Reference
vault Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
hashicorp/vault:= 5.11.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
vault.concept.audit-deviceSource-
A Vault audit device receiving security audit records.
-
Used by
audit. vault.concept.auth-configurationSource-
A role, mapping, certificate, or setting supporting a Vault auth method.
-
Used by 32 Rules
alicloud-auth-backend-roleapprole-auth-backend-roleaws-auth-backend-certaws-auth-backend-clientaws-auth-backend-config-identityaws-auth-backend-identity-whitelistaws-auth-backend-roleaws-auth-backend-role-tagaws-auth-backend-roletag-blacklistaws-auth-backend-sts-roleazure-auth-backend-configazure-auth-backend-rolecert-auth-backend-rolecf-auth-backend-configcf-auth-backend-rolegcp-auth-backend-rolegithub-teamjwt-auth-backend-rolekerberos-auth-backend-configkerberos-auth-backend-groupkerberos-auth-backend-ldap-configkubernetes-auth-backend-roleldap-auth-backend-groupoci-auth-backendoci-auth-backend-roleokta-auth-backend-groupradius-auth-backendsaml-auth-backend-rolescep-auth-backend-rolespiffe-auth-backend-configspiffe-auth-backend-roletoken-auth-backend-role
vault.concept.auth-methodSource-
A mounted Vault auth method verifying a human or machine identity.
-
Used by 34 Rules
alicloud-auth-backend-roleapprole-auth-backend-roleauth-backendaws-auth-backend-certaws-auth-backend-clientaws-auth-backend-roleaws-auth-backend-sts-roleazure-auth-backend-configazure-auth-backend-rolecert-auth-backend-rolecf-auth-backend-configcf-auth-backend-rolegcp-auth-backendgcp-auth-backend-rolegithub-auth-backendgithub-teamjwt-auth-backendjwt-auth-backend-rolekerberos-auth-backend-configkerberos-auth-backend-groupkubernetes-auth-backend-configkubernetes-auth-backend-roleldap-auth-backendldap-auth-backend-groupoci-auth-backendoci-auth-backend-roleokta-auth-backendokta-auth-backend-groupradius-auth-backendsaml-auth-backendsaml-auth-backend-rolescep-auth-backend-rolespiffe-auth-backend-configspiffe-auth-backend-role
vault.concept.backup-planSource-
A managed policy scheduling and retaining backups.
-
Used by
raft-snapshot-agent-config. -
A Vault-managed or integrated certificate authority and issuer boundary.
vault.concept.data-transformationSource-
A durable Vault Transform data-protection transformation.
-
Used by
transform-transformation. vault.concept.encryption-configurationSource-
A key distribution, replication, transform, or cache setting supporting Vault encryption.
vault.concept.external-ca-integrationSource-
A Vault PKI integration delegating certificate issuance to an external authority.
-
Used by
pki-external-ca-secret-backend-role. vault.concept.governance-configurationSource-
A policy, quota, or administrative object supporting Vault governance.
vault.concept.identity-applicationSource-
An application or relying-party client registered with an identity platform.
-
Used by
identity-oidc-client. vault.concept.identity-configurationSource-
An alias, membership, assignment, MFA, scope, or role supporting Vault identity.
-
Used by 21 Rules
identity-entity-aliasidentity-entity-policiesidentity-group-aliasidentity-group-member-entity-idsidentity-group-member-group-idsidentity-group-policiesidentity-mfa-duoidentity-mfa-login-enforcementidentity-mfa-oktaidentity-mfa-pingididentity-mfa-totpidentity-oidcidentity-oidc-assignmentidentity-oidc-key-allowed-client-ididentity-oidc-roleidentity-oidc-scopemfa-duomfa-oktamfa-pingidmfa-totpoauth-resource-server-config-profile
vault.concept.identity-entitySource-
A canonical Vault identity joining aliases from one or more auth methods.
-
Used by
identity-entity. vault.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by
identity-group. vault.concept.key-management-integrationSource-
A Vault Key Management integration distributing keys to an external key service.
-
Used by 4 Rules
vault.concept.kmip-listenerSource-
A Vault KMIP protocol listener serving key-management clients.
-
Used by
kmip-secret-listener. vault.concept.kmip-scopeSource-
An isolated Vault KMIP tenancy scope containing roles and managed objects.
-
Used by
kmip-secret-scope. vault.concept.kubernetes-auth-integrationSource-
A Vault Kubernetes authentication integration connecting a mounted auth method to a Kubernetes cluster.
-
Used by
kubernetes-auth-backend-config. vault.concept.namespaceSource-
An isolated Vault tenancy boundary for secrets, auth methods, identities, and policies.
-
Used by 56 Rules
ad-secret-backendagent-registrationalicloud-secret-backendauditauth-backendaws-secret-backendazure-secret-backendconsul-secret-backenddatabase-secrets-mountgcp-auth-backendgcp-secret-backendgcpkms-secret-backendgcpkms-secret-backend-keygithub-auth-backendidentity-entityidentity-groupidentity-oidc-clientidentity-oidc-keyidentity-oidc-providerjwt-auth-backendkeymgmt-aws-kmskeymgmt-azure-kmskeymgmt-gcp-kmskeymgmt-keykmip-secret-backendkmip-secret-ca-generatedkmip-secret-ca-importedkmip-secret-listenerkmip-secret-scopekubernetes-auth-backend-configkubernetes-secret-backendldap-auth-backendldap-secret-backendmongodbatlas-secret-backendmountnamespacenomad-secret-backendokta-auth-backendpki-external-ca-secret-backend-rolepki-secret-backend-issuerpki-secret-backend-keypki-secret-backend-root-certplugin-runtimerabbitmq-secret-backendraft-snapshot-agent-configsaml-auth-backendsecrets-sync-aws-destinationsecrets-sync-azure-destinationsecrets-sync-gcp-destinationsecrets-sync-gh-destinationsecrets-sync-github-appssecrets-sync-vercel-destinationssh-secret-backend-caterraform-cloud-secret-backendtransform-transformationtransit-secret-backend-key
vault.concept.oidc-providerSource-
A Vault OpenID Connect identity provider boundary.
-
Used by
identity-oidc-provider. vault.concept.operations-configurationSource-
An audit, Raft, or continuity setting supporting Vault operations.
-
Used by
audit-request-header,raft-autopilot. vault.concept.pki-configurationSource-
A role, protocol, revocation, issuer, or lifecycle setting supporting Vault PKI or KMIP.
-
Used by 12 Rules
kmip-secret-rolepki-secret-backend-config-acmepki-secret-backend-config-auto-tidypki-secret-backend-config-clusterpki-secret-backend-config-cmpv2pki-secret-backend-config-estpki-secret-backend-config-issuerspki-secret-backend-config-sceppki-secret-backend-config-urlspki-secret-backend-crl-configpki-secret-backend-intermediate-set-signedpki-secret-backend-role
vault.concept.plugin-configurationSource-
A plugin registration or version setting supporting a Vault plugin runtime.
-
Used by
plugin,plugin-pinned-version. vault.concept.plugin-runtimeSource-
A runtime boundary executing external Vault plugins.
-
Used by
plugin-runtime. vault.concept.secret-definitionSource-
A managed Vault secret definition whose values remain outside architecture output.
-
Used by
generic-secret,kv-secret,kv-secret-v2. vault.concept.secret-readSource-
A read-only lookup of Vault secret material whose values remain outside architecture output.
-
Used by
generic-secret-read,kv-secret-read,kv-secret-v2-read. vault.concept.secret-sync-configurationSource-
A destination association or service setting supporting Vault Secrets Sync.
-
Used by
secrets-sync-association,secrets-sync-config. vault.concept.secret-sync-destinationSource-
An external cloud or SaaS destination receiving secrets through Vault Secrets Sync.
vault.concept.secrets-engineSource-
A mounted Vault secrets engine storing, generating, or transforming sensitive data.
-
Used by 34 Rules
ad-secret-backendalicloud-secret-backendaws-secret-backendazure-secret-backendconsul-secret-backenddatabase-secret-backend-connectiondatabase-secret-backend-roledatabase-secret-backend-static-roledatabase-secrets-mountgcp-secret-backendgcpkms-secret-backendkmip-secret-backendkubernetes-secret-backendkv-secret-backend-v2ldap-secret-backendmongodbatlas-secret-backendmountnomad-secret-backendos-secret-backendpki-secret-backend-config-acmepki-secret-backend-config-auto-tidypki-secret-backend-config-clusterpki-secret-backend-config-cmpv2pki-secret-backend-config-estpki-secret-backend-config-issuerspki-secret-backend-config-sceppki-secret-backend-config-urlspki-secret-backend-crl-configpki-secret-backend-intermediate-set-signedpki-secret-backend-rolerabbitmq-secret-backendspiffe-secret-backend-configterraform-cloud-secret-backendtransit-secret-cache-config
vault.concept.secrets-engine-configurationSource-
A connection, role, library, account, or setting supporting a Vault secrets engine.
-
Used by 29 Rules
ad-secret-libraryad-secret-rolealicloud-secret-backend-roleaws-secret-backend-roleaws-secret-backend-static-roleazure-secret-backend-roleazure-secret-backend-static-roleconsul-secret-backend-roledatabase-secret-backend-connectiondatabase-secret-backend-roledatabase-secret-backend-static-rolegcp-secret-impersonated-accountgcp-secret-rolesetgcp-secret-static-accountkubernetes-secret-backend-rolekv-secret-backend-v2ldap-secret-backend-dynamic-roleldap-secret-backend-library-setldap-secret-backend-static-rolemongodbatlas-secret-rolenomad-secret-roleos-secret-backendos-secret-backend-accountos-secret-backend-hostrabbitmq-secret-backend-rolespiffe-secret-backend-configspiffe-secret-backend-rolessh-secret-backend-roleterraform-cloud-secret-role
vault.concept.vault-agentSource-
A registered Vault Agent workload identity boundary.
-
Used by
agent-registration.
vault.context.ownershipSource-
Administrative or lifecycle ownership.
-
Used by 56 Rules
ad-secret-backendagent-registrationalicloud-secret-backendauditauth-backendaws-secret-backendazure-secret-backendconsul-secret-backenddatabase-secrets-mountgcp-auth-backendgcp-secret-backendgcpkms-secret-backendgcpkms-secret-backend-keygithub-auth-backendidentity-entityidentity-groupidentity-oidc-clientidentity-oidc-keyidentity-oidc-providerjwt-auth-backendkeymgmt-aws-kmskeymgmt-azure-kmskeymgmt-gcp-kmskeymgmt-keykmip-secret-backendkmip-secret-ca-generatedkmip-secret-ca-importedkmip-secret-listenerkmip-secret-scopekubernetes-auth-backend-configkubernetes-secret-backendldap-auth-backendldap-secret-backendmongodbatlas-secret-backendmountnamespacenomad-secret-backendokta-auth-backendpki-external-ca-secret-backend-rolepki-secret-backend-issuerpki-secret-backend-keypki-secret-backend-root-certplugin-runtimerabbitmq-secret-backendraft-snapshot-agent-configsaml-auth-backendsecrets-sync-aws-destinationsecrets-sync-azure-destinationsecrets-sync-gcp-destinationsecrets-sync-gh-destinationsecrets-sync-github-appssecrets-sync-vercel-destinationssh-secret-backend-caterraform-cloud-secret-backendtransform-transformationtransit-secret-backend-key
vault.relation.authenticates-kubernetes-clusterSource-
Introduced by a labeled emission. Used by
kubernetes-auth-backend-config. vault.relation.configures-auth-methodSource-
Introduced by a labeled emission. Used by
kubernetes-auth-backend-config. vault.relation.issues-kubernetes-credentials-forSource-
Introduced by a labeled emission. Used by
kubernetes-secret-backend. vault.relation.stores-snapshots-inSource-
Introduced by a labeled emission. Used by
raft-snapshot-agent-config. vault.relation.uses-cloud-identitySource-
Introduced by a labeled emission.
vault.relation.uses-encryption-keySource-
Introduced by a labeled emission. Used by
raft-snapshot-agent-config,secrets-sync-aws-destination,secrets-sync-gcp-destination. vault.relation.uses-signing-keySource-
Introduced by a labeled emission. Used by
identity-oidc-client.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
vault.rule.ad-secret-backend Source
Matches resource instances of vault_ad_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["backend"]scope:"provider"
Endpoint
attributes:["id", "backend"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.ad-secret-library Source
Matches resource instances of vault_ad_secret_library.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.ad-secret-role Source
Matches resource instances of vault_ad_secret_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.agent-registration Source
Matches resource instances of vault_agent_registration.
Classification: vault.concept.vault-agent.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.alicloud-auth-backend-role Source
Matches resource instances of vault_alicloud_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.alicloud-secret-backend-role Source
Matches resource instances of vault_alicloud_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.alicloud-secret-backend Source
Matches resource instances of vault_alicloud_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["mount"]scope:"provider"
Endpoint
attributes:["mount"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.approle-auth-backend-role Source
Matches resource instances of vault_approle_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.audit-request-header Source
Matches resource instances of vault_audit_request_header.
Classification: vault.concept.operations-configuration.
vault.rule.audit Source
Matches resource instances of vault_audit.
Classification: vault.concept.audit-device.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.auth-backend Source
Matches resource instances of vault_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.aws-auth-backend-cert Source
Matches resource instances of vault_aws_auth_backend_cert.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.aws-auth-backend-client Source
Matches resource instances of vault_aws_auth_backend_client.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.aws-auth-backend-config-identity Source
Matches resource instances of vault_aws_auth_backend_config_identity.
Classification: vault.concept.auth-configuration.
vault.rule.aws-auth-backend-identity-whitelist Source
Matches resource instances of vault_aws_auth_backend_identity_whitelist.
Classification: vault.concept.auth-configuration.
vault.rule.aws-auth-backend-role-tag Source
Matches resource instances of vault_aws_auth_backend_role_tag.
Classification: vault.concept.auth-configuration.
vault.rule.aws-auth-backend-role Source
Matches resource instances of vault_aws_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.aws-auth-backend-roletag-blacklist Source
Matches resource instances of vault_aws_auth_backend_roletag_blacklist.
Classification: vault.concept.auth-configuration.
vault.rule.aws-auth-backend-sts-role Source
Matches resource instances of vault_aws_auth_backend_sts_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.aws-secret-backend-role Source
Matches resource instances of vault_aws_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.aws-secret-backend-static-role Source
Matches resource instances of vault_aws_secret_backend_static_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.aws-secret-backend Source
Matches resource instances of vault_aws_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.azure-auth-backend-config Source
Matches resource instances of vault_azure_auth_backend_config.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.azure-auth-backend-role Source
Matches resource instances of vault_azure_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.azure-secret-backend-role Source
Matches resource instances of vault_azure_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.azure-secret-backend-static-role Source
Matches resource instances of vault_azure_secret_backend_static_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.azure-secret-backend Source
Matches resource instances of vault_azure_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.cert-auth-backend-role Source
Matches resource instances of vault_cert_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.cf-auth-backend-config Source
Matches resource instances of vault_cf_auth_backend_config.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.cf-auth-backend-role Source
Matches resource instances of vault_cf_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.config-control-group Source
Matches resource instances of vault_config_control_group.
Classification: vault.concept.governance-configuration.
vault.rule.config-group-policy-application Source
Matches resource instances of vault_config_group_policy_application.
Classification: vault.concept.governance-configuration.
vault.rule.consul-secret-backend-role Source
Matches resource instances of vault_consul_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.consul-secret-backend Source
Matches resource instances of vault_consul_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.database-secret-backend-connection Source
Matches resource instances of vault_database_secret_backend_connection.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.database-secret-backend-role Source
Matches resource instances of vault_database_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.database-secret-backend-static-role Source
Matches resource instances of vault_database_secret_backend_static_role.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.database-secrets-mount Source
Matches resource instances of vault_database_secrets_mount.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.egp-policy Source
Matches resource instances of vault_egp_policy.
Classification: vault.concept.governance-configuration.
vault.rule.gcp-auth-backend-role Source
Matches resource instances of vault_gcp_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.gcp-auth-backend Source
Matches resource instances of vault_gcp_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.service_account_email.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.service_account_email
on_null:"absent"on_empty:"absent"
vault.rule.gcp-secret-backend Source
Matches resource instances of vault_gcp_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.service_account_email.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.service_account_email
on_null:"absent"on_empty:"absent"
vault.rule.gcp-secret-impersonated-account Source
Matches resource instances of vault_gcp_secret_impersonated_account.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.gcp-secret-roleset Source
Matches resource instances of vault_gcp_secret_roleset.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.gcp-secret-static-account Source
Matches resource instances of vault_gcp_secret_static_account.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.gcpkms-secret-backend-key Source
Matches resource instances of vault_gcpkms_secret_backend_key.
Classification: vault.concept.encryption-key.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["key_name"]scope:"provider"
Endpoint
attributes:["key_name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.gcpkms-secret-backend Source
Matches resource instances of vault_gcpkms_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.generic-secret-read Source
Matches data instances of vault_generic_secret.
Classification: vault.concept.secret-read.
vault.rule.generic-secret Source
Matches resource instances of vault_generic_secret.
Classification: vault.concept.secret-definition.
vault.rule.github-auth-backend Source
Matches resource instances of vault_github_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.github-team Source
Matches resource instances of vault_github_team.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.identity-entity-alias Source
Matches resource instances of vault_identity_entity_alias.
Classification: vault.concept.identity-configuration.
vault.rule.identity-entity-policies Source
Matches resource instances of vault_identity_entity_policies.
Classification: vault.concept.identity-configuration.
vault.rule.identity-entity Source
Matches resource instances of vault_identity_entity.
Classification: vault.concept.identity-entity.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.identity-group-alias Source
Matches resource instances of vault_identity_group_alias.
Classification: vault.concept.identity-configuration.
vault.rule.identity-group-member-entity-ids Source
Matches resource instances of vault_identity_group_member_entity_ids.
Classification: vault.concept.identity-configuration.
vault.rule.identity-group-member-group-ids Source
Matches resource instances of vault_identity_group_member_group_ids.
Classification: vault.concept.identity-configuration.
vault.rule.identity-group-policies Source
Matches resource instances of vault_identity_group_policies.
Classification: vault.concept.identity-configuration.
vault.rule.identity-group Source
Matches resource instances of vault_identity_group.
Classification: vault.concept.identity-group.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.identity-mfa-duo Source
Matches resource instances of vault_identity_mfa_duo.
Classification: vault.concept.identity-configuration.
vault.rule.identity-mfa-login-enforcement Source
Matches resource instances of vault_identity_mfa_login_enforcement.
Classification: vault.concept.identity-configuration.
vault.rule.identity-mfa-okta Source
Matches resource instances of vault_identity_mfa_okta.
Classification: vault.concept.identity-configuration.
vault.rule.identity-mfa-pingid Source
Matches resource instances of vault_identity_mfa_pingid.
Classification: vault.concept.identity-configuration.
vault.rule.identity-mfa-totp Source
Matches resource instances of vault_identity_mfa_totp.
Classification: vault.concept.identity-configuration.
vault.rule.identity-oidc-assignment Source
Matches resource instances of vault_identity_oidc_assignment.
Classification: vault.concept.identity-configuration.
vault.rule.identity-oidc-client Source
Matches resource instances of vault_identity_oidc_client.
Classification: vault.concept.identity-application.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-signing-key: targetsvault.rule.identity-oidc-keythroughsource.key.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.key
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
vault.rule.identity-oidc-key-allowed-client-id Source
Matches resource instances of vault_identity_oidc_key_allowed_client_id.
Classification: vault.concept.identity-configuration.
vault.rule.identity-oidc-key Source
Matches resource instances of vault_identity_oidc_key.
Classification: vault.concept.encryption-key.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.identity-oidc-provider Source
Matches resource instances of vault_identity_oidc_provider.
Classification: vault.concept.oidc-provider.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.identity-oidc-role Source
Matches resource instances of vault_identity_oidc_role.
Classification: vault.concept.identity-configuration.
vault.rule.identity-oidc-scope Source
Matches resource instances of vault_identity_oidc_scope.
Classification: vault.concept.identity-configuration.
vault.rule.identity-oidc Source
Matches resource instances of vault_identity_oidc.
Classification: vault.concept.identity-configuration.
vault.rule.jwt-auth-backend-role Source
Matches resource instances of vault_jwt_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.jwt-auth-backend Source
Matches resource instances of vault_jwt_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kerberos-auth-backend-config Source
Matches resource instances of vault_kerberos_auth_backend_config.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.kerberos-auth-backend-group Source
Matches resource instances of vault_kerberos_auth_backend_group.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.kerberos-auth-backend-ldap-config Source
Matches resource instances of vault_kerberos_auth_backend_ldap_config.
Classification: vault.concept.auth-configuration.
vault.rule.keymgmt-aws-kms Source
Matches resource instances of vault_keymgmt_aws_kms.
Classification: vault.concept.key-management-integration.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.keymgmt-azure-kms Source
Matches resource instances of vault_keymgmt_azure_kms.
Classification: vault.concept.key-management-integration.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.keymgmt-distribute-key Source
Matches resource instances of vault_keymgmt_distribute_key.
Classification: vault.concept.encryption-configuration.
Contributions
- targets
vault.rule.keymgmt-keythroughsource.key_name. - targets
vault.concept.key-management-integrationthroughsource.kms_name.
Conditions, identity and resolution
Contribution through source.key_name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
Contribution through source.kms_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
vault.rule.keymgmt-gcp-kms Source
Matches resource instances of vault_keymgmt_gcp_kms.
Classification: vault.concept.key-management-integration.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.keymgmt-key Source
Matches resource instances of vault_keymgmt_key.
Classification: vault.concept.encryption-key.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.keymgmt-replicate-key Source
Matches resource instances of vault_keymgmt_replicate_key.
Classification: vault.concept.encryption-configuration.
vault.rule.kmip-secret-backend Source
Matches resource instances of vault_kmip_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kmip-secret-ca-generated Source
Matches resource instances of vault_kmip_secret_ca_generated.
Classification: vault.concept.certificate-authority.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kmip-secret-ca-imported Source
Matches resource instances of vault_kmip_secret_ca_imported.
Classification: vault.concept.certificate-authority.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kmip-secret-listener Source
Matches resource instances of vault_kmip_secret_listener.
Classification: vault.concept.kmip-listener.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kmip-secret-role Source
Matches resource instances of vault_kmip_secret_role.
Classification: vault.concept.pki-configuration.
vault.rule.kmip-secret-scope Source
Matches resource instances of vault_kmip_secret_scope.
Classification: vault.concept.kmip-scope.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.kubernetes-auth-backend-config Source
Matches resource instances of vault_kubernetes_auth_backend_config.
Classification: vault.concept.kubernetes-auth-integration.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.authenticates-kubernetes-cluster: targetsrf.concept.kubernetes-clusterthroughsource.kubernetes_host.vault.relation.configures-auth-method: targetsvault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.kubernetes_host
on_null:"absent"on_empty:"absent"
Relation through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.kubernetes-auth-backend-role Source
Matches resource instances of vault_kubernetes_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.kubernetes-secret-backend-role Source
Matches resource instances of vault_kubernetes_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.kubernetes-secret-backend Source
Matches resource instances of vault_kubernetes_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.issues-kubernetes-credentials-for: targetsrf.concept.kubernetes-clusterthroughsource.kubernetes_host.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.kubernetes_host
on_null:"absent"on_empty:"absent"
vault.rule.kv-secret-backend-v2 Source
Matches resource instances of vault_kv_secret_backend_v2.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.kv-secret-v2-read Source
Matches data instances of vault_kv_secret_v2.
Classification: vault.concept.secret-read.
vault.rule.kv-secret-v2 Source
Matches resource instances of vault_kv_secret_v2.
Classification: vault.concept.secret-definition.
vault.rule.kv-secret-read Source
Matches data instances of vault_kv_secret.
Classification: vault.concept.secret-read.
vault.rule.kv-secret Source
Matches resource instances of vault_kv_secret.
Classification: vault.concept.secret-definition.
vault.rule.ldap-auth-backend-group Source
Matches resource instances of vault_ldap_auth_backend_group.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.ldap-auth-backend Source
Matches resource instances of vault_ldap_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.ldap-secret-backend-dynamic-role Source
Matches resource instances of vault_ldap_secret_backend_dynamic_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.ldap-secret-backend-library-set Source
Matches resource instances of vault_ldap_secret_backend_library_set.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.ldap-secret-backend-static-role Source
Matches resource instances of vault_ldap_secret_backend_static_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.ldap-secret-backend Source
Matches resource instances of vault_ldap_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.managed-keys Source
Matches resource instances of vault_managed_keys.
Classification: vault.concept.encryption-configuration.
vault.rule.mfa-duo Source
Matches resource instances of vault_mfa_duo.
Classification: vault.concept.identity-configuration.
vault.rule.mfa-okta Source
Matches resource instances of vault_mfa_okta.
Classification: vault.concept.identity-configuration.
vault.rule.mfa-pingid Source
Matches resource instances of vault_mfa_pingid.
Classification: vault.concept.identity-configuration.
vault.rule.mfa-totp Source
Matches resource instances of vault_mfa_totp.
Classification: vault.concept.identity-configuration.
vault.rule.mongodbatlas-secret-backend Source
Matches resource instances of vault_mongodbatlas_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.mongodbatlas-secret-role Source
Matches resource instances of vault_mongodbatlas_secret_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.mount Source
Matches resource instances of vault_mount.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.namespace Source
Matches resource instances of vault_namespace.
Classification: vault.concept.namespace.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.nomad-secret-backend Source
Matches resource instances of vault_nomad_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["backend"]scope:"provider"
Endpoint
attributes:["id", "backend"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.nomad-secret-role Source
Matches resource instances of vault_nomad_secret_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.oauth-resource-server-config-profile Source
Matches resource instances of vault_oauth_resource_server_config_profile.
Classification: vault.concept.identity-configuration.
vault.rule.oci-auth-backend-role Source
Matches resource instances of vault_oci_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.oci-auth-backend Source
Matches resource instances of vault_oci_auth_backend.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.path.
Conditions, identity and resolution
Contribution through source.path
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.okta-auth-backend-group Source
Matches resource instances of vault_okta_auth_backend_group.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.path.
Conditions, identity and resolution
Contribution through source.path
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.okta-auth-backend Source
Matches resource instances of vault_okta_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.os-secret-backend-account Source
Matches resource instances of vault_os_secret_backend_account.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.os-secret-backend-host Source
Matches resource instances of vault_os_secret_backend_host.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.os-secret-backend Source
Matches resource instances of vault_os_secret_backend.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.password-policy Source
Matches resource instances of vault_password_policy.
Classification: vault.concept.governance-configuration.
vault.rule.pki-external-ca-secret-backend-role Source
Matches resource instances of vault_pki_external_ca_secret_backend_role.
Classification: vault.concept.external-ca-integration.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-acme Source
Matches resource instances of vault_pki_secret_backend_config_acme.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-auto-tidy Source
Matches resource instances of vault_pki_secret_backend_config_auto_tidy.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-cluster Source
Matches resource instances of vault_pki_secret_backend_config_cluster.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-cmpv2 Source
Matches resource instances of vault_pki_secret_backend_config_cmpv2.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-est Source
Matches resource instances of vault_pki_secret_backend_config_est.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-issuers Source
Matches resource instances of vault_pki_secret_backend_config_issuers.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-scep Source
Matches resource instances of vault_pki_secret_backend_config_scep.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-config-urls Source
Matches resource instances of vault_pki_secret_backend_config_urls.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-crl-config Source
Matches resource instances of vault_pki_secret_backend_crl_config.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-intermediate-set-signed Source
Matches resource instances of vault_pki_secret_backend_intermediate_set_signed.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-issuer Source
Matches resource instances of vault_pki_secret_backend_issuer.
Classification: vault.concept.certificate-authority.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-key Source
Matches resource instances of vault_pki_secret_backend_key.
Classification: vault.concept.encryption-key.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["key_name"]scope:"provider"
Endpoint
attributes:["id", "key_id", "key_name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-role Source
Matches resource instances of vault_pki_secret_backend_role.
Classification: vault.concept.pki-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.pki-secret-backend-root-cert Source
Matches resource instances of vault_pki_secret_backend_root_cert.
Classification: vault.concept.certificate-authority.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.plugin-pinned-version Source
Matches resource instances of vault_plugin_pinned_version.
Classification: vault.concept.plugin-configuration.
vault.rule.plugin-runtime Source
Matches resource instances of vault_plugin_runtime.
Classification: vault.concept.plugin-runtime.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.plugin Source
Matches resource instances of vault_plugin.
Classification: vault.concept.plugin-configuration.
vault.rule.policy Source
Matches resource instances of vault_policy.
Classification: vault.concept.governance-configuration.
vault.rule.rabbitmq-secret-backend-role Source
Matches resource instances of vault_rabbitmq_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.rabbitmq-secret-backend Source
Matches resource instances of vault_rabbitmq_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.radius-auth-backend Source
Matches resource instances of vault_radius_auth_backend.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.raft-autopilot Source
Matches resource instances of vault_raft_autopilot.
Classification: vault.concept.operations-configuration.
vault.rule.raft-snapshot-agent-config Source
Matches resource instances of vault_raft_snapshot_agent_config.
Classification: vault.concept.backup-plan.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.stores-snapshots-in: targetsrf.concept.object-storage-containerthroughsource.aws_s3_bucket.vault.relation.stores-snapshots-in: targetsrf.concept.object-storage-containerthroughsource.azure_container_name.vault.relation.stores-snapshots-in: targetsrf.concept.object-storage-containerthroughsource.google_gcs_bucket.vault.relation.uses-encryption-key: targetsvault.concept.encryption-keythroughsource.aws_s3_kms_key.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.aws_s3_bucket
on_null:"absent"on_empty:"absent"
Relation through source.azure_container_name
on_null:"absent"on_empty:"absent"
Relation through source.google_gcs_bucket
on_null:"absent"on_empty:"absent"
Relation through source.aws_s3_kms_key
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
vault.rule.rgp-policy Source
Matches resource instances of vault_rgp_policy.
Classification: vault.concept.governance-configuration.
vault.rule.rotation-policy Source
Matches resource instances of vault_rotation_policy.
Classification: vault.concept.governance-configuration.
vault.rule.saml-auth-backend-role Source
Matches resource instances of vault_saml_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.path.
Conditions, identity and resolution
Contribution through source.path
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.saml-auth-backend Source
Matches resource instances of vault_saml_auth_backend.
Classification: vault.concept.auth-method.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["path"]scope:"provider"
Endpoint
attributes:["id", "path"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.scep-auth-backend-role Source
Matches resource instances of vault_scep_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.secrets-sync-association Source
Matches resource instances of vault_secrets_sync_association.
Classification: vault.concept.secret-sync-configuration.
Contributions
- targets
vault.concept.secret-sync-destinationthroughsource.name.
Conditions, identity and resolution
Contribution through source.name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
vault.rule.secrets-sync-aws-destination Source
Matches resource instances of vault_secrets_sync_aws_destination.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-encryption-key: targetsvault.concept.encryption-keythroughsource.kms_key_id.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.kms_key_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
vault.rule.secrets-sync-azure-destination Source
Matches resource instances of vault_secrets_sync_azure_destination.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.client_id.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.client_id
on_null:"absent"on_empty:"absent"
vault.rule.secrets-sync-config Source
Matches resource instances of vault_secrets_sync_config.
Classification: vault.concept.secret-sync-configuration.
vault.rule.secrets-sync-gcp-destination Source
Matches resource instances of vault_secrets_sync_gcp_destination.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Relations
vault.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.service_account_email.vault.relation.uses-encryption-key: targetsvault.concept.encryption-keythroughsource.kms_key_id.vault.relation.uses-encryption-key: targetsvault.concept.encryption-keythroughsource.global_kms_key.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
Relation through source.service_account_email
on_null:"absent"on_empty:"absent"
Relation through source.kms_key_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.global_kms_key
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
vault.rule.secrets-sync-gh-destination Source
Matches resource instances of vault_secrets_sync_gh_destination.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.secrets-sync-github-apps Source
Matches resource instances of vault_secrets_sync_github_apps.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.secrets-sync-vercel-destination Source
Matches resource instances of vault_secrets_sync_vercel_destination.
Classification: vault.concept.secret-sync-destination.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.spiffe-auth-backend-config Source
Matches resource instances of vault_spiffe_auth_backend_config.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.spiffe-auth-backend-role Source
Matches resource instances of vault_spiffe_auth_backend_role.
Classification: vault.concept.auth-configuration.
Contributions
- targets
vault.concept.auth-methodthroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.spiffe-secret-backend-config Source
Matches resource instances of vault_spiffe_secret_backend_config.
Classification: vault.concept.secrets-engine-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.mount.
Conditions, identity and resolution
Contribution through source.mount
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"
vault.rule.spiffe-secret-backend-role Source
Matches resource instances of vault_spiffe_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.ssh-secret-backend-ca Source
Matches resource instances of vault_ssh_secret_backend_ca.
Classification: vault.concept.certificate-authority.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.ssh-secret-backend-role Source
Matches resource instances of vault_ssh_secret_backend_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.terraform-cloud-secret-backend Source
Matches resource instances of vault_terraform_cloud_secret_backend.
Classification: vault.concept.secrets-engine.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["backend"]scope:"provider"
Endpoint
attributes:["id", "backend"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.terraform-cloud-secret-role Source
Matches resource instances of vault_terraform_cloud_secret_role.
Classification: vault.concept.secrets-engine-configuration.
vault.rule.token-auth-backend-role Source
Matches resource instances of vault_token_auth_backend_role.
Classification: vault.concept.auth-configuration.
vault.rule.transform-alphabet Source
Matches resource instances of vault_transform_alphabet.
Classification: vault.concept.encryption-configuration.
vault.rule.transform-key-configuration Source
Matches resource instances of vault_transform_key_configuration.
Classification: vault.concept.encryption-configuration.
vault.rule.transform-role Source
Matches resource instances of vault_transform_role.
Classification: vault.concept.encryption-configuration.
vault.rule.transform-template Source
Matches resource instances of vault_transform_template.
Classification: vault.concept.encryption-configuration.
vault.rule.transform-transformation Source
Matches resource instances of vault_transform_transformation.
Classification: vault.concept.data-transformation.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.transit-secret-backend-key Source
Matches resource instances of vault_transit_secret_backend_key.
Classification: vault.concept.encryption-key.
Contexts
vault.context.ownership: targetsvault.concept.namespacethroughsource.namespace.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.namespace
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.pathmatch.strategy:"exact"
vault.rule.transit-secret-cache-config Source
Matches resource instances of vault_transit_secret_cache_config.
Classification: vault.concept.encryption-configuration.
Contributions
- targets
vault.concept.secrets-enginethroughsource.backend.
Conditions, identity and resolution
Contribution through source.backend
on_null:"absent"on_empty:"absent"match.by:target.pathmatch.strategy:"exact"