resource` instances of `google_os_config_guest_policies`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.vm-manager-os-policy-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-vm-manager-os-policy-assignment"></div>

Matches `resource` instances of `google_os_config_os_policy_assignment`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.vm-manager-patch-deployment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L21-L27">Source</a></summary>

<div id="rule-vm-manager-patch-deployment"></div>

Matches `resource` instances of `google_os_config_patch_deployment`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.vm-manager-folder-policy-orchestrator</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-vm-manager-folder-policy-orchestrator"></div>

Matches `resource` instances of `google_os_config_v2_policy_orchestrator_for_folder`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.vm-manager-organization-policy-orchestrator</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L45-L51">Source</a></summary>

<div id="rule-vm-manager-organization-policy-orchestrator"></div>

Matches `resource` instances of `google_os_config_v2_policy_orchestrator_for_organization`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.vm-manager-policy-orchestrator</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/operations/vm-manager.rf.hcl#L29-L35">Source</a></summary>

<div id="rule-vm-manager-policy-orchestrator"></div>

Matches `resource` instances of `google_os_config_v2_policy_orchestrator`.

**Classification:** [`google.concept.vm-manager-policy`](#google-concept-vm-manager-policy).

</details>

<details>
<summary><code>google.rule.parallelstore-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/file-storage.rf.hcl#L51-L73">Source</a></summary>

<div id="rule-parallelstore-instance"></div>

Matches `resource` instances of `google_parallelstore_instance`.

**Classification:** [`google.concept.managed-file-storage`](#google-concept-managed-file-storage).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.private-ca-pool</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/private-ca.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-private-ca-pool"></div>

Matches `resource` instances of `google_privateca_ca_pool`.

**Classification:** [`google.concept.private-ca-pool`](#google-concept-private-ca-pool).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.private-certificate-authority</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/private-ca.rf.hcl#L26-L45">Source</a></summary>

<div id="rule-private-certificate-authority"></div>

Matches `resource` instances of `google_privateca_certificate_authority`.

**Classification:** [`google.concept.private-certificate-authority`](#google-concept-private-certificate-authority).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.private-ca-pool`](#google-concept-private-ca-pool) through `source.pool`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.pool`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.name, target.id]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.project-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/project-iam.rf.hcl#L28-L53">Source</a></summary>

<div id="rule-project-iam-binding"></div>

Matches `resource` instances of `google_project_iam_binding`.

**Classification:** [`google.concept.service-identity-binding`](#google-concept-service-identity-binding).

**Contributions**

- targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.members`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.members`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `prefix`: `"serviceAccount:"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.project-iam-member</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/project-iam.rf.hcl#L1-L26">Source</a></summary>

<div id="rule-project-iam-member"></div>

Matches `resource` instances of `google_project_iam_member`.

**Classification:** [`google.concept.service-identity-binding`](#google-concept-service-identity-binding).

**Contributions**

- targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.member`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.member`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `prefix`: `"serviceAccount:"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.project-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/project-iam.rf.hcl#L55-L61">Source</a></summary>

<div id="rule-project-iam-policy"></div>

Matches `resource` instances of `google_project_iam_policy`.

**Classification:** [`google.concept.service-identity-binding`](#google-concept-service-identity-binding).

</details>

<details>
<summary><code>google.rule.google-cloud-project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/governance-management/resource-hierarchy.rf.hcl#L6-L21">Source</a></summary>

<div id="rule-google-cloud-project"></div>

Matches `resource` instances of `google_project`.

**Classification:** [`google.concept.google-cloud-project`](#google-concept-google-cloud-project).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["project_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "project_id"]`

</details>

</details>

<details>
<summary><code>google.rule.pubsub-lite-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L111-L117">Source</a></summary>

<div id="rule-pubsub-lite-subscription"></div>

Matches `resource` instances of `google_pubsub_lite_subscription`.

**Classification:** [`google.concept.message-subscription`](#google-concept-message-subscription).

</details>

<details>
<summary><code>google.rule.pubsub-lite-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L94-L109">Source</a></summary>

<div id="rule-pubsub-lite-topic"></div>

Matches `resource` instances of `google_pubsub_lite_topic`.

**Classification:** [`google.concept.message-topic`](#google-concept-message-topic).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.pubsub-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L34-L92">Source</a></summary>

<div id="rule-pubsub-subscription"></div>

Matches `resource` instances of `google_pubsub_subscription`.

**Classification:** [`google.concept.message-subscription`](#google-concept-message-subscription).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

**Relations**

- [`google.relation.subscribes-to`](#google-relation-subscribes-to): targets [`google.concept.message-topic`](#google-concept-message-topic) through `source.topic`.
- [`google.relation.delivers-to`](#google-relation-delivers-to): targets [`google.concept.cloud-run-service`](#google-concept-cloud-run-service) through `source.push_config[0].push_endpoint`.
- [`google.relation.delivers-to`](#google-relation-delivers-to): targets [`google.concept.message-topic`](#google-concept-message-topic) through `source.dead_letter_policy[0].dead_letter_topic`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.topic`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.id, target.name]`
- `match.strategy`: `"exact"`

**Relation through `source.push_config[0].push_endpoint`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.uri`
- `match.strategy`: `"exact"`

**Relation through `source.dead_letter_policy[0].dead_letter_topic`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `[target.id, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.pubsub-topic</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/messaging-eventing/pubsub.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-pubsub-topic"></div>

Matches `resource` instances of `google_pubsub_topic`.

**Classification:** [`google.concept.message-topic`](#google-concept-message-topic).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.memorystore-redis-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/memorystore.rf.hcl#L41-L63">Source</a></summary>

<div id="rule-memorystore-redis-cluster"></div>

Matches `resource` instances of `google_redis_cluster`.

**Classification:** [`google.concept.managed-cache`](#google-concept-managed-cache).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.memorystore-redis-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/memorystore.rf.hcl#L1-L39">Source</a></summary>

<div id="rule-memorystore-redis-instance"></div>

Matches `resource` instances of `google_redis_instance`.

**Classification:** [`google.concept.managed-cache`](#google-concept-managed-cache).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.authorized_network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.authorized_network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.secret-manager-regional-secret-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/secret-manager.rf.hcl#L91-L109">Source</a></summary>

<div id="rule-secret-manager-regional-secret-version"></div>

Matches `resource` instances of `google_secret_manager_regional_secret_version`.

**Classification:** [`google.concept.secret-manager-secret-version`](#google-concept-secret-manager-secret-version).

**Contributions**

- targets [`google.concept.managed-secret`](#google-concept-managed-secret) through `source.secret`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.secret`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.secret-manager-regional-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/secret-manager.rf.hcl#L58-L89">Source</a></summary>

<div id="rule-secret-manager-regional-secret"></div>

Matches `resource` instances of `google_secret_manager_regional_secret`.

**Classification:** [`google.concept.managed-secret`](#google-concept-managed-secret).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.secret-manager-secret-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/secret-manager.rf.hcl#L38-L56">Source</a></summary>

<div id="rule-secret-manager-secret-version"></div>

Matches `resource` instances of `google_secret_manager_secret_version`.

**Classification:** [`google.concept.secret-manager-secret-version`](#google-concept-secret-manager-secret-version).

**Contributions**

- targets [`google.concept.managed-secret`](#google-concept-managed-secret) through `source.secret`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.secret`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.secret-manager-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/security/secret-manager.rf.hcl#L5-L36">Source</a></summary>

<div id="rule-secret-manager-secret"></div>

Matches `resource` instances of `google_secret_manager_secret`.

**Classification:** [`google.concept.managed-secret`](#google-concept-managed-secret).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.secure-source-manager-repository</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L43-L49">Source</a></summary>

<div id="rule-secure-source-manager-repository"></div>

Matches `resource` instances of `google_secure_source_manager_repository`.

**Classification:** [`google.concept.source-repository`](#google-concept-source-repository).

</details>

<details>
<summary><code>google.rule.service-account-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/service-accounts.rf.hcl#L40-L61">Source</a></summary>

<div id="rule-service-account-key"></div>

Matches `resource` instances of `google_service_account_key`.

**Classification:** [`google.concept.service-credential`](#google-concept-service-credential).

**Contributions**

- targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_account_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.service_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.email]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.iam-service-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/identity-iam/service-accounts.rf.hcl#L5-L38">Source</a></summary>

<div id="rule-iam-service-account"></div>

Matches `resource` instances of `google_service_account`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

**Contexts**

- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["email", "id"]`
- `scope`: `"global"`

**Endpoint**

- `attributes`: `["email", "id", "member", "name"]`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.service-networking-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/private-services-access.rf.hcl#L1-L22">Source</a></summary>

<div id="rule-service-networking-connection"></div>

Matches `resource` instances of `google_service_networking_connection`.

**Classification:** [`google.concept.service-networking-detail`](#google-concept-service-networking-detail).

**Contributions**

- targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-source-repository</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/developer-ci-cd/source-management.rf.hcl#L51-L57">Source</a></summary>

<div id="rule-cloud-source-repository"></div>

Matches `resource` instances of `google_sourcerepo_repository`.

**Classification:** [`google.concept.source-repository`](#google-concept-source-repository).

</details>

<details>
<summary><code>google.rule.spanner-database</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/spanner.rf.hcl#L22-L43">Source</a></summary>

<div id="rule-spanner-database"></div>

Matches `resource` instances of `google_spanner_database`.

**Classification:** [`google.concept.spanner-database`](#google-concept-spanner-database).

**Contributions**

- targets [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database) through `source.instance`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.instance`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.name, target.id]`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.spanner-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/spanner.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-spanner-instance"></div>

Matches `resource` instances of `google_spanner_instance`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

</details>

</details>

<details>
<summary><code>google.rule.cloud-sql-instance</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/databases/cloud-sql.rf.hcl#L1-L48">Source</a></summary>

<div id="rule-cloud-sql-instance"></div>

Matches `resource` instances of `google_sql_database_instance`.

**Classification:** [`rf.concept.managed-database`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-managed-database).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.settings[0].ip_configuration[0].private_network`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name", "self_link"]`

**Context through `source.settings[0].ip_configuration[0].private_network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-storage-bucket-iam-member</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/cloud-storage.rf.hcl#L18-L39">Source</a></summary>

<div id="rule-cloud-storage-bucket-iam-member"></div>

Matches `resource` instances of `google_storage_bucket_iam_member`.

**Classification:** [`google.concept.access-binding`](#google-concept-access-binding).

**Contributions**

- targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.bucket`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.bucket`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"last-segment"`

</details>

</details>

<details>
<summary><code>google.rule.cloud-storage-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/storage/cloud-storage.rf.hcl#L1-L16">Source</a></summary>

<div id="rule-cloud-storage-bucket"></div>

Matches `resource` instances of `google_storage_bucket`.

**Classification:** [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name", "self_link"]`

</details>

</details>

<details>
<summary><code>google.rule.tpu-vm</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/compute/specialized-compute.rf.hcl#L3-L9">Source</a></summary>

<div id="rule-tpu-vm"></div>

Matches `resource` instances of `google_tpu_v2_vm`.

**Classification:** [`google.concept.compute-instance`](#google-concept-compute-instance).

</details>

<details>
<summary><code>google.rule.vector-search-index</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/data-analytics/vector-search.rf.hcl#L3-L9">Source</a></summary>

<div id="rule-vector-search-index"></div>

Matches `resource` instances of `google_vector_search_index`.

**Classification:** [`google.concept.vertex-ai-vector-index`](#google-concept-vertex-ai-vector-index).

</details>

<details>
<summary><code>google.rule.vertex-ai-model-garden-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L23-L29">Source</a></summary>

<div id="rule-vertex-ai-model-garden-endpoint"></div>

Matches `resource` instances of `google_vertex_ai_endpoint_with_model_garden_deployment`.

**Classification:** [`google.concept.ai-inference-endpoint`](#google-concept-ai-inference-endpoint).

</details>

<details>
<summary><code>google.rule.vertex-ai-endpoint</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L15-L21">Source</a></summary>

<div id="rule-vertex-ai-endpoint"></div>

Matches `resource` instances of `google_vertex_ai_endpoint`.

**Classification:** [`google.concept.ai-inference-endpoint`](#google-concept-ai-inference-endpoint).

</details>

<details>
<summary><code>google.rule.vertex-ai-feature-online-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L48-L54">Source</a></summary>

<div id="rule-vertex-ai-feature-online-store"></div>

Matches `resource` instances of `google_vertex_ai_feature_online_store`.

**Classification:** [`google.concept.vertex-ai-feature-store`](#google-concept-vertex-ai-feature-store).

</details>

<details>
<summary><code>google.rule.vertex-ai-feature-store</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L40-L46">Source</a></summary>

<div id="rule-vertex-ai-feature-store"></div>

Matches `resource` instances of `google_vertex_ai_featurestore`.

**Classification:** [`google.concept.vertex-ai-feature-store`](#google-concept-vertex-ai-feature-store).

</details>

<details>
<summary><code>google.rule.vertex-ai-vector-index</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/ai-ml/vertex-ai.rf.hcl#L31-L37">Source</a></summary>

<div id="rule-vertex-ai-vector-index"></div>

Matches `resource` instances of `google_vertex_ai_index`.

**Classification:** [`google.concept.vertex-ai-vector-index`](#google-concept-vertex-ai-vector-index).

</details>

<details>
<summary><code>google.rule.vmware-engine-network</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/vmware-engine.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-vmware-engine-network"></div>

Matches `resource` instances of `google_vmwareengine_network`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.vmware-engine-subnet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/hybrid-distributed-cloud/vmware-engine.rf.hcl#L22-L37">Source</a></summary>

<div id="rule-vmware-engine-subnet"></div>

Matches `resource` instances of `google_vmwareengine_subnet`.

**Classification:** [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>google.rule.serverless-vpc-access-connector</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/google/network/vpc-access.rf.hcl#L5-L68">Source</a></summary>

<div id="rule-serverless-vpc-access-connector"></div>

Matches `resource` instances of `google_vpc_access_connector`.

**Classification:** [`google.concept.serverless-vpc-access-connector`](#google-concept-serverless-vpc-access-connector).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.network`.
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.subnet`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-subnet) through `source.subnet[0].name`.
- [`google.context.ownership`](#google-context-ownership): targets [`google.concept.google-cloud-project`](#google-concept-google-cloud-project) through `source.project`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "self_link"]`

**Context through `source.network`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.id, target.self_link, target.name]`
- `match.strategy`: `"exact"`

**Context through `source.subnet[0].name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `[target.name, target.id, target.self_link]`
- `match.strategy`: `"exact"`

**Context through `source.project`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.project_id`
- `match.strategy`: `"exact"`

</details>

</details>
