Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/kubernetes: >= 2.0.0, < 3.0.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
kubernetes_daemon_set_v1resourcedaemon-setkubernetes-daemon-set
kubernetes_deployment_v1resourcedeploymentkubernetes-deployment
kubernetes_horizontal_pod_autoscaler_v1resourcehorizontal-pod-autoscalerkubernetes-horizontal-pod-autoscaler
kubernetes_ingress_v1resourceingresskubernetes-ingress
kubernetes_namespace_v1resourcenamespacekubernetes-namespace
kubernetes_network_policy_v1resourcenetwork-policykubernetes-network-policy
kubernetes_persistent_volume_claim_v1resourcepersistent-volume-claimkubernetes-persistent-volume-claim
kubernetes_service_account_v1resourceservice-accountkubernetes-service-account
kubernetes_service_v1resourceservicekubernetes-service
kubernetes_stateful_set_v1resourcestateful-setkubernetes-stateful-set

Local vocabulary

Concepts

kubernetes.concept.daemon-set Source

A pod scheduler runs on every selected node.

Used by kubernetes-daemon-set.

kubernetes.concept.deployment Source

A declaratively managed set of replica pods.

Used by kubernetes-deployment.

kubernetes.concept.horizontal-pod-autoscaler Source

A controller that scales a workload by observed demand.

Used by kubernetes-horizontal-pod-autoscaler.

kubernetes.concept.ingress Source

HTTP routing into cluster services from outside the cluster.

Used by kubernetes-ingress.

kubernetes.concept.network-policy Source

A namespace-scoped policy controlling pod network traffic.

Used by kubernetes-network-policy.

kubernetes.concept.persistent-volume-claim Source

A request for persistent storage bound to a volume.

Used by kubernetes-persistent-volume-claim.

kubernetes.concept.service Source

A stable network endpoint in front of a set of pods.

Used by kubernetes-service.

kubernetes.concept.service-account Source

An identity a pod runs under inside the cluster.

Used by kubernetes-deployment, kubernetes-service-account, kubernetes-stateful-set.

kubernetes.concept.stateful-set Source

A stateful workload whose pods keep stable identity and storage.

Used by kubernetes-stateful-set.

Contexts

Relations

kubernetes.relation.runs-as Source

Introduced by a labeled emission. Used by kubernetes-deployment, kubernetes-stateful-set.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

kubernetes.rule.kubernetes-daemon-set Source

Matches resource instances of kubernetes_daemon_set_v1.

Classification: kubernetes.concept.daemon-set.

Contexts

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-deployment Source

Matches resource instances of kubernetes_deployment_v1.

Classification: kubernetes.concept.deployment.

Contexts

Relations

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"

Relation through source.spec[0].template[0].spec[0].service_account_name

  • on_null: "absent"
  • on_empty: "absent"
kubernetes.rule.kubernetes-horizontal-pod-autoscaler Source

Matches resource instances of kubernetes_horizontal_pod_autoscaler_v1.

Classification: kubernetes.concept.horizontal-pod-autoscaler.

Contexts

Conditions, identity and resolution

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-ingress Source

Matches resource instances of kubernetes_ingress_v1.

Classification: kubernetes.concept.ingress.

Contexts

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-namespace Source

Matches resource instances of kubernetes_namespace_v1.

Classification: kubernetes.concept.namespace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "metadata[0].name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "metadata[0].name"]

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"
kubernetes.rule.kubernetes-network-policy Source

Matches resource instances of kubernetes_network_policy_v1.

Classification: kubernetes.concept.network-policy.

Contexts

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-persistent-volume-claim Source

Matches resource instances of kubernetes_persistent_volume_claim_v1.

Classification: kubernetes.concept.persistent-volume-claim.

Contexts

Conditions, identity and resolution

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-service-account Source

Matches resource instances of kubernetes_service_account_v1.

Classification: kubernetes.concept.service-account.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "metadata[0].name"]

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-service Source

Matches resource instances of kubernetes_service_v1.

Classification: kubernetes.concept.service.

Contexts

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"
kubernetes.rule.kubernetes-stateful-set Source

Matches resource instances of kubernetes_stateful_set_v1.

Classification: kubernetes.concept.stateful-set.

Contexts

Relations

Conditions, identity and resolution

Context through provider.host

  • on_null: "indeterminate"
  • on_empty: "indeterminate"

Context through source.metadata[0].namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.metadata[0].name
  • match.strategy: "exact"

Relation through source.spec[0].template[0].spec[0].service_account_name

  • on_null: "absent"
  • on_empty: "absent"