Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/hcp: = 0.114.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
hcp_aws_network_peeringdatanetwork-peeringaws-network-peering-lookup
hcp_aws_network_peeringresourcenetwork-peeringaws-network-peering
hcp_aws_transit_gateway_attachmentdatatransit-gateway-attachmentaws-transit-gateway-attachment-lookup
hcp_aws_transit_gateway_attachmentresourcetransit-gateway-attachmentaws-transit-gateway-attachment
hcp_azure_peering_connectiondatanetwork-peeringazure-peering-connection-lookup
hcp_azure_peering_connectionresourcenetwork-peeringazure-peering-connection
hcp_boundary_clusterdataboundary-clusterboundary-cluster-lookup
hcp_boundary_clusterresourceboundary-clusterboundary-cluster
hcp_consul_clusterdataconsul-dedicated-clusterconsul-cluster-lookup
hcp_consul_clusterresourceconsul-dedicated-clusterconsul-cluster
hcp_consul_snapshotresourceconsul-configurationconsul-snapshot
hcp_dns_forwarding_ruledatanetwork-configurationdns-forwarding-rule-lookup
hcp_dns_forwarding_ruleresourcenetwork-configurationdns-forwarding-rule
hcp_dns_forwardingdatadns-forwardingdns-forwarding-lookup
hcp_dns_forwardingresourcedns-forwardingdns-forwarding
hcp_group_iam_bindingresourceaccess-control-configurationgroup-iam-binding
hcp_group_iam_policyresourceaccess-control-configurationgroup-iam-policy
hcp_group_membersresourceaccess-control-configurationgroup-members
hcp_groupdataidentity-groupgroup-lookup
hcp_groupresourceidentity-groupgroup
hcp_hvn_peering_connectiondatanetwork-peeringhvn-peering-connection-lookup
hcp_hvn_peering_connectionresourcenetwork-peeringhvn-peering-connection
hcp_hvn_routedatanetwork-configurationhvn-route-lookup
hcp_hvn_routeresourcenetwork-configurationhvn-route
hcp_hvndatavirtual-networkhvn-lookup
hcp_hvnresourcevirtual-networkhvn
hcp_iam_workload_identity_providerresourceworkload-identity-provideriam-workload-identity-provider
hcp_notifications_webhookresourcenotification-webhooknotifications-webhook
hcp_organization_iam_bindingresourceaccess-control-configurationorganization-iam-binding
hcp_organization_iam_policyresourceaccess-control-configurationorganization-iam-policy
hcp_organizationdataorganizationorganization-lookup
hcp_packer_artifactdatapacker-artifactpacker-artifact-lookup
hcp_packer_bucket_iam_bindingresourcepacker-configurationpacker-bucket-iam-binding
hcp_packer_bucket_iam_policyresourcepacker-configurationpacker-bucket-iam-policy
hcp_packer_bucketresourcepacker-bucketpacker-bucket
hcp_packer_channel_assignmentresourcepacker-configurationpacker-channel-assignment
hcp_packer_channelresourcepacker-channelpacker-channel
hcp_packer_versiondatapacker-versionpacker-version-lookup
hcp_private_linkdataprivate-link-serviceprivate-link-lookup
hcp_private_linkresourceprivate-link-serviceprivate-link
hcp_project_iam_bindingresourceaccess-control-configurationproject-iam-binding
hcp_project_iam_policyresourceaccess-control-configurationproject-iam-policy
hcp_projectdataprojectproject-lookup
hcp_projectresourceprojectproject
hcp_resource_control_policyresourceaccess-control-configurationresource-control-policy
hcp_service_principaldataservice-identityservice-principal-lookup
hcp_service_principalresourceservice-identityservice-principal
hcp_vault_clusterdatavault-dedicated-clustervault-cluster-lookup
hcp_vault_clusterresourcevault-dedicated-clustervault-cluster
hcp_vault_plugindatavault-pluginvault-plugin-lookup
hcp_vault_pluginresourcevault-pluginvault-plugin
hcp_vault_radar_integration_jira_connectionresourcevault-radar-integrationvault-radar-integration-jira-connection
hcp_vault_radar_integration_jira_subscriptionresourcevault-radar-configurationvault-radar-integration-jira-subscription
hcp_vault_radar_integration_slack_connectionresourcevault-radar-integrationvault-radar-integration-slack-connection
hcp_vault_radar_integration_slack_subscriptionresourcevault-radar-configurationvault-radar-integration-slack-subscription
hcp_vault_radar_resource_iam_bindingresourcevault-radar-configurationvault-radar-resource-iam-binding
hcp_vault_radar_resource_iam_policyresourcevault-radar-configurationvault-radar-resource-iam-policy
hcp_vault_radar_secret_manager_vault_dedicatedresourcevault-radar-secret-managervault-radar-secret-manager-vault-dedicated
hcp_vault_radar_source_github_cloudresourcevault-radar-sourcevault-radar-source-github-cloud
hcp_vault_radar_source_github_enterpriseresourcevault-radar-sourcevault-radar-source-github-enterprise
hcp_vault_secrets_app_iam_bindingresourcevault-secrets-configurationvault-secrets-app-iam-binding
hcp_vault_secrets_app_iam_policyresourcevault-secrets-configurationvault-secrets-app-iam-policy
hcp_vault_secrets_appdatavault-secrets-applicationvault-secrets-app-lookup
hcp_vault_secrets_appresourcevault-secrets-applicationvault-secrets-app
hcp_vault_secrets_dynamic_secretdatavault-secrets-configurationvault-secrets-dynamic-secret-lookup
hcp_vault_secrets_dynamic_secretresourcemanaged-secretvault-secrets-dynamic-secret
hcp_vault_secrets_integration_awsresourcevault-secrets-integrationvault-secrets-integration-aws
hcp_vault_secrets_integration_azureresourcevault-secrets-integrationvault-secrets-integration-azure
hcp_vault_secrets_integration_confluentresourcevault-secrets-integrationvault-secrets-integration-confluent
hcp_vault_secrets_integration_gcpresourcevault-secrets-integrationvault-secrets-integration-gcp
hcp_vault_secrets_integration_mongodbatlasresourcevault-secrets-integrationvault-secrets-integration-mongodbatlas
hcp_vault_secrets_integration_twilioresourcevault-secrets-integrationvault-secrets-integration-twilio
hcp_vault_secrets_integrationresourcevault-secrets-integrationvault-secrets-integration
hcp_vault_secrets_rotating_secretdatavault-secrets-configurationvault-secrets-rotating-secret-lookup
hcp_vault_secrets_rotating_secretresourcemanaged-secretvault-secrets-rotating-secret
hcp_vault_secrets_secretdatavault-secrets-configurationvault-secrets-secret-lookup
hcp_vault_secrets_secretresourcemanaged-secretvault-secrets-secret
hcp_vault_secrets_syncresourcevault-secrets-syncvault-secrets-sync
hcp_waypoint_actiondatawaypoint-configurationwaypoint-action-lookup
hcp_waypoint_actionresourcewaypoint-configurationwaypoint-action
hcp_waypoint_add_on_definitiondatawaypoint-add-on-definitionwaypoint-add-on-definition-lookup
hcp_waypoint_add_on_definitionresourcewaypoint-add-on-definitionwaypoint-add-on-definition
hcp_waypoint_add_ondatawaypoint-add-onwaypoint-add-on-lookup
hcp_waypoint_add_onresourcewaypoint-add-onwaypoint-add-on
hcp_waypoint_agent_groupdatawaypoint-agent-groupwaypoint-agent-group-lookup
hcp_waypoint_agent_groupresourcewaypoint-agent-groupwaypoint-agent-group
hcp_waypoint_applicationdatawaypoint-applicationwaypoint-application-lookup
hcp_waypoint_applicationresourcewaypoint-applicationwaypoint-application
hcp_waypoint_templatedatawaypoint-templatewaypoint-template-lookup
hcp_waypoint_templateresourcewaypoint-templatewaypoint-template
hcp_waypoint_tfc_configresourcewaypoint-configurationwaypoint-tfc-config

Local vocabulary

Concepts

hcp.concept.access-control-configuration Source

An IAM binding, membership, policy, or constraint supporting an HCP boundary.

Used by 8 Rules
hcp.concept.boundary-cluster Source

A HashiCorp-managed Boundary control plane on HCP.

Used by boundary-cluster, boundary-cluster-lookup.

hcp.concept.consul-configuration Source

A legacy snapshot or supporting setting for an HCP Consul Dedicated cluster.

Used by consul-snapshot.

hcp.concept.consul-dedicated-cluster Source

A legacy HCP Consul Dedicated cluster retained for provider-state architecture after end of life.

Used by consul-cluster, consul-cluster-lookup, consul-snapshot.

hcp.concept.dns-forwarding Source

A private DNS forwarding boundary associated with an HVN connection.

Used by 4 Rules
hcp.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by 5 Rules
hcp.concept.managed-secret Source

A managed secret identity whose sensitive value stays outside architecture output.

Used by vault-secrets-dynamic-secret, vault-secrets-rotating-secret, vault-secrets-secret.

hcp.concept.network-configuration Source

A route or supporting setting attached to HCP network connectivity.

Used by 4 Rules
hcp.concept.network-peering Source

A direct private connectivity agreement between virtual networks.

Used by 6 Rules
hcp.concept.notification-webhook Source

A webhook receiving HCP project resource lifecycle events.

Used by notifications-webhook.

hcp.concept.organization Source

A top-level HCP ownership and governance boundary.

Used by organization-lookup, resource-control-policy.

hcp.concept.packer-artifact Source

An HCP Packer record locating a built machine image on an external platform.

Used by packer-artifact-lookup.

hcp.concept.packer-bucket Source

An HCP Packer registry boundary grouping machine-image metadata.

Used by 6 Rules
hcp.concept.packer-channel Source

A named HCP Packer release channel selecting an image version.

Used by packer-channel, packer-channel-assignment, packer-version-lookup.

hcp.concept.packer-configuration Source

An assignment or access setting supporting HCP Packer registry architecture.

Used by packer-bucket-iam-binding, packer-bucket-iam-policy, packer-channel-assignment.

hcp.concept.packer-version Source

A version of machine-image metadata in HCP Packer.

Used by packer-artifact-lookup, packer-channel-assignment, packer-version-lookup.

A provider-side private connectivity service exposing an HCP Vault Dedicated cluster to approved consumers.

Used by private-link, private-link-lookup.

hcp.concept.project Source

An HCP boundary grouping managed products and access.

Used by 53 Rules
hcp.concept.transit-gateway-attachment Source

An attachment connecting an HVN to an AWS Transit Gateway.

Used by aws-transit-gateway-attachment, aws-transit-gateway-attachment-lookup.

hcp.concept.vault-dedicated-cluster Source

A HashiCorp-managed Vault Dedicated cluster on HCP.

Used by 7 Rules
hcp.concept.vault-plugin Source

A custom plugin installed into an HCP Vault Dedicated cluster.

Used by vault-plugin, vault-plugin-lookup.

hcp.concept.vault-radar-configuration Source

A subscription or access setting supporting HCP Vault Radar.

Used by 4 Rules
hcp.concept.vault-radar-integration Source

An external workflow destination integrated with HCP Vault Radar.

Used by 4 Rules
hcp.concept.vault-radar-secret-manager Source

A Vault Dedicated secret manager correlated with HCP Vault Radar findings.

Used by vault-radar-secret-manager-vault-dedicated.

hcp.concept.vault-radar-source Source

A source repository scanned by HCP Vault Radar for secret exposure.

Used by vault-radar-source-github-cloud, vault-radar-source-github-enterprise.

hcp.concept.vault-secrets-configuration Source

A secret read or access setting supporting an HCP Vault Secrets application.

Used by 5 Rules
hcp.concept.vault-secrets-sync Source

An HCP Vault Secrets destination synchronizing application secrets externally.

Used by vault-secrets-app, vault-secrets-sync.

hcp.concept.waypoint-add-on Source

Supporting infrastructure installed for an HCP Waypoint application.

Used by waypoint-add-on, waypoint-add-on-lookup.

hcp.concept.waypoint-add-on-definition Source

A reusable HCP Waypoint definition for application supporting infrastructure.

Used by 4 Rules
hcp.concept.waypoint-agent-group Source

A group of agents executing HCP Waypoint actions.

Used by waypoint-agent-group, waypoint-agent-group-lookup.

hcp.concept.waypoint-application Source

An application instantiated and managed through HCP Waypoint.

Used by 4 Rules
hcp.concept.waypoint-configuration Source

An action or HCP Terraform connection supporting HCP Waypoint.

Used by waypoint-action, waypoint-action-lookup, waypoint-tfc-config.

hcp.concept.waypoint-template Source

A reusable HCP Waypoint golden pattern for application infrastructure.

Used by 4 Rules
hcp.concept.workload-identity-provider Source

An HCP federation boundary exchanging an external workload identity for a service principal.

Used by iam-workload-identity-provider.

Contexts

hcp.context.ownership Source

Administrative or lifecycle ownership.

Used by 55 Rules

Relations

hcp.relation.belongs-to-version Source

Introduced by a labeled emission. Used by packer-artifact-lookup.

hcp.relation.connects-vault-cluster Source

Introduced by a labeled emission. Used by vault-radar-secret-manager-vault-dedicated.

hcp.relation.exposes-vault-cluster Source

Introduced by a labeled emission. Used by private-link, private-link-lookup.

hcp.relation.extends-application Source

Introduced by a labeled emission. Used by waypoint-add-on, waypoint-add-on-lookup.

hcp.relation.extends-cluster Source

Introduced by a labeled emission. Used by vault-plugin, vault-plugin-lookup.

hcp.relation.federates-to Source

Introduced by a labeled emission. Used by iam-workload-identity-provider.

hcp.relation.instantiates-definition Source

Introduced by a labeled emission. Used by waypoint-add-on, waypoint-add-on-lookup.

hcp.relation.replicates-from Source

Introduced by a labeled emission.

Used by 4 Rules
hcp.relation.selected-by-channel Source

Introduced by a labeled emission. Used by packer-version-lookup.

hcp.relation.syncs-to Source

Introduced by a labeled emission. Used by vault-secrets-app.

hcp.relation.uses-integration Source

Introduced by a labeled emission. Used by vault-secrets-dynamic-secret, vault-secrets-rotating-secret, vault-secrets-sync.

hcp.relation.uses-template Source

Introduced by a labeled emission. Used by waypoint-application, waypoint-application-lookup.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

hcp.rule.aws-network-peering-lookup Source

Matches data instances of hcp_aws_network_peering.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.peer_vpc_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.aws-network-peering Source

Matches resource instances of hcp_aws_network_peering.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.peer_vpc_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.aws-transit-gateway-attachment-lookup Source

Matches data instances of hcp_aws_transit_gateway_attachment.

Classification: hcp.concept.transit-gateway-attachment.

Contexts

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.aws-transit-gateway-attachment Source

Matches resource instances of hcp_aws_transit_gateway_attachment.

Classification: hcp.concept.transit-gateway-attachment.

Contexts

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.azure-peering-connection-lookup Source

Matches data instances of hcp_azure_peering_connection.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_link

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.peer_vnet_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.azure-peering-connection Source

Matches resource instances of hcp_azure_peering_connection.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_link

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.peer_vnet_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.boundary-cluster-lookup Source

Matches data instances of hcp_boundary_cluster.

Classification: hcp.concept.boundary-cluster.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.boundary-cluster Source

Matches resource instances of hcp_boundary_cluster.

Classification: hcp.concept.boundary-cluster.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.consul-cluster-lookup Source

Matches data instances of hcp_consul_cluster.

Classification: hcp.concept.consul-dedicated-cluster.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "cluster_id", "self_link"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "cluster_id", "self_link"]

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.primary_link

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.consul-cluster Source

Matches resource instances of hcp_consul_cluster.

Classification: hcp.concept.consul-dedicated-cluster.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "cluster_id", "self_link"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "cluster_id", "self_link"]

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.primary_link

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.consul-snapshot Source

Matches resource instances of hcp_consul_snapshot.

Classification: hcp.concept.consul-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.cluster_id
  • match.strategy: "exact"
hcp.rule.dns-forwarding-rule-lookup Source

Matches data instances of hcp_dns_forwarding_rule.

Classification: hcp.concept.network-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.dns_forwarding_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.dns_forwarding_id
  • match.strategy: "exact"
hcp.rule.dns-forwarding-rule Source

Matches resource instances of hcp_dns_forwarding_rule.

Classification: hcp.concept.network-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.dns_forwarding_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.dns_forwarding_id
  • match.strategy: "exact"
hcp.rule.dns-forwarding-lookup Source

Matches data instances of hcp_dns_forwarding.

Classification: hcp.concept.dns-forwarding.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "dns_forwarding_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "dns_forwarding_id"]

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.dns-forwarding Source

Matches resource instances of hcp_dns_forwarding.

Classification: hcp.concept.dns-forwarding.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "dns_forwarding_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "dns_forwarding_id"]

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.group-iam-binding Source

Matches resource instances of hcp_group_iam_binding.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.group-iam-policy Source

Matches resource instances of hcp_group_iam_policy.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.group-members Source

Matches resource instances of hcp_group_members.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.group

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.group-lookup Source

Matches data instances of hcp_group.

Classification: hcp.concept.identity-group.

Conditions, identity and resolution

Identity

  • attributes: ["resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.group Source

Matches resource instances of hcp_group.

Classification: hcp.concept.identity-group.

Conditions, identity and resolution

Identity

  • attributes: ["resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.hvn-peering-connection-lookup Source

Matches data instances of hcp_hvn_peering_connection.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_1

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.hvn_2

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.hvn-peering-connection Source

Matches resource instances of hcp_hvn_peering_connection.

Classification: hcp.concept.network-peering.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_1

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.hvn_2

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.hvn-route-lookup Source

Matches data instances of hcp_hvn_route.

Classification: hcp.concept.network-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.hvn_link

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.hvn-route Source

Matches resource instances of hcp_hvn_route.

Classification: hcp.concept.network-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.hvn_link

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.hvn-lookup Source

Matches data instances of hcp_hvn.

Classification: rf.concept.virtual-network.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "hvn_id", "self_link"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "hvn_id", "self_link"]

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.hvn Source

Matches resource instances of hcp_hvn.

Classification: rf.concept.virtual-network.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "hvn_id", "self_link"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "hvn_id", "self_link"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.iam-workload-identity-provider Source

Matches resource instances of hcp_iam_workload_identity_provider.

Classification: hcp.concept.workload-identity-provider.

Relations

Conditions, identity and resolution

Relation through source.service_principal

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.notifications-webhook Source

Matches resource instances of hcp_notifications_webhook.

Classification: hcp.concept.notification-webhook.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.organization-iam-binding Source

Matches resource instances of hcp_organization_iam_binding.

Classification: hcp.concept.access-control-configuration.

hcp.rule.organization-iam-policy Source

Matches resource instances of hcp_organization_iam_policy.

Classification: hcp.concept.access-control-configuration.

hcp.rule.organization-lookup Source

Matches data instances of hcp_organization.

Classification: hcp.concept.organization.

Conditions, identity and resolution

Identity

  • attributes: ["resource_id"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.packer-artifact-lookup Source

Matches data instances of hcp_packer_artifact.

Classification: hcp.concept.packer-artifact.

Contexts

Relations

Conditions, identity and resolution

Context through source.bucket_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.version_fingerprint

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.fingerprint
  • match.strategy: "exact"
hcp.rule.packer-bucket-iam-binding Source

Matches resource instances of hcp_packer_bucket_iam_binding.

Classification: hcp.concept.packer-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.resource_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.packer-bucket-iam-policy Source

Matches resource instances of hcp_packer_bucket_iam_policy.

Classification: hcp.concept.packer-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.resource_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.packer-bucket Source

Matches resource instances of hcp_packer_bucket.

Classification: hcp.concept.packer-bucket.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name", "resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.packer-channel-assignment Source

Matches resource instances of hcp_packer_channel_assignment.

Classification: hcp.concept.packer-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.channel_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.version_fingerprint

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.fingerprint
  • match.strategy: "exact"
hcp.rule.packer-channel Source

Matches resource instances of hcp_packer_channel.

Classification: hcp.concept.packer-channel.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.bucket_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.packer-version-lookup Source

Matches data instances of hcp_packer_version.

Classification: hcp.concept.packer-version.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "fingerprint"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "fingerprint"]

Context through source.bucket_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.channel_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.private-link-lookup Source

Matches data instances of hcp_private_link.

Classification: hcp.concept.private-link-service.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.vault_cluster_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.cluster_id
  • match.strategy: "exact"
hcp.rule.private-link Source

Matches resource instances of hcp_private_link.

Classification: hcp.concept.private-link-service.

Contexts

Relations

Conditions, identity and resolution

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.vault_cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.cluster_id
  • match.strategy: "exact"
hcp.rule.project-iam-binding Source

Matches resource instances of hcp_project_iam_binding.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.project-iam-policy Source

Matches resource instances of hcp_project_iam_policy.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.project-lookup Source

Matches data instances of hcp_project.

Classification: hcp.concept.project.

Conditions, identity and resolution

Identity

  • attributes: ["resource_id"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.project Source

Matches resource instances of hcp_project.

Classification: hcp.concept.project.

Conditions, identity and resolution

Identity

  • attributes: ["resource_id"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.resource-control-policy Source

Matches resource instances of hcp_resource_control_policy.

Classification: hcp.concept.access-control-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.organization_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.service-principal-lookup Source

Matches data instances of hcp_service_principal.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.service-principal Source

Matches resource instances of hcp_service_principal.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["resource_id", "resource_name"]
hcp.rule.vault-cluster-lookup Source

Matches data instances of hcp_vault_cluster.

Classification: hcp.concept.vault-dedicated-cluster.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "cluster_id", "self_link", "vault_public_endpoint_url"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]

Context through source.hvn_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.primary_link

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.vault-cluster Source

Matches resource instances of hcp_vault_cluster.

Classification: hcp.concept.vault-dedicated-cluster.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "cluster_id", "self_link", "vault_public_endpoint_url"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]

Context through source.hvn_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.hvn_id
  • match.strategy: "exact"

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.primary_link

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.self_link
  • match.strategy: "exact"
hcp.rule.vault-plugin-lookup Source

Matches data instances of hcp_vault_plugin.

Classification: hcp.concept.vault-plugin.

Contexts

Relations

Conditions, identity and resolution

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.cluster_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.cluster_id
  • match.strategy: "exact"
hcp.rule.vault-plugin Source

Matches resource instances of hcp_vault_plugin.

Classification: hcp.concept.vault-plugin.

Contexts

Relations

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.cluster_id
  • match.strategy: "exact"
hcp.rule.vault-radar-integration-jira-connection Source

Matches resource instances of hcp_vault_radar_integration_jira_connection.

Classification: hcp.concept.vault-radar-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-radar-integration-jira-subscription Source

Matches resource instances of hcp_vault_radar_integration_jira_subscription.

Classification: hcp.concept.vault-radar-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.connection_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.vault-radar-integration-slack-connection Source

Matches resource instances of hcp_vault_radar_integration_slack_connection.

Classification: hcp.concept.vault-radar-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-radar-integration-slack-subscription Source

Matches resource instances of hcp_vault_radar_integration_slack_subscription.

Classification: hcp.concept.vault-radar-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.connection_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.vault-radar-resource-iam-binding Source

Matches resource instances of hcp_vault_radar_resource_iam_binding.

Classification: hcp.concept.vault-radar-configuration.

hcp.rule.vault-radar-resource-iam-policy Source

Matches resource instances of hcp_vault_radar_resource_iam_policy.

Classification: hcp.concept.vault-radar-configuration.

hcp.rule.vault-radar-secret-manager-vault-dedicated Source

Matches resource instances of hcp_vault_radar_secret_manager_vault_dedicated.

Classification: hcp.concept.vault-radar-secret-manager.

Contexts

Relations

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.vault_url

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.vault_public_endpoint_url
  • match.strategy: "exact"
hcp.rule.vault-radar-source-github-cloud Source

Matches resource instances of hcp_vault_radar_source_github_cloud.

Classification: hcp.concept.vault-radar-source.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-radar-source-github-enterprise Source

Matches resource instances of hcp_vault_radar_source_github_enterprise.

Classification: hcp.concept.vault-radar-source.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-app-iam-binding Source

Matches resource instances of hcp_vault_secrets_app_iam_binding.

Classification: hcp.concept.vault-secrets-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.resource_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-app-iam-policy Source

Matches resource instances of hcp_vault_secrets_app_iam_policy.

Classification: hcp.concept.vault-secrets-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.resource_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.resource_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-app-lookup Source

Matches data instances of hcp_vault_secrets_app.

Classification: hcp.concept.vault-secrets-application.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["app_name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "app_name"]

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-app Source

Matches resource instances of hcp_vault_secrets_app.

Classification: hcp.concept.vault-secrets-application.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["app_name", "resource_name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "app_name", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.sync_names

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.vault-secrets-dynamic-secret-lookup Source

Matches data instances of hcp_vault_secrets_dynamic_secret.

Classification: hcp.concept.vault-secrets-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.app_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.app_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-dynamic-secret Source

Matches resource instances of hcp_vault_secrets_dynamic_secret.

Classification: hcp.concept.managed-secret.

Contexts

Relations

Conditions, identity and resolution

Context through source.app_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.app_name
  • match.strategy: "exact"

Relation through source.integration_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.gcp_impersonate_service_account.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-aws Source

Matches resource instances of hcp_vault_secrets_integration_aws.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-azure Source

Matches resource instances of hcp_vault_secrets_integration_azure.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.federated_workload_identity.client_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-confluent Source

Matches resource instances of hcp_vault_secrets_integration_confluent.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-gcp Source

Matches resource instances of hcp_vault_secrets_integration_gcp.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.federated_workload_identity.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"

Relation through source.service_account_key.client_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-mongodbatlas Source

Matches resource instances of hcp_vault_secrets_integration_mongodbatlas.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration-twilio Source

Matches resource instances of hcp_vault_secrets_integration_twilio.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.vault-secrets-integration Source

Matches resource instances of hcp_vault_secrets_integration.

Classification: hcp.concept.vault-secrets-integration.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id", "resource_name"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.azure_federated_workload_identity.client_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.gcp_federated_workload_identity.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"

Relation through source.gcp_service_account_key.client_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
hcp.rule.vault-secrets-rotating-secret-lookup Source

Matches data instances of hcp_vault_secrets_rotating_secret.

Classification: hcp.concept.vault-secrets-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.app_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.app_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-rotating-secret Source

Matches resource instances of hcp_vault_secrets_rotating_secret.

Classification: hcp.concept.managed-secret.

Contexts

Relations

Conditions, identity and resolution

Context through source.app_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.app_name
  • match.strategy: "exact"

Relation through source.integration_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.azure_application_password.app_client_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.confluent_service_account.service_account_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.gcp_service_account_key.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
hcp.rule.vault-secrets-secret-lookup Source

Matches data instances of hcp_vault_secrets_secret.

Classification: hcp.concept.vault-secrets-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.app_name

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.app_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-secret Source

Matches resource instances of hcp_vault_secrets_secret.

Classification: hcp.concept.managed-secret.

Contexts

Conditions, identity and resolution

Context through source.app_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.app_name
  • match.strategy: "exact"
hcp.rule.vault-secrets-sync Source

Matches resource instances of hcp_vault_secrets_sync.

Classification: hcp.concept.vault-secrets-sync.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "resource_id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.integration_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
hcp.rule.waypoint-action-lookup Source

Matches data instances of hcp_waypoint_action.

Classification: hcp.concept.waypoint-configuration.

hcp.rule.waypoint-action Source

Matches resource instances of hcp_waypoint_action.

Classification: hcp.concept.waypoint-configuration.

hcp.rule.waypoint-add-on-definition-lookup Source

Matches data instances of hcp_waypoint_add_on_definition.

Classification: hcp.concept.waypoint-add-on-definition.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-add-on-definition Source

Matches resource instances of hcp_waypoint_add_on_definition.

Classification: hcp.concept.waypoint-add-on-definition.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-add-on-lookup Source

Matches data instances of hcp_waypoint_add_on.

Classification: hcp.concept.waypoint-add-on.

Contexts

Relations

Conditions, identity and resolution

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.application_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.definition_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.waypoint-add-on Source

Matches resource instances of hcp_waypoint_add_on.

Classification: hcp.concept.waypoint-add-on.

Contexts

Relations

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.application_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.definition_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.waypoint-agent-group-lookup Source

Matches data instances of hcp_waypoint_agent_group.

Classification: hcp.concept.waypoint-agent-group.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-agent-group Source

Matches resource instances of hcp_waypoint_agent_group.

Classification: hcp.concept.waypoint-agent-group.

Contexts

Conditions, identity and resolution

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-application-lookup Source

Matches data instances of hcp_waypoint_application.

Classification: hcp.concept.waypoint-application.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.template_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.waypoint-application Source

Matches resource instances of hcp_waypoint_application.

Classification: hcp.concept.waypoint-application.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"

Relation through source.template_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
hcp.rule.waypoint-template-lookup Source

Matches data instances of hcp_waypoint_template.

Classification: hcp.concept.waypoint-template.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-template Source

Matches resource instances of hcp_waypoint_template.

Classification: hcp.concept.waypoint-template.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.project_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.resource_id
  • match.strategy: "exact"
hcp.rule.waypoint-tfc-config Source

Matches resource instances of hcp_waypoint_tfc_config.

Classification: hcp.concept.waypoint-configuration.