Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • kestra-io/kestra: >= 0.15.0, < 1.0.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
kestra_bindingresourceaccess-bindingbinding
kestra_flowresourceflowflow
kestra_groupresourceidentity-groupgroup
kestra_namespace_secretresourcenamespace-secretnamespace-secret
kestra_namespaceresourcenamespacenamespace
kestra_roledataaccess-roleexisting-role
kestra_roleresourceaccess-rolerole
kestra_user_passwordresourceuser-credentialuser-password
kestra_userresourceuser-accountuser

Local vocabulary

Concepts

kestra.concept.access-binding Source

A Kestra role binding for an external principal.

Used by binding.

kestra.concept.access-role Source

A Kestra role defining an access permission set.

Used by binding, existing-role, role.

kestra.concept.flow Source

A declaratively managed Kestra orchestration flow.

Used by flow.

kestra.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by group.

kestra.concept.namespace Source

A Kestra namespace that organizes orchestration resources.

Used by 5 Rules
kestra.concept.namespace-secret Source

A secret declaration attached to a Kestra namespace.

Used by namespace-secret.

kestra.concept.user-account Source

A Kestra user account.

Used by user, user-password.

kestra.concept.user-credential Source

A basic-auth credential attached to a Kestra user.

Used by user-password.

Contexts

kestra.context.ownership Source

Administrative or lifecycle ownership.

Used by flow, group, role.

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

kestra.rule.binding Source

Matches resource instances of kestra_binding.

Classification: kestra.concept.access-binding.

Contributions

Conditions, identity and resolution

Contribution through source.role_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
kestra.rule.flow Source

Matches resource instances of kestra_flow.

Classification: kestra.concept.flow.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.namespace_id
  • match.strategy: "dot-ancestor"
kestra.rule.group Source

Matches resource instances of kestra_group.

Classification: kestra.concept.identity-group.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.namespace_id
  • match.strategy: "dot-ancestor"
kestra.rule.namespace-secret Source

Matches resource instances of kestra_namespace_secret.

Classification: kestra.concept.namespace-secret.

Contributions

Conditions, identity and resolution

Contribution through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.namespace_id
  • match.strategy: "dot-ancestor"
kestra.rule.namespace Source

Matches resource instances of kestra_namespace.

Classification: kestra.concept.namespace.

Conditions, identity and resolution

Identity

  • attributes: ["namespace_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "namespace_id"]
kestra.rule.existing-role Source

Matches data instances of kestra_role.

Classification: kestra.concept.access-role.

Conditions, identity and resolution

Identity

  • attributes: ["role_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "role_id"]
kestra.rule.role Source

Matches resource instances of kestra_role.

Classification: kestra.concept.access-role.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.namespace_id
  • match.strategy: "dot-ancestor"
kestra.rule.user-password Source

Matches resource instances of kestra_user_password.

Classification: kestra.concept.user-credential.

Contributions

Conditions, identity and resolution

Contribution through source.user_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
kestra.rule.user Source

Matches resource instances of kestra_user.

Classification: kestra.concept.user-account.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]