# kestra Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `kestra-io/kestra`: `>= 0.15.0, < 1.0.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `kestra_binding` | `resource` | [`access-binding`](#kestra-concept-access-binding) | [`binding`](#rule-binding) |
| `kestra_flow` | `resource` | [`flow`](#kestra-concept-flow) | [`flow`](#rule-flow) |
| `kestra_group` | `resource` | [`identity-group`](#kestra-concept-identity-group) | [`group`](#rule-group) |
| `kestra_namespace_secret` | `resource` | [`namespace-secret`](#kestra-concept-namespace-secret) | [`namespace-secret`](#rule-namespace-secret) |
| `kestra_namespace` | `resource` | [`namespace`](#kestra-concept-namespace) | [`namespace`](#rule-namespace) |
| `kestra_role` | `data` | [`access-role`](#kestra-concept-access-role) | [`existing-role`](#rule-existing-role) |
| `kestra_role` | `resource` | [`access-role`](#kestra-concept-access-role) | [`role`](#rule-role) |
| `kestra_user_password` | `resource` | [`user-credential`](#kestra-concept-user-credential) | [`user-password`](#rule-user-password) |
| `kestra_user` | `resource` | [`user-account`](#kestra-concept-user-account) | [`user`](#rule-user) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="kestra-concept-access-binding"><code>kestra.concept.access-binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Kestra role binding for an external principal.

</dd>
<dd>

Used by [`binding`](#rule-binding).

</dd>
</div>

<div>
<dt id="kestra-concept-access-role"><code>kestra.concept.access-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Kestra role defining an access permission set.

</dd>
<dd>

Used by [`binding`](#rule-binding), [`existing-role`](#rule-existing-role), [`role`](#rule-role).

</dd>
</div>

<div>
<dt id="kestra-concept-flow"><code>kestra.concept.flow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/orchestration/workflows.rf.hcl#L5-L7">Source</a></dt>
<dd>

A declaratively managed Kestra orchestration flow.

</dd>
<dd>

Used by [`flow`](#rule-flow).

</dd>
</div>

<div>
<dt id="kestra-concept-identity-group"><code>kestra.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>

Used by [`group`](#rule-group).

</dd>
</div>

<div>
<dt id="kestra-concept-namespace"><code>kestra.concept.namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/orchestration/workflows.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Kestra namespace that organizes orchestration resources.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`flow`](#rule-flow)
- [`group`](#rule-group)
- [`namespace`](#rule-namespace)
- [`namespace-secret`](#rule-namespace-secret)
- [`role`](#rule-role)

</details>

</dd>
</div>

<div>
<dt id="kestra-concept-namespace-secret"><code>kestra.concept.namespace-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/security/namespace-secrets.rf.hcl#L1-L3">Source</a></dt>
<dd>

A secret declaration attached to a Kestra namespace.

</dd>
<dd>

Used by [`namespace-secret`](#rule-namespace-secret).

</dd>
</div>

<div>
<dt id="kestra-concept-user-account"><code>kestra.concept.user-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/users.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Kestra user account.

</dd>
<dd>

Used by [`user`](#rule-user), [`user-password`](#rule-user-password).

</dd>
</div>

<div>
<dt id="kestra-concept-user-credential"><code>kestra.concept.user-credential</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/users.rf.hcl#L5-L7">Source</a></dt>
<dd>

A basic-auth credential attached to a Kestra user.

</dd>
<dd>

Used by [`user-password`](#rule-user-password).

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="kestra-context-ownership"><code>kestra.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>

Used by [`flow`](#rule-flow), [`group`](#rule-group), [`role`](#rule-role).

</dd>
</div>

</dl>

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>kestra.rule.binding</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L84-L105">Source</a></summary>

<div id="rule-binding"></div>

Matches `resource` instances of `kestra_binding`.

**Classification:** [`kestra.concept.access-binding`](#kestra-concept-access-binding).

**Contributions**

- targets [`kestra.concept.access-role`](#kestra-concept-access-role) through `source.role_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.role_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>kestra.rule.flow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/orchestration/workflows.rf.hcl#L26-L48">Source</a></summary>

<div id="rule-flow"></div>

Matches `resource` instances of `kestra_flow`.

**Classification:** [`kestra.concept.flow`](#kestra-concept-flow).

**Contexts**

- [`kestra.context.ownership`](#kestra-context-ownership): targets [`kestra.concept.namespace`](#kestra-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.namespace_id`
- `match.strategy`: `"dot-ancestor"`

</details>

</details>

<details>
<summary><code>kestra.rule.group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L9-L31">Source</a></summary>

<div id="rule-group"></div>

Matches `resource` instances of `kestra_group`.

**Classification:** [`kestra.concept.identity-group`](#kestra-concept-identity-group).

**Contexts**

- [`kestra.context.ownership`](#kestra-context-ownership): targets [`kestra.concept.namespace`](#kestra-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.namespace_id`
- `match.strategy`: `"dot-ancestor"`

</details>

</details>

<details>
<summary><code>kestra.rule.namespace-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/security/namespace-secrets.rf.hcl#L5-L26">Source</a></summary>

<div id="rule-namespace-secret"></div>

Matches `resource` instances of `kestra_namespace_secret`.

**Classification:** [`kestra.concept.namespace-secret`](#kestra-concept-namespace-secret).

**Contributions**

- targets [`kestra.concept.namespace`](#kestra-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.namespace_id`
- `match.strategy`: `"dot-ancestor"`

</details>

</details>

<details>
<summary><code>kestra.rule.namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/orchestration/workflows.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-namespace"></div>

Matches `resource` instances of `kestra_namespace`.

**Classification:** [`kestra.concept.namespace`](#kestra-concept-namespace).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["namespace_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "namespace_id"]`

</details>

</details>

<details>
<summary><code>kestra.rule.existing-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L66-L82">Source</a></summary>

<div id="rule-existing-role"></div>

Matches `data` instances of `kestra_role`.

**Classification:** [`kestra.concept.access-role`](#kestra-concept-access-role).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["role_id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "role_id"]`

</details>

</details>

<details>
<summary><code>kestra.rule.role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/access-control.rf.hcl#L33-L64">Source</a></summary>

<div id="rule-role"></div>

Matches `resource` instances of `kestra_role`.

**Classification:** [`kestra.concept.access-role`](#kestra-concept-access-role).

**Contexts**

- [`kestra.context.ownership`](#kestra-context-ownership): targets [`kestra.concept.namespace`](#kestra-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.namespace_id`
- `match.strategy`: `"dot-ancestor"`

</details>

</details>

<details>
<summary><code>kestra.rule.user-password</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/users.rf.hcl#L26-L44">Source</a></summary>

<div id="rule-user-password"></div>

Matches `resource` instances of `kestra_user_password`.

**Classification:** [`kestra.concept.user-credential`](#kestra-concept-user-credential).

**Contributions**

- targets [`kestra.concept.user-account`](#kestra-concept-user-account) through `source.user_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.user_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>kestra.rule.user</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/kestra/identity-iam/users.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-user"></div>

Matches `resource` instances of `kestra_user`.

**Classification:** [`kestra.concept.user-account`](#kestra-concept-user-account).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>
