Reference
kubernetes Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/kubernetes:>= 2.0.0, < 3.0.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
kubernetes.concept.daemon-setSource-
A pod scheduler runs on every selected node.
-
Used by
kubernetes-daemon-set. kubernetes.concept.deploymentSource-
A declaratively managed set of replica pods.
-
Used by
kubernetes-deployment. kubernetes.concept.horizontal-pod-autoscalerSource-
A controller that scales a workload by observed demand.
-
Used by
kubernetes-horizontal-pod-autoscaler. kubernetes.concept.ingressSource-
HTTP routing into cluster services from outside the cluster.
-
Used by
kubernetes-ingress. kubernetes.concept.namespaceSource-
A namespace partitioning one cluster's workloads, services, and storage.
kubernetes.concept.network-policySource-
A namespace-scoped policy controlling pod network traffic.
-
Used by
kubernetes-network-policy. kubernetes.concept.persistent-volume-claimSource-
A request for persistent storage bound to a volume.
-
Used by
kubernetes-persistent-volume-claim. kubernetes.concept.serviceSource-
A stable network endpoint in front of a set of pods.
-
Used by
kubernetes-service. kubernetes.concept.service-accountSource-
An identity a pod runs under inside the cluster.
-
Used by
kubernetes-deployment,kubernetes-service-account,kubernetes-stateful-set. kubernetes.concept.stateful-setSource-
A stateful workload whose pods keep stable identity and storage.
-
Used by
kubernetes-stateful-set.
kubernetes.relation.runs-asSource-
Introduced by a labeled emission. Used by
kubernetes-deployment,kubernetes-stateful-set.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
kubernetes.rule.kubernetes-daemon-set Source
Matches resource instances of kubernetes_daemon_set_v1.
Classification: kubernetes.concept.daemon-set.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-deployment Source
Matches resource instances of kubernetes_deployment_v1.
Classification: kubernetes.concept.deployment.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Relations
kubernetes.relation.runs-as: targetskubernetes.concept.service-accountthroughsource.spec[0].template[0].spec[0].service_account_name.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
Relation through source.spec[0].template[0].spec[0].service_account_name
on_null:"absent"on_empty:"absent"
kubernetes.rule.kubernetes-horizontal-pod-autoscaler Source
Matches resource instances of kubernetes_horizontal_pod_autoscaler_v1.
Classification: kubernetes.concept.horizontal-pod-autoscaler.
Contexts
kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-ingress Source
Matches resource instances of kubernetes_ingress_v1.
Classification: kubernetes.concept.ingress.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-namespace Source
Matches resource instances of kubernetes_namespace_v1.
Classification: kubernetes.concept.namespace.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.
Conditions, identity and resolution
Identity
attributes:["id", "metadata[0].name"]scope:"provider"
Endpoint
attributes:["id", "metadata[0].name"]
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
kubernetes.rule.kubernetes-network-policy Source
Matches resource instances of kubernetes_network_policy_v1.
Classification: kubernetes.concept.network-policy.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-persistent-volume-claim Source
Matches resource instances of kubernetes_persistent_volume_claim_v1.
Classification: kubernetes.concept.persistent-volume-claim.
Contexts
kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-service-account Source
Matches resource instances of kubernetes_service_account_v1.
Classification: kubernetes.concept.service-account.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id", "metadata[0].name"]
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-service Source
Matches resource instances of kubernetes_service_v1.
Classification: kubernetes.concept.service.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
kubernetes.rule.kubernetes-stateful-set Source
Matches resource instances of kubernetes_stateful_set_v1.
Classification: kubernetes.concept.stateful-set.
Contexts
rf.context.runtime: targetsrf.concept.kubernetes-clusterthroughprovider.host.kubernetes.context.ownership: targetskubernetes.concept.namespacethroughsource.metadata[0].namespace.
Relations
kubernetes.relation.runs-as: targetskubernetes.concept.service-accountthroughsource.spec[0].template[0].spec[0].service_account_name.
Conditions, identity and resolution
Context through provider.host
on_null:"indeterminate"on_empty:"indeterminate"
Context through source.metadata[0].namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.metadata[0].namematch.strategy:"exact"
Relation through source.spec[0].template[0].spec[0].service_account_name
on_null:"absent"on_empty:"absent"