# hcp Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `hashicorp/hcp`: `= 0.114.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `hcp_aws_network_peering` | `data` | [`network-peering`](#hcp-concept-network-peering) | [`aws-network-peering-lookup`](#rule-aws-network-peering-lookup) |
| `hcp_aws_network_peering` | `resource` | [`network-peering`](#hcp-concept-network-peering) | [`aws-network-peering`](#rule-aws-network-peering) |
| `hcp_aws_transit_gateway_attachment` | `data` | [`transit-gateway-attachment`](#hcp-concept-transit-gateway-attachment) | [`aws-transit-gateway-attachment-lookup`](#rule-aws-transit-gateway-attachment-lookup) |
| `hcp_aws_transit_gateway_attachment` | `resource` | [`transit-gateway-attachment`](#hcp-concept-transit-gateway-attachment) | [`aws-transit-gateway-attachment`](#rule-aws-transit-gateway-attachment) |
| `hcp_azure_peering_connection` | `data` | [`network-peering`](#hcp-concept-network-peering) | [`azure-peering-connection-lookup`](#rule-azure-peering-connection-lookup) |
| `hcp_azure_peering_connection` | `resource` | [`network-peering`](#hcp-concept-network-peering) | [`azure-peering-connection`](#rule-azure-peering-connection) |
| `hcp_boundary_cluster` | `data` | [`boundary-cluster`](#hcp-concept-boundary-cluster) | [`boundary-cluster-lookup`](#rule-boundary-cluster-lookup) |
| `hcp_boundary_cluster` | `resource` | [`boundary-cluster`](#hcp-concept-boundary-cluster) | [`boundary-cluster`](#rule-boundary-cluster) |
| `hcp_consul_cluster` | `data` | [`consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster) | [`consul-cluster-lookup`](#rule-consul-cluster-lookup) |
| `hcp_consul_cluster` | `resource` | [`consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster) | [`consul-cluster`](#rule-consul-cluster) |
| `hcp_consul_snapshot` | `resource` | [`consul-configuration`](#hcp-concept-consul-configuration) | [`consul-snapshot`](#rule-consul-snapshot) |
| `hcp_dns_forwarding_rule` | `data` | [`network-configuration`](#hcp-concept-network-configuration) | [`dns-forwarding-rule-lookup`](#rule-dns-forwarding-rule-lookup) |
| `hcp_dns_forwarding_rule` | `resource` | [`network-configuration`](#hcp-concept-network-configuration) | [`dns-forwarding-rule`](#rule-dns-forwarding-rule) |
| `hcp_dns_forwarding` | `data` | [`dns-forwarding`](#hcp-concept-dns-forwarding) | [`dns-forwarding-lookup`](#rule-dns-forwarding-lookup) |
| `hcp_dns_forwarding` | `resource` | [`dns-forwarding`](#hcp-concept-dns-forwarding) | [`dns-forwarding`](#rule-dns-forwarding) |
| `hcp_group_iam_binding` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`group-iam-binding`](#rule-group-iam-binding) |
| `hcp_group_iam_policy` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`group-iam-policy`](#rule-group-iam-policy) |
| `hcp_group_members` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`group-members`](#rule-group-members) |
| `hcp_group` | `data` | [`identity-group`](#hcp-concept-identity-group) | [`group-lookup`](#rule-group-lookup) |
| `hcp_group` | `resource` | [`identity-group`](#hcp-concept-identity-group) | [`group`](#rule-group) |
| `hcp_hvn_peering_connection` | `data` | [`network-peering`](#hcp-concept-network-peering) | [`hvn-peering-connection-lookup`](#rule-hvn-peering-connection-lookup) |
| `hcp_hvn_peering_connection` | `resource` | [`network-peering`](#hcp-concept-network-peering) | [`hvn-peering-connection`](#rule-hvn-peering-connection) |
| `hcp_hvn_route` | `data` | [`network-configuration`](#hcp-concept-network-configuration) | [`hvn-route-lookup`](#rule-hvn-route-lookup) |
| `hcp_hvn_route` | `resource` | [`network-configuration`](#hcp-concept-network-configuration) | [`hvn-route`](#rule-hvn-route) |
| `hcp_hvn` | `data` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`hvn-lookup`](#rule-hvn-lookup) |
| `hcp_hvn` | `resource` | [`virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) | [`hvn`](#rule-hvn) |
| `hcp_iam_workload_identity_provider` | `resource` | [`workload-identity-provider`](#hcp-concept-workload-identity-provider) | [`iam-workload-identity-provider`](#rule-iam-workload-identity-provider) |
| `hcp_notifications_webhook` | `resource` | [`notification-webhook`](#hcp-concept-notification-webhook) | [`notifications-webhook`](#rule-notifications-webhook) |
| `hcp_organization_iam_binding` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`organization-iam-binding`](#rule-organization-iam-binding) |
| `hcp_organization_iam_policy` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`organization-iam-policy`](#rule-organization-iam-policy) |
| `hcp_organization` | `data` | [`organization`](#hcp-concept-organization) | [`organization-lookup`](#rule-organization-lookup) |
| `hcp_packer_artifact` | `data` | [`packer-artifact`](#hcp-concept-packer-artifact) | [`packer-artifact-lookup`](#rule-packer-artifact-lookup) |
| `hcp_packer_bucket_iam_binding` | `resource` | [`packer-configuration`](#hcp-concept-packer-configuration) | [`packer-bucket-iam-binding`](#rule-packer-bucket-iam-binding) |
| `hcp_packer_bucket_iam_policy` | `resource` | [`packer-configuration`](#hcp-concept-packer-configuration) | [`packer-bucket-iam-policy`](#rule-packer-bucket-iam-policy) |
| `hcp_packer_bucket` | `resource` | [`packer-bucket`](#hcp-concept-packer-bucket) | [`packer-bucket`](#rule-packer-bucket) |
| `hcp_packer_channel_assignment` | `resource` | [`packer-configuration`](#hcp-concept-packer-configuration) | [`packer-channel-assignment`](#rule-packer-channel-assignment) |
| `hcp_packer_channel` | `resource` | [`packer-channel`](#hcp-concept-packer-channel) | [`packer-channel`](#rule-packer-channel) |
| `hcp_packer_version` | `data` | [`packer-version`](#hcp-concept-packer-version) | [`packer-version-lookup`](#rule-packer-version-lookup) |
| `hcp_private_link` | `data` | [`private-link-service`](#hcp-concept-private-link-service) | [`private-link-lookup`](#rule-private-link-lookup) |
| `hcp_private_link` | `resource` | [`private-link-service`](#hcp-concept-private-link-service) | [`private-link`](#rule-private-link) |
| `hcp_project_iam_binding` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`project-iam-binding`](#rule-project-iam-binding) |
| `hcp_project_iam_policy` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`project-iam-policy`](#rule-project-iam-policy) |
| `hcp_project` | `data` | [`project`](#hcp-concept-project) | [`project-lookup`](#rule-project-lookup) |
| `hcp_project` | `resource` | [`project`](#hcp-concept-project) | [`project`](#rule-project) |
| `hcp_resource_control_policy` | `resource` | [`access-control-configuration`](#hcp-concept-access-control-configuration) | [`resource-control-policy`](#rule-resource-control-policy) |
| `hcp_service_principal` | `data` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`service-principal-lookup`](#rule-service-principal-lookup) |
| `hcp_service_principal` | `resource` | [`service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) | [`service-principal`](#rule-service-principal) |
| `hcp_vault_cluster` | `data` | [`vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) | [`vault-cluster-lookup`](#rule-vault-cluster-lookup) |
| `hcp_vault_cluster` | `resource` | [`vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) | [`vault-cluster`](#rule-vault-cluster) |
| `hcp_vault_plugin` | `data` | [`vault-plugin`](#hcp-concept-vault-plugin) | [`vault-plugin-lookup`](#rule-vault-plugin-lookup) |
| `hcp_vault_plugin` | `resource` | [`vault-plugin`](#hcp-concept-vault-plugin) | [`vault-plugin`](#rule-vault-plugin) |
| `hcp_vault_radar_integration_jira_connection` | `resource` | [`vault-radar-integration`](#hcp-concept-vault-radar-integration) | [`vault-radar-integration-jira-connection`](#rule-vault-radar-integration-jira-connection) |
| `hcp_vault_radar_integration_jira_subscription` | `resource` | [`vault-radar-configuration`](#hcp-concept-vault-radar-configuration) | [`vault-radar-integration-jira-subscription`](#rule-vault-radar-integration-jira-subscription) |
| `hcp_vault_radar_integration_slack_connection` | `resource` | [`vault-radar-integration`](#hcp-concept-vault-radar-integration) | [`vault-radar-integration-slack-connection`](#rule-vault-radar-integration-slack-connection) |
| `hcp_vault_radar_integration_slack_subscription` | `resource` | [`vault-radar-configuration`](#hcp-concept-vault-radar-configuration) | [`vault-radar-integration-slack-subscription`](#rule-vault-radar-integration-slack-subscription) |
| `hcp_vault_radar_resource_iam_binding` | `resource` | [`vault-radar-configuration`](#hcp-concept-vault-radar-configuration) | [`vault-radar-resource-iam-binding`](#rule-vault-radar-resource-iam-binding) |
| `hcp_vault_radar_resource_iam_policy` | `resource` | [`vault-radar-configuration`](#hcp-concept-vault-radar-configuration) | [`vault-radar-resource-iam-policy`](#rule-vault-radar-resource-iam-policy) |
| `hcp_vault_radar_secret_manager_vault_dedicated` | `resource` | [`vault-radar-secret-manager`](#hcp-concept-vault-radar-secret-manager) | [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated) |
| `hcp_vault_radar_source_github_cloud` | `resource` | [`vault-radar-source`](#hcp-concept-vault-radar-source) | [`vault-radar-source-github-cloud`](#rule-vault-radar-source-github-cloud) |
| `hcp_vault_radar_source_github_enterprise` | `resource` | [`vault-radar-source`](#hcp-concept-vault-radar-source) | [`vault-radar-source-github-enterprise`](#rule-vault-radar-source-github-enterprise) |
| `hcp_vault_secrets_app_iam_binding` | `resource` | [`vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration) | [`vault-secrets-app-iam-binding`](#rule-vault-secrets-app-iam-binding) |
| `hcp_vault_secrets_app_iam_policy` | `resource` | [`vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration) | [`vault-secrets-app-iam-policy`](#rule-vault-secrets-app-iam-policy) |
| `hcp_vault_secrets_app` | `data` | [`vault-secrets-application`](#hcp-concept-vault-secrets-application) | [`vault-secrets-app-lookup`](#rule-vault-secrets-app-lookup) |
| `hcp_vault_secrets_app` | `resource` | [`vault-secrets-application`](#hcp-concept-vault-secrets-application) | [`vault-secrets-app`](#rule-vault-secrets-app) |
| `hcp_vault_secrets_dynamic_secret` | `data` | [`vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration) | [`vault-secrets-dynamic-secret-lookup`](#rule-vault-secrets-dynamic-secret-lookup) |
| `hcp_vault_secrets_dynamic_secret` | `resource` | [`managed-secret`](#hcp-concept-managed-secret) | [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret) |
| `hcp_vault_secrets_integration_aws` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-aws`](#rule-vault-secrets-integration-aws) |
| `hcp_vault_secrets_integration_azure` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-azure`](#rule-vault-secrets-integration-azure) |
| `hcp_vault_secrets_integration_confluent` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-confluent`](#rule-vault-secrets-integration-confluent) |
| `hcp_vault_secrets_integration_gcp` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-gcp`](#rule-vault-secrets-integration-gcp) |
| `hcp_vault_secrets_integration_mongodbatlas` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-mongodbatlas`](#rule-vault-secrets-integration-mongodbatlas) |
| `hcp_vault_secrets_integration_twilio` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration-twilio`](#rule-vault-secrets-integration-twilio) |
| `hcp_vault_secrets_integration` | `resource` | [`vault-secrets-integration`](#hcp-concept-vault-secrets-integration) | [`vault-secrets-integration`](#rule-vault-secrets-integration) |
| `hcp_vault_secrets_rotating_secret` | `data` | [`vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration) | [`vault-secrets-rotating-secret-lookup`](#rule-vault-secrets-rotating-secret-lookup) |
| `hcp_vault_secrets_rotating_secret` | `resource` | [`managed-secret`](#hcp-concept-managed-secret) | [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret) |
| `hcp_vault_secrets_secret` | `data` | [`vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration) | [`vault-secrets-secret-lookup`](#rule-vault-secrets-secret-lookup) |
| `hcp_vault_secrets_secret` | `resource` | [`managed-secret`](#hcp-concept-managed-secret) | [`vault-secrets-secret`](#rule-vault-secrets-secret) |
| `hcp_vault_secrets_sync` | `resource` | [`vault-secrets-sync`](#hcp-concept-vault-secrets-sync) | [`vault-secrets-sync`](#rule-vault-secrets-sync) |
| `hcp_waypoint_action` | `data` | [`waypoint-configuration`](#hcp-concept-waypoint-configuration) | [`waypoint-action-lookup`](#rule-waypoint-action-lookup) |
| `hcp_waypoint_action` | `resource` | [`waypoint-configuration`](#hcp-concept-waypoint-configuration) | [`waypoint-action`](#rule-waypoint-action) |
| `hcp_waypoint_add_on_definition` | `data` | [`waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition) | [`waypoint-add-on-definition-lookup`](#rule-waypoint-add-on-definition-lookup) |
| `hcp_waypoint_add_on_definition` | `resource` | [`waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition) | [`waypoint-add-on-definition`](#rule-waypoint-add-on-definition) |
| `hcp_waypoint_add_on` | `data` | [`waypoint-add-on`](#hcp-concept-waypoint-add-on) | [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup) |
| `hcp_waypoint_add_on` | `resource` | [`waypoint-add-on`](#hcp-concept-waypoint-add-on) | [`waypoint-add-on`](#rule-waypoint-add-on) |
| `hcp_waypoint_agent_group` | `data` | [`waypoint-agent-group`](#hcp-concept-waypoint-agent-group) | [`waypoint-agent-group-lookup`](#rule-waypoint-agent-group-lookup) |
| `hcp_waypoint_agent_group` | `resource` | [`waypoint-agent-group`](#hcp-concept-waypoint-agent-group) | [`waypoint-agent-group`](#rule-waypoint-agent-group) |
| `hcp_waypoint_application` | `data` | [`waypoint-application`](#hcp-concept-waypoint-application) | [`waypoint-application-lookup`](#rule-waypoint-application-lookup) |
| `hcp_waypoint_application` | `resource` | [`waypoint-application`](#hcp-concept-waypoint-application) | [`waypoint-application`](#rule-waypoint-application) |
| `hcp_waypoint_template` | `data` | [`waypoint-template`](#hcp-concept-waypoint-template) | [`waypoint-template-lookup`](#rule-waypoint-template-lookup) |
| `hcp_waypoint_template` | `resource` | [`waypoint-template`](#hcp-concept-waypoint-template) | [`waypoint-template`](#rule-waypoint-template) |
| `hcp_waypoint_tfc_config` | `resource` | [`waypoint-configuration`](#hcp-concept-waypoint-configuration) | [`waypoint-tfc-config`](#rule-waypoint-tfc-config) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="hcp-concept-access-control-configuration"><code>hcp.concept.access-control-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L1-L3">Source</a></dt>
<dd>

An IAM binding, membership, policy, or constraint supporting an HCP boundary.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`group-iam-binding`](#rule-group-iam-binding)
- [`group-iam-policy`](#rule-group-iam-policy)
- [`group-members`](#rule-group-members)
- [`organization-iam-binding`](#rule-organization-iam-binding)
- [`organization-iam-policy`](#rule-organization-iam-policy)
- [`project-iam-binding`](#rule-project-iam-binding)
- [`project-iam-policy`](#rule-project-iam-policy)
- [`resource-control-policy`](#rule-resource-control-policy)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-boundary-cluster"><code>hcp.concept.boundary-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/boundary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A HashiCorp-managed Boundary control plane on HCP.

</dd>
<dd>

Used by [`boundary-cluster`](#rule-boundary-cluster), [`boundary-cluster-lookup`](#rule-boundary-cluster-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-consul-configuration"><code>hcp.concept.consul-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L1-L3">Source</a></dt>
<dd>

A legacy snapshot or supporting setting for an HCP Consul Dedicated cluster.

</dd>
<dd>

Used by [`consul-snapshot`](#rule-consul-snapshot).

</dd>
</div>

<div>
<dt id="hcp-concept-consul-dedicated-cluster"><code>hcp.concept.consul-dedicated-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L5-L7">Source</a></dt>
<dd>

A legacy HCP Consul Dedicated cluster retained for provider-state architecture after end of life.

</dd>
<dd>

Used by [`consul-cluster`](#rule-consul-cluster), [`consul-cluster-lookup`](#rule-consul-cluster-lookup), [`consul-snapshot`](#rule-consul-snapshot).

</dd>
</div>

<div>
<dt id="hcp-concept-dns-forwarding"><code>hcp.concept.dns-forwarding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/dns-forwarding.rf.hcl#L1-L3">Source</a></dt>
<dd>

A private DNS forwarding boundary associated with an HVN connection.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`dns-forwarding`](#rule-dns-forwarding)
- [`dns-forwarding-lookup`](#rule-dns-forwarding-lookup)
- [`dns-forwarding-rule`](#rule-dns-forwarding-rule)
- [`dns-forwarding-rule-lookup`](#rule-dns-forwarding-rule-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-identity-group"><code>hcp.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`group`](#rule-group)
- [`group-iam-binding`](#rule-group-iam-binding)
- [`group-iam-policy`](#rule-group-iam-policy)
- [`group-lookup`](#rule-group-lookup)
- [`group-members`](#rule-group-members)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-managed-secret"><code>hcp.concept.managed-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed secret identity whose sensitive value stays outside architecture output.

</dd>
<dd>

Used by [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret), [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret), [`vault-secrets-secret`](#rule-vault-secrets-secret).

</dd>
</div>

<div>
<dt id="hcp-concept-network-configuration"><code>hcp.concept.network-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L1-L3">Source</a></dt>
<dd>

A route or supporting setting attached to HCP network connectivity.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`dns-forwarding-rule`](#rule-dns-forwarding-rule)
- [`dns-forwarding-rule-lookup`](#rule-dns-forwarding-rule-lookup)
- [`hvn-route`](#rule-hvn-route)
- [`hvn-route-lookup`](#rule-hvn-route-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-network-peering"><code>hcp.concept.network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vocabulary.rf.hcl#L9-L11">Source</a></dt>
<dd>

A direct private connectivity agreement between virtual networks.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`aws-network-peering`](#rule-aws-network-peering)
- [`aws-network-peering-lookup`](#rule-aws-network-peering-lookup)
- [`azure-peering-connection`](#rule-azure-peering-connection)
- [`azure-peering-connection-lookup`](#rule-azure-peering-connection-lookup)
- [`hvn-peering-connection`](#rule-hvn-peering-connection)
- [`hvn-peering-connection-lookup`](#rule-hvn-peering-connection-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-notification-webhook"><code>hcp.concept.notification-webhook</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/operations/audit-notifications.rf.hcl#L2-L4">Source</a></dt>
<dd>

A webhook receiving HCP project resource lifecycle events.

</dd>
<dd>

Used by [`notifications-webhook`](#rule-notifications-webhook).

</dd>
</div>

<div>
<dt id="hcp-concept-organization"><code>hcp.concept.organization</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/projects-organizations.rf.hcl#L1-L3">Source</a></dt>
<dd>

A top-level HCP ownership and governance boundary.

</dd>
<dd>

Used by [`organization-lookup`](#rule-organization-lookup), [`resource-control-policy`](#rule-resource-control-policy).

</dd>
</div>

<div>
<dt id="hcp-concept-packer-artifact"><code>hcp.concept.packer-artifact</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L1-L3">Source</a></dt>
<dd>

An HCP Packer record locating a built machine image on an external platform.

</dd>
<dd>

Used by [`packer-artifact-lookup`](#rule-packer-artifact-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-packer-bucket"><code>hcp.concept.packer-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L5-L7">Source</a></dt>
<dd>

An HCP Packer registry boundary grouping machine-image metadata.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`packer-artifact-lookup`](#rule-packer-artifact-lookup)
- [`packer-bucket`](#rule-packer-bucket)
- [`packer-bucket-iam-binding`](#rule-packer-bucket-iam-binding)
- [`packer-bucket-iam-policy`](#rule-packer-bucket-iam-policy)
- [`packer-channel`](#rule-packer-channel)
- [`packer-version-lookup`](#rule-packer-version-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-packer-channel"><code>hcp.concept.packer-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L9-L11">Source</a></dt>
<dd>

A named HCP Packer release channel selecting an image version.

</dd>
<dd>

Used by [`packer-channel`](#rule-packer-channel), [`packer-channel-assignment`](#rule-packer-channel-assignment), [`packer-version-lookup`](#rule-packer-version-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-packer-configuration"><code>hcp.concept.packer-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L13-L15">Source</a></dt>
<dd>

An assignment or access setting supporting HCP Packer registry architecture.

</dd>
<dd>

Used by [`packer-bucket-iam-binding`](#rule-packer-bucket-iam-binding), [`packer-bucket-iam-policy`](#rule-packer-bucket-iam-policy), [`packer-channel-assignment`](#rule-packer-channel-assignment).

</dd>
</div>

<div>
<dt id="hcp-concept-packer-version"><code>hcp.concept.packer-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L17-L19">Source</a></dt>
<dd>

A version of machine-image metadata in HCP Packer.

</dd>
<dd>

Used by [`packer-artifact-lookup`](#rule-packer-artifact-lookup), [`packer-channel-assignment`](#rule-packer-channel-assignment), [`packer-version-lookup`](#rule-packer-version-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-private-link-service"><code>hcp.concept.private-link-service</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L5-L7">Source</a></dt>
<dd>

A provider-side private connectivity service exposing an HCP Vault Dedicated cluster to approved consumers.

</dd>
<dd>

Used by [`private-link`](#rule-private-link), [`private-link-lookup`](#rule-private-link-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-project"><code>hcp.concept.project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/projects-organizations.rf.hcl#L5-L7">Source</a></dt>
<dd>

An HCP boundary grouping managed products and access.

</dd>
<dd>


<details>
<summary>Used by 53 Rules</summary>

- [`aws-network-peering`](#rule-aws-network-peering)
- [`aws-network-peering-lookup`](#rule-aws-network-peering-lookup)
- [`aws-transit-gateway-attachment`](#rule-aws-transit-gateway-attachment)
- [`aws-transit-gateway-attachment-lookup`](#rule-aws-transit-gateway-attachment-lookup)
- [`azure-peering-connection`](#rule-azure-peering-connection)
- [`azure-peering-connection-lookup`](#rule-azure-peering-connection-lookup)
- [`boundary-cluster`](#rule-boundary-cluster)
- [`boundary-cluster-lookup`](#rule-boundary-cluster-lookup)
- [`consul-cluster`](#rule-consul-cluster)
- [`consul-cluster-lookup`](#rule-consul-cluster-lookup)
- [`dns-forwarding`](#rule-dns-forwarding)
- [`dns-forwarding-lookup`](#rule-dns-forwarding-lookup)
- [`hvn`](#rule-hvn)
- [`hvn-lookup`](#rule-hvn-lookup)
- [`hvn-peering-connection`](#rule-hvn-peering-connection)
- [`hvn-peering-connection-lookup`](#rule-hvn-peering-connection-lookup)
- [`notifications-webhook`](#rule-notifications-webhook)
- [`packer-bucket`](#rule-packer-bucket)
- [`private-link`](#rule-private-link)
- [`private-link-lookup`](#rule-private-link-lookup)
- [`project`](#rule-project)
- [`project-iam-binding`](#rule-project-iam-binding)
- [`project-iam-policy`](#rule-project-iam-policy)
- [`project-lookup`](#rule-project-lookup)
- [`vault-cluster`](#rule-vault-cluster)
- [`vault-cluster-lookup`](#rule-vault-cluster-lookup)
- [`vault-plugin`](#rule-vault-plugin)
- [`vault-plugin-lookup`](#rule-vault-plugin-lookup)
- [`vault-radar-integration-jira-connection`](#rule-vault-radar-integration-jira-connection)
- [`vault-radar-integration-slack-connection`](#rule-vault-radar-integration-slack-connection)
- [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated)
- [`vault-radar-source-github-cloud`](#rule-vault-radar-source-github-cloud)
- [`vault-radar-source-github-enterprise`](#rule-vault-radar-source-github-enterprise)
- [`vault-secrets-app`](#rule-vault-secrets-app)
- [`vault-secrets-app-lookup`](#rule-vault-secrets-app-lookup)
- [`vault-secrets-integration`](#rule-vault-secrets-integration)
- [`vault-secrets-integration-aws`](#rule-vault-secrets-integration-aws)
- [`vault-secrets-integration-azure`](#rule-vault-secrets-integration-azure)
- [`vault-secrets-integration-confluent`](#rule-vault-secrets-integration-confluent)
- [`vault-secrets-integration-gcp`](#rule-vault-secrets-integration-gcp)
- [`vault-secrets-integration-mongodbatlas`](#rule-vault-secrets-integration-mongodbatlas)
- [`vault-secrets-integration-twilio`](#rule-vault-secrets-integration-twilio)
- [`vault-secrets-sync`](#rule-vault-secrets-sync)
- [`waypoint-add-on`](#rule-waypoint-add-on)
- [`waypoint-add-on-definition`](#rule-waypoint-add-on-definition)
- [`waypoint-add-on-definition-lookup`](#rule-waypoint-add-on-definition-lookup)
- [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup)
- [`waypoint-agent-group`](#rule-waypoint-agent-group)
- [`waypoint-agent-group-lookup`](#rule-waypoint-agent-group-lookup)
- [`waypoint-application`](#rule-waypoint-application)
- [`waypoint-application-lookup`](#rule-waypoint-application-lookup)
- [`waypoint-template`](#rule-waypoint-template)
- [`waypoint-template-lookup`](#rule-waypoint-template-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-transit-gateway-attachment"><code>hcp.concept.transit-gateway-attachment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L9-L11">Source</a></dt>
<dd>

An attachment connecting an HVN to an AWS Transit Gateway.

</dd>
<dd>

Used by [`aws-transit-gateway-attachment`](#rule-aws-transit-gateway-attachment), [`aws-transit-gateway-attachment-lookup`](#rule-aws-transit-gateway-attachment-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-vault-dedicated-cluster"><code>hcp.concept.vault-dedicated-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L1-L3">Source</a></dt>
<dd>

A HashiCorp-managed Vault Dedicated cluster on HCP.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`private-link`](#rule-private-link)
- [`private-link-lookup`](#rule-private-link-lookup)
- [`vault-cluster`](#rule-vault-cluster)
- [`vault-cluster-lookup`](#rule-vault-cluster-lookup)
- [`vault-plugin`](#rule-vault-plugin)
- [`vault-plugin-lookup`](#rule-vault-plugin-lookup)
- [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-plugin"><code>hcp.concept.vault-plugin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L5-L7">Source</a></dt>
<dd>

A custom plugin installed into an HCP Vault Dedicated cluster.

</dd>
<dd>

Used by [`vault-plugin`](#rule-vault-plugin), [`vault-plugin-lookup`](#rule-vault-plugin-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-vault-radar-configuration"><code>hcp.concept.vault-radar-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L1-L3">Source</a></dt>
<dd>

A subscription or access setting supporting HCP Vault Radar.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`vault-radar-integration-jira-subscription`](#rule-vault-radar-integration-jira-subscription)
- [`vault-radar-integration-slack-subscription`](#rule-vault-radar-integration-slack-subscription)
- [`vault-radar-resource-iam-binding`](#rule-vault-radar-resource-iam-binding)
- [`vault-radar-resource-iam-policy`](#rule-vault-radar-resource-iam-policy)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-radar-integration"><code>hcp.concept.vault-radar-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L5-L7">Source</a></dt>
<dd>

An external workflow destination integrated with HCP Vault Radar.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`vault-radar-integration-jira-connection`](#rule-vault-radar-integration-jira-connection)
- [`vault-radar-integration-jira-subscription`](#rule-vault-radar-integration-jira-subscription)
- [`vault-radar-integration-slack-connection`](#rule-vault-radar-integration-slack-connection)
- [`vault-radar-integration-slack-subscription`](#rule-vault-radar-integration-slack-subscription)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-radar-secret-manager"><code>hcp.concept.vault-radar-secret-manager</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L9-L11">Source</a></dt>
<dd>

A Vault Dedicated secret manager correlated with HCP Vault Radar findings.

</dd>
<dd>

Used by [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated).

</dd>
</div>

<div>
<dt id="hcp-concept-vault-radar-source"><code>hcp.concept.vault-radar-source</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L13-L15">Source</a></dt>
<dd>

A source repository scanned by HCP Vault Radar for secret exposure.

</dd>
<dd>

Used by [`vault-radar-source-github-cloud`](#rule-vault-radar-source-github-cloud), [`vault-radar-source-github-enterprise`](#rule-vault-radar-source-github-enterprise).

</dd>
</div>

<div>
<dt id="hcp-concept-vault-secrets-application"><code>hcp.concept.vault-secrets-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L1-L3">Source</a></dt>
<dd>

An HCP Vault Secrets application boundary grouping secrets and sync destinations.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`vault-secrets-app`](#rule-vault-secrets-app)
- [`vault-secrets-app-iam-binding`](#rule-vault-secrets-app-iam-binding)
- [`vault-secrets-app-iam-policy`](#rule-vault-secrets-app-iam-policy)
- [`vault-secrets-app-lookup`](#rule-vault-secrets-app-lookup)
- [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret)
- [`vault-secrets-dynamic-secret-lookup`](#rule-vault-secrets-dynamic-secret-lookup)
- [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret)
- [`vault-secrets-rotating-secret-lookup`](#rule-vault-secrets-rotating-secret-lookup)
- [`vault-secrets-secret`](#rule-vault-secrets-secret)
- [`vault-secrets-secret-lookup`](#rule-vault-secrets-secret-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-secrets-configuration"><code>hcp.concept.vault-secrets-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L5-L7">Source</a></dt>
<dd>

A secret read or access setting supporting an HCP Vault Secrets application.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`vault-secrets-app-iam-binding`](#rule-vault-secrets-app-iam-binding)
- [`vault-secrets-app-iam-policy`](#rule-vault-secrets-app-iam-policy)
- [`vault-secrets-dynamic-secret-lookup`](#rule-vault-secrets-dynamic-secret-lookup)
- [`vault-secrets-rotating-secret-lookup`](#rule-vault-secrets-rotating-secret-lookup)
- [`vault-secrets-secret-lookup`](#rule-vault-secrets-secret-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-secrets-integration"><code>hcp.concept.vault-secrets-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L9-L11">Source</a></dt>
<dd>

An HCP Vault Secrets integration with an external cloud or SaaS platform.

</dd>
<dd>


<details>
<summary>Used by 10 Rules</summary>

- [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret)
- [`vault-secrets-integration`](#rule-vault-secrets-integration)
- [`vault-secrets-integration-aws`](#rule-vault-secrets-integration-aws)
- [`vault-secrets-integration-azure`](#rule-vault-secrets-integration-azure)
- [`vault-secrets-integration-confluent`](#rule-vault-secrets-integration-confluent)
- [`vault-secrets-integration-gcp`](#rule-vault-secrets-integration-gcp)
- [`vault-secrets-integration-mongodbatlas`](#rule-vault-secrets-integration-mongodbatlas)
- [`vault-secrets-integration-twilio`](#rule-vault-secrets-integration-twilio)
- [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret)
- [`vault-secrets-sync`](#rule-vault-secrets-sync)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-vault-secrets-sync"><code>hcp.concept.vault-secrets-sync</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L13-L15">Source</a></dt>
<dd>

An HCP Vault Secrets destination synchronizing application secrets externally.

</dd>
<dd>

Used by [`vault-secrets-app`](#rule-vault-secrets-app), [`vault-secrets-sync`](#rule-vault-secrets-sync).

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-add-on"><code>hcp.concept.waypoint-add-on</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L1-L3">Source</a></dt>
<dd>

Supporting infrastructure installed for an HCP Waypoint application.

</dd>
<dd>

Used by [`waypoint-add-on`](#rule-waypoint-add-on), [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-add-on-definition"><code>hcp.concept.waypoint-add-on-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L5-L7">Source</a></dt>
<dd>

A reusable HCP Waypoint definition for application supporting infrastructure.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`waypoint-add-on`](#rule-waypoint-add-on)
- [`waypoint-add-on-definition`](#rule-waypoint-add-on-definition)
- [`waypoint-add-on-definition-lookup`](#rule-waypoint-add-on-definition-lookup)
- [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-agent-group"><code>hcp.concept.waypoint-agent-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L9-L11">Source</a></dt>
<dd>

A group of agents executing HCP Waypoint actions.

</dd>
<dd>

Used by [`waypoint-agent-group`](#rule-waypoint-agent-group), [`waypoint-agent-group-lookup`](#rule-waypoint-agent-group-lookup).

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-application"><code>hcp.concept.waypoint-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L13-L15">Source</a></dt>
<dd>

An application instantiated and managed through HCP Waypoint.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`waypoint-add-on`](#rule-waypoint-add-on)
- [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup)
- [`waypoint-application`](#rule-waypoint-application)
- [`waypoint-application-lookup`](#rule-waypoint-application-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-configuration"><code>hcp.concept.waypoint-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L17-L19">Source</a></dt>
<dd>

An action or HCP Terraform connection supporting HCP Waypoint.

</dd>
<dd>

Used by [`waypoint-action`](#rule-waypoint-action), [`waypoint-action-lookup`](#rule-waypoint-action-lookup), [`waypoint-tfc-config`](#rule-waypoint-tfc-config).

</dd>
</div>

<div>
<dt id="hcp-concept-waypoint-template"><code>hcp.concept.waypoint-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L21-L23">Source</a></dt>
<dd>

A reusable HCP Waypoint golden pattern for application infrastructure.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`waypoint-application`](#rule-waypoint-application)
- [`waypoint-application-lookup`](#rule-waypoint-application-lookup)
- [`waypoint-template`](#rule-waypoint-template)
- [`waypoint-template-lookup`](#rule-waypoint-template-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-concept-workload-identity-provider"><code>hcp.concept.workload-identity-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L5-L7">Source</a></dt>
<dd>

An HCP federation boundary exchanging an external workload identity for a service principal.

</dd>
<dd>

Used by [`iam-workload-identity-provider`](#rule-iam-workload-identity-provider).

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="hcp-context-ownership"><code>hcp.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vocabulary.rf.hcl#L13-L15">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>


<details>
<summary>Used by 55 Rules</summary>

- [`aws-network-peering`](#rule-aws-network-peering)
- [`aws-network-peering-lookup`](#rule-aws-network-peering-lookup)
- [`aws-transit-gateway-attachment`](#rule-aws-transit-gateway-attachment)
- [`aws-transit-gateway-attachment-lookup`](#rule-aws-transit-gateway-attachment-lookup)
- [`azure-peering-connection`](#rule-azure-peering-connection)
- [`azure-peering-connection-lookup`](#rule-azure-peering-connection-lookup)
- [`boundary-cluster`](#rule-boundary-cluster)
- [`boundary-cluster-lookup`](#rule-boundary-cluster-lookup)
- [`consul-cluster`](#rule-consul-cluster)
- [`consul-cluster-lookup`](#rule-consul-cluster-lookup)
- [`dns-forwarding`](#rule-dns-forwarding)
- [`dns-forwarding-lookup`](#rule-dns-forwarding-lookup)
- [`hvn`](#rule-hvn)
- [`hvn-lookup`](#rule-hvn-lookup)
- [`hvn-peering-connection`](#rule-hvn-peering-connection)
- [`hvn-peering-connection-lookup`](#rule-hvn-peering-connection-lookup)
- [`notifications-webhook`](#rule-notifications-webhook)
- [`packer-artifact-lookup`](#rule-packer-artifact-lookup)
- [`packer-bucket`](#rule-packer-bucket)
- [`packer-channel`](#rule-packer-channel)
- [`packer-version-lookup`](#rule-packer-version-lookup)
- [`private-link`](#rule-private-link)
- [`private-link-lookup`](#rule-private-link-lookup)
- [`vault-cluster`](#rule-vault-cluster)
- [`vault-cluster-lookup`](#rule-vault-cluster-lookup)
- [`vault-plugin`](#rule-vault-plugin)
- [`vault-plugin-lookup`](#rule-vault-plugin-lookup)
- [`vault-radar-integration-jira-connection`](#rule-vault-radar-integration-jira-connection)
- [`vault-radar-integration-slack-connection`](#rule-vault-radar-integration-slack-connection)
- [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated)
- [`vault-radar-source-github-cloud`](#rule-vault-radar-source-github-cloud)
- [`vault-radar-source-github-enterprise`](#rule-vault-radar-source-github-enterprise)
- [`vault-secrets-app`](#rule-vault-secrets-app)
- [`vault-secrets-app-lookup`](#rule-vault-secrets-app-lookup)
- [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret)
- [`vault-secrets-integration`](#rule-vault-secrets-integration)
- [`vault-secrets-integration-aws`](#rule-vault-secrets-integration-aws)
- [`vault-secrets-integration-azure`](#rule-vault-secrets-integration-azure)
- [`vault-secrets-integration-confluent`](#rule-vault-secrets-integration-confluent)
- [`vault-secrets-integration-gcp`](#rule-vault-secrets-integration-gcp)
- [`vault-secrets-integration-mongodbatlas`](#rule-vault-secrets-integration-mongodbatlas)
- [`vault-secrets-integration-twilio`](#rule-vault-secrets-integration-twilio)
- [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret)
- [`vault-secrets-secret`](#rule-vault-secrets-secret)
- [`vault-secrets-sync`](#rule-vault-secrets-sync)
- [`waypoint-add-on`](#rule-waypoint-add-on)
- [`waypoint-add-on-definition`](#rule-waypoint-add-on-definition)
- [`waypoint-add-on-definition-lookup`](#rule-waypoint-add-on-definition-lookup)
- [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup)
- [`waypoint-agent-group`](#rule-waypoint-agent-group)
- [`waypoint-agent-group-lookup`](#rule-waypoint-agent-group-lookup)
- [`waypoint-application`](#rule-waypoint-application)
- [`waypoint-application-lookup`](#rule-waypoint-application-lookup)
- [`waypoint-template`](#rule-waypoint-template)
- [`waypoint-template-lookup`](#rule-waypoint-template-lookup)

</details>

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="hcp-relation-belongs-to-version"><code>hcp.relation.belongs-to-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L42-L52">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`packer-artifact-lookup`](#rule-packer-artifact-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-connects-vault-cluster"><code>hcp.relation.connects-vault-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L162-L172">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`vault-radar-secret-manager-vault-dedicated`](#rule-vault-radar-secret-manager-vault-dedicated).

</dd>
</div>

<div>
<dt id="hcp-relation-exposes-vault-cluster"><code>hcp.relation.exposes-vault-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L513-L523">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`private-link`](#rule-private-link), [`private-link-lookup`](#rule-private-link-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-extends-application"><code>hcp.relation.extends-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L65-L75">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`waypoint-add-on`](#rule-waypoint-add-on), [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-extends-cluster"><code>hcp.relation.extends-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L155-L165">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`vault-plugin`](#rule-vault-plugin), [`vault-plugin-lookup`](#rule-vault-plugin-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-federates-to"><code>hcp.relation.federates-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L111-L124">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`iam-workload-identity-provider`](#rule-iam-workload-identity-provider).

</dd>
</div>

<div>
<dt id="hcp-relation-instantiates-definition"><code>hcp.relation.instantiates-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L77-L87">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`waypoint-add-on`](#rule-waypoint-add-on), [`waypoint-add-on-lookup`](#rule-waypoint-add-on-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-peers-with"><code>hcp.relation.peers-with</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L52-L65">Source</a></dt>
<dd>

Introduced by a labeled emission.

<details>
<summary>Used by 6 Rules</summary>

- [`aws-network-peering`](#rule-aws-network-peering)
- [`aws-network-peering-lookup`](#rule-aws-network-peering-lookup)
- [`azure-peering-connection`](#rule-azure-peering-connection)
- [`azure-peering-connection-lookup`](#rule-azure-peering-connection-lookup)
- [`hvn-peering-connection`](#rule-hvn-peering-connection)
- [`hvn-peering-connection-lookup`](#rule-hvn-peering-connection-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-relation-replicates-from"><code>hcp.relation.replicates-from</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L57-L67">Source</a></dt>
<dd>

Introduced by a labeled emission.

<details>
<summary>Used by 4 Rules</summary>

- [`consul-cluster`](#rule-consul-cluster)
- [`consul-cluster-lookup`](#rule-consul-cluster-lookup)
- [`vault-cluster`](#rule-vault-cluster)
- [`vault-cluster-lookup`](#rule-vault-cluster-lookup)

</details>

</dd>
</div>

<div>
<dt id="hcp-relation-selected-by-channel"><code>hcp.relation.selected-by-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L220-L230">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`packer-version-lookup`](#rule-packer-version-lookup).

</dd>
</div>

<div>
<dt id="hcp-relation-syncs-to"><code>hcp.relation.syncs-to</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L49-L59">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`vault-secrets-app`](#rule-vault-secrets-app).

</dd>
</div>

<div>
<dt id="hcp-relation-uses-cloud-identity"><code>hcp.relation.uses-cloud-identity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L168-L181">Source</a></dt>
<dd>

Introduced by a labeled emission.

<details>
<summary>Used by 5 Rules</summary>

- [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret)
- [`vault-secrets-integration`](#rule-vault-secrets-integration)
- [`vault-secrets-integration-azure`](#rule-vault-secrets-integration-azure)
- [`vault-secrets-integration-gcp`](#rule-vault-secrets-integration-gcp)
- [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret)

</details>

</dd>
</div>

<div>
<dt id="hcp-relation-uses-integration"><code>hcp.relation.uses-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L156-L166">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`vault-secrets-dynamic-secret`](#rule-vault-secrets-dynamic-secret), [`vault-secrets-rotating-secret`](#rule-vault-secrets-rotating-secret), [`vault-secrets-sync`](#rule-vault-secrets-sync).

</dd>
</div>

<div>
<dt id="hcp-relation-uses-template"><code>hcp.relation.uses-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L287-L297">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`waypoint-application`](#rule-waypoint-application), [`waypoint-application-lookup`](#rule-waypoint-application-lookup).

</dd>
</div>

</dl>

## RF Vocabulary used

- [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity)
- [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network)
- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network)

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>hcp.rule.aws-network-peering-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L68-L122">Source</a></summary>

<div id="rule-aws-network-peering-lookup"></div>

Matches `data` instances of `hcp_aws_network_peering`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.peer_vpc_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.peer_vpc_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.aws-network-peering</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L13-L66">Source</a></summary>

<div id="rule-aws-network-peering"></div>

Matches `resource` instances of `hcp_aws_network_peering`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.peer_vpc_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.peer_vpc_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.aws-transit-gateway-attachment-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L164-L203">Source</a></summary>

<div id="rule-aws-transit-gateway-attachment-lookup"></div>

Matches `data` instances of `hcp_aws_transit_gateway_attachment`.

**Classification:** [`hcp.concept.transit-gateway-attachment`](#hcp-concept-transit-gateway-attachment).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.aws-transit-gateway-attachment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L124-L162">Source</a></summary>

<div id="rule-aws-transit-gateway-attachment"></div>

Matches `resource` instances of `hcp_aws_transit_gateway_attachment`.

**Classification:** [`hcp.concept.transit-gateway-attachment`](#hcp-concept-transit-gateway-attachment).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.azure-peering-connection-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L260-L314">Source</a></summary>

<div id="rule-azure-peering-connection-lookup"></div>

Matches `data` instances of `hcp_azure_peering_connection`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_link`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.peer_vnet_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_link`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.peer_vnet_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.azure-peering-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L205-L258">Source</a></summary>

<div id="rule-azure-peering-connection"></div>

Matches `resource` instances of `hcp_azure_peering_connection`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_link`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.peer_vnet_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_link`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.peer_vnet_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.boundary-cluster-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/boundary.rf.hcl#L29-L52">Source</a></summary>

<div id="rule-boundary-cluster-lookup"></div>

Matches `data` instances of `hcp_boundary_cluster`.

**Classification:** [`hcp.concept.boundary-cluster`](#hcp-concept-boundary-cluster).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.boundary-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/boundary.rf.hcl#L5-L27">Source</a></summary>

<div id="rule-boundary-cluster"></div>

Matches `resource` instances of `hcp_boundary_cluster`.

**Classification:** [`hcp.concept.boundary-cluster`](#hcp-concept-boundary-cluster).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.consul-cluster-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L70-L130">Source</a></summary>

<div id="rule-consul-cluster-lookup"></div>

Matches `data` instances of `hcp_consul_cluster`.

**Classification:** [`hcp.concept.consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.replicates-from`](#hcp-relation-replicates-from): targets [`hcp.concept.consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster) through `source.primary_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "cluster_id", "self_link"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "cluster_id", "self_link"]`

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.primary_link`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.consul-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L9-L68">Source</a></summary>

<div id="rule-consul-cluster"></div>

Matches `resource` instances of `hcp_consul_cluster`.

**Classification:** [`hcp.concept.consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.replicates-from`](#hcp-relation-replicates-from): targets [`hcp.concept.consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster) through `source.primary_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "cluster_id", "self_link"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "cluster_id", "self_link"]`

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.primary_link`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.consul-snapshot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/consul-dedicated.rf.hcl#L132-L150">Source</a></summary>

<div id="rule-consul-snapshot"></div>

Matches `resource` instances of `hcp_consul_snapshot`.

**Classification:** [`hcp.concept.consul-configuration`](#hcp-concept-consul-configuration).

**Contributions**

- targets [`hcp.concept.consul-dedicated-cluster`](#hcp-concept-consul-dedicated-cluster) through `source.cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.cluster_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.cluster_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.dns-forwarding-rule-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/dns-forwarding.rf.hcl#L124-L143">Source</a></summary>

<div id="rule-dns-forwarding-rule-lookup"></div>

Matches `data` instances of `hcp_dns_forwarding_rule`.

**Classification:** [`hcp.concept.network-configuration`](#hcp-concept-network-configuration).

**Contributions**

- targets [`hcp.concept.dns-forwarding`](#hcp-concept-dns-forwarding) through `source.dns_forwarding_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.dns_forwarding_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.dns_forwarding_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.dns-forwarding-rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/dns-forwarding.rf.hcl#L104-L122">Source</a></summary>

<div id="rule-dns-forwarding-rule"></div>

Matches `resource` instances of `hcp_dns_forwarding_rule`.

**Classification:** [`hcp.concept.network-configuration`](#hcp-concept-network-configuration).

**Contributions**

- targets [`hcp.concept.dns-forwarding`](#hcp-concept-dns-forwarding) through `source.dns_forwarding_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.dns_forwarding_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.dns_forwarding_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.dns-forwarding-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/dns-forwarding.rf.hcl#L54-L102">Source</a></summary>

<div id="rule-dns-forwarding-lookup"></div>

Matches `data` instances of `hcp_dns_forwarding`.

**Classification:** [`hcp.concept.dns-forwarding`](#hcp-concept-dns-forwarding).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "dns_forwarding_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "dns_forwarding_id"]`

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.dns-forwarding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/dns-forwarding.rf.hcl#L5-L52">Source</a></summary>

<div id="rule-dns-forwarding"></div>

Matches `resource` instances of `hcp_dns_forwarding`.

**Classification:** [`hcp.concept.dns-forwarding`](#hcp-concept-dns-forwarding).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "dns_forwarding_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "dns_forwarding_id"]`

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.group-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L26-L44">Source</a></summary>

<div id="rule-group-iam-binding"></div>

Matches `resource` instances of `hcp_group_iam_binding`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.identity-group`](#hcp-concept-identity-group) through `source.name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.group-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L46-L64">Source</a></summary>

<div id="rule-group-iam-policy"></div>

Matches `resource` instances of `hcp_group_iam_policy`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.identity-group`](#hcp-concept-identity-group) through `source.name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.group-members</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L84-L102">Source</a></summary>

<div id="rule-group-members"></div>

Matches `resource` instances of `hcp_group_members`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.identity-group`](#hcp-concept-identity-group) through `source.group`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.group`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.group-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L66-L82">Source</a></summary>

<div id="rule-group-lookup"></div>

Matches `data` instances of `hcp_group`.

**Classification:** [`hcp.concept.identity-group`](#hcp-concept-identity-group).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-group"></div>

Matches `resource` instances of `hcp_group`.

**Classification:** [`hcp.concept.identity-group`](#hcp-concept-identity-group).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn-peering-connection-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L371-L425">Source</a></summary>

<div id="rule-hvn-peering-connection-lookup"></div>

Matches `data` instances of `hcp_hvn_peering_connection`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_1`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_2`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_1`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.hvn_2`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn-peering-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L316-L369">Source</a></summary>

<div id="rule-hvn-peering-connection"></div>

Matches `resource` instances of `hcp_hvn_peering_connection`.

**Classification:** [`hcp.concept.network-peering`](#hcp-concept-network-peering).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_1`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.peers-with`](#hcp-relation-peers-with): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_2`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_1`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.hvn_2`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn-route-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L450-L472">Source</a></summary>

<div id="rule-hvn-route-lookup"></div>

Matches `data` instances of `hcp_hvn_route`.

**Classification:** [`hcp.concept.network-configuration`](#hcp-concept-network-configuration).

**Contributions**

- targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.hvn_link`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn-route</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L427-L448">Source</a></summary>

<div id="rule-hvn-route"></div>

Matches `resource` instances of `hcp_hvn_route`.

**Classification:** [`hcp.concept.network-configuration`](#hcp-concept-network-configuration).

**Contributions**

- targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.hvn_link`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/virtual-networks.rf.hcl#L34-L66">Source</a></summary>

<div id="rule-hvn-lookup"></div>

Matches `data` instances of `hcp_hvn`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "hvn_id", "self_link"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "hvn_id", "self_link"]`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.hvn</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/virtual-networks.rf.hcl#L1-L32">Source</a></summary>

<div id="rule-hvn"></div>

Matches `resource` instances of `hcp_hvn`.

**Classification:** [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "hvn_id", "self_link"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "hvn_id", "self_link"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.iam-workload-identity-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L104-L125">Source</a></summary>

<div id="rule-iam-workload-identity-provider"></div>

Matches `resource` instances of `hcp_iam_workload_identity_provider`.

**Classification:** [`hcp.concept.workload-identity-provider`](#hcp-concept-workload-identity-provider).

**Relations**

- [`hcp.relation.federates-to`](#hcp-relation-federates-to): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_principal`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.service_principal`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.notifications-webhook</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/operations/audit-notifications.rf.hcl#L7-L29">Source</a></summary>

<div id="rule-notifications-webhook"></div>

Matches `resource` instances of `hcp_notifications_webhook`.

**Classification:** [`hcp.concept.notification-webhook`](#hcp-concept-notification-webhook).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.organization-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L127-L133">Source</a></summary>

<div id="rule-organization-iam-binding"></div>

Matches `resource` instances of `hcp_organization_iam_binding`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

</details>

<details>
<summary><code>hcp.rule.organization-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L135-L141">Source</a></summary>

<div id="rule-organization-iam-policy"></div>

Matches `resource` instances of `hcp_organization_iam_policy`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

</details>

<details>
<summary><code>hcp.rule.organization-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/projects-organizations.rf.hcl#L9-L25">Source</a></summary>

<div id="rule-organization-lookup"></div>

Matches `data` instances of `hcp_organization`.

**Classification:** [`hcp.concept.organization`](#hcp-concept-organization).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-artifact-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L21-L53">Source</a></summary>

<div id="rule-packer-artifact-lookup"></div>

Matches `data` instances of `hcp_packer_artifact`.

**Classification:** [`hcp.concept.packer-artifact`](#hcp-concept-packer-artifact).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket) through `source.bucket_name`.

**Relations**

- [`hcp.relation.belongs-to-version`](#hcp-relation-belongs-to-version): targets [`hcp.concept.packer-version`](#hcp-concept-packer-version) through `source.version_fingerprint`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.bucket_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.version_fingerprint`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.fingerprint`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-bucket-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L88-L106">Source</a></summary>

<div id="rule-packer-bucket-iam-binding"></div>

Matches `resource` instances of `hcp_packer_bucket_iam_binding`.

**Classification:** [`hcp.concept.packer-configuration`](#hcp-concept-packer-configuration).

**Contributions**

- targets [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket) through `source.resource_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-bucket-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L108-L126">Source</a></summary>

<div id="rule-packer-bucket-iam-policy"></div>

Matches `resource` instances of `hcp_packer_bucket_iam_policy`.

**Classification:** [`hcp.concept.packer-configuration`](#hcp-concept-packer-configuration).

**Contributions**

- targets [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket) through `source.resource_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-bucket</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L55-L86">Source</a></summary>

<div id="rule-packer-bucket"></div>

Matches `resource` instances of `hcp_packer_bucket`.

**Classification:** [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name", "resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-channel-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L158-L188">Source</a></summary>

<div id="rule-packer-channel-assignment"></div>

Matches `resource` instances of `hcp_packer_channel_assignment`.

**Classification:** [`hcp.concept.packer-configuration`](#hcp-concept-packer-configuration).

**Contributions**

- targets [`hcp.concept.packer-channel`](#hcp-concept-packer-channel) through `source.channel_name`.
- targets [`hcp.concept.packer-version`](#hcp-concept-packer-version) through `source.version_fingerprint`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.channel_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.version_fingerprint`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.fingerprint`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-channel</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L128-L156">Source</a></summary>

<div id="rule-packer-channel"></div>

Matches `resource` instances of `hcp_packer_channel`.

**Classification:** [`hcp.concept.packer-channel`](#hcp-concept-packer-channel).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket) through `source.bucket_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.bucket_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.packer-version-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/packer/registry.rf.hcl#L190-L231">Source</a></summary>

<div id="rule-packer-version-lookup"></div>

Matches `data` instances of `hcp_packer_version`.

**Classification:** [`hcp.concept.packer-version`](#hcp-concept-packer-version).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.packer-bucket`](#hcp-concept-packer-bucket) through `source.bucket_name`.

**Relations**

- [`hcp.relation.selected-by-channel`](#hcp-relation-selected-by-channel): targets [`hcp.concept.packer-channel`](#hcp-concept-packer-channel) through `source.channel_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "fingerprint"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "fingerprint"]`

**Context through `source.bucket_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.channel_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.private-link-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L526-L577">Source</a></summary>

<div id="rule-private-link-lookup"></div>

Matches `data` instances of `hcp_private_link`.

**Classification:** [`hcp.concept.private-link-service`](#hcp-concept-private-link-service).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.exposes-vault-cluster`](#hcp-relation-exposes-vault-cluster): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.vault_cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.vault_cluster_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.cluster_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.private-link</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/network/connectivity.rf.hcl#L474-L524">Source</a></summary>

<div id="rule-private-link"></div>

Matches `resource` instances of `hcp_private_link`.

**Classification:** [`hcp.concept.private-link-service`](#hcp-concept-private-link-service).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.exposes-vault-cluster`](#hcp-relation-exposes-vault-cluster): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.vault_cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.vault_cluster_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.cluster_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.project-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L143-L164">Source</a></summary>

<div id="rule-project-iam-binding"></div>

Matches `resource` instances of `hcp_project_iam_binding`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.project-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L166-L187">Source</a></summary>

<div id="rule-project-iam-policy"></div>

Matches `resource` instances of `hcp_project_iam_policy`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.project-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/projects-organizations.rf.hcl#L44-L60">Source</a></summary>

<div id="rule-project-lookup"></div>

Matches `data` instances of `hcp_project`.

**Classification:** [`hcp.concept.project`](#hcp-concept-project).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.project</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/projects-organizations.rf.hcl#L27-L42">Source</a></summary>

<div id="rule-project"></div>

Matches `resource` instances of `hcp_project`.

**Classification:** [`hcp.concept.project`](#hcp-concept-project).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.resource-control-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L189-L210">Source</a></summary>

<div id="rule-resource-control-policy"></div>

Matches `resource` instances of `hcp_resource_control_policy`.

**Classification:** [`hcp.concept.access-control-configuration`](#hcp-concept-access-control-configuration).

**Contributions**

- targets [`hcp.concept.organization`](#hcp-concept-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.service-principal-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L229-L245">Source</a></summary>

<div id="rule-service-principal-lookup"></div>

Matches `data` instances of `hcp_service_principal`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.service-principal</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/platform/identity-access.rf.hcl#L212-L227">Source</a></summary>

<div id="rule-service-principal"></div>

Matches `resource` instances of `hcp_service_principal`.

**Classification:** [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["resource_id", "resource_name"]`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-cluster-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L70-L130">Source</a></summary>

<div id="rule-vault-cluster-lookup"></div>

Matches `data` instances of `hcp_vault_cluster`.

**Classification:** [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.replicates-from`](#hcp-relation-replicates-from): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.primary_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "cluster_id", "self_link", "vault_public_endpoint_url"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]`

**Context through `source.hvn_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.primary_link`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L9-L68">Source</a></summary>

<div id="rule-vault-cluster"></div>

Matches `resource` instances of `hcp_vault_cluster`.

**Classification:** [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster).

**Contexts**

- [`rf.context.network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-context-network): targets [`rf.concept.virtual-network`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-virtual-network) through `source.hvn_id`.
- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.replicates-from`](#hcp-relation-replicates-from): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.primary_link`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "cluster_id", "self_link", "vault_public_endpoint_url"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "cluster_id", "self_link", "vault_public_endpoint_url", "vault_private_endpoint_url"]`

**Context through `source.hvn_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.hvn_id`
- `match.strategy`: `"exact"`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.primary_link`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.self_link`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-plugin-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L168-L203">Source</a></summary>

<div id="rule-vault-plugin-lookup"></div>

Matches `data` instances of `hcp_vault_plugin`.

**Classification:** [`hcp.concept.vault-plugin`](#hcp-concept-vault-plugin).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.extends-cluster`](#hcp-relation-extends-cluster): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.cluster_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.cluster_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-plugin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/services/vault-dedicated.rf.hcl#L132-L166">Source</a></summary>

<div id="rule-vault-plugin"></div>

Matches `resource` instances of `hcp_vault_plugin`.

**Classification:** [`hcp.concept.vault-plugin`](#hcp-concept-vault-plugin).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.extends-cluster`](#hcp-relation-extends-cluster): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.cluster_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.cluster_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.cluster_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-integration-jira-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L17-L48">Source</a></summary>

<div id="rule-vault-radar-integration-jira-connection"></div>

Matches `resource` instances of `hcp_vault_radar_integration_jira_connection`.

**Classification:** [`hcp.concept.vault-radar-integration`](#hcp-concept-vault-radar-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-integration-jira-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L50-L68">Source</a></summary>

<div id="rule-vault-radar-integration-jira-subscription"></div>

Matches `resource` instances of `hcp_vault_radar_integration_jira_subscription`.

**Classification:** [`hcp.concept.vault-radar-configuration`](#hcp-concept-vault-radar-configuration).

**Contributions**

- targets [`hcp.concept.vault-radar-integration`](#hcp-concept-vault-radar-integration) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-integration-slack-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L70-L101">Source</a></summary>

<div id="rule-vault-radar-integration-slack-connection"></div>

Matches `resource` instances of `hcp_vault_radar_integration_slack_connection`.

**Classification:** [`hcp.concept.vault-radar-integration`](#hcp-concept-vault-radar-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-integration-slack-subscription</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L103-L121">Source</a></summary>

<div id="rule-vault-radar-integration-slack-subscription"></div>

Matches `resource` instances of `hcp_vault_radar_integration_slack_subscription`.

**Classification:** [`hcp.concept.vault-radar-configuration`](#hcp-concept-vault-radar-configuration).

**Contributions**

- targets [`hcp.concept.vault-radar-integration`](#hcp-concept-vault-radar-integration) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-resource-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L123-L129">Source</a></summary>

<div id="rule-vault-radar-resource-iam-binding"></div>

Matches `resource` instances of `hcp_vault_radar_resource_iam_binding`.

**Classification:** [`hcp.concept.vault-radar-configuration`](#hcp-concept-vault-radar-configuration).

</details>

<details>
<summary><code>hcp.rule.vault-radar-resource-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L131-L137">Source</a></summary>

<div id="rule-vault-radar-resource-iam-policy"></div>

Matches `resource` instances of `hcp_vault_radar_resource_iam_policy`.

**Classification:** [`hcp.concept.vault-radar-configuration`](#hcp-concept-vault-radar-configuration).

</details>

<details>
<summary><code>hcp.rule.vault-radar-secret-manager-vault-dedicated</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L139-L173">Source</a></summary>

<div id="rule-vault-radar-secret-manager-vault-dedicated"></div>

Matches `resource` instances of `hcp_vault_radar_secret_manager_vault_dedicated`.

**Classification:** [`hcp.concept.vault-radar-secret-manager`](#hcp-concept-vault-radar-secret-manager).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.connects-vault-cluster`](#hcp-relation-connects-vault-cluster): targets [`hcp.concept.vault-dedicated-cluster`](#hcp-concept-vault-dedicated-cluster) through `source.vault_url`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.vault_url`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.vault_public_endpoint_url`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-source-github-cloud</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L175-L197">Source</a></summary>

<div id="rule-vault-radar-source-github-cloud"></div>

Matches `resource` instances of `hcp_vault_radar_source_github_cloud`.

**Classification:** [`hcp.concept.vault-radar-source`](#hcp-concept-vault-radar-source).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-radar-source-github-enterprise</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-radar/sources-integrations.rf.hcl#L199-L221">Source</a></summary>

<div id="rule-vault-radar-source-github-enterprise"></div>

Matches `resource` instances of `hcp_vault_radar_source_github_enterprise`.

**Classification:** [`hcp.concept.vault-radar-source`](#hcp-concept-vault-radar-source).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-app-iam-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L62-L80">Source</a></summary>

<div id="rule-vault-secrets-app-iam-binding"></div>

Matches `resource` instances of `hcp_vault_secrets_app_iam_binding`.

**Classification:** [`hcp.concept.vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration).

**Contributions**

- targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.resource_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-app-iam-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L82-L100">Source</a></summary>

<div id="rule-vault-secrets-app-iam-policy"></div>

Matches `resource` instances of `hcp_vault_secrets_app_iam_policy`.

**Classification:** [`hcp.concept.vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration).

**Contributions**

- targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.resource_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.resource_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-app-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L102-L134">Source</a></summary>

<div id="rule-vault-secrets-app-lookup"></div>

Matches `data` instances of `hcp_vault_secrets_app`.

**Classification:** [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["app_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "app_name"]`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-app</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L17-L60">Source</a></summary>

<div id="rule-vault-secrets-app"></div>

Matches `resource` instances of `hcp_vault_secrets_app`.

**Classification:** [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.syncs-to`](#hcp-relation-syncs-to): targets [`hcp.concept.vault-secrets-sync`](#hcp-concept-vault-secrets-sync) through `source.sync_names`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["app_name", "resource_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "app_name", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.sync_names`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-dynamic-secret-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L184-L203">Source</a></summary>

<div id="rule-vault-secrets-dynamic-secret-lookup"></div>

Matches `data` instances of `hcp_vault_secrets_dynamic_secret`.

**Classification:** [`hcp.concept.vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration).

**Contributions**

- targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.app_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-dynamic-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L136-L182">Source</a></summary>

<div id="rule-vault-secrets-dynamic-secret"></div>

Matches `resource` instances of `hcp_vault_secrets_dynamic_secret`.

**Classification:** [`hcp.concept.managed-secret`](#hcp-concept-managed-secret).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

**Relations**

- [`hcp.relation.uses-integration`](#hcp-relation-uses-integration): targets [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration) through `source.integration_name`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.gcp_impersonate_service_account.service_account_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.app_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

**Relation through `source.integration_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.gcp_impersonate_service_account.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-aws</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L283-L315">Source</a></summary>

<div id="rule-vault-secrets-integration-aws"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_aws`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-azure</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L317-L363">Source</a></summary>

<div id="rule-vault-secrets-integration-azure"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_azure`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.federated_workload_identity.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.federated_workload_identity.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-confluent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L365-L396">Source</a></summary>

<div id="rule-vault-secrets-integration-confluent"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_confluent`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-gcp</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L398-L459">Source</a></summary>

<div id="rule-vault-secrets-integration-gcp"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_gcp`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.federated_workload_identity.service_account_email`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_account_key.client_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.federated_workload_identity.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

**Relation through `source.service_account_key.client_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-mongodbatlas</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L461-L492">Source</a></summary>

<div id="rule-vault-secrets-integration-mongodbatlas"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_mongodbatlas`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration-twilio</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L494-L525">Source</a></summary>

<div id="rule-vault-secrets-integration-twilio"></div>

Matches `resource` instances of `hcp_vault_secrets_integration_twilio`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L205-L281">Source</a></summary>

<div id="rule-vault-secrets-integration"></div>

Matches `resource` instances of `hcp_vault_secrets_integration`.

**Classification:** [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.azure_federated_workload_identity.client_id`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.gcp_federated_workload_identity.service_account_email`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.gcp_service_account_key.client_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id", "resource_name"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.azure_federated_workload_identity.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.gcp_federated_workload_identity.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

**Relation through `source.gcp_service_account_key.client_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-rotating-secret-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L605-L624">Source</a></summary>

<div id="rule-vault-secrets-rotating-secret-lookup"></div>

Matches `data` instances of `hcp_vault_secrets_rotating_secret`.

**Classification:** [`hcp.concept.vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration).

**Contributions**

- targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.app_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-rotating-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L527-L603">Source</a></summary>

<div id="rule-vault-secrets-rotating-secret"></div>

Matches `resource` instances of `hcp_vault_secrets_rotating_secret`.

**Classification:** [`hcp.concept.managed-secret`](#hcp-concept-managed-secret).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

**Relations**

- [`hcp.relation.uses-integration`](#hcp-relation-uses-integration): targets [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration) through `source.integration_name`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.azure_application_password.app_client_id`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.confluent_service_account.service_account_id`.
- [`hcp.relation.uses-cloud-identity`](#hcp-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.gcp_service_account_key.service_account_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.app_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

**Relation through `source.integration_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Relation through `source.azure_application_password.app_client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.confluent_service_account.service_account_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.gcp_service_account_key.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.email`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-secret-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L647-L666">Source</a></summary>

<div id="rule-vault-secrets-secret-lookup"></div>

Matches `data` instances of `hcp_vault_secrets_secret`.

**Classification:** [`hcp.concept.vault-secrets-configuration`](#hcp-concept-vault-secrets-configuration).

**Contributions**

- targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.app_name`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L626-L645">Source</a></summary>

<div id="rule-vault-secrets-secret"></div>

Matches `resource` instances of `hcp_vault_secrets_secret`.

**Classification:** [`hcp.concept.managed-secret`](#hcp-concept-managed-secret).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.vault-secrets-application`](#hcp-concept-vault-secrets-application) through `source.app_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.app_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.app_name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.vault-secrets-sync</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/vault-secrets/applications-integrations.rf.hcl#L668-L711">Source</a></summary>

<div id="rule-vault-secrets-sync"></div>

Matches `resource` instances of `hcp_vault_secrets_sync`.

**Classification:** [`hcp.concept.vault-secrets-sync`](#hcp-concept-vault-secrets-sync).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-integration`](#hcp-relation-uses-integration): targets [`hcp.concept.vault-secrets-integration`](#hcp-concept-vault-secrets-integration) through `source.integration_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name", "resource_id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.integration_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-action-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L33-L40">Source</a></summary>

<div id="rule-waypoint-action-lookup"></div>

Matches `data` instances of `hcp_waypoint_action`.

**Classification:** [`hcp.concept.waypoint-configuration`](#hcp-concept-waypoint-configuration).

</details>

<details>
<summary><code>hcp.rule.waypoint-action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-waypoint-action"></div>

Matches `resource` instances of `hcp_waypoint_action`.

**Classification:** [`hcp.concept.waypoint-configuration`](#hcp-concept-waypoint-configuration).

</details>

<details>
<summary><code>hcp.rule.waypoint-add-on-definition-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L123-L155">Source</a></summary>

<div id="rule-waypoint-add-on-definition-lookup"></div>

Matches `data` instances of `hcp_waypoint_add_on_definition`.

**Classification:** [`hcp.concept.waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-add-on-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L90-L121">Source</a></summary>

<div id="rule-waypoint-add-on-definition"></div>

Matches `resource` instances of `hcp_waypoint_add_on_definition`.

**Classification:** [`hcp.concept.waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-add-on-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L157-L204">Source</a></summary>

<div id="rule-waypoint-add-on-lookup"></div>

Matches `data` instances of `hcp_waypoint_add_on`.

**Classification:** [`hcp.concept.waypoint-add-on`](#hcp-concept-waypoint-add-on).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.extends-application`](#hcp-relation-extends-application): targets [`hcp.concept.waypoint-application`](#hcp-concept-waypoint-application) through `source.application_id`.
- [`hcp.relation.instantiates-definition`](#hcp-relation-instantiates-definition): targets [`hcp.concept.waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition) through `source.definition_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.application_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.definition_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-add-on</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L42-L88">Source</a></summary>

<div id="rule-waypoint-add-on"></div>

Matches `resource` instances of `hcp_waypoint_add_on`.

**Classification:** [`hcp.concept.waypoint-add-on`](#hcp-concept-waypoint-add-on).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.extends-application`](#hcp-relation-extends-application): targets [`hcp.concept.waypoint-application`](#hcp-concept-waypoint-application) through `source.application_id`.
- [`hcp.relation.instantiates-definition`](#hcp-relation-instantiates-definition): targets [`hcp.concept.waypoint-add-on-definition`](#hcp-concept-waypoint-add-on-definition) through `source.definition_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.application_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.definition_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-agent-group-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L230-L253">Source</a></summary>

<div id="rule-waypoint-agent-group-lookup"></div>

Matches `data` instances of `hcp_waypoint_agent_group`.

**Classification:** [`hcp.concept.waypoint-agent-group`](#hcp-concept-waypoint-agent-group).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-agent-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L206-L228">Source</a></summary>

<div id="rule-waypoint-agent-group"></div>

Matches `resource` instances of `hcp_waypoint_agent_group`.

**Classification:** [`hcp.concept.waypoint-agent-group`](#hcp-concept-waypoint-agent-group).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-application-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L300-L344">Source</a></summary>

<div id="rule-waypoint-application-lookup"></div>

Matches `data` instances of `hcp_waypoint_application`.

**Classification:** [`hcp.concept.waypoint-application`](#hcp-concept-waypoint-application).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-template`](#hcp-relation-uses-template): targets [`hcp.concept.waypoint-template`](#hcp-concept-waypoint-template) through `source.template_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.template_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L255-L298">Source</a></summary>

<div id="rule-waypoint-application"></div>

Matches `resource` instances of `hcp_waypoint_application`.

**Classification:** [`hcp.concept.waypoint-application`](#hcp-concept-waypoint-application).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

**Relations**

- [`hcp.relation.uses-template`](#hcp-relation-uses-template): targets [`hcp.concept.waypoint-template`](#hcp-concept-waypoint-template) through `source.template_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

**Relation through `source.template_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-template-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L379-L411">Source</a></summary>

<div id="rule-waypoint-template-lookup"></div>

Matches `data` instances of `hcp_waypoint_template`.

**Classification:** [`hcp.concept.waypoint-template`](#hcp-concept-waypoint-template).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L346-L377">Source</a></summary>

<div id="rule-waypoint-template"></div>

Matches `resource` instances of `hcp_waypoint_template`.

**Classification:** [`hcp.concept.waypoint-template`](#hcp-concept-waypoint-template).

**Contexts**

- [`hcp.context.ownership`](#hcp-context-ownership): targets [`hcp.concept.project`](#hcp-concept-project) through `source.project_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.project_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.resource_id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>hcp.rule.waypoint-tfc-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/hcp/waypoint/applications.rf.hcl#L413-L419">Source</a></summary>

<div id="rule-waypoint-tfc-config"></div>

Matches `resource` instances of `hcp_waypoint_tfc_config`.

**Classification:** [`hcp.concept.waypoint-configuration`](#hcp-concept-waypoint-configuration).

</details>
