Reference
hcp Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/hcp:= 0.114.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
hcp.concept.access-control-configurationSource-
An IAM binding, membership, policy, or constraint supporting an HCP boundary.
hcp.concept.boundary-clusterSource-
A HashiCorp-managed Boundary control plane on HCP.
-
Used by
boundary-cluster,boundary-cluster-lookup. hcp.concept.consul-configurationSource-
A legacy snapshot or supporting setting for an HCP Consul Dedicated cluster.
-
Used by
consul-snapshot. hcp.concept.consul-dedicated-clusterSource-
A legacy HCP Consul Dedicated cluster retained for provider-state architecture after end of life.
-
Used by
consul-cluster,consul-cluster-lookup,consul-snapshot. hcp.concept.dns-forwardingSource-
A private DNS forwarding boundary associated with an HVN connection.
hcp.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by 5 Rules
hcp.concept.managed-secretSource-
A managed secret identity whose sensitive value stays outside architecture output.
-
Used by
vault-secrets-dynamic-secret,vault-secrets-rotating-secret,vault-secrets-secret. hcp.concept.network-configurationSource-
A route or supporting setting attached to HCP network connectivity.
-
Used by 4 Rules
hcp.concept.network-peeringSource-
A direct private connectivity agreement between virtual networks.
hcp.concept.notification-webhookSource-
A webhook receiving HCP project resource lifecycle events.
-
Used by
notifications-webhook. hcp.concept.organizationSource-
A top-level HCP ownership and governance boundary.
-
Used by
organization-lookup,resource-control-policy. hcp.concept.packer-artifactSource-
An HCP Packer record locating a built machine image on an external platform.
-
Used by
packer-artifact-lookup. hcp.concept.packer-channelSource-
A named HCP Packer release channel selecting an image version.
-
Used by
packer-channel,packer-channel-assignment,packer-version-lookup. hcp.concept.packer-configurationSource-
An assignment or access setting supporting HCP Packer registry architecture.
-
Used by
packer-bucket-iam-binding,packer-bucket-iam-policy,packer-channel-assignment. hcp.concept.packer-versionSource-
A version of machine-image metadata in HCP Packer.
-
Used by
packer-artifact-lookup,packer-channel-assignment,packer-version-lookup. hcp.concept.private-link-serviceSource-
A provider-side private connectivity service exposing an HCP Vault Dedicated cluster to approved consumers.
-
Used by
private-link,private-link-lookup. hcp.concept.projectSource-
An HCP boundary grouping managed products and access.
-
Used by 53 Rules
aws-network-peeringaws-network-peering-lookupaws-transit-gateway-attachmentaws-transit-gateway-attachment-lookupazure-peering-connectionazure-peering-connection-lookupboundary-clusterboundary-cluster-lookupconsul-clusterconsul-cluster-lookupdns-forwardingdns-forwarding-lookuphvnhvn-lookuphvn-peering-connectionhvn-peering-connection-lookupnotifications-webhookpacker-bucketprivate-linkprivate-link-lookupprojectproject-iam-bindingproject-iam-policyproject-lookupvault-clustervault-cluster-lookupvault-pluginvault-plugin-lookupvault-radar-integration-jira-connectionvault-radar-integration-slack-connectionvault-radar-secret-manager-vault-dedicatedvault-radar-source-github-cloudvault-radar-source-github-enterprisevault-secrets-appvault-secrets-app-lookupvault-secrets-integrationvault-secrets-integration-awsvault-secrets-integration-azurevault-secrets-integration-confluentvault-secrets-integration-gcpvault-secrets-integration-mongodbatlasvault-secrets-integration-twiliovault-secrets-syncwaypoint-add-onwaypoint-add-on-definitionwaypoint-add-on-definition-lookupwaypoint-add-on-lookupwaypoint-agent-groupwaypoint-agent-group-lookupwaypoint-applicationwaypoint-application-lookupwaypoint-templatewaypoint-template-lookup
hcp.concept.transit-gateway-attachmentSource-
An attachment connecting an HVN to an AWS Transit Gateway.
-
Used by
aws-transit-gateway-attachment,aws-transit-gateway-attachment-lookup. hcp.concept.vault-pluginSource-
A custom plugin installed into an HCP Vault Dedicated cluster.
-
Used by
vault-plugin,vault-plugin-lookup. hcp.concept.vault-radar-configurationSource-
A subscription or access setting supporting HCP Vault Radar.
hcp.concept.vault-radar-integrationSource-
An external workflow destination integrated with HCP Vault Radar.
hcp.concept.vault-radar-secret-managerSource-
A Vault Dedicated secret manager correlated with HCP Vault Radar findings.
hcp.concept.vault-radar-sourceSource-
A source repository scanned by HCP Vault Radar for secret exposure.
-
Used by
vault-radar-source-github-cloud,vault-radar-source-github-enterprise. hcp.concept.vault-secrets-applicationSource-
An HCP Vault Secrets application boundary grouping secrets and sync destinations.
hcp.concept.vault-secrets-configurationSource-
A secret read or access setting supporting an HCP Vault Secrets application.
hcp.concept.vault-secrets-integrationSource-
An HCP Vault Secrets integration with an external cloud or SaaS platform.
-
Used by 10 Rules
vault-secrets-dynamic-secretvault-secrets-integrationvault-secrets-integration-awsvault-secrets-integration-azurevault-secrets-integration-confluentvault-secrets-integration-gcpvault-secrets-integration-mongodbatlasvault-secrets-integration-twiliovault-secrets-rotating-secretvault-secrets-sync
hcp.concept.vault-secrets-syncSource-
An HCP Vault Secrets destination synchronizing application secrets externally.
-
Used by
vault-secrets-app,vault-secrets-sync. hcp.concept.waypoint-add-onSource-
Supporting infrastructure installed for an HCP Waypoint application.
-
Used by
waypoint-add-on,waypoint-add-on-lookup. hcp.concept.waypoint-add-on-definitionSource-
A reusable HCP Waypoint definition for application supporting infrastructure.
hcp.concept.waypoint-applicationSource-
An application instantiated and managed through HCP Waypoint.
hcp.concept.waypoint-configurationSource-
An action or HCP Terraform connection supporting HCP Waypoint.
-
Used by
waypoint-action,waypoint-action-lookup,waypoint-tfc-config. hcp.concept.waypoint-templateSource-
A reusable HCP Waypoint golden pattern for application infrastructure.
hcp.concept.workload-identity-providerSource-
An HCP federation boundary exchanging an external workload identity for a service principal.
-
Used by
iam-workload-identity-provider.
hcp.context.ownershipSource-
Administrative or lifecycle ownership.
-
Used by 55 Rules
aws-network-peeringaws-network-peering-lookupaws-transit-gateway-attachmentaws-transit-gateway-attachment-lookupazure-peering-connectionazure-peering-connection-lookupboundary-clusterboundary-cluster-lookupconsul-clusterconsul-cluster-lookupdns-forwardingdns-forwarding-lookuphvnhvn-lookuphvn-peering-connectionhvn-peering-connection-lookupnotifications-webhookpacker-artifact-lookuppacker-bucketpacker-channelpacker-version-lookupprivate-linkprivate-link-lookupvault-clustervault-cluster-lookupvault-pluginvault-plugin-lookupvault-radar-integration-jira-connectionvault-radar-integration-slack-connectionvault-radar-secret-manager-vault-dedicatedvault-radar-source-github-cloudvault-radar-source-github-enterprisevault-secrets-appvault-secrets-app-lookupvault-secrets-dynamic-secretvault-secrets-integrationvault-secrets-integration-awsvault-secrets-integration-azurevault-secrets-integration-confluentvault-secrets-integration-gcpvault-secrets-integration-mongodbatlasvault-secrets-integration-twiliovault-secrets-rotating-secretvault-secrets-secretvault-secrets-syncwaypoint-add-onwaypoint-add-on-definitionwaypoint-add-on-definition-lookupwaypoint-add-on-lookupwaypoint-agent-groupwaypoint-agent-group-lookupwaypoint-applicationwaypoint-application-lookupwaypoint-templatewaypoint-template-lookup
hcp.relation.belongs-to-versionSource-
Introduced by a labeled emission. Used by
packer-artifact-lookup. hcp.relation.connects-vault-clusterSource-
Introduced by a labeled emission. Used by
vault-radar-secret-manager-vault-dedicated. hcp.relation.exposes-vault-clusterSource-
Introduced by a labeled emission. Used by
private-link,private-link-lookup. hcp.relation.extends-applicationSource-
Introduced by a labeled emission. Used by
waypoint-add-on,waypoint-add-on-lookup. hcp.relation.extends-clusterSource-
Introduced by a labeled emission. Used by
vault-plugin,vault-plugin-lookup. hcp.relation.federates-toSource-
Introduced by a labeled emission. Used by
iam-workload-identity-provider. hcp.relation.instantiates-definitionSource-
Introduced by a labeled emission. Used by
waypoint-add-on,waypoint-add-on-lookup. hcp.relation.peers-withSource-
Introduced by a labeled emission.
hcp.relation.replicates-fromSource-
Introduced by a labeled emission.
Used by 4 Rules
hcp.relation.selected-by-channelSource-
Introduced by a labeled emission. Used by
packer-version-lookup. hcp.relation.syncs-toSource-
Introduced by a labeled emission. Used by
vault-secrets-app. hcp.relation.uses-cloud-identitySource-
Introduced by a labeled emission.
hcp.relation.uses-integrationSource-
Introduced by a labeled emission. Used by
vault-secrets-dynamic-secret,vault-secrets-rotating-secret,vault-secrets-sync. hcp.relation.uses-templateSource-
Introduced by a labeled emission. Used by
waypoint-application,waypoint-application-lookup.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
hcp.rule.aws-network-peering-lookup Source
Matches data instances of hcp_aws_network_peering.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.peer_vpc_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.peer_vpc_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.idmatch.strategy:"exact"
hcp.rule.aws-network-peering Source
Matches resource instances of hcp_aws_network_peering.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.peer_vpc_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.peer_vpc_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
hcp.rule.aws-transit-gateway-attachment-lookup Source
Matches data instances of hcp_aws_transit_gateway_attachment.
Classification: hcp.concept.transit-gateway-attachment.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.aws-transit-gateway-attachment Source
Matches resource instances of hcp_aws_transit_gateway_attachment.
Classification: hcp.concept.transit-gateway-attachment.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.azure-peering-connection-lookup Source
Matches data instances of hcp_azure_peering_connection.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_link.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.peer_vnet_name.
Conditions, identity and resolution
Context through source.hvn_link
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.peer_vnet_name
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.namematch.strategy:"exact"
hcp.rule.azure-peering-connection Source
Matches resource instances of hcp_azure_peering_connection.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_link.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.peer_vnet_name.
Conditions, identity and resolution
Context through source.hvn_link
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.peer_vnet_name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
hcp.rule.boundary-cluster-lookup Source
Matches data instances of hcp_boundary_cluster.
Classification: hcp.concept.boundary-cluster.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.boundary-cluster Source
Matches resource instances of hcp_boundary_cluster.
Classification: hcp.concept.boundary-cluster.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.consul-cluster-lookup Source
Matches data instances of hcp_consul_cluster.
Classification: hcp.concept.consul-dedicated-cluster.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.replicates-from: targetshcp.concept.consul-dedicated-clusterthroughsource.primary_link.
Conditions, identity and resolution
Identity
attributes:["id", "cluster_id", "self_link"]scope:"provider"
Endpoint
attributes:["id", "cluster_id", "self_link"]
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.primary_link
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.consul-cluster Source
Matches resource instances of hcp_consul_cluster.
Classification: hcp.concept.consul-dedicated-cluster.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.replicates-from: targetshcp.concept.consul-dedicated-clusterthroughsource.primary_link.
Conditions, identity and resolution
Identity
attributes:["id", "cluster_id", "self_link"]scope:"provider"
Endpoint
attributes:["id", "cluster_id", "self_link"]
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.primary_link
on_null:"absent"on_empty:"absent"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.consul-snapshot Source
Matches resource instances of hcp_consul_snapshot.
Classification: hcp.concept.consul-configuration.
Contributions
- targets
hcp.concept.consul-dedicated-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Contribution through source.cluster_id
on_null:"absent"on_empty:"absent"match.by:target.cluster_idmatch.strategy:"exact"
hcp.rule.dns-forwarding-rule-lookup Source
Matches data instances of hcp_dns_forwarding_rule.
Classification: hcp.concept.network-configuration.
Contributions
- targets
hcp.concept.dns-forwardingthroughsource.dns_forwarding_id.
Conditions, identity and resolution
Contribution through source.dns_forwarding_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.dns_forwarding_idmatch.strategy:"exact"
hcp.rule.dns-forwarding-rule Source
Matches resource instances of hcp_dns_forwarding_rule.
Classification: hcp.concept.network-configuration.
Contributions
- targets
hcp.concept.dns-forwardingthroughsource.dns_forwarding_id.
Conditions, identity and resolution
Contribution through source.dns_forwarding_id
on_null:"absent"on_empty:"absent"match.by:target.dns_forwarding_idmatch.strategy:"exact"
hcp.rule.dns-forwarding-lookup Source
Matches data instances of hcp_dns_forwarding.
Classification: hcp.concept.dns-forwarding.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id", "dns_forwarding_id"]scope:"provider"
Endpoint
attributes:["id", "dns_forwarding_id"]
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.dns-forwarding Source
Matches resource instances of hcp_dns_forwarding.
Classification: hcp.concept.dns-forwarding.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id", "dns_forwarding_id"]scope:"provider"
Endpoint
attributes:["id", "dns_forwarding_id"]
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.group-iam-binding Source
Matches resource instances of hcp_group_iam_binding.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.identity-groupthroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.group-iam-policy Source
Matches resource instances of hcp_group_iam_policy.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.identity-groupthroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.group-members Source
Matches resource instances of hcp_group_members.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.identity-groupthroughsource.group.
Conditions, identity and resolution
Contribution through source.group
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.group-lookup Source
Matches data instances of hcp_group.
Classification: hcp.concept.identity-group.
Conditions, identity and resolution
Identity
attributes:["resource_name"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.group Source
Matches resource instances of hcp_group.
Classification: hcp.concept.identity-group.
Conditions, identity and resolution
Identity
attributes:["resource_name"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.hvn-peering-connection-lookup Source
Matches data instances of hcp_hvn_peering_connection.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_1.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.hvn_2.
Conditions, identity and resolution
Context through source.hvn_1
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.hvn_2
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.hvn-peering-connection Source
Matches resource instances of hcp_hvn_peering_connection.
Classification: hcp.concept.network-peering.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_1.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.peers-with: targetsrf.concept.virtual-networkthroughsource.hvn_2.
Conditions, identity and resolution
Context through source.hvn_1
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.hvn_2
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.hvn-route-lookup Source
Matches data instances of hcp_hvn_route.
Classification: hcp.concept.network-configuration.
Contributions
- targets
rf.concept.virtual-networkthroughsource.hvn_link.
Conditions, identity and resolution
Contribution through source.hvn_link
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.hvn-route Source
Matches resource instances of hcp_hvn_route.
Classification: hcp.concept.network-configuration.
Contributions
- targets
rf.concept.virtual-networkthroughsource.hvn_link.
Conditions, identity and resolution
Contribution through source.hvn_link
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.hvn-lookup Source
Matches data instances of hcp_hvn.
Classification: rf.concept.virtual-network.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id", "hvn_id", "self_link"]scope:"provider"
Endpoint
attributes:["id", "hvn_id", "self_link"]
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.hvn Source
Matches resource instances of hcp_hvn.
Classification: rf.concept.virtual-network.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id", "hvn_id", "self_link"]scope:"provider"
Endpoint
attributes:["id", "hvn_id", "self_link"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.iam-workload-identity-provider Source
Matches resource instances of hcp_iam_workload_identity_provider.
Classification: hcp.concept.workload-identity-provider.
Relations
hcp.relation.federates-to: targetsrf.concept.service-identitythroughsource.service_principal.
Conditions, identity and resolution
Relation through source.service_principal
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.notifications-webhook Source
Matches resource instances of hcp_notifications_webhook.
Classification: hcp.concept.notification-webhook.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.organization-iam-binding Source
Matches resource instances of hcp_organization_iam_binding.
Classification: hcp.concept.access-control-configuration.
hcp.rule.organization-iam-policy Source
Matches resource instances of hcp_organization_iam_policy.
Classification: hcp.concept.access-control-configuration.
hcp.rule.organization-lookup Source
Matches data instances of hcp_organization.
Classification: hcp.concept.organization.
Conditions, identity and resolution
Identity
attributes:["resource_id"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.packer-artifact-lookup Source
Matches data instances of hcp_packer_artifact.
Classification: hcp.concept.packer-artifact.
Contexts
hcp.context.ownership: targetshcp.concept.packer-bucketthroughsource.bucket_name.
Relations
hcp.relation.belongs-to-version: targetshcp.concept.packer-versionthroughsource.version_fingerprint.
Conditions, identity and resolution
Context through source.bucket_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
Relation through source.version_fingerprint
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.fingerprintmatch.strategy:"exact"
hcp.rule.packer-bucket-iam-binding Source
Matches resource instances of hcp_packer_bucket_iam_binding.
Classification: hcp.concept.packer-configuration.
Contributions
- targets
hcp.concept.packer-bucketthroughsource.resource_name.
Conditions, identity and resolution
Contribution through source.resource_name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.packer-bucket-iam-policy Source
Matches resource instances of hcp_packer_bucket_iam_policy.
Classification: hcp.concept.packer-configuration.
Contributions
- targets
hcp.concept.packer-bucketthroughsource.resource_name.
Conditions, identity and resolution
Contribution through source.resource_name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.packer-bucket Source
Matches resource instances of hcp_packer_bucket.
Classification: hcp.concept.packer-bucket.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["name", "resource_name"]scope:"provider"
Endpoint
attributes:["name", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.packer-channel-assignment Source
Matches resource instances of hcp_packer_channel_assignment.
Classification: hcp.concept.packer-configuration.
Contributions
- targets
hcp.concept.packer-channelthroughsource.channel_name. - targets
hcp.concept.packer-versionthroughsource.version_fingerprint.
Conditions, identity and resolution
Contribution through source.channel_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Contribution through source.version_fingerprint
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.fingerprintmatch.strategy:"exact"
hcp.rule.packer-channel Source
Matches resource instances of hcp_packer_channel.
Classification: hcp.concept.packer-channel.
Contexts
hcp.context.ownership: targetshcp.concept.packer-bucketthroughsource.bucket_name.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.bucket_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
hcp.rule.packer-version-lookup Source
Matches data instances of hcp_packer_version.
Classification: hcp.concept.packer-version.
Contexts
hcp.context.ownership: targetshcp.concept.packer-bucketthroughsource.bucket_name.
Relations
hcp.relation.selected-by-channel: targetshcp.concept.packer-channelthroughsource.channel_name.
Conditions, identity and resolution
Identity
attributes:["id", "fingerprint"]scope:"provider"
Endpoint
attributes:["id", "fingerprint"]
Context through source.bucket_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
Relation through source.channel_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.namematch.strategy:"exact"
hcp.rule.private-link-lookup Source
Matches data instances of hcp_private_link.
Classification: hcp.concept.private-link-service.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.exposes-vault-cluster: targetshcp.concept.vault-dedicated-clusterthroughsource.vault_cluster_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.vault_cluster_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.cluster_idmatch.strategy:"exact"
hcp.rule.private-link Source
Matches resource instances of hcp_private_link.
Classification: hcp.concept.private-link-service.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.exposes-vault-cluster: targetshcp.concept.vault-dedicated-clusterthroughsource.vault_cluster_id.
Conditions, identity and resolution
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.vault_cluster_id
on_null:"absent"on_empty:"absent"match.by:target.cluster_idmatch.strategy:"exact"
hcp.rule.project-iam-binding Source
Matches resource instances of hcp_project_iam_binding.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Contribution through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.project-iam-policy Source
Matches resource instances of hcp_project_iam_policy.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Contribution through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.project-lookup Source
Matches data instances of hcp_project.
Classification: hcp.concept.project.
Conditions, identity and resolution
Identity
attributes:["resource_id"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.project Source
Matches resource instances of hcp_project.
Classification: hcp.concept.project.
Conditions, identity and resolution
Identity
attributes:["resource_id"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.resource-control-policy Source
Matches resource instances of hcp_resource_control_policy.
Classification: hcp.concept.access-control-configuration.
Contributions
- targets
hcp.concept.organizationthroughsource.organization_id.
Conditions, identity and resolution
Contribution through source.organization_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.service-principal-lookup Source
Matches data instances of hcp_service_principal.
Classification: rf.concept.service-identity.
Conditions, identity and resolution
Identity
attributes:["resource_name"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.service-principal Source
Matches resource instances of hcp_service_principal.
Classification: rf.concept.service-identity.
Conditions, identity and resolution
Identity
attributes:["resource_name"]scope:"provider"
Endpoint
attributes:["resource_id", "resource_name"]
hcp.rule.vault-cluster-lookup Source
Matches data instances of hcp_vault_cluster.
Classification: hcp.concept.vault-dedicated-cluster.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.replicates-from: targetshcp.concept.vault-dedicated-clusterthroughsource.primary_link.
Conditions, identity and resolution
Identity
attributes:["id", "cluster_id", "self_link", "vault_public_endpoint_url"]scope:"provider"
Endpoint
attributes:["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]
Context through source.hvn_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.primary_link
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.vault-cluster Source
Matches resource instances of hcp_vault_cluster.
Classification: hcp.concept.vault-dedicated-cluster.
Contexts
rf.context.network: targetsrf.concept.virtual-networkthroughsource.hvn_id.hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.replicates-from: targetshcp.concept.vault-dedicated-clusterthroughsource.primary_link.
Conditions, identity and resolution
Identity
attributes:["id", "cluster_id", "self_link", "vault_public_endpoint_url"]scope:"provider"
Endpoint
attributes:["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]
Context through source.hvn_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.hvn_idmatch.strategy:"exact"
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.primary_link
on_null:"absent"on_empty:"absent"match.by:target.self_linkmatch.strategy:"exact"
hcp.rule.vault-plugin-lookup Source
Matches data instances of hcp_vault_plugin.
Classification: hcp.concept.vault-plugin.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.extends-cluster: targetshcp.concept.vault-dedicated-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.cluster_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.cluster_idmatch.strategy:"exact"
hcp.rule.vault-plugin Source
Matches resource instances of hcp_vault_plugin.
Classification: hcp.concept.vault-plugin.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.extends-cluster: targetshcp.concept.vault-dedicated-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.cluster_id
on_null:"absent"on_empty:"absent"match.by:target.cluster_idmatch.strategy:"exact"
hcp.rule.vault-radar-integration-jira-connection Source
Matches resource instances of hcp_vault_radar_integration_jira_connection.
Classification: hcp.concept.vault-radar-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-radar-integration-jira-subscription Source
Matches resource instances of hcp_vault_radar_integration_jira_subscription.
Classification: hcp.concept.vault-radar-configuration.
Contributions
- targets
hcp.concept.vault-radar-integrationthroughsource.connection_id.
Conditions, identity and resolution
Contribution through source.connection_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
hcp.rule.vault-radar-integration-slack-connection Source
Matches resource instances of hcp_vault_radar_integration_slack_connection.
Classification: hcp.concept.vault-radar-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-radar-integration-slack-subscription Source
Matches resource instances of hcp_vault_radar_integration_slack_subscription.
Classification: hcp.concept.vault-radar-configuration.
Contributions
- targets
hcp.concept.vault-radar-integrationthroughsource.connection_id.
Conditions, identity and resolution
Contribution through source.connection_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
hcp.rule.vault-radar-resource-iam-binding Source
Matches resource instances of hcp_vault_radar_resource_iam_binding.
Classification: hcp.concept.vault-radar-configuration.
hcp.rule.vault-radar-resource-iam-policy Source
Matches resource instances of hcp_vault_radar_resource_iam_policy.
Classification: hcp.concept.vault-radar-configuration.
hcp.rule.vault-radar-secret-manager-vault-dedicated Source
Matches resource instances of hcp_vault_radar_secret_manager_vault_dedicated.
Classification: hcp.concept.vault-radar-secret-manager.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.connects-vault-cluster: targetshcp.concept.vault-dedicated-clusterthroughsource.vault_url.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.vault_url
on_null:"absent"on_empty:"absent"match.by:target.vault_public_endpoint_urlmatch.strategy:"exact"
hcp.rule.vault-radar-source-github-cloud Source
Matches resource instances of hcp_vault_radar_source_github_cloud.
Classification: hcp.concept.vault-radar-source.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-radar-source-github-enterprise Source
Matches resource instances of hcp_vault_radar_source_github_enterprise.
Classification: hcp.concept.vault-radar-source.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-app-iam-binding Source
Matches resource instances of hcp_vault_secrets_app_iam_binding.
Classification: hcp.concept.vault-secrets-configuration.
Contributions
- targets
hcp.concept.vault-secrets-applicationthroughsource.resource_name.
Conditions, identity and resolution
Contribution through source.resource_name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.vault-secrets-app-iam-policy Source
Matches resource instances of hcp_vault_secrets_app_iam_policy.
Classification: hcp.concept.vault-secrets-configuration.
Contributions
- targets
hcp.concept.vault-secrets-applicationthroughsource.resource_name.
Conditions, identity and resolution
Contribution through source.resource_name
on_null:"absent"on_empty:"absent"match.by:target.resource_namematch.strategy:"exact"
hcp.rule.vault-secrets-app-lookup Source
Matches data instances of hcp_vault_secrets_app.
Classification: hcp.concept.vault-secrets-application.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["app_name"]scope:"provider"
Endpoint
attributes:["id", "app_name"]
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-app Source
Matches resource instances of hcp_vault_secrets_app.
Classification: hcp.concept.vault-secrets-application.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.syncs-to: targetshcp.concept.vault-secrets-syncthroughsource.sync_names.
Conditions, identity and resolution
Identity
attributes:["app_name", "resource_name"]scope:"provider"
Endpoint
attributes:["id", "app_name", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.sync_names
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
hcp.rule.vault-secrets-dynamic-secret-lookup Source
Matches data instances of hcp_vault_secrets_dynamic_secret.
Classification: hcp.concept.vault-secrets-configuration.
Contributions
- targets
hcp.concept.vault-secrets-applicationthroughsource.app_name.
Conditions, identity and resolution
Contribution through source.app_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.app_namematch.strategy:"exact"
hcp.rule.vault-secrets-dynamic-secret Source
Matches resource instances of hcp_vault_secrets_dynamic_secret.
Classification: hcp.concept.managed-secret.
Contexts
hcp.context.ownership: targetshcp.concept.vault-secrets-applicationthroughsource.app_name.
Relations
hcp.relation.uses-integration: targetshcp.concept.vault-secrets-integrationthroughsource.integration_name.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_impersonate_service_account.service_account_email.
Conditions, identity and resolution
Context through source.app_name
on_null:"absent"on_empty:"absent"match.by:target.app_namematch.strategy:"exact"
Relation through source.integration_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.gcp_impersonate_service_account.service_account_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-aws Source
Matches resource instances of hcp_vault_secrets_integration_aws.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-azure Source
Matches resource instances of hcp_vault_secrets_integration_azure.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.federated_workload_identity.client_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.federated_workload_identity.client_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-confluent Source
Matches resource instances of hcp_vault_secrets_integration_confluent.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-gcp Source
Matches resource instances of hcp_vault_secrets_integration_gcp.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.federated_workload_identity.service_account_email.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.service_account_key.client_email.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.federated_workload_identity.service_account_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
Relation through source.service_account_key.client_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-mongodbatlas Source
Matches resource instances of hcp_vault_secrets_integration_mongodbatlas.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-integration-twilio Source
Matches resource instances of hcp_vault_secrets_integration_twilio.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.vault-secrets-integration Source
Matches resource instances of hcp_vault_secrets_integration.
Classification: hcp.concept.vault-secrets-integration.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.azure_federated_workload_identity.client_id.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_federated_workload_identity.service_account_email.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_service_account_key.client_email.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id", "resource_name"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.azure_federated_workload_identity.client_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.gcp_federated_workload_identity.service_account_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
Relation through source.gcp_service_account_key.client_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
hcp.rule.vault-secrets-rotating-secret-lookup Source
Matches data instances of hcp_vault_secrets_rotating_secret.
Classification: hcp.concept.vault-secrets-configuration.
Contributions
- targets
hcp.concept.vault-secrets-applicationthroughsource.app_name.
Conditions, identity and resolution
Contribution through source.app_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.app_namematch.strategy:"exact"
hcp.rule.vault-secrets-rotating-secret Source
Matches resource instances of hcp_vault_secrets_rotating_secret.
Classification: hcp.concept.managed-secret.
Contexts
hcp.context.ownership: targetshcp.concept.vault-secrets-applicationthroughsource.app_name.
Relations
hcp.relation.uses-integration: targetshcp.concept.vault-secrets-integrationthroughsource.integration_name.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.azure_application_password.app_client_id.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.confluent_service_account.service_account_id.hcp.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_service_account_key.service_account_email.
Conditions, identity and resolution
Context through source.app_name
on_null:"absent"on_empty:"absent"match.by:target.app_namematch.strategy:"exact"
Relation through source.integration_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.azure_application_password.app_client_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.confluent_service_account.service_account_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.gcp_service_account_key.service_account_email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
hcp.rule.vault-secrets-secret-lookup Source
Matches data instances of hcp_vault_secrets_secret.
Classification: hcp.concept.vault-secrets-configuration.
Contributions
- targets
hcp.concept.vault-secrets-applicationthroughsource.app_name.
Conditions, identity and resolution
Contribution through source.app_name
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.app_namematch.strategy:"exact"
hcp.rule.vault-secrets-secret Source
Matches resource instances of hcp_vault_secrets_secret.
Classification: hcp.concept.managed-secret.
Contexts
hcp.context.ownership: targetshcp.concept.vault-secrets-applicationthroughsource.app_name.
Conditions, identity and resolution
Context through source.app_name
on_null:"absent"on_empty:"absent"match.by:target.app_namematch.strategy:"exact"
hcp.rule.vault-secrets-sync Source
Matches resource instances of hcp_vault_secrets_sync.
Classification: hcp.concept.vault-secrets-sync.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-integration: targetshcp.concept.vault-secrets-integrationthroughsource.integration_name.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "resource_id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.integration_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
hcp.rule.waypoint-action-lookup Source
Matches data instances of hcp_waypoint_action.
Classification: hcp.concept.waypoint-configuration.
hcp.rule.waypoint-action Source
Matches resource instances of hcp_waypoint_action.
Classification: hcp.concept.waypoint-configuration.
hcp.rule.waypoint-add-on-definition-lookup Source
Matches data instances of hcp_waypoint_add_on_definition.
Classification: hcp.concept.waypoint-add-on-definition.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-add-on-definition Source
Matches resource instances of hcp_waypoint_add_on_definition.
Classification: hcp.concept.waypoint-add-on-definition.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-add-on-lookup Source
Matches data instances of hcp_waypoint_add_on.
Classification: hcp.concept.waypoint-add-on.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.extends-application: targetshcp.concept.waypoint-applicationthroughsource.application_id.hcp.relation.instantiates-definition: targetshcp.concept.waypoint-add-on-definitionthroughsource.definition_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.application_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
Relation through source.definition_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
hcp.rule.waypoint-add-on Source
Matches resource instances of hcp_waypoint_add_on.
Classification: hcp.concept.waypoint-add-on.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.extends-application: targetshcp.concept.waypoint-applicationthroughsource.application_id.hcp.relation.instantiates-definition: targetshcp.concept.waypoint-add-on-definitionthroughsource.definition_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.application_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.definition_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
hcp.rule.waypoint-agent-group-lookup Source
Matches data instances of hcp_waypoint_agent_group.
Classification: hcp.concept.waypoint-agent-group.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-agent-group Source
Matches resource instances of hcp_waypoint_agent_group.
Classification: hcp.concept.waypoint-agent-group.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-application-lookup Source
Matches data instances of hcp_waypoint_application.
Classification: hcp.concept.waypoint-application.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-template: targetshcp.concept.waypoint-templatethroughsource.template_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.template_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
hcp.rule.waypoint-application Source
Matches resource instances of hcp_waypoint_application.
Classification: hcp.concept.waypoint-application.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Relations
hcp.relation.uses-template: targetshcp.concept.waypoint-templatethroughsource.template_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
Relation through source.template_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
hcp.rule.waypoint-template-lookup Source
Matches data instances of hcp_waypoint_template.
Classification: hcp.concept.waypoint-template.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"indeterminate"on_empty:"indeterminate"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-template Source
Matches resource instances of hcp_waypoint_template.
Classification: hcp.concept.waypoint-template.
Contexts
hcp.context.ownership: targetshcp.concept.projectthroughsource.project_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.project_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.resource_idmatch.strategy:"exact"
hcp.rule.waypoint-tfc-config Source
Matches resource instances of hcp_waypoint_tfc_config.
Classification: hcp.concept.waypoint-configuration.