Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • hashicorp/vault: = 5.11.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
vault_ad_secret_backendresourcesecrets-enginead-secret-backend
vault_ad_secret_libraryresourcesecrets-engine-configurationad-secret-library
vault_ad_secret_roleresourcesecrets-engine-configurationad-secret-role
vault_agent_registrationresourcevault-agentagent-registration
vault_alicloud_auth_backend_roleresourceauth-configurationalicloud-auth-backend-role
vault_alicloud_secret_backend_roleresourcesecrets-engine-configurationalicloud-secret-backend-role
vault_alicloud_secret_backendresourcesecrets-enginealicloud-secret-backend
vault_approle_auth_backend_roleresourceauth-configurationapprole-auth-backend-role
vault_audit_request_headerresourceoperations-configurationaudit-request-header
vault_auditresourceaudit-deviceaudit
vault_auth_backendresourceauth-methodauth-backend
vault_aws_auth_backend_certresourceauth-configurationaws-auth-backend-cert
vault_aws_auth_backend_clientresourceauth-configurationaws-auth-backend-client
vault_aws_auth_backend_config_identityresourceauth-configurationaws-auth-backend-config-identity
vault_aws_auth_backend_identity_whitelistresourceauth-configurationaws-auth-backend-identity-whitelist
vault_aws_auth_backend_role_tagresourceauth-configurationaws-auth-backend-role-tag
vault_aws_auth_backend_roleresourceauth-configurationaws-auth-backend-role
vault_aws_auth_backend_roletag_blacklistresourceauth-configurationaws-auth-backend-roletag-blacklist
vault_aws_auth_backend_sts_roleresourceauth-configurationaws-auth-backend-sts-role
vault_aws_secret_backend_roleresourcesecrets-engine-configurationaws-secret-backend-role
vault_aws_secret_backend_static_roleresourcesecrets-engine-configurationaws-secret-backend-static-role
vault_aws_secret_backendresourcesecrets-engineaws-secret-backend
vault_azure_auth_backend_configresourceauth-configurationazure-auth-backend-config
vault_azure_auth_backend_roleresourceauth-configurationazure-auth-backend-role
vault_azure_secret_backend_roleresourcesecrets-engine-configurationazure-secret-backend-role
vault_azure_secret_backend_static_roleresourcesecrets-engine-configurationazure-secret-backend-static-role
vault_azure_secret_backendresourcesecrets-engineazure-secret-backend
vault_cert_auth_backend_roleresourceauth-configurationcert-auth-backend-role
vault_cf_auth_backend_configresourceauth-configurationcf-auth-backend-config
vault_cf_auth_backend_roleresourceauth-configurationcf-auth-backend-role
vault_config_control_groupresourcegovernance-configurationconfig-control-group
vault_config_group_policy_applicationresourcegovernance-configurationconfig-group-policy-application
vault_consul_secret_backend_roleresourcesecrets-engine-configurationconsul-secret-backend-role
vault_consul_secret_backendresourcesecrets-engineconsul-secret-backend
vault_database_secret_backend_connectionresourcesecrets-engine-configurationdatabase-secret-backend-connection
vault_database_secret_backend_roleresourcesecrets-engine-configurationdatabase-secret-backend-role
vault_database_secret_backend_static_roleresourcesecrets-engine-configurationdatabase-secret-backend-static-role
vault_database_secrets_mountresourcesecrets-enginedatabase-secrets-mount
vault_egp_policyresourcegovernance-configurationegp-policy
vault_gcp_auth_backend_roleresourceauth-configurationgcp-auth-backend-role
vault_gcp_auth_backendresourceauth-methodgcp-auth-backend
vault_gcp_secret_backendresourcesecrets-enginegcp-secret-backend
vault_gcp_secret_impersonated_accountresourcesecrets-engine-configurationgcp-secret-impersonated-account
vault_gcp_secret_rolesetresourcesecrets-engine-configurationgcp-secret-roleset
vault_gcp_secret_static_accountresourcesecrets-engine-configurationgcp-secret-static-account
vault_gcpkms_secret_backend_keyresourceencryption-keygcpkms-secret-backend-key
vault_gcpkms_secret_backendresourcesecrets-enginegcpkms-secret-backend
vault_generic_secretdatasecret-readgeneric-secret-read
vault_generic_secretresourcesecret-definitiongeneric-secret
vault_github_auth_backendresourceauth-methodgithub-auth-backend
vault_github_teamresourceauth-configurationgithub-team
vault_identity_entity_aliasresourceidentity-configurationidentity-entity-alias
vault_identity_entity_policiesresourceidentity-configurationidentity-entity-policies
vault_identity_entityresourceidentity-entityidentity-entity
vault_identity_group_aliasresourceidentity-configurationidentity-group-alias
vault_identity_group_member_entity_idsresourceidentity-configurationidentity-group-member-entity-ids
vault_identity_group_member_group_idsresourceidentity-configurationidentity-group-member-group-ids
vault_identity_group_policiesresourceidentity-configurationidentity-group-policies
vault_identity_groupresourceidentity-groupidentity-group
vault_identity_mfa_duoresourceidentity-configurationidentity-mfa-duo
vault_identity_mfa_login_enforcementresourceidentity-configurationidentity-mfa-login-enforcement
vault_identity_mfa_oktaresourceidentity-configurationidentity-mfa-okta
vault_identity_mfa_pingidresourceidentity-configurationidentity-mfa-pingid
vault_identity_mfa_totpresourceidentity-configurationidentity-mfa-totp
vault_identity_oidc_assignmentresourceidentity-configurationidentity-oidc-assignment
vault_identity_oidc_clientresourceidentity-applicationidentity-oidc-client
vault_identity_oidc_key_allowed_client_idresourceidentity-configurationidentity-oidc-key-allowed-client-id
vault_identity_oidc_keyresourceencryption-keyidentity-oidc-key
vault_identity_oidc_providerresourceoidc-provideridentity-oidc-provider
vault_identity_oidc_roleresourceidentity-configurationidentity-oidc-role
vault_identity_oidc_scoperesourceidentity-configurationidentity-oidc-scope
vault_identity_oidcresourceidentity-configurationidentity-oidc
vault_jwt_auth_backend_roleresourceauth-configurationjwt-auth-backend-role
vault_jwt_auth_backendresourceauth-methodjwt-auth-backend
vault_kerberos_auth_backend_configresourceauth-configurationkerberos-auth-backend-config
vault_kerberos_auth_backend_groupresourceauth-configurationkerberos-auth-backend-group
vault_kerberos_auth_backend_ldap_configresourceauth-configurationkerberos-auth-backend-ldap-config
vault_keymgmt_aws_kmsresourcekey-management-integrationkeymgmt-aws-kms
vault_keymgmt_azure_kmsresourcekey-management-integrationkeymgmt-azure-kms
vault_keymgmt_distribute_keyresourceencryption-configurationkeymgmt-distribute-key
vault_keymgmt_gcp_kmsresourcekey-management-integrationkeymgmt-gcp-kms
vault_keymgmt_keyresourceencryption-keykeymgmt-key
vault_keymgmt_replicate_keyresourceencryption-configurationkeymgmt-replicate-key
vault_kmip_secret_backendresourcesecrets-enginekmip-secret-backend
vault_kmip_secret_ca_generatedresourcecertificate-authoritykmip-secret-ca-generated
vault_kmip_secret_ca_importedresourcecertificate-authoritykmip-secret-ca-imported
vault_kmip_secret_listenerresourcekmip-listenerkmip-secret-listener
vault_kmip_secret_roleresourcepki-configurationkmip-secret-role
vault_kmip_secret_scoperesourcekmip-scopekmip-secret-scope
vault_kubernetes_auth_backend_configresourcekubernetes-auth-integrationkubernetes-auth-backend-config
vault_kubernetes_auth_backend_roleresourceauth-configurationkubernetes-auth-backend-role
vault_kubernetes_secret_backend_roleresourcesecrets-engine-configurationkubernetes-secret-backend-role
vault_kubernetes_secret_backendresourcesecrets-enginekubernetes-secret-backend
vault_kv_secret_backend_v2resourcesecrets-engine-configurationkv-secret-backend-v2
vault_kv_secret_v2datasecret-readkv-secret-v2-read
vault_kv_secret_v2resourcesecret-definitionkv-secret-v2
vault_kv_secretdatasecret-readkv-secret-read
vault_kv_secretresourcesecret-definitionkv-secret
vault_ldap_auth_backend_groupresourceauth-configurationldap-auth-backend-group
vault_ldap_auth_backendresourceauth-methodldap-auth-backend
vault_ldap_secret_backend_dynamic_roleresourcesecrets-engine-configurationldap-secret-backend-dynamic-role
vault_ldap_secret_backend_library_setresourcesecrets-engine-configurationldap-secret-backend-library-set
vault_ldap_secret_backend_static_roleresourcesecrets-engine-configurationldap-secret-backend-static-role
vault_ldap_secret_backendresourcesecrets-engineldap-secret-backend
vault_managed_keysresourceencryption-configurationmanaged-keys
vault_mfa_duoresourceidentity-configurationmfa-duo
vault_mfa_oktaresourceidentity-configurationmfa-okta
vault_mfa_pingidresourceidentity-configurationmfa-pingid
vault_mfa_totpresourceidentity-configurationmfa-totp
vault_mongodbatlas_secret_backendresourcesecrets-enginemongodbatlas-secret-backend
vault_mongodbatlas_secret_roleresourcesecrets-engine-configurationmongodbatlas-secret-role
vault_mountresourcesecrets-enginemount
vault_namespaceresourcenamespacenamespace
vault_nomad_secret_backendresourcesecrets-enginenomad-secret-backend
vault_nomad_secret_roleresourcesecrets-engine-configurationnomad-secret-role
vault_oauth_resource_server_config_profileresourceidentity-configurationoauth-resource-server-config-profile
vault_oci_auth_backend_roleresourceauth-configurationoci-auth-backend-role
vault_oci_auth_backendresourceauth-configurationoci-auth-backend
vault_okta_auth_backend_groupresourceauth-configurationokta-auth-backend-group
vault_okta_auth_backendresourceauth-methodokta-auth-backend
vault_os_secret_backend_accountresourcesecrets-engine-configurationos-secret-backend-account
vault_os_secret_backend_hostresourcesecrets-engine-configurationos-secret-backend-host
vault_os_secret_backendresourcesecrets-engine-configurationos-secret-backend
vault_password_policyresourcegovernance-configurationpassword-policy
vault_pki_external_ca_secret_backend_roleresourceexternal-ca-integrationpki-external-ca-secret-backend-role
vault_pki_secret_backend_config_acmeresourcepki-configurationpki-secret-backend-config-acme
vault_pki_secret_backend_config_auto_tidyresourcepki-configurationpki-secret-backend-config-auto-tidy
vault_pki_secret_backend_config_clusterresourcepki-configurationpki-secret-backend-config-cluster
vault_pki_secret_backend_config_cmpv2resourcepki-configurationpki-secret-backend-config-cmpv2
vault_pki_secret_backend_config_estresourcepki-configurationpki-secret-backend-config-est
vault_pki_secret_backend_config_issuersresourcepki-configurationpki-secret-backend-config-issuers
vault_pki_secret_backend_config_scepresourcepki-configurationpki-secret-backend-config-scep
vault_pki_secret_backend_config_urlsresourcepki-configurationpki-secret-backend-config-urls
vault_pki_secret_backend_crl_configresourcepki-configurationpki-secret-backend-crl-config
vault_pki_secret_backend_intermediate_set_signedresourcepki-configurationpki-secret-backend-intermediate-set-signed
vault_pki_secret_backend_issuerresourcecertificate-authoritypki-secret-backend-issuer
vault_pki_secret_backend_keyresourceencryption-keypki-secret-backend-key
vault_pki_secret_backend_roleresourcepki-configurationpki-secret-backend-role
vault_pki_secret_backend_root_certresourcecertificate-authoritypki-secret-backend-root-cert
vault_plugin_pinned_versionresourceplugin-configurationplugin-pinned-version
vault_plugin_runtimeresourceplugin-runtimeplugin-runtime
vault_pluginresourceplugin-configurationplugin
vault_policyresourcegovernance-configurationpolicy
vault_rabbitmq_secret_backend_roleresourcesecrets-engine-configurationrabbitmq-secret-backend-role
vault_rabbitmq_secret_backendresourcesecrets-enginerabbitmq-secret-backend
vault_radius_auth_backendresourceauth-configurationradius-auth-backend
vault_raft_autopilotresourceoperations-configurationraft-autopilot
vault_raft_snapshot_agent_configresourcebackup-planraft-snapshot-agent-config
vault_rgp_policyresourcegovernance-configurationrgp-policy
vault_rotation_policyresourcegovernance-configurationrotation-policy
vault_saml_auth_backend_roleresourceauth-configurationsaml-auth-backend-role
vault_saml_auth_backendresourceauth-methodsaml-auth-backend
vault_scep_auth_backend_roleresourceauth-configurationscep-auth-backend-role
vault_secrets_sync_associationresourcesecret-sync-configurationsecrets-sync-association
vault_secrets_sync_aws_destinationresourcesecret-sync-destinationsecrets-sync-aws-destination
vault_secrets_sync_azure_destinationresourcesecret-sync-destinationsecrets-sync-azure-destination
vault_secrets_sync_configresourcesecret-sync-configurationsecrets-sync-config
vault_secrets_sync_gcp_destinationresourcesecret-sync-destinationsecrets-sync-gcp-destination
vault_secrets_sync_gh_destinationresourcesecret-sync-destinationsecrets-sync-gh-destination
vault_secrets_sync_github_appsresourcesecret-sync-destinationsecrets-sync-github-apps
vault_secrets_sync_vercel_destinationresourcesecret-sync-destinationsecrets-sync-vercel-destination
vault_spiffe_auth_backend_configresourceauth-configurationspiffe-auth-backend-config
vault_spiffe_auth_backend_roleresourceauth-configurationspiffe-auth-backend-role
vault_spiffe_secret_backend_configresourcesecrets-engine-configurationspiffe-secret-backend-config
vault_spiffe_secret_backend_roleresourcesecrets-engine-configurationspiffe-secret-backend-role
vault_ssh_secret_backend_caresourcecertificate-authorityssh-secret-backend-ca
vault_ssh_secret_backend_roleresourcesecrets-engine-configurationssh-secret-backend-role
vault_terraform_cloud_secret_backendresourcesecrets-engineterraform-cloud-secret-backend
vault_terraform_cloud_secret_roleresourcesecrets-engine-configurationterraform-cloud-secret-role
vault_token_auth_backend_roleresourceauth-configurationtoken-auth-backend-role
vault_transform_alphabetresourceencryption-configurationtransform-alphabet
vault_transform_key_configurationresourceencryption-configurationtransform-key-configuration
vault_transform_roleresourceencryption-configurationtransform-role
vault_transform_templateresourceencryption-configurationtransform-template
vault_transform_transformationresourcedata-transformationtransform-transformation
vault_transit_secret_backend_keyresourceencryption-keytransit-secret-backend-key
vault_transit_secret_cache_configresourceencryption-configurationtransit-secret-cache-config

Local vocabulary

Concepts

vault.concept.audit-device Source

A Vault audit device receiving security audit records.

Used by audit.

vault.concept.auth-configuration Source

A role, mapping, certificate, or setting supporting a Vault auth method.

Used by 32 Rules
vault.concept.auth-method Source

A mounted Vault auth method verifying a human or machine identity.

Used by 34 Rules
vault.concept.backup-plan Source

A managed policy scheduling and retaining backups.

Used by raft-snapshot-agent-config.

vault.concept.certificate-authority Source

A Vault-managed or integrated certificate authority and issuer boundary.

Used by 5 Rules
vault.concept.data-transformation Source

A durable Vault Transform data-protection transformation.

Used by transform-transformation.

vault.concept.encryption-configuration Source

A key distribution, replication, transform, or cache setting supporting Vault encryption.

Used by 8 Rules
vault.concept.external-ca-integration Source

A Vault PKI integration delegating certificate issuance to an external authority.

Used by pki-external-ca-secret-backend-role.

vault.concept.governance-configuration Source

A policy, quota, or administrative object supporting Vault governance.

Used by 7 Rules
vault.concept.identity-application Source

An application or relying-party client registered with an identity platform.

Used by identity-oidc-client.

vault.concept.identity-entity Source

A canonical Vault identity joining aliases from one or more auth methods.

Used by identity-entity.

vault.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by identity-group.

vault.concept.key-management-integration Source

A Vault Key Management integration distributing keys to an external key service.

Used by 4 Rules
vault.concept.kmip-listener Source

A Vault KMIP protocol listener serving key-management clients.

Used by kmip-secret-listener.

vault.concept.kmip-scope Source

An isolated Vault KMIP tenancy scope containing roles and managed objects.

Used by kmip-secret-scope.

vault.concept.kubernetes-auth-integration Source

A Vault Kubernetes authentication integration connecting a mounted auth method to a Kubernetes cluster.

Used by kubernetes-auth-backend-config.

vault.concept.namespace Source

An isolated Vault tenancy boundary for secrets, auth methods, identities, and policies.

Used by 56 Rules
vault.concept.oidc-provider Source

A Vault OpenID Connect identity provider boundary.

Used by identity-oidc-provider.

vault.concept.operations-configuration Source

An audit, Raft, or continuity setting supporting Vault operations.

Used by audit-request-header, raft-autopilot.

vault.concept.plugin-configuration Source

A plugin registration or version setting supporting a Vault plugin runtime.

Used by plugin, plugin-pinned-version.

vault.concept.plugin-runtime Source

A runtime boundary executing external Vault plugins.

Used by plugin-runtime.

vault.concept.secret-definition Source

A managed Vault secret definition whose values remain outside architecture output.

Used by generic-secret, kv-secret, kv-secret-v2.

vault.concept.secret-read Source

A read-only lookup of Vault secret material whose values remain outside architecture output.

Used by generic-secret-read, kv-secret-read, kv-secret-v2-read.

vault.concept.secret-sync-configuration Source

A destination association or service setting supporting Vault Secrets Sync.

Used by secrets-sync-association, secrets-sync-config.

vault.concept.secret-sync-destination Source

An external cloud or SaaS destination receiving secrets through Vault Secrets Sync.

Used by 7 Rules
vault.concept.secrets-engine Source

A mounted Vault secrets engine storing, generating, or transforming sensitive data.

Used by 34 Rules
vault.concept.secrets-engine-configuration Source

A connection, role, library, account, or setting supporting a Vault secrets engine.

Used by 29 Rules
vault.concept.vault-agent Source

A registered Vault Agent workload identity boundary.

Used by agent-registration.

Contexts

vault.context.ownership Source

Administrative or lifecycle ownership.

Used by 56 Rules

Relations

vault.relation.authenticates-kubernetes-cluster Source

Introduced by a labeled emission. Used by kubernetes-auth-backend-config.

vault.relation.configures-auth-method Source

Introduced by a labeled emission. Used by kubernetes-auth-backend-config.

vault.relation.issues-kubernetes-credentials-for Source

Introduced by a labeled emission. Used by kubernetes-secret-backend.

vault.relation.stores-snapshots-in Source

Introduced by a labeled emission. Used by raft-snapshot-agent-config.

vault.relation.uses-cloud-identity Source

Introduced by a labeled emission.

Used by 4 Rules
vault.relation.uses-encryption-key Source

Introduced by a labeled emission. Used by raft-snapshot-agent-config, secrets-sync-aws-destination, secrets-sync-gcp-destination.

vault.relation.uses-signing-key Source

Introduced by a labeled emission. Used by identity-oidc-client.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

vault.rule.ad-secret-backend Source

Matches resource instances of vault_ad_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["backend"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "backend"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.ad-secret-library Source

Matches resource instances of vault_ad_secret_library.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.ad-secret-role Source

Matches resource instances of vault_ad_secret_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.agent-registration Source

Matches resource instances of vault_agent_registration.

Classification: vault.concept.vault-agent.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.alicloud-auth-backend-role Source

Matches resource instances of vault_alicloud_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.alicloud-secret-backend-role Source

Matches resource instances of vault_alicloud_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.alicloud-secret-backend Source

Matches resource instances of vault_alicloud_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["mount"]
  • scope: "provider"

Endpoint

  • attributes: ["mount"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.approle-auth-backend-role Source

Matches resource instances of vault_approle_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.audit-request-header Source

Matches resource instances of vault_audit_request_header.

Classification: vault.concept.operations-configuration.

vault.rule.audit Source

Matches resource instances of vault_audit.

Classification: vault.concept.audit-device.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.auth-backend Source

Matches resource instances of vault_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.aws-auth-backend-cert Source

Matches resource instances of vault_aws_auth_backend_cert.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.aws-auth-backend-client Source

Matches resource instances of vault_aws_auth_backend_client.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.aws-auth-backend-config-identity Source

Matches resource instances of vault_aws_auth_backend_config_identity.

Classification: vault.concept.auth-configuration.

vault.rule.aws-auth-backend-identity-whitelist Source

Matches resource instances of vault_aws_auth_backend_identity_whitelist.

Classification: vault.concept.auth-configuration.

vault.rule.aws-auth-backend-role-tag Source

Matches resource instances of vault_aws_auth_backend_role_tag.

Classification: vault.concept.auth-configuration.

vault.rule.aws-auth-backend-role Source

Matches resource instances of vault_aws_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.aws-auth-backend-roletag-blacklist Source

Matches resource instances of vault_aws_auth_backend_roletag_blacklist.

Classification: vault.concept.auth-configuration.

vault.rule.aws-auth-backend-sts-role Source

Matches resource instances of vault_aws_auth_backend_sts_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.aws-secret-backend-role Source

Matches resource instances of vault_aws_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.aws-secret-backend-static-role Source

Matches resource instances of vault_aws_secret_backend_static_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.aws-secret-backend Source

Matches resource instances of vault_aws_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.azure-auth-backend-config Source

Matches resource instances of vault_azure_auth_backend_config.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.azure-auth-backend-role Source

Matches resource instances of vault_azure_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.azure-secret-backend-role Source

Matches resource instances of vault_azure_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.azure-secret-backend-static-role Source

Matches resource instances of vault_azure_secret_backend_static_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.azure-secret-backend Source

Matches resource instances of vault_azure_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.cert-auth-backend-role Source

Matches resource instances of vault_cert_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.cf-auth-backend-config Source

Matches resource instances of vault_cf_auth_backend_config.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.cf-auth-backend-role Source

Matches resource instances of vault_cf_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.config-control-group Source

Matches resource instances of vault_config_control_group.

Classification: vault.concept.governance-configuration.

vault.rule.config-group-policy-application Source

Matches resource instances of vault_config_group_policy_application.

Classification: vault.concept.governance-configuration.

vault.rule.consul-secret-backend-role Source

Matches resource instances of vault_consul_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.consul-secret-backend Source

Matches resource instances of vault_consul_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.database-secret-backend-connection Source

Matches resource instances of vault_database_secret_backend_connection.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.database-secret-backend-role Source

Matches resource instances of vault_database_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.database-secret-backend-static-role Source

Matches resource instances of vault_database_secret_backend_static_role.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.database-secrets-mount Source

Matches resource instances of vault_database_secrets_mount.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.egp-policy Source

Matches resource instances of vault_egp_policy.

Classification: vault.concept.governance-configuration.

vault.rule.gcp-auth-backend-role Source

Matches resource instances of vault_gcp_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.gcp-auth-backend Source

Matches resource instances of vault_gcp_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
vault.rule.gcp-secret-backend Source

Matches resource instances of vault_gcp_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.service_account_email

  • on_null: "absent"
  • on_empty: "absent"
vault.rule.gcp-secret-impersonated-account Source

Matches resource instances of vault_gcp_secret_impersonated_account.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.gcp-secret-roleset Source

Matches resource instances of vault_gcp_secret_roleset.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.gcp-secret-static-account Source

Matches resource instances of vault_gcp_secret_static_account.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.gcpkms-secret-backend-key Source

Matches resource instances of vault_gcpkms_secret_backend_key.

Classification: vault.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["key_name"]
  • scope: "provider"

Endpoint

  • attributes: ["key_name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.gcpkms-secret-backend Source

Matches resource instances of vault_gcpkms_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.generic-secret-read Source

Matches data instances of vault_generic_secret.

Classification: vault.concept.secret-read.

vault.rule.generic-secret Source

Matches resource instances of vault_generic_secret.

Classification: vault.concept.secret-definition.

vault.rule.github-auth-backend Source

Matches resource instances of vault_github_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.github-team Source

Matches resource instances of vault_github_team.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.identity-entity-alias Source

Matches resource instances of vault_identity_entity_alias.

Classification: vault.concept.identity-configuration.

vault.rule.identity-entity-policies Source

Matches resource instances of vault_identity_entity_policies.

Classification: vault.concept.identity-configuration.

vault.rule.identity-entity Source

Matches resource instances of vault_identity_entity.

Classification: vault.concept.identity-entity.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.identity-group-alias Source

Matches resource instances of vault_identity_group_alias.

Classification: vault.concept.identity-configuration.

vault.rule.identity-group-member-entity-ids Source

Matches resource instances of vault_identity_group_member_entity_ids.

Classification: vault.concept.identity-configuration.

vault.rule.identity-group-member-group-ids Source

Matches resource instances of vault_identity_group_member_group_ids.

Classification: vault.concept.identity-configuration.

vault.rule.identity-group-policies Source

Matches resource instances of vault_identity_group_policies.

Classification: vault.concept.identity-configuration.

vault.rule.identity-group Source

Matches resource instances of vault_identity_group.

Classification: vault.concept.identity-group.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.identity-mfa-duo Source

Matches resource instances of vault_identity_mfa_duo.

Classification: vault.concept.identity-configuration.

vault.rule.identity-mfa-login-enforcement Source

Matches resource instances of vault_identity_mfa_login_enforcement.

Classification: vault.concept.identity-configuration.

vault.rule.identity-mfa-okta Source

Matches resource instances of vault_identity_mfa_okta.

Classification: vault.concept.identity-configuration.

vault.rule.identity-mfa-pingid Source

Matches resource instances of vault_identity_mfa_pingid.

Classification: vault.concept.identity-configuration.

vault.rule.identity-mfa-totp Source

Matches resource instances of vault_identity_mfa_totp.

Classification: vault.concept.identity-configuration.

vault.rule.identity-oidc-assignment Source

Matches resource instances of vault_identity_oidc_assignment.

Classification: vault.concept.identity-configuration.

vault.rule.identity-oidc-client Source

Matches resource instances of vault_identity_oidc_client.

Classification: vault.concept.identity-application.

Contexts

Relations

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.key

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
vault.rule.identity-oidc-key-allowed-client-id Source

Matches resource instances of vault_identity_oidc_key_allowed_client_id.

Classification: vault.concept.identity-configuration.

vault.rule.identity-oidc-key Source

Matches resource instances of vault_identity_oidc_key.

Classification: vault.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.identity-oidc-provider Source

Matches resource instances of vault_identity_oidc_provider.

Classification: vault.concept.oidc-provider.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.identity-oidc-role Source

Matches resource instances of vault_identity_oidc_role.

Classification: vault.concept.identity-configuration.

vault.rule.identity-oidc-scope Source

Matches resource instances of vault_identity_oidc_scope.

Classification: vault.concept.identity-configuration.

vault.rule.identity-oidc Source

Matches resource instances of vault_identity_oidc.

Classification: vault.concept.identity-configuration.

vault.rule.jwt-auth-backend-role Source

Matches resource instances of vault_jwt_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.jwt-auth-backend Source

Matches resource instances of vault_jwt_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kerberos-auth-backend-config Source

Matches resource instances of vault_kerberos_auth_backend_config.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kerberos-auth-backend-group Source

Matches resource instances of vault_kerberos_auth_backend_group.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kerberos-auth-backend-ldap-config Source

Matches resource instances of vault_kerberos_auth_backend_ldap_config.

Classification: vault.concept.auth-configuration.

vault.rule.keymgmt-aws-kms Source

Matches resource instances of vault_keymgmt_aws_kms.

Classification: vault.concept.key-management-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.keymgmt-azure-kms Source

Matches resource instances of vault_keymgmt_azure_kms.

Classification: vault.concept.key-management-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.keymgmt-distribute-key Source

Matches resource instances of vault_keymgmt_distribute_key.

Classification: vault.concept.encryption-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.key_name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"

Contribution through source.kms_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
vault.rule.keymgmt-gcp-kms Source

Matches resource instances of vault_keymgmt_gcp_kms.

Classification: vault.concept.key-management-integration.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.keymgmt-key Source

Matches resource instances of vault_keymgmt_key.

Classification: vault.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.keymgmt-replicate-key Source

Matches resource instances of vault_keymgmt_replicate_key.

Classification: vault.concept.encryption-configuration.

vault.rule.kmip-secret-backend Source

Matches resource instances of vault_kmip_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kmip-secret-ca-generated Source

Matches resource instances of vault_kmip_secret_ca_generated.

Classification: vault.concept.certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kmip-secret-ca-imported Source

Matches resource instances of vault_kmip_secret_ca_imported.

Classification: vault.concept.certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kmip-secret-listener Source

Matches resource instances of vault_kmip_secret_listener.

Classification: vault.concept.kmip-listener.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kmip-secret-role Source

Matches resource instances of vault_kmip_secret_role.

Classification: vault.concept.pki-configuration.

vault.rule.kmip-secret-scope Source

Matches resource instances of vault_kmip_secret_scope.

Classification: vault.concept.kmip-scope.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kubernetes-auth-backend-config Source

Matches resource instances of vault_kubernetes_auth_backend_config.

Classification: vault.concept.kubernetes-auth-integration.

Contexts

Relations

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.kubernetes_host

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kubernetes-auth-backend-role Source

Matches resource instances of vault_kubernetes_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kubernetes-secret-backend-role Source

Matches resource instances of vault_kubernetes_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.kubernetes-secret-backend Source

Matches resource instances of vault_kubernetes_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.kubernetes_host

  • on_null: "absent"
  • on_empty: "absent"
vault.rule.kv-secret-backend-v2 Source

Matches resource instances of vault_kv_secret_backend_v2.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.kv-secret-v2-read Source

Matches data instances of vault_kv_secret_v2.

Classification: vault.concept.secret-read.

vault.rule.kv-secret-v2 Source

Matches resource instances of vault_kv_secret_v2.

Classification: vault.concept.secret-definition.

vault.rule.kv-secret-read Source

Matches data instances of vault_kv_secret.

Classification: vault.concept.secret-read.

vault.rule.kv-secret Source

Matches resource instances of vault_kv_secret.

Classification: vault.concept.secret-definition.

vault.rule.ldap-auth-backend-group Source

Matches resource instances of vault_ldap_auth_backend_group.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.ldap-auth-backend Source

Matches resource instances of vault_ldap_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.ldap-secret-backend-dynamic-role Source

Matches resource instances of vault_ldap_secret_backend_dynamic_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.ldap-secret-backend-library-set Source

Matches resource instances of vault_ldap_secret_backend_library_set.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.ldap-secret-backend-static-role Source

Matches resource instances of vault_ldap_secret_backend_static_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.ldap-secret-backend Source

Matches resource instances of vault_ldap_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.managed-keys Source

Matches resource instances of vault_managed_keys.

Classification: vault.concept.encryption-configuration.

vault.rule.mfa-duo Source

Matches resource instances of vault_mfa_duo.

Classification: vault.concept.identity-configuration.

vault.rule.mfa-okta Source

Matches resource instances of vault_mfa_okta.

Classification: vault.concept.identity-configuration.

vault.rule.mfa-pingid Source

Matches resource instances of vault_mfa_pingid.

Classification: vault.concept.identity-configuration.

vault.rule.mfa-totp Source

Matches resource instances of vault_mfa_totp.

Classification: vault.concept.identity-configuration.

vault.rule.mongodbatlas-secret-backend Source

Matches resource instances of vault_mongodbatlas_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.mongodbatlas-secret-role Source

Matches resource instances of vault_mongodbatlas_secret_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.mount Source

Matches resource instances of vault_mount.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.namespace Source

Matches resource instances of vault_namespace.

Classification: vault.concept.namespace.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.nomad-secret-backend Source

Matches resource instances of vault_nomad_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["backend"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "backend"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.nomad-secret-role Source

Matches resource instances of vault_nomad_secret_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.oauth-resource-server-config-profile Source

Matches resource instances of vault_oauth_resource_server_config_profile.

Classification: vault.concept.identity-configuration.

vault.rule.oci-auth-backend-role Source

Matches resource instances of vault_oci_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.oci-auth-backend Source

Matches resource instances of vault_oci_auth_backend.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.path

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.okta-auth-backend-group Source

Matches resource instances of vault_okta_auth_backend_group.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.path

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.okta-auth-backend Source

Matches resource instances of vault_okta_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.os-secret-backend-account Source

Matches resource instances of vault_os_secret_backend_account.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.os-secret-backend-host Source

Matches resource instances of vault_os_secret_backend_host.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.os-secret-backend Source

Matches resource instances of vault_os_secret_backend.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.password-policy Source

Matches resource instances of vault_password_policy.

Classification: vault.concept.governance-configuration.

vault.rule.pki-external-ca-secret-backend-role Source

Matches resource instances of vault_pki_external_ca_secret_backend_role.

Classification: vault.concept.external-ca-integration.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-acme Source

Matches resource instances of vault_pki_secret_backend_config_acme.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-auto-tidy Source

Matches resource instances of vault_pki_secret_backend_config_auto_tidy.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-cluster Source

Matches resource instances of vault_pki_secret_backend_config_cluster.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-cmpv2 Source

Matches resource instances of vault_pki_secret_backend_config_cmpv2.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-est Source

Matches resource instances of vault_pki_secret_backend_config_est.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-issuers Source

Matches resource instances of vault_pki_secret_backend_config_issuers.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-scep Source

Matches resource instances of vault_pki_secret_backend_config_scep.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-config-urls Source

Matches resource instances of vault_pki_secret_backend_config_urls.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-crl-config Source

Matches resource instances of vault_pki_secret_backend_crl_config.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-intermediate-set-signed Source

Matches resource instances of vault_pki_secret_backend_intermediate_set_signed.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-issuer Source

Matches resource instances of vault_pki_secret_backend_issuer.

Classification: vault.concept.certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-key Source

Matches resource instances of vault_pki_secret_backend_key.

Classification: vault.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["key_name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "key_id", "key_name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-role Source

Matches resource instances of vault_pki_secret_backend_role.

Classification: vault.concept.pki-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.pki-secret-backend-root-cert Source

Matches resource instances of vault_pki_secret_backend_root_cert.

Classification: vault.concept.certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.plugin-pinned-version Source

Matches resource instances of vault_plugin_pinned_version.

Classification: vault.concept.plugin-configuration.

vault.rule.plugin-runtime Source

Matches resource instances of vault_plugin_runtime.

Classification: vault.concept.plugin-runtime.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.plugin Source

Matches resource instances of vault_plugin.

Classification: vault.concept.plugin-configuration.

vault.rule.policy Source

Matches resource instances of vault_policy.

Classification: vault.concept.governance-configuration.

vault.rule.rabbitmq-secret-backend-role Source

Matches resource instances of vault_rabbitmq_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.rabbitmq-secret-backend Source

Matches resource instances of vault_rabbitmq_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.radius-auth-backend Source

Matches resource instances of vault_radius_auth_backend.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.raft-autopilot Source

Matches resource instances of vault_raft_autopilot.

Classification: vault.concept.operations-configuration.

vault.rule.raft-snapshot-agent-config Source

Matches resource instances of vault_raft_snapshot_agent_config.

Classification: vault.concept.backup-plan.

Contexts

Relations

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.aws_s3_bucket

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.azure_container_name

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.google_gcs_bucket

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.aws_s3_kms_key

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
vault.rule.rgp-policy Source

Matches resource instances of vault_rgp_policy.

Classification: vault.concept.governance-configuration.

vault.rule.rotation-policy Source

Matches resource instances of vault_rotation_policy.

Classification: vault.concept.governance-configuration.

vault.rule.saml-auth-backend-role Source

Matches resource instances of vault_saml_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.path

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.saml-auth-backend Source

Matches resource instances of vault_saml_auth_backend.

Classification: vault.concept.auth-method.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["path"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "path"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.scep-auth-backend-role Source

Matches resource instances of vault_scep_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.secrets-sync-association Source

Matches resource instances of vault_secrets_sync_association.

Classification: vault.concept.secret-sync-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
vault.rule.secrets-sync-aws-destination Source

Matches resource instances of vault_secrets_sync_aws_destination.

Classification: vault.concept.secret-sync-destination.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.kms_key_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
vault.rule.secrets-sync-azure-destination Source

Matches resource instances of vault_secrets_sync_azure_destination.

Classification: vault.concept.secret-sync-destination.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.client_id

  • on_null: "absent"
  • on_empty: "absent"
vault.rule.secrets-sync-config Source

Matches resource instances of vault_secrets_sync_config.

Classification: vault.concept.secret-sync-configuration.

vault.rule.secrets-sync-gcp-destination Source

Matches resource instances of vault_secrets_sync_gcp_destination.

Classification: vault.concept.secret-sync-destination.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"

Relation through source.service_account_email

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.kms_key_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.global_kms_key

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
vault.rule.secrets-sync-gh-destination Source

Matches resource instances of vault_secrets_sync_gh_destination.

Classification: vault.concept.secret-sync-destination.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.secrets-sync-github-apps Source

Matches resource instances of vault_secrets_sync_github_apps.

Classification: vault.concept.secret-sync-destination.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.secrets-sync-vercel-destination Source

Matches resource instances of vault_secrets_sync_vercel_destination.

Classification: vault.concept.secret-sync-destination.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.spiffe-auth-backend-config Source

Matches resource instances of vault_spiffe_auth_backend_config.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.spiffe-auth-backend-role Source

Matches resource instances of vault_spiffe_auth_backend_role.

Classification: vault.concept.auth-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.spiffe-secret-backend-config Source

Matches resource instances of vault_spiffe_secret_backend_config.

Classification: vault.concept.secrets-engine-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.mount

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.spiffe-secret-backend-role Source

Matches resource instances of vault_spiffe_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.ssh-secret-backend-ca Source

Matches resource instances of vault_ssh_secret_backend_ca.

Classification: vault.concept.certificate-authority.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.ssh-secret-backend-role Source

Matches resource instances of vault_ssh_secret_backend_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.terraform-cloud-secret-backend Source

Matches resource instances of vault_terraform_cloud_secret_backend.

Classification: vault.concept.secrets-engine.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["backend"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "backend"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.terraform-cloud-secret-role Source

Matches resource instances of vault_terraform_cloud_secret_role.

Classification: vault.concept.secrets-engine-configuration.

vault.rule.token-auth-backend-role Source

Matches resource instances of vault_token_auth_backend_role.

Classification: vault.concept.auth-configuration.

vault.rule.transform-alphabet Source

Matches resource instances of vault_transform_alphabet.

Classification: vault.concept.encryption-configuration.

vault.rule.transform-key-configuration Source

Matches resource instances of vault_transform_key_configuration.

Classification: vault.concept.encryption-configuration.

vault.rule.transform-role Source

Matches resource instances of vault_transform_role.

Classification: vault.concept.encryption-configuration.

vault.rule.transform-template Source

Matches resource instances of vault_transform_template.

Classification: vault.concept.encryption-configuration.

vault.rule.transform-transformation Source

Matches resource instances of vault_transform_transformation.

Classification: vault.concept.data-transformation.

Contexts

Conditions, identity and resolution

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.transit-secret-backend-key Source

Matches resource instances of vault_transit_secret_backend_key.

Classification: vault.concept.encryption-key.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.namespace

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.path
  • match.strategy: "exact"
vault.rule.transit-secret-cache-config Source

Matches resource instances of vault_transit_secret_cache_config.

Classification: vault.concept.encryption-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.backend

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.path
  • match.strategy: "exact"