Reference
kestra Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
kestra-io/kestra:>= 0.15.0, < 1.0.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
kestra.concept.access-bindingSource-
A Kestra role binding for an external principal.
-
Used by
binding. kestra.concept.access-roleSource-
A Kestra role defining an access permission set.
-
Used by
binding,existing-role,role. kestra.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by
group. kestra.concept.namespaceSource-
A Kestra namespace that organizes orchestration resources.
-
Used by 5 Rules
kestra.concept.namespace-secretSource-
A secret declaration attached to a Kestra namespace.
-
Used by
namespace-secret. kestra.concept.user-credentialSource-
A basic-auth credential attached to a Kestra user.
-
Used by
user-password.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
kestra.rule.binding Source
Matches resource instances of kestra_binding.
Classification: kestra.concept.access-binding.
Contributions
- targets
kestra.concept.access-rolethroughsource.role_id.
Conditions, identity and resolution
Contribution through source.role_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
kestra.rule.flow Source
Matches resource instances of kestra_flow.
Classification: kestra.concept.flow.
Contexts
kestra.context.ownership: targetskestra.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namespace_idmatch.strategy:"dot-ancestor"
kestra.rule.group Source
Matches resource instances of kestra_group.
Classification: kestra.concept.identity-group.
Contexts
kestra.context.ownership: targetskestra.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namespace_idmatch.strategy:"dot-ancestor"
kestra.rule.namespace-secret Source
Matches resource instances of kestra_namespace_secret.
Classification: kestra.concept.namespace-secret.
Contributions
- targets
kestra.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Contribution through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namespace_idmatch.strategy:"dot-ancestor"
kestra.rule.namespace Source
Matches resource instances of kestra_namespace.
Classification: kestra.concept.namespace.
Conditions, identity and resolution
Identity
attributes:["namespace_id"]scope:"provider"
Endpoint
attributes:["id", "namespace_id"]
kestra.rule.existing-role Source
Matches data instances of kestra_role.
Classification: kestra.concept.access-role.
Conditions, identity and resolution
Identity
attributes:["role_id"]scope:"provider"
Endpoint
attributes:["id", "role_id"]
kestra.rule.role Source
Matches resource instances of kestra_role.
Classification: kestra.concept.access-role.
Contexts
kestra.context.ownership: targetskestra.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namespace_idmatch.strategy:"dot-ancestor"
kestra.rule.user-password Source
Matches resource instances of kestra_user_password.
Classification: kestra.concept.user-credential.
Contributions
- targets
kestra.concept.user-accountthroughsource.user_id.
Conditions, identity and resolution
Contribution through source.user_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
kestra.rule.user Source
Matches resource instances of kestra_user.
Classification: kestra.concept.user-account.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]