# vault Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `hashicorp/vault`: `= 5.11.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `vault_ad_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`ad-secret-backend`](#rule-ad-secret-backend) |
| `vault_ad_secret_library` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ad-secret-library`](#rule-ad-secret-library) |
| `vault_ad_secret_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ad-secret-role`](#rule-ad-secret-role) |
| `vault_agent_registration` | `resource` | [`vault-agent`](#vault-concept-vault-agent) | [`agent-registration`](#rule-agent-registration) |
| `vault_alicloud_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`alicloud-auth-backend-role`](#rule-alicloud-auth-backend-role) |
| `vault_alicloud_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`alicloud-secret-backend-role`](#rule-alicloud-secret-backend-role) |
| `vault_alicloud_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`alicloud-secret-backend`](#rule-alicloud-secret-backend) |
| `vault_approle_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`approle-auth-backend-role`](#rule-approle-auth-backend-role) |
| `vault_audit_request_header` | `resource` | [`operations-configuration`](#vault-concept-operations-configuration) | [`audit-request-header`](#rule-audit-request-header) |
| `vault_audit` | `resource` | [`audit-device`](#vault-concept-audit-device) | [`audit`](#rule-audit) |
| `vault_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`auth-backend`](#rule-auth-backend) |
| `vault_aws_auth_backend_cert` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-cert`](#rule-aws-auth-backend-cert) |
| `vault_aws_auth_backend_client` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-client`](#rule-aws-auth-backend-client) |
| `vault_aws_auth_backend_config_identity` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-config-identity`](#rule-aws-auth-backend-config-identity) |
| `vault_aws_auth_backend_identity_whitelist` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-identity-whitelist`](#rule-aws-auth-backend-identity-whitelist) |
| `vault_aws_auth_backend_role_tag` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-role-tag`](#rule-aws-auth-backend-role-tag) |
| `vault_aws_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-role`](#rule-aws-auth-backend-role) |
| `vault_aws_auth_backend_roletag_blacklist` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-roletag-blacklist`](#rule-aws-auth-backend-roletag-blacklist) |
| `vault_aws_auth_backend_sts_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`aws-auth-backend-sts-role`](#rule-aws-auth-backend-sts-role) |
| `vault_aws_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`aws-secret-backend-role`](#rule-aws-secret-backend-role) |
| `vault_aws_secret_backend_static_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`aws-secret-backend-static-role`](#rule-aws-secret-backend-static-role) |
| `vault_aws_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`aws-secret-backend`](#rule-aws-secret-backend) |
| `vault_azure_auth_backend_config` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`azure-auth-backend-config`](#rule-azure-auth-backend-config) |
| `vault_azure_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`azure-auth-backend-role`](#rule-azure-auth-backend-role) |
| `vault_azure_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`azure-secret-backend-role`](#rule-azure-secret-backend-role) |
| `vault_azure_secret_backend_static_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`azure-secret-backend-static-role`](#rule-azure-secret-backend-static-role) |
| `vault_azure_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`azure-secret-backend`](#rule-azure-secret-backend) |
| `vault_cert_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`cert-auth-backend-role`](#rule-cert-auth-backend-role) |
| `vault_cf_auth_backend_config` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`cf-auth-backend-config`](#rule-cf-auth-backend-config) |
| `vault_cf_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`cf-auth-backend-role`](#rule-cf-auth-backend-role) |
| `vault_config_control_group` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`config-control-group`](#rule-config-control-group) |
| `vault_config_group_policy_application` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`config-group-policy-application`](#rule-config-group-policy-application) |
| `vault_consul_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`consul-secret-backend-role`](#rule-consul-secret-backend-role) |
| `vault_consul_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`consul-secret-backend`](#rule-consul-secret-backend) |
| `vault_database_secret_backend_connection` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`database-secret-backend-connection`](#rule-database-secret-backend-connection) |
| `vault_database_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`database-secret-backend-role`](#rule-database-secret-backend-role) |
| `vault_database_secret_backend_static_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`database-secret-backend-static-role`](#rule-database-secret-backend-static-role) |
| `vault_database_secrets_mount` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`database-secrets-mount`](#rule-database-secrets-mount) |
| `vault_egp_policy` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`egp-policy`](#rule-egp-policy) |
| `vault_gcp_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`gcp-auth-backend-role`](#rule-gcp-auth-backend-role) |
| `vault_gcp_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`gcp-auth-backend`](#rule-gcp-auth-backend) |
| `vault_gcp_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`gcp-secret-backend`](#rule-gcp-secret-backend) |
| `vault_gcp_secret_impersonated_account` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`gcp-secret-impersonated-account`](#rule-gcp-secret-impersonated-account) |
| `vault_gcp_secret_roleset` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`gcp-secret-roleset`](#rule-gcp-secret-roleset) |
| `vault_gcp_secret_static_account` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`gcp-secret-static-account`](#rule-gcp-secret-static-account) |
| `vault_gcpkms_secret_backend_key` | `resource` | [`encryption-key`](#vault-concept-encryption-key) | [`gcpkms-secret-backend-key`](#rule-gcpkms-secret-backend-key) |
| `vault_gcpkms_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`gcpkms-secret-backend`](#rule-gcpkms-secret-backend) |
| `vault_generic_secret` | `data` | [`secret-read`](#vault-concept-secret-read) | [`generic-secret-read`](#rule-generic-secret-read) |
| `vault_generic_secret` | `resource` | [`secret-definition`](#vault-concept-secret-definition) | [`generic-secret`](#rule-generic-secret) |
| `vault_github_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`github-auth-backend`](#rule-github-auth-backend) |
| `vault_github_team` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`github-team`](#rule-github-team) |
| `vault_identity_entity_alias` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-entity-alias`](#rule-identity-entity-alias) |
| `vault_identity_entity_policies` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-entity-policies`](#rule-identity-entity-policies) |
| `vault_identity_entity` | `resource` | [`identity-entity`](#vault-concept-identity-entity) | [`identity-entity`](#rule-identity-entity) |
| `vault_identity_group_alias` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-group-alias`](#rule-identity-group-alias) |
| `vault_identity_group_member_entity_ids` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-group-member-entity-ids`](#rule-identity-group-member-entity-ids) |
| `vault_identity_group_member_group_ids` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-group-member-group-ids`](#rule-identity-group-member-group-ids) |
| `vault_identity_group_policies` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-group-policies`](#rule-identity-group-policies) |
| `vault_identity_group` | `resource` | [`identity-group`](#vault-concept-identity-group) | [`identity-group`](#rule-identity-group) |
| `vault_identity_mfa_duo` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-mfa-duo`](#rule-identity-mfa-duo) |
| `vault_identity_mfa_login_enforcement` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-mfa-login-enforcement`](#rule-identity-mfa-login-enforcement) |
| `vault_identity_mfa_okta` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-mfa-okta`](#rule-identity-mfa-okta) |
| `vault_identity_mfa_pingid` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-mfa-pingid`](#rule-identity-mfa-pingid) |
| `vault_identity_mfa_totp` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-mfa-totp`](#rule-identity-mfa-totp) |
| `vault_identity_oidc_assignment` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-oidc-assignment`](#rule-identity-oidc-assignment) |
| `vault_identity_oidc_client` | `resource` | [`identity-application`](#vault-concept-identity-application) | [`identity-oidc-client`](#rule-identity-oidc-client) |
| `vault_identity_oidc_key_allowed_client_id` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-oidc-key-allowed-client-id`](#rule-identity-oidc-key-allowed-client-id) |
| `vault_identity_oidc_key` | `resource` | [`encryption-key`](#vault-concept-encryption-key) | [`identity-oidc-key`](#rule-identity-oidc-key) |
| `vault_identity_oidc_provider` | `resource` | [`oidc-provider`](#vault-concept-oidc-provider) | [`identity-oidc-provider`](#rule-identity-oidc-provider) |
| `vault_identity_oidc_role` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-oidc-role`](#rule-identity-oidc-role) |
| `vault_identity_oidc_scope` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-oidc-scope`](#rule-identity-oidc-scope) |
| `vault_identity_oidc` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`identity-oidc`](#rule-identity-oidc) |
| `vault_jwt_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`jwt-auth-backend-role`](#rule-jwt-auth-backend-role) |
| `vault_jwt_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`jwt-auth-backend`](#rule-jwt-auth-backend) |
| `vault_kerberos_auth_backend_config` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`kerberos-auth-backend-config`](#rule-kerberos-auth-backend-config) |
| `vault_kerberos_auth_backend_group` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`kerberos-auth-backend-group`](#rule-kerberos-auth-backend-group) |
| `vault_kerberos_auth_backend_ldap_config` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`kerberos-auth-backend-ldap-config`](#rule-kerberos-auth-backend-ldap-config) |
| `vault_keymgmt_aws_kms` | `resource` | [`key-management-integration`](#vault-concept-key-management-integration) | [`keymgmt-aws-kms`](#rule-keymgmt-aws-kms) |
| `vault_keymgmt_azure_kms` | `resource` | [`key-management-integration`](#vault-concept-key-management-integration) | [`keymgmt-azure-kms`](#rule-keymgmt-azure-kms) |
| `vault_keymgmt_distribute_key` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`keymgmt-distribute-key`](#rule-keymgmt-distribute-key) |
| `vault_keymgmt_gcp_kms` | `resource` | [`key-management-integration`](#vault-concept-key-management-integration) | [`keymgmt-gcp-kms`](#rule-keymgmt-gcp-kms) |
| `vault_keymgmt_key` | `resource` | [`encryption-key`](#vault-concept-encryption-key) | [`keymgmt-key`](#rule-keymgmt-key) |
| `vault_keymgmt_replicate_key` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`keymgmt-replicate-key`](#rule-keymgmt-replicate-key) |
| `vault_kmip_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`kmip-secret-backend`](#rule-kmip-secret-backend) |
| `vault_kmip_secret_ca_generated` | `resource` | [`certificate-authority`](#vault-concept-certificate-authority) | [`kmip-secret-ca-generated`](#rule-kmip-secret-ca-generated) |
| `vault_kmip_secret_ca_imported` | `resource` | [`certificate-authority`](#vault-concept-certificate-authority) | [`kmip-secret-ca-imported`](#rule-kmip-secret-ca-imported) |
| `vault_kmip_secret_listener` | `resource` | [`kmip-listener`](#vault-concept-kmip-listener) | [`kmip-secret-listener`](#rule-kmip-secret-listener) |
| `vault_kmip_secret_role` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`kmip-secret-role`](#rule-kmip-secret-role) |
| `vault_kmip_secret_scope` | `resource` | [`kmip-scope`](#vault-concept-kmip-scope) | [`kmip-secret-scope`](#rule-kmip-secret-scope) |
| `vault_kubernetes_auth_backend_config` | `resource` | [`kubernetes-auth-integration`](#vault-concept-kubernetes-auth-integration) | [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config) |
| `vault_kubernetes_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`kubernetes-auth-backend-role`](#rule-kubernetes-auth-backend-role) |
| `vault_kubernetes_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`kubernetes-secret-backend-role`](#rule-kubernetes-secret-backend-role) |
| `vault_kubernetes_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`kubernetes-secret-backend`](#rule-kubernetes-secret-backend) |
| `vault_kv_secret_backend_v2` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`kv-secret-backend-v2`](#rule-kv-secret-backend-v2) |
| `vault_kv_secret_v2` | `data` | [`secret-read`](#vault-concept-secret-read) | [`kv-secret-v2-read`](#rule-kv-secret-v2-read) |
| `vault_kv_secret_v2` | `resource` | [`secret-definition`](#vault-concept-secret-definition) | [`kv-secret-v2`](#rule-kv-secret-v2) |
| `vault_kv_secret` | `data` | [`secret-read`](#vault-concept-secret-read) | [`kv-secret-read`](#rule-kv-secret-read) |
| `vault_kv_secret` | `resource` | [`secret-definition`](#vault-concept-secret-definition) | [`kv-secret`](#rule-kv-secret) |
| `vault_ldap_auth_backend_group` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`ldap-auth-backend-group`](#rule-ldap-auth-backend-group) |
| `vault_ldap_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`ldap-auth-backend`](#rule-ldap-auth-backend) |
| `vault_ldap_secret_backend_dynamic_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ldap-secret-backend-dynamic-role`](#rule-ldap-secret-backend-dynamic-role) |
| `vault_ldap_secret_backend_library_set` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ldap-secret-backend-library-set`](#rule-ldap-secret-backend-library-set) |
| `vault_ldap_secret_backend_static_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ldap-secret-backend-static-role`](#rule-ldap-secret-backend-static-role) |
| `vault_ldap_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`ldap-secret-backend`](#rule-ldap-secret-backend) |
| `vault_managed_keys` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`managed-keys`](#rule-managed-keys) |
| `vault_mfa_duo` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`mfa-duo`](#rule-mfa-duo) |
| `vault_mfa_okta` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`mfa-okta`](#rule-mfa-okta) |
| `vault_mfa_pingid` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`mfa-pingid`](#rule-mfa-pingid) |
| `vault_mfa_totp` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`mfa-totp`](#rule-mfa-totp) |
| `vault_mongodbatlas_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`mongodbatlas-secret-backend`](#rule-mongodbatlas-secret-backend) |
| `vault_mongodbatlas_secret_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`mongodbatlas-secret-role`](#rule-mongodbatlas-secret-role) |
| `vault_mount` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`mount`](#rule-mount) |
| `vault_namespace` | `resource` | [`namespace`](#vault-concept-namespace) | [`namespace`](#rule-namespace) |
| `vault_nomad_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`nomad-secret-backend`](#rule-nomad-secret-backend) |
| `vault_nomad_secret_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`nomad-secret-role`](#rule-nomad-secret-role) |
| `vault_oauth_resource_server_config_profile` | `resource` | [`identity-configuration`](#vault-concept-identity-configuration) | [`oauth-resource-server-config-profile`](#rule-oauth-resource-server-config-profile) |
| `vault_oci_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`oci-auth-backend-role`](#rule-oci-auth-backend-role) |
| `vault_oci_auth_backend` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`oci-auth-backend`](#rule-oci-auth-backend) |
| `vault_okta_auth_backend_group` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`okta-auth-backend-group`](#rule-okta-auth-backend-group) |
| `vault_okta_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`okta-auth-backend`](#rule-okta-auth-backend) |
| `vault_os_secret_backend_account` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`os-secret-backend-account`](#rule-os-secret-backend-account) |
| `vault_os_secret_backend_host` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`os-secret-backend-host`](#rule-os-secret-backend-host) |
| `vault_os_secret_backend` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`os-secret-backend`](#rule-os-secret-backend) |
| `vault_password_policy` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`password-policy`](#rule-password-policy) |
| `vault_pki_external_ca_secret_backend_role` | `resource` | [`external-ca-integration`](#vault-concept-external-ca-integration) | [`pki-external-ca-secret-backend-role`](#rule-pki-external-ca-secret-backend-role) |
| `vault_pki_secret_backend_config_acme` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-acme`](#rule-pki-secret-backend-config-acme) |
| `vault_pki_secret_backend_config_auto_tidy` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-auto-tidy`](#rule-pki-secret-backend-config-auto-tidy) |
| `vault_pki_secret_backend_config_cluster` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-cluster`](#rule-pki-secret-backend-config-cluster) |
| `vault_pki_secret_backend_config_cmpv2` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-cmpv2`](#rule-pki-secret-backend-config-cmpv2) |
| `vault_pki_secret_backend_config_est` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-est`](#rule-pki-secret-backend-config-est) |
| `vault_pki_secret_backend_config_issuers` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-issuers`](#rule-pki-secret-backend-config-issuers) |
| `vault_pki_secret_backend_config_scep` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-scep`](#rule-pki-secret-backend-config-scep) |
| `vault_pki_secret_backend_config_urls` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-config-urls`](#rule-pki-secret-backend-config-urls) |
| `vault_pki_secret_backend_crl_config` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-crl-config`](#rule-pki-secret-backend-crl-config) |
| `vault_pki_secret_backend_intermediate_set_signed` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-intermediate-set-signed`](#rule-pki-secret-backend-intermediate-set-signed) |
| `vault_pki_secret_backend_issuer` | `resource` | [`certificate-authority`](#vault-concept-certificate-authority) | [`pki-secret-backend-issuer`](#rule-pki-secret-backend-issuer) |
| `vault_pki_secret_backend_key` | `resource` | [`encryption-key`](#vault-concept-encryption-key) | [`pki-secret-backend-key`](#rule-pki-secret-backend-key) |
| `vault_pki_secret_backend_role` | `resource` | [`pki-configuration`](#vault-concept-pki-configuration) | [`pki-secret-backend-role`](#rule-pki-secret-backend-role) |
| `vault_pki_secret_backend_root_cert` | `resource` | [`certificate-authority`](#vault-concept-certificate-authority) | [`pki-secret-backend-root-cert`](#rule-pki-secret-backend-root-cert) |
| `vault_plugin_pinned_version` | `resource` | [`plugin-configuration`](#vault-concept-plugin-configuration) | [`plugin-pinned-version`](#rule-plugin-pinned-version) |
| `vault_plugin_runtime` | `resource` | [`plugin-runtime`](#vault-concept-plugin-runtime) | [`plugin-runtime`](#rule-plugin-runtime) |
| `vault_plugin` | `resource` | [`plugin-configuration`](#vault-concept-plugin-configuration) | [`plugin`](#rule-plugin) |
| `vault_policy` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`policy`](#rule-policy) |
| `vault_rabbitmq_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`rabbitmq-secret-backend-role`](#rule-rabbitmq-secret-backend-role) |
| `vault_rabbitmq_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`rabbitmq-secret-backend`](#rule-rabbitmq-secret-backend) |
| `vault_radius_auth_backend` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`radius-auth-backend`](#rule-radius-auth-backend) |
| `vault_raft_autopilot` | `resource` | [`operations-configuration`](#vault-concept-operations-configuration) | [`raft-autopilot`](#rule-raft-autopilot) |
| `vault_raft_snapshot_agent_config` | `resource` | [`backup-plan`](#vault-concept-backup-plan) | [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config) |
| `vault_rgp_policy` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`rgp-policy`](#rule-rgp-policy) |
| `vault_rotation_policy` | `resource` | [`governance-configuration`](#vault-concept-governance-configuration) | [`rotation-policy`](#rule-rotation-policy) |
| `vault_saml_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`saml-auth-backend-role`](#rule-saml-auth-backend-role) |
| `vault_saml_auth_backend` | `resource` | [`auth-method`](#vault-concept-auth-method) | [`saml-auth-backend`](#rule-saml-auth-backend) |
| `vault_scep_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`scep-auth-backend-role`](#rule-scep-auth-backend-role) |
| `vault_secrets_sync_association` | `resource` | [`secret-sync-configuration`](#vault-concept-secret-sync-configuration) | [`secrets-sync-association`](#rule-secrets-sync-association) |
| `vault_secrets_sync_aws_destination` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination) |
| `vault_secrets_sync_azure_destination` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-azure-destination`](#rule-secrets-sync-azure-destination) |
| `vault_secrets_sync_config` | `resource` | [`secret-sync-configuration`](#vault-concept-secret-sync-configuration) | [`secrets-sync-config`](#rule-secrets-sync-config) |
| `vault_secrets_sync_gcp_destination` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination) |
| `vault_secrets_sync_gh_destination` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-gh-destination`](#rule-secrets-sync-gh-destination) |
| `vault_secrets_sync_github_apps` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-github-apps`](#rule-secrets-sync-github-apps) |
| `vault_secrets_sync_vercel_destination` | `resource` | [`secret-sync-destination`](#vault-concept-secret-sync-destination) | [`secrets-sync-vercel-destination`](#rule-secrets-sync-vercel-destination) |
| `vault_spiffe_auth_backend_config` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`spiffe-auth-backend-config`](#rule-spiffe-auth-backend-config) |
| `vault_spiffe_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`spiffe-auth-backend-role`](#rule-spiffe-auth-backend-role) |
| `vault_spiffe_secret_backend_config` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`spiffe-secret-backend-config`](#rule-spiffe-secret-backend-config) |
| `vault_spiffe_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`spiffe-secret-backend-role`](#rule-spiffe-secret-backend-role) |
| `vault_ssh_secret_backend_ca` | `resource` | [`certificate-authority`](#vault-concept-certificate-authority) | [`ssh-secret-backend-ca`](#rule-ssh-secret-backend-ca) |
| `vault_ssh_secret_backend_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`ssh-secret-backend-role`](#rule-ssh-secret-backend-role) |
| `vault_terraform_cloud_secret_backend` | `resource` | [`secrets-engine`](#vault-concept-secrets-engine) | [`terraform-cloud-secret-backend`](#rule-terraform-cloud-secret-backend) |
| `vault_terraform_cloud_secret_role` | `resource` | [`secrets-engine-configuration`](#vault-concept-secrets-engine-configuration) | [`terraform-cloud-secret-role`](#rule-terraform-cloud-secret-role) |
| `vault_token_auth_backend_role` | `resource` | [`auth-configuration`](#vault-concept-auth-configuration) | [`token-auth-backend-role`](#rule-token-auth-backend-role) |
| `vault_transform_alphabet` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`transform-alphabet`](#rule-transform-alphabet) |
| `vault_transform_key_configuration` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`transform-key-configuration`](#rule-transform-key-configuration) |
| `vault_transform_role` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`transform-role`](#rule-transform-role) |
| `vault_transform_template` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`transform-template`](#rule-transform-template) |
| `vault_transform_transformation` | `resource` | [`data-transformation`](#vault-concept-data-transformation) | [`transform-transformation`](#rule-transform-transformation) |
| `vault_transit_secret_backend_key` | `resource` | [`encryption-key`](#vault-concept-encryption-key) | [`transit-secret-backend-key`](#rule-transit-secret-backend-key) |
| `vault_transit_secret_cache_config` | `resource` | [`encryption-configuration`](#vault-concept-encryption-configuration) | [`transit-secret-cache-config`](#rule-transit-secret-cache-config) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="vault-concept-audit-device"><code>vault.concept.audit-device</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Vault audit device receiving security audit records.

</dd>
<dd>

Used by [`audit`](#rule-audit).

</dd>
</div>

<div>
<dt id="vault-concept-auth-configuration"><code>vault.concept.auth-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L1-L3">Source</a></dt>
<dd>

A role, mapping, certificate, or setting supporting a Vault auth method.

</dd>
<dd>


<details>
<summary>Used by 32 Rules</summary>

- [`alicloud-auth-backend-role`](#rule-alicloud-auth-backend-role)
- [`approle-auth-backend-role`](#rule-approle-auth-backend-role)
- [`aws-auth-backend-cert`](#rule-aws-auth-backend-cert)
- [`aws-auth-backend-client`](#rule-aws-auth-backend-client)
- [`aws-auth-backend-config-identity`](#rule-aws-auth-backend-config-identity)
- [`aws-auth-backend-identity-whitelist`](#rule-aws-auth-backend-identity-whitelist)
- [`aws-auth-backend-role`](#rule-aws-auth-backend-role)
- [`aws-auth-backend-role-tag`](#rule-aws-auth-backend-role-tag)
- [`aws-auth-backend-roletag-blacklist`](#rule-aws-auth-backend-roletag-blacklist)
- [`aws-auth-backend-sts-role`](#rule-aws-auth-backend-sts-role)
- [`azure-auth-backend-config`](#rule-azure-auth-backend-config)
- [`azure-auth-backend-role`](#rule-azure-auth-backend-role)
- [`cert-auth-backend-role`](#rule-cert-auth-backend-role)
- [`cf-auth-backend-config`](#rule-cf-auth-backend-config)
- [`cf-auth-backend-role`](#rule-cf-auth-backend-role)
- [`gcp-auth-backend-role`](#rule-gcp-auth-backend-role)
- [`github-team`](#rule-github-team)
- [`jwt-auth-backend-role`](#rule-jwt-auth-backend-role)
- [`kerberos-auth-backend-config`](#rule-kerberos-auth-backend-config)
- [`kerberos-auth-backend-group`](#rule-kerberos-auth-backend-group)
- [`kerberos-auth-backend-ldap-config`](#rule-kerberos-auth-backend-ldap-config)
- [`kubernetes-auth-backend-role`](#rule-kubernetes-auth-backend-role)
- [`ldap-auth-backend-group`](#rule-ldap-auth-backend-group)
- [`oci-auth-backend`](#rule-oci-auth-backend)
- [`oci-auth-backend-role`](#rule-oci-auth-backend-role)
- [`okta-auth-backend-group`](#rule-okta-auth-backend-group)
- [`radius-auth-backend`](#rule-radius-auth-backend)
- [`saml-auth-backend-role`](#rule-saml-auth-backend-role)
- [`scep-auth-backend-role`](#rule-scep-auth-backend-role)
- [`spiffe-auth-backend-config`](#rule-spiffe-auth-backend-config)
- [`spiffe-auth-backend-role`](#rule-spiffe-auth-backend-role)
- [`token-auth-backend-role`](#rule-token-auth-backend-role)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-auth-method"><code>vault.concept.auth-method</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L5-L7">Source</a></dt>
<dd>

A mounted Vault auth method verifying a human or machine identity.

</dd>
<dd>


<details>
<summary>Used by 34 Rules</summary>

- [`alicloud-auth-backend-role`](#rule-alicloud-auth-backend-role)
- [`approle-auth-backend-role`](#rule-approle-auth-backend-role)
- [`auth-backend`](#rule-auth-backend)
- [`aws-auth-backend-cert`](#rule-aws-auth-backend-cert)
- [`aws-auth-backend-client`](#rule-aws-auth-backend-client)
- [`aws-auth-backend-role`](#rule-aws-auth-backend-role)
- [`aws-auth-backend-sts-role`](#rule-aws-auth-backend-sts-role)
- [`azure-auth-backend-config`](#rule-azure-auth-backend-config)
- [`azure-auth-backend-role`](#rule-azure-auth-backend-role)
- [`cert-auth-backend-role`](#rule-cert-auth-backend-role)
- [`cf-auth-backend-config`](#rule-cf-auth-backend-config)
- [`cf-auth-backend-role`](#rule-cf-auth-backend-role)
- [`gcp-auth-backend`](#rule-gcp-auth-backend)
- [`gcp-auth-backend-role`](#rule-gcp-auth-backend-role)
- [`github-auth-backend`](#rule-github-auth-backend)
- [`github-team`](#rule-github-team)
- [`jwt-auth-backend`](#rule-jwt-auth-backend)
- [`jwt-auth-backend-role`](#rule-jwt-auth-backend-role)
- [`kerberos-auth-backend-config`](#rule-kerberos-auth-backend-config)
- [`kerberos-auth-backend-group`](#rule-kerberos-auth-backend-group)
- [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config)
- [`kubernetes-auth-backend-role`](#rule-kubernetes-auth-backend-role)
- [`ldap-auth-backend`](#rule-ldap-auth-backend)
- [`ldap-auth-backend-group`](#rule-ldap-auth-backend-group)
- [`oci-auth-backend`](#rule-oci-auth-backend)
- [`oci-auth-backend-role`](#rule-oci-auth-backend-role)
- [`okta-auth-backend`](#rule-okta-auth-backend)
- [`okta-auth-backend-group`](#rule-okta-auth-backend-group)
- [`radius-auth-backend`](#rule-radius-auth-backend)
- [`saml-auth-backend`](#rule-saml-auth-backend)
- [`saml-auth-backend-role`](#rule-saml-auth-backend-role)
- [`scep-auth-backend-role`](#rule-scep-auth-backend-role)
- [`spiffe-auth-backend-config`](#rule-spiffe-auth-backend-config)
- [`spiffe-auth-backend-role`](#rule-spiffe-auth-backend-role)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-backup-plan"><code>vault.concept.backup-plan</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed policy scheduling and retaining backups.

</dd>
<dd>

Used by [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config).

</dd>
</div>

<div>
<dt id="vault-concept-certificate-authority"><code>vault.concept.certificate-authority</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Vault-managed or integrated certificate authority and issuer boundary.

</dd>
<dd>


<details>
<summary>Used by 5 Rules</summary>

- [`kmip-secret-ca-generated`](#rule-kmip-secret-ca-generated)
- [`kmip-secret-ca-imported`](#rule-kmip-secret-ca-imported)
- [`pki-secret-backend-issuer`](#rule-pki-secret-backend-issuer)
- [`pki-secret-backend-root-cert`](#rule-pki-secret-backend-root-cert)
- [`ssh-secret-backend-ca`](#rule-ssh-secret-backend-ca)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-data-transformation"><code>vault.concept.data-transformation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L1-L3">Source</a></dt>
<dd>

A durable Vault Transform data-protection transformation.

</dd>
<dd>

Used by [`transform-transformation`](#rule-transform-transformation).

</dd>
</div>

<div>
<dt id="vault-concept-encryption-configuration"><code>vault.concept.encryption-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L5-L7">Source</a></dt>
<dd>

A key distribution, replication, transform, or cache setting supporting Vault encryption.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`keymgmt-distribute-key`](#rule-keymgmt-distribute-key)
- [`keymgmt-replicate-key`](#rule-keymgmt-replicate-key)
- [`managed-keys`](#rule-managed-keys)
- [`transform-alphabet`](#rule-transform-alphabet)
- [`transform-key-configuration`](#rule-transform-key-configuration)
- [`transform-role`](#rule-transform-role)
- [`transform-template`](#rule-transform-template)
- [`transit-secret-cache-config`](#rule-transit-secret-cache-config)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-encryption-key"><code>vault.concept.encryption-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/vocabulary.rf.hcl#L5-L7">Source</a></dt>
<dd>

A managed key used for cryptographic operations.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`gcpkms-secret-backend-key`](#rule-gcpkms-secret-backend-key)
- [`identity-oidc-key`](#rule-identity-oidc-key)
- [`keymgmt-key`](#rule-keymgmt-key)
- [`pki-secret-backend-key`](#rule-pki-secret-backend-key)
- [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config)
- [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination)
- [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination)
- [`transit-secret-backend-key`](#rule-transit-secret-backend-key)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-external-ca-integration"><code>vault.concept.external-ca-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L5-L7">Source</a></dt>
<dd>

A Vault PKI integration delegating certificate issuance to an external authority.

</dd>
<dd>

Used by [`pki-external-ca-secret-backend-role`](#rule-pki-external-ca-secret-backend-role).

</dd>
</div>

<div>
<dt id="vault-concept-governance-configuration"><code>vault.concept.governance-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L1-L3">Source</a></dt>
<dd>

A policy, quota, or administrative object supporting Vault governance.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`config-control-group`](#rule-config-control-group)
- [`config-group-policy-application`](#rule-config-group-policy-application)
- [`egp-policy`](#rule-egp-policy)
- [`password-policy`](#rule-password-policy)
- [`policy`](#rule-policy)
- [`rgp-policy`](#rule-rgp-policy)
- [`rotation-policy`](#rule-rotation-policy)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-identity-application"><code>vault.concept.identity-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/vocabulary.rf.hcl#L9-L11">Source</a></dt>
<dd>

An application or relying-party client registered with an identity platform.

</dd>
<dd>

Used by [`identity-oidc-client`](#rule-identity-oidc-client).

</dd>
</div>

<div>
<dt id="vault-concept-identity-configuration"><code>vault.concept.identity-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L1-L3">Source</a></dt>
<dd>

An alias, membership, assignment, MFA, scope, or role supporting Vault identity.

</dd>
<dd>


<details>
<summary>Used by 21 Rules</summary>

- [`identity-entity-alias`](#rule-identity-entity-alias)
- [`identity-entity-policies`](#rule-identity-entity-policies)
- [`identity-group-alias`](#rule-identity-group-alias)
- [`identity-group-member-entity-ids`](#rule-identity-group-member-entity-ids)
- [`identity-group-member-group-ids`](#rule-identity-group-member-group-ids)
- [`identity-group-policies`](#rule-identity-group-policies)
- [`identity-mfa-duo`](#rule-identity-mfa-duo)
- [`identity-mfa-login-enforcement`](#rule-identity-mfa-login-enforcement)
- [`identity-mfa-okta`](#rule-identity-mfa-okta)
- [`identity-mfa-pingid`](#rule-identity-mfa-pingid)
- [`identity-mfa-totp`](#rule-identity-mfa-totp)
- [`identity-oidc`](#rule-identity-oidc)
- [`identity-oidc-assignment`](#rule-identity-oidc-assignment)
- [`identity-oidc-key-allowed-client-id`](#rule-identity-oidc-key-allowed-client-id)
- [`identity-oidc-role`](#rule-identity-oidc-role)
- [`identity-oidc-scope`](#rule-identity-oidc-scope)
- [`mfa-duo`](#rule-mfa-duo)
- [`mfa-okta`](#rule-mfa-okta)
- [`mfa-pingid`](#rule-mfa-pingid)
- [`mfa-totp`](#rule-mfa-totp)
- [`oauth-resource-server-config-profile`](#rule-oauth-resource-server-config-profile)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-identity-entity"><code>vault.concept.identity-entity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L5-L7">Source</a></dt>
<dd>

A canonical Vault identity joining aliases from one or more auth methods.

</dd>
<dd>

Used by [`identity-entity`](#rule-identity-entity).

</dd>
</div>

<div>
<dt id="vault-concept-identity-group"><code>vault.concept.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/vocabulary.rf.hcl#L13-L15">Source</a></dt>
<dd>

A managed group principal used to assign access collectively.

</dd>
<dd>

Used by [`identity-group`](#rule-identity-group).

</dd>
</div>

<div>
<dt id="vault-concept-key-management-integration"><code>vault.concept.key-management-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L9-L11">Source</a></dt>
<dd>

A Vault Key Management integration distributing keys to an external key service.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`keymgmt-aws-kms`](#rule-keymgmt-aws-kms)
- [`keymgmt-azure-kms`](#rule-keymgmt-azure-kms)
- [`keymgmt-distribute-key`](#rule-keymgmt-distribute-key)
- [`keymgmt-gcp-kms`](#rule-keymgmt-gcp-kms)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-kmip-listener"><code>vault.concept.kmip-listener</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L9-L11">Source</a></dt>
<dd>

A Vault KMIP protocol listener serving key-management clients.

</dd>
<dd>

Used by [`kmip-secret-listener`](#rule-kmip-secret-listener).

</dd>
</div>

<div>
<dt id="vault-concept-kmip-scope"><code>vault.concept.kmip-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L13-L15">Source</a></dt>
<dd>

An isolated Vault KMIP tenancy scope containing roles and managed objects.

</dd>
<dd>

Used by [`kmip-secret-scope`](#rule-kmip-secret-scope).

</dd>
</div>

<div>
<dt id="vault-concept-kubernetes-auth-integration"><code>vault.concept.kubernetes-auth-integration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L9-L11">Source</a></dt>
<dd>

A Vault Kubernetes authentication integration connecting a mounted auth method to a Kubernetes cluster.

</dd>
<dd>

Used by [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config).

</dd>
</div>

<div>
<dt id="vault-concept-namespace"><code>vault.concept.namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L5-L7">Source</a></dt>
<dd>

An isolated Vault tenancy boundary for secrets, auth methods, identities, and policies.

</dd>
<dd>


<details>
<summary>Used by 56 Rules</summary>

- [`ad-secret-backend`](#rule-ad-secret-backend)
- [`agent-registration`](#rule-agent-registration)
- [`alicloud-secret-backend`](#rule-alicloud-secret-backend)
- [`audit`](#rule-audit)
- [`auth-backend`](#rule-auth-backend)
- [`aws-secret-backend`](#rule-aws-secret-backend)
- [`azure-secret-backend`](#rule-azure-secret-backend)
- [`consul-secret-backend`](#rule-consul-secret-backend)
- [`database-secrets-mount`](#rule-database-secrets-mount)
- [`gcp-auth-backend`](#rule-gcp-auth-backend)
- [`gcp-secret-backend`](#rule-gcp-secret-backend)
- [`gcpkms-secret-backend`](#rule-gcpkms-secret-backend)
- [`gcpkms-secret-backend-key`](#rule-gcpkms-secret-backend-key)
- [`github-auth-backend`](#rule-github-auth-backend)
- [`identity-entity`](#rule-identity-entity)
- [`identity-group`](#rule-identity-group)
- [`identity-oidc-client`](#rule-identity-oidc-client)
- [`identity-oidc-key`](#rule-identity-oidc-key)
- [`identity-oidc-provider`](#rule-identity-oidc-provider)
- [`jwt-auth-backend`](#rule-jwt-auth-backend)
- [`keymgmt-aws-kms`](#rule-keymgmt-aws-kms)
- [`keymgmt-azure-kms`](#rule-keymgmt-azure-kms)
- [`keymgmt-gcp-kms`](#rule-keymgmt-gcp-kms)
- [`keymgmt-key`](#rule-keymgmt-key)
- [`kmip-secret-backend`](#rule-kmip-secret-backend)
- [`kmip-secret-ca-generated`](#rule-kmip-secret-ca-generated)
- [`kmip-secret-ca-imported`](#rule-kmip-secret-ca-imported)
- [`kmip-secret-listener`](#rule-kmip-secret-listener)
- [`kmip-secret-scope`](#rule-kmip-secret-scope)
- [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config)
- [`kubernetes-secret-backend`](#rule-kubernetes-secret-backend)
- [`ldap-auth-backend`](#rule-ldap-auth-backend)
- [`ldap-secret-backend`](#rule-ldap-secret-backend)
- [`mongodbatlas-secret-backend`](#rule-mongodbatlas-secret-backend)
- [`mount`](#rule-mount)
- [`namespace`](#rule-namespace)
- [`nomad-secret-backend`](#rule-nomad-secret-backend)
- [`okta-auth-backend`](#rule-okta-auth-backend)
- [`pki-external-ca-secret-backend-role`](#rule-pki-external-ca-secret-backend-role)
- [`pki-secret-backend-issuer`](#rule-pki-secret-backend-issuer)
- [`pki-secret-backend-key`](#rule-pki-secret-backend-key)
- [`pki-secret-backend-root-cert`](#rule-pki-secret-backend-root-cert)
- [`plugin-runtime`](#rule-plugin-runtime)
- [`rabbitmq-secret-backend`](#rule-rabbitmq-secret-backend)
- [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config)
- [`saml-auth-backend`](#rule-saml-auth-backend)
- [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination)
- [`secrets-sync-azure-destination`](#rule-secrets-sync-azure-destination)
- [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination)
- [`secrets-sync-gh-destination`](#rule-secrets-sync-gh-destination)
- [`secrets-sync-github-apps`](#rule-secrets-sync-github-apps)
- [`secrets-sync-vercel-destination`](#rule-secrets-sync-vercel-destination)
- [`ssh-secret-backend-ca`](#rule-ssh-secret-backend-ca)
- [`terraform-cloud-secret-backend`](#rule-terraform-cloud-secret-backend)
- [`transform-transformation`](#rule-transform-transformation)
- [`transit-secret-backend-key`](#rule-transit-secret-backend-key)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-oidc-provider"><code>vault.concept.oidc-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L9-L11">Source</a></dt>
<dd>

A Vault OpenID Connect identity provider boundary.

</dd>
<dd>

Used by [`identity-oidc-provider`](#rule-identity-oidc-provider).

</dd>
</div>

<div>
<dt id="vault-concept-operations-configuration"><code>vault.concept.operations-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L5-L7">Source</a></dt>
<dd>

An audit, Raft, or continuity setting supporting Vault operations.

</dd>
<dd>

Used by [`audit-request-header`](#rule-audit-request-header), [`raft-autopilot`](#rule-raft-autopilot).

</dd>
</div>

<div>
<dt id="vault-concept-pki-configuration"><code>vault.concept.pki-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L17-L19">Source</a></dt>
<dd>

A role, protocol, revocation, issuer, or lifecycle setting supporting Vault PKI or KMIP.

</dd>
<dd>


<details>
<summary>Used by 12 Rules</summary>

- [`kmip-secret-role`](#rule-kmip-secret-role)
- [`pki-secret-backend-config-acme`](#rule-pki-secret-backend-config-acme)
- [`pki-secret-backend-config-auto-tidy`](#rule-pki-secret-backend-config-auto-tidy)
- [`pki-secret-backend-config-cluster`](#rule-pki-secret-backend-config-cluster)
- [`pki-secret-backend-config-cmpv2`](#rule-pki-secret-backend-config-cmpv2)
- [`pki-secret-backend-config-est`](#rule-pki-secret-backend-config-est)
- [`pki-secret-backend-config-issuers`](#rule-pki-secret-backend-config-issuers)
- [`pki-secret-backend-config-scep`](#rule-pki-secret-backend-config-scep)
- [`pki-secret-backend-config-urls`](#rule-pki-secret-backend-config-urls)
- [`pki-secret-backend-crl-config`](#rule-pki-secret-backend-crl-config)
- [`pki-secret-backend-intermediate-set-signed`](#rule-pki-secret-backend-intermediate-set-signed)
- [`pki-secret-backend-role`](#rule-pki-secret-backend-role)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-plugin-configuration"><code>vault.concept.plugin-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/system/plugins.rf.hcl#L1-L3">Source</a></dt>
<dd>

A plugin registration or version setting supporting a Vault plugin runtime.

</dd>
<dd>

Used by [`plugin`](#rule-plugin), [`plugin-pinned-version`](#rule-plugin-pinned-version).

</dd>
</div>

<div>
<dt id="vault-concept-plugin-runtime"><code>vault.concept.plugin-runtime</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/system/plugins.rf.hcl#L5-L7">Source</a></dt>
<dd>

A runtime boundary executing external Vault plugins.

</dd>
<dd>

Used by [`plugin-runtime`](#rule-plugin-runtime).

</dd>
</div>

<div>
<dt id="vault-concept-secret-definition"><code>vault.concept.secret-definition</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L1-L3">Source</a></dt>
<dd>

A managed Vault secret definition whose values remain outside architecture output.

</dd>
<dd>

Used by [`generic-secret`](#rule-generic-secret), [`kv-secret`](#rule-kv-secret), [`kv-secret-v2`](#rule-kv-secret-v2).

</dd>
</div>

<div>
<dt id="vault-concept-secret-read"><code>vault.concept.secret-read</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L5-L7">Source</a></dt>
<dd>

A read-only lookup of Vault secret material whose values remain outside architecture output.

</dd>
<dd>

Used by [`generic-secret-read`](#rule-generic-secret-read), [`kv-secret-read`](#rule-kv-secret-read), [`kv-secret-v2-read`](#rule-kv-secret-v2-read).

</dd>
</div>

<div>
<dt id="vault-concept-secret-sync-configuration"><code>vault.concept.secret-sync-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L1-L3">Source</a></dt>
<dd>

A destination association or service setting supporting Vault Secrets Sync.

</dd>
<dd>

Used by [`secrets-sync-association`](#rule-secrets-sync-association), [`secrets-sync-config`](#rule-secrets-sync-config).

</dd>
</div>

<div>
<dt id="vault-concept-secret-sync-destination"><code>vault.concept.secret-sync-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L5-L7">Source</a></dt>
<dd>

An external cloud or SaaS destination receiving secrets through Vault Secrets Sync.

</dd>
<dd>


<details>
<summary>Used by 7 Rules</summary>

- [`secrets-sync-association`](#rule-secrets-sync-association)
- [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination)
- [`secrets-sync-azure-destination`](#rule-secrets-sync-azure-destination)
- [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination)
- [`secrets-sync-gh-destination`](#rule-secrets-sync-gh-destination)
- [`secrets-sync-github-apps`](#rule-secrets-sync-github-apps)
- [`secrets-sync-vercel-destination`](#rule-secrets-sync-vercel-destination)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-secrets-engine"><code>vault.concept.secrets-engine</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L9-L11">Source</a></dt>
<dd>

A mounted Vault secrets engine storing, generating, or transforming sensitive data.

</dd>
<dd>


<details>
<summary>Used by 34 Rules</summary>

- [`ad-secret-backend`](#rule-ad-secret-backend)
- [`alicloud-secret-backend`](#rule-alicloud-secret-backend)
- [`aws-secret-backend`](#rule-aws-secret-backend)
- [`azure-secret-backend`](#rule-azure-secret-backend)
- [`consul-secret-backend`](#rule-consul-secret-backend)
- [`database-secret-backend-connection`](#rule-database-secret-backend-connection)
- [`database-secret-backend-role`](#rule-database-secret-backend-role)
- [`database-secret-backend-static-role`](#rule-database-secret-backend-static-role)
- [`database-secrets-mount`](#rule-database-secrets-mount)
- [`gcp-secret-backend`](#rule-gcp-secret-backend)
- [`gcpkms-secret-backend`](#rule-gcpkms-secret-backend)
- [`kmip-secret-backend`](#rule-kmip-secret-backend)
- [`kubernetes-secret-backend`](#rule-kubernetes-secret-backend)
- [`kv-secret-backend-v2`](#rule-kv-secret-backend-v2)
- [`ldap-secret-backend`](#rule-ldap-secret-backend)
- [`mongodbatlas-secret-backend`](#rule-mongodbatlas-secret-backend)
- [`mount`](#rule-mount)
- [`nomad-secret-backend`](#rule-nomad-secret-backend)
- [`os-secret-backend`](#rule-os-secret-backend)
- [`pki-secret-backend-config-acme`](#rule-pki-secret-backend-config-acme)
- [`pki-secret-backend-config-auto-tidy`](#rule-pki-secret-backend-config-auto-tidy)
- [`pki-secret-backend-config-cluster`](#rule-pki-secret-backend-config-cluster)
- [`pki-secret-backend-config-cmpv2`](#rule-pki-secret-backend-config-cmpv2)
- [`pki-secret-backend-config-est`](#rule-pki-secret-backend-config-est)
- [`pki-secret-backend-config-issuers`](#rule-pki-secret-backend-config-issuers)
- [`pki-secret-backend-config-scep`](#rule-pki-secret-backend-config-scep)
- [`pki-secret-backend-config-urls`](#rule-pki-secret-backend-config-urls)
- [`pki-secret-backend-crl-config`](#rule-pki-secret-backend-crl-config)
- [`pki-secret-backend-intermediate-set-signed`](#rule-pki-secret-backend-intermediate-set-signed)
- [`pki-secret-backend-role`](#rule-pki-secret-backend-role)
- [`rabbitmq-secret-backend`](#rule-rabbitmq-secret-backend)
- [`spiffe-secret-backend-config`](#rule-spiffe-secret-backend-config)
- [`terraform-cloud-secret-backend`](#rule-terraform-cloud-secret-backend)
- [`transit-secret-cache-config`](#rule-transit-secret-cache-config)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-secrets-engine-configuration"><code>vault.concept.secrets-engine-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L13-L15">Source</a></dt>
<dd>

A connection, role, library, account, or setting supporting a Vault secrets engine.

</dd>
<dd>


<details>
<summary>Used by 29 Rules</summary>

- [`ad-secret-library`](#rule-ad-secret-library)
- [`ad-secret-role`](#rule-ad-secret-role)
- [`alicloud-secret-backend-role`](#rule-alicloud-secret-backend-role)
- [`aws-secret-backend-role`](#rule-aws-secret-backend-role)
- [`aws-secret-backend-static-role`](#rule-aws-secret-backend-static-role)
- [`azure-secret-backend-role`](#rule-azure-secret-backend-role)
- [`azure-secret-backend-static-role`](#rule-azure-secret-backend-static-role)
- [`consul-secret-backend-role`](#rule-consul-secret-backend-role)
- [`database-secret-backend-connection`](#rule-database-secret-backend-connection)
- [`database-secret-backend-role`](#rule-database-secret-backend-role)
- [`database-secret-backend-static-role`](#rule-database-secret-backend-static-role)
- [`gcp-secret-impersonated-account`](#rule-gcp-secret-impersonated-account)
- [`gcp-secret-roleset`](#rule-gcp-secret-roleset)
- [`gcp-secret-static-account`](#rule-gcp-secret-static-account)
- [`kubernetes-secret-backend-role`](#rule-kubernetes-secret-backend-role)
- [`kv-secret-backend-v2`](#rule-kv-secret-backend-v2)
- [`ldap-secret-backend-dynamic-role`](#rule-ldap-secret-backend-dynamic-role)
- [`ldap-secret-backend-library-set`](#rule-ldap-secret-backend-library-set)
- [`ldap-secret-backend-static-role`](#rule-ldap-secret-backend-static-role)
- [`mongodbatlas-secret-role`](#rule-mongodbatlas-secret-role)
- [`nomad-secret-role`](#rule-nomad-secret-role)
- [`os-secret-backend`](#rule-os-secret-backend)
- [`os-secret-backend-account`](#rule-os-secret-backend-account)
- [`os-secret-backend-host`](#rule-os-secret-backend-host)
- [`rabbitmq-secret-backend-role`](#rule-rabbitmq-secret-backend-role)
- [`spiffe-secret-backend-config`](#rule-spiffe-secret-backend-config)
- [`spiffe-secret-backend-role`](#rule-spiffe-secret-backend-role)
- [`ssh-secret-backend-role`](#rule-ssh-secret-backend-role)
- [`terraform-cloud-secret-role`](#rule-terraform-cloud-secret-role)

</details>

</dd>
</div>

<div>
<dt id="vault-concept-vault-agent"><code>vault.concept.vault-agent</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L9-L11">Source</a></dt>
<dd>

A registered Vault Agent workload identity boundary.

</dd>
<dd>

Used by [`agent-registration`](#rule-agent-registration).

</dd>
</div>

</dl>

### Contexts

<dl>

<div>
<dt id="vault-context-ownership"><code>vault.context.ownership</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/vocabulary.rf.hcl#L17-L19">Source</a></dt>
<dd>

Administrative or lifecycle ownership.

</dd>
<dd>


<details>
<summary>Used by 56 Rules</summary>

- [`ad-secret-backend`](#rule-ad-secret-backend)
- [`agent-registration`](#rule-agent-registration)
- [`alicloud-secret-backend`](#rule-alicloud-secret-backend)
- [`audit`](#rule-audit)
- [`auth-backend`](#rule-auth-backend)
- [`aws-secret-backend`](#rule-aws-secret-backend)
- [`azure-secret-backend`](#rule-azure-secret-backend)
- [`consul-secret-backend`](#rule-consul-secret-backend)
- [`database-secrets-mount`](#rule-database-secrets-mount)
- [`gcp-auth-backend`](#rule-gcp-auth-backend)
- [`gcp-secret-backend`](#rule-gcp-secret-backend)
- [`gcpkms-secret-backend`](#rule-gcpkms-secret-backend)
- [`gcpkms-secret-backend-key`](#rule-gcpkms-secret-backend-key)
- [`github-auth-backend`](#rule-github-auth-backend)
- [`identity-entity`](#rule-identity-entity)
- [`identity-group`](#rule-identity-group)
- [`identity-oidc-client`](#rule-identity-oidc-client)
- [`identity-oidc-key`](#rule-identity-oidc-key)
- [`identity-oidc-provider`](#rule-identity-oidc-provider)
- [`jwt-auth-backend`](#rule-jwt-auth-backend)
- [`keymgmt-aws-kms`](#rule-keymgmt-aws-kms)
- [`keymgmt-azure-kms`](#rule-keymgmt-azure-kms)
- [`keymgmt-gcp-kms`](#rule-keymgmt-gcp-kms)
- [`keymgmt-key`](#rule-keymgmt-key)
- [`kmip-secret-backend`](#rule-kmip-secret-backend)
- [`kmip-secret-ca-generated`](#rule-kmip-secret-ca-generated)
- [`kmip-secret-ca-imported`](#rule-kmip-secret-ca-imported)
- [`kmip-secret-listener`](#rule-kmip-secret-listener)
- [`kmip-secret-scope`](#rule-kmip-secret-scope)
- [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config)
- [`kubernetes-secret-backend`](#rule-kubernetes-secret-backend)
- [`ldap-auth-backend`](#rule-ldap-auth-backend)
- [`ldap-secret-backend`](#rule-ldap-secret-backend)
- [`mongodbatlas-secret-backend`](#rule-mongodbatlas-secret-backend)
- [`mount`](#rule-mount)
- [`namespace`](#rule-namespace)
- [`nomad-secret-backend`](#rule-nomad-secret-backend)
- [`okta-auth-backend`](#rule-okta-auth-backend)
- [`pki-external-ca-secret-backend-role`](#rule-pki-external-ca-secret-backend-role)
- [`pki-secret-backend-issuer`](#rule-pki-secret-backend-issuer)
- [`pki-secret-backend-key`](#rule-pki-secret-backend-key)
- [`pki-secret-backend-root-cert`](#rule-pki-secret-backend-root-cert)
- [`plugin-runtime`](#rule-plugin-runtime)
- [`rabbitmq-secret-backend`](#rule-rabbitmq-secret-backend)
- [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config)
- [`saml-auth-backend`](#rule-saml-auth-backend)
- [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination)
- [`secrets-sync-azure-destination`](#rule-secrets-sync-azure-destination)
- [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination)
- [`secrets-sync-gh-destination`](#rule-secrets-sync-gh-destination)
- [`secrets-sync-github-apps`](#rule-secrets-sync-github-apps)
- [`secrets-sync-vercel-destination`](#rule-secrets-sync-vercel-destination)
- [`ssh-secret-backend-ca`](#rule-ssh-secret-backend-ca)
- [`terraform-cloud-secret-backend`](#rule-terraform-cloud-secret-backend)
- [`transform-transformation`](#rule-transform-transformation)
- [`transit-secret-backend-key`](#rule-transit-secret-backend-key)

</details>

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="vault-relation-authenticates-kubernetes-cluster"><code>vault.relation.authenticates-kubernetes-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L535-L540">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config).

</dd>
</div>

<div>
<dt id="vault-relation-configures-auth-method"><code>vault.relation.configures-auth-method</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L542-L552">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`kubernetes-auth-backend-config`](#rule-kubernetes-auth-backend-config).

</dd>
</div>

<div>
<dt id="vault-relation-issues-kubernetes-credentials-for"><code>vault.relation.issues-kubernetes-credentials-for</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L519-L524">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`kubernetes-secret-backend`](#rule-kubernetes-secret-backend).

</dd>
</div>

<div>
<dt id="vault-relation-stores-snapshots-in"><code>vault.relation.stores-snapshots-in</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L100-L105">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config).

</dd>
</div>

<div>
<dt id="vault-relation-uses-cloud-identity"><code>vault.relation.uses-cloud-identity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L330-L335">Source</a></dt>
<dd>

Introduced by a labeled emission.

<details>
<summary>Used by 4 Rules</summary>

- [`gcp-auth-backend`](#rule-gcp-auth-backend)
- [`gcp-secret-backend`](#rule-gcp-secret-backend)
- [`secrets-sync-azure-destination`](#rule-secrets-sync-azure-destination)
- [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination)

</details>

</dd>
</div>

<div>
<dt id="vault-relation-uses-encryption-key"><code>vault.relation.uses-encryption-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L121-L134">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`raft-snapshot-agent-config`](#rule-raft-snapshot-agent-config), [`secrets-sync-aws-destination`](#rule-secrets-sync-aws-destination), [`secrets-sync-gcp-destination`](#rule-secrets-sync-gcp-destination).

</dd>
</div>

<div>
<dt id="vault-relation-uses-signing-key"><code>vault.relation.uses-signing-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L188-L201">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`identity-oidc-client`](#rule-identity-oidc-client).

</dd>
</div>

</dl>

## RF Vocabulary used

- [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster)
- [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container)
- [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity)

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>vault.rule.ad-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L17-L48">Source</a></summary>

<div id="rule-ad-secret-backend"></div>

Matches `resource` instances of `vault_ad_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["backend"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "backend"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.ad-secret-library</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L50-L56">Source</a></summary>

<div id="rule-ad-secret-library"></div>

Matches `resource` instances of `vault_ad_secret_library`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.ad-secret-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L58-L64">Source</a></summary>

<div id="rule-ad-secret-role"></div>

Matches `resource` instances of `vault_ad_secret_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.agent-registration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L13-L35">Source</a></summary>

<div id="rule-agent-registration"></div>

Matches `resource` instances of `vault_agent_registration`.

**Classification:** [`vault.concept.vault-agent`](#vault-concept-vault-agent).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.alicloud-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L13-L31">Source</a></summary>

<div id="rule-alicloud-auth-backend-role"></div>

Matches `resource` instances of `vault_alicloud_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.alicloud-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L99-L105">Source</a></summary>

<div id="rule-alicloud-secret-backend-role"></div>

Matches `resource` instances of `vault_alicloud_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.alicloud-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L66-L97">Source</a></summary>

<div id="rule-alicloud-secret-backend"></div>

Matches `resource` instances of `vault_alicloud_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["mount"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["mount"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.approle-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L33-L51">Source</a></summary>

<div id="rule-approle-auth-backend-role"></div>

Matches `resource` instances of `vault_approle_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.audit-request-header</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L61-L67">Source</a></summary>

<div id="rule-audit-request-header"></div>

Matches `resource` instances of `vault_audit_request_header`.

**Classification:** [`vault.concept.operations-configuration`](#vault-concept-operations-configuration).

</details>

<details>
<summary><code>vault.rule.audit</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L37-L59">Source</a></summary>

<div id="rule-audit"></div>

Matches `resource` instances of `vault_audit`.

**Classification:** [`vault.concept.audit-device`](#vault-concept-audit-device).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L53-L84">Source</a></summary>

<div id="rule-auth-backend"></div>

Matches `resource` instances of `vault_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-cert</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L86-L104">Source</a></summary>

<div id="rule-aws-auth-backend-cert"></div>

Matches `resource` instances of `vault_aws_auth_backend_cert`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L106-L124">Source</a></summary>

<div id="rule-aws-auth-backend-client"></div>

Matches `resource` instances of `vault_aws_auth_backend_client`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-config-identity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L126-L132">Source</a></summary>

<div id="rule-aws-auth-backend-config-identity"></div>

Matches `resource` instances of `vault_aws_auth_backend_config_identity`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-identity-whitelist</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L134-L140">Source</a></summary>

<div id="rule-aws-auth-backend-identity-whitelist"></div>

Matches `resource` instances of `vault_aws_auth_backend_identity_whitelist`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-role-tag</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L162-L168">Source</a></summary>

<div id="rule-aws-auth-backend-role-tag"></div>

Matches `resource` instances of `vault_aws_auth_backend_role_tag`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L142-L160">Source</a></summary>

<div id="rule-aws-auth-backend-role"></div>

Matches `resource` instances of `vault_aws_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-roletag-blacklist</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L170-L176">Source</a></summary>

<div id="rule-aws-auth-backend-roletag-blacklist"></div>

Matches `resource` instances of `vault_aws_auth_backend_roletag_blacklist`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.aws-auth-backend-sts-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L178-L196">Source</a></summary>

<div id="rule-aws-auth-backend-sts-role"></div>

Matches `resource` instances of `vault_aws_auth_backend_sts_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.aws-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L141-L147">Source</a></summary>

<div id="rule-aws-secret-backend-role"></div>

Matches `resource` instances of `vault_aws_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.aws-secret-backend-static-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L149-L155">Source</a></summary>

<div id="rule-aws-secret-backend-static-role"></div>

Matches `resource` instances of `vault_aws_secret_backend_static_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.aws-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L107-L139">Source</a></summary>

<div id="rule-aws-secret-backend"></div>

Matches `resource` instances of `vault_aws_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.azure-auth-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L198-L216">Source</a></summary>

<div id="rule-azure-auth-backend-config"></div>

Matches `resource` instances of `vault_azure_auth_backend_config`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.azure-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L218-L236">Source</a></summary>

<div id="rule-azure-auth-backend-role"></div>

Matches `resource` instances of `vault_azure_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.azure-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L190-L196">Source</a></summary>

<div id="rule-azure-secret-backend-role"></div>

Matches `resource` instances of `vault_azure_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.azure-secret-backend-static-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L198-L204">Source</a></summary>

<div id="rule-azure-secret-backend-static-role"></div>

Matches `resource` instances of `vault_azure_secret_backend_static_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.azure-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L157-L188">Source</a></summary>

<div id="rule-azure-secret-backend"></div>

Matches `resource` instances of `vault_azure_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.cert-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L238-L256">Source</a></summary>

<div id="rule-cert-auth-backend-role"></div>

Matches `resource` instances of `vault_cert_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.cf-auth-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L258-L276">Source</a></summary>

<div id="rule-cf-auth-backend-config"></div>

Matches `resource` instances of `vault_cf_auth_backend_config`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.cf-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L278-L296">Source</a></summary>

<div id="rule-cf-auth-backend-role"></div>

Matches `resource` instances of `vault_cf_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.config-control-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-config-control-group"></div>

Matches `resource` instances of `vault_config_control_group`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.config-group-policy-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-config-group-policy-application"></div>

Matches `resource` instances of `vault_config_group_policy_application`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.consul-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L239-L245">Source</a></summary>

<div id="rule-consul-secret-backend-role"></div>

Matches `resource` instances of `vault_consul_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.consul-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L206-L237">Source</a></summary>

<div id="rule-consul-secret-backend"></div>

Matches `resource` instances of `vault_consul_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.database-secret-backend-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L247-L265">Source</a></summary>

<div id="rule-database-secret-backend-connection"></div>

Matches `resource` instances of `vault_database_secret_backend_connection`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.database-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L267-L285">Source</a></summary>

<div id="rule-database-secret-backend-role"></div>

Matches `resource` instances of `vault_database_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.database-secret-backend-static-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L287-L305">Source</a></summary>

<div id="rule-database-secret-backend-static-role"></div>

Matches `resource` instances of `vault_database_secret_backend_static_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.database-secrets-mount</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L307-L338">Source</a></summary>

<div id="rule-database-secrets-mount"></div>

Matches `resource` instances of `vault_database_secrets_mount`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.egp-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L25-L31">Source</a></summary>

<div id="rule-egp-policy"></div>

Matches `resource` instances of `vault_egp_policy`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.gcp-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L338-L356">Source</a></summary>

<div id="rule-gcp-auth-backend-role"></div>

Matches `resource` instances of `vault_gcp_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.gcp-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L298-L336">Source</a></summary>

<div id="rule-gcp-auth-backend"></div>

Matches `resource` instances of `vault_gcp_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-cloud-identity`](#vault-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_account_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

</details>

</details>

<details>
<summary><code>vault.rule.gcp-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L340-L378">Source</a></summary>

<div id="rule-gcp-secret-backend"></div>

Matches `resource` instances of `vault_gcp_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-cloud-identity`](#vault-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_account_email`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

</details>

</details>

<details>
<summary><code>vault.rule.gcp-secret-impersonated-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L380-L386">Source</a></summary>

<div id="rule-gcp-secret-impersonated-account"></div>

Matches `resource` instances of `vault_gcp_secret_impersonated_account`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.gcp-secret-roleset</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L388-L394">Source</a></summary>

<div id="rule-gcp-secret-roleset"></div>

Matches `resource` instances of `vault_gcp_secret_roleset`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.gcp-secret-static-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L396-L402">Source</a></summary>

<div id="rule-gcp-secret-static-account"></div>

Matches `resource` instances of `vault_gcp_secret_static_account`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.gcpkms-secret-backend-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L13-L44">Source</a></summary>

<div id="rule-gcpkms-secret-backend-key"></div>

Matches `resource` instances of `vault_gcpkms_secret_backend_key`.

**Classification:** [`vault.concept.encryption-key`](#vault-concept-encryption-key).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["key_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["key_name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.gcpkms-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L404-L435">Source</a></summary>

<div id="rule-gcpkms-secret-backend"></div>

Matches `resource` instances of `vault_gcpkms_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.generic-secret-read</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L445-L452">Source</a></summary>

<div id="rule-generic-secret-read"></div>

Matches `data` instances of `vault_generic_secret`.

**Classification:** [`vault.concept.secret-read`](#vault-concept-secret-read).

</details>

<details>
<summary><code>vault.rule.generic-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L437-L443">Source</a></summary>

<div id="rule-generic-secret"></div>

Matches `resource` instances of `vault_generic_secret`.

**Classification:** [`vault.concept.secret-definition`](#vault-concept-secret-definition).

</details>

<details>
<summary><code>vault.rule.github-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L358-L389">Source</a></summary>

<div id="rule-github-auth-backend"></div>

Matches `resource` instances of `vault_github_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.github-team</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L391-L409">Source</a></summary>

<div id="rule-github-team"></div>

Matches `resource` instances of `vault_github_team`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-entity-alias</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L37-L43">Source</a></summary>

<div id="rule-identity-entity-alias"></div>

Matches `resource` instances of `vault_identity_entity_alias`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-entity-policies</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L45-L51">Source</a></summary>

<div id="rule-identity-entity-policies"></div>

Matches `resource` instances of `vault_identity_entity_policies`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-entity</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L13-L35">Source</a></summary>

<div id="rule-identity-entity"></div>

Matches `resource` instances of `vault_identity_entity`.

**Classification:** [`vault.concept.identity-entity`](#vault-concept-identity-entity).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-group-alias</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L77-L83">Source</a></summary>

<div id="rule-identity-group-alias"></div>

Matches `resource` instances of `vault_identity_group_alias`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-group-member-entity-ids</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L85-L91">Source</a></summary>

<div id="rule-identity-group-member-entity-ids"></div>

Matches `resource` instances of `vault_identity_group_member_entity_ids`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-group-member-group-ids</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L93-L99">Source</a></summary>

<div id="rule-identity-group-member-group-ids"></div>

Matches `resource` instances of `vault_identity_group_member_group_ids`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-group-policies</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L101-L107">Source</a></summary>

<div id="rule-identity-group-policies"></div>

Matches `resource` instances of `vault_identity_group_policies`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L53-L75">Source</a></summary>

<div id="rule-identity-group"></div>

Matches `resource` instances of `vault_identity_group`.

**Classification:** [`vault.concept.identity-group`](#vault-concept-identity-group).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-mfa-duo</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L109-L115">Source</a></summary>

<div id="rule-identity-mfa-duo"></div>

Matches `resource` instances of `vault_identity_mfa_duo`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-mfa-login-enforcement</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L117-L123">Source</a></summary>

<div id="rule-identity-mfa-login-enforcement"></div>

Matches `resource` instances of `vault_identity_mfa_login_enforcement`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-mfa-okta</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L125-L131">Source</a></summary>

<div id="rule-identity-mfa-okta"></div>

Matches `resource` instances of `vault_identity_mfa_okta`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-mfa-pingid</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L133-L139">Source</a></summary>

<div id="rule-identity-mfa-pingid"></div>

Matches `resource` instances of `vault_identity_mfa_pingid`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-mfa-totp</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L141-L147">Source</a></summary>

<div id="rule-identity-mfa-totp"></div>

Matches `resource` instances of `vault_identity_mfa_totp`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-oidc-assignment</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L157-L163">Source</a></summary>

<div id="rule-identity-oidc-assignment"></div>

Matches `resource` instances of `vault_identity_oidc_assignment`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-oidc-client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L165-L202">Source</a></summary>

<div id="rule-identity-oidc-client"></div>

Matches `resource` instances of `vault_identity_oidc_client`.

**Classification:** [`vault.concept.identity-application`](#vault-concept-identity-application).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-signing-key`](#vault-relation-uses-signing-key): targets [`vault.rule.identity-oidc-key`](#rule-identity-oidc-key) through `source.key`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.key`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-oidc-key-allowed-client-id</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L237-L243">Source</a></summary>

<div id="rule-identity-oidc-key-allowed-client-id"></div>

Matches `resource` instances of `vault_identity_oidc_key_allowed_client_id`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-oidc-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L204-L235">Source</a></summary>

<div id="rule-identity-oidc-key"></div>

Matches `resource` instances of `vault_identity_oidc_key`.

**Classification:** [`vault.concept.encryption-key`](#vault-concept-encryption-key).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-oidc-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L245-L267">Source</a></summary>

<div id="rule-identity-oidc-provider"></div>

Matches `resource` instances of `vault_identity_oidc_provider`.

**Classification:** [`vault.concept.oidc-provider`](#vault-concept-oidc-provider).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.identity-oidc-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L269-L275">Source</a></summary>

<div id="rule-identity-oidc-role"></div>

Matches `resource` instances of `vault_identity_oidc_role`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-oidc-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L277-L283">Source</a></summary>

<div id="rule-identity-oidc-scope"></div>

Matches `resource` instances of `vault_identity_oidc_scope`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.identity-oidc</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L149-L155">Source</a></summary>

<div id="rule-identity-oidc"></div>

Matches `resource` instances of `vault_identity_oidc`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.jwt-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L444-L462">Source</a></summary>

<div id="rule-jwt-auth-backend-role"></div>

Matches `resource` instances of `vault_jwt_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.jwt-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L411-L442">Source</a></summary>

<div id="rule-jwt-auth-backend"></div>

Matches `resource` instances of `vault_jwt_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kerberos-auth-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L464-L482">Source</a></summary>

<div id="rule-kerberos-auth-backend-config"></div>

Matches `resource` instances of `vault_kerberos_auth_backend_config`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kerberos-auth-backend-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L484-L502">Source</a></summary>

<div id="rule-kerberos-auth-backend-group"></div>

Matches `resource` instances of `vault_kerberos_auth_backend_group`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kerberos-auth-backend-ldap-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L504-L510">Source</a></summary>

<div id="rule-kerberos-auth-backend-ldap-config"></div>

Matches `resource` instances of `vault_kerberos_auth_backend_ldap_config`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.keymgmt-aws-kms</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L46-L77">Source</a></summary>

<div id="rule-keymgmt-aws-kms"></div>

Matches `resource` instances of `vault_keymgmt_aws_kms`.

**Classification:** [`vault.concept.key-management-integration`](#vault-concept-key-management-integration).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.keymgmt-azure-kms</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L79-L110">Source</a></summary>

<div id="rule-keymgmt-azure-kms"></div>

Matches `resource` instances of `vault_keymgmt_azure_kms`.

**Classification:** [`vault.concept.key-management-integration`](#vault-concept-key-management-integration).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.keymgmt-distribute-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L112-L145">Source</a></summary>

<div id="rule-keymgmt-distribute-key"></div>

Matches `resource` instances of `vault_keymgmt_distribute_key`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

**Contributions**

- targets [`vault.rule.keymgmt-key`](#rule-keymgmt-key) through `source.key_name`.
- targets [`vault.concept.key-management-integration`](#vault-concept-key-management-integration) through `source.kms_name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.key_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

**Contribution through `source.kms_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.keymgmt-gcp-kms</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L147-L178">Source</a></summary>

<div id="rule-keymgmt-gcp-kms"></div>

Matches `resource` instances of `vault_keymgmt_gcp_kms`.

**Classification:** [`vault.concept.key-management-integration`](#vault-concept-key-management-integration).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.keymgmt-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L180-L211">Source</a></summary>

<div id="rule-keymgmt-key"></div>

Matches `resource` instances of `vault_keymgmt_key`.

**Classification:** [`vault.concept.encryption-key`](#vault-concept-encryption-key).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.keymgmt-replicate-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L213-L219">Source</a></summary>

<div id="rule-keymgmt-replicate-key"></div>

Matches `resource` instances of `vault_keymgmt_replicate_key`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.kmip-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L454-L485">Source</a></summary>

<div id="rule-kmip-secret-backend"></div>

Matches `resource` instances of `vault_kmip_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kmip-secret-ca-generated</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L21-L43">Source</a></summary>

<div id="rule-kmip-secret-ca-generated"></div>

Matches `resource` instances of `vault_kmip_secret_ca_generated`.

**Classification:** [`vault.concept.certificate-authority`](#vault-concept-certificate-authority).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kmip-secret-ca-imported</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L45-L67">Source</a></summary>

<div id="rule-kmip-secret-ca-imported"></div>

Matches `resource` instances of `vault_kmip_secret_ca_imported`.

**Classification:** [`vault.concept.certificate-authority`](#vault-concept-certificate-authority).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kmip-secret-listener</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L69-L91">Source</a></summary>

<div id="rule-kmip-secret-listener"></div>

Matches `resource` instances of `vault_kmip_secret_listener`.

**Classification:** [`vault.concept.kmip-listener`](#vault-concept-kmip-listener).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kmip-secret-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L93-L99">Source</a></summary>

<div id="rule-kmip-secret-role"></div>

Matches `resource` instances of `vault_kmip_secret_role`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

</details>

<details>
<summary><code>vault.rule.kmip-secret-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L101-L123">Source</a></summary>

<div id="rule-kmip-secret-scope"></div>

Matches `resource` instances of `vault_kmip_secret_scope`.

**Classification:** [`vault.concept.kmip-scope`](#vault-concept-kmip-scope).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kubernetes-auth-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L512-L553">Source</a></summary>

<div id="rule-kubernetes-auth-backend-config"></div>

Matches `resource` instances of `vault_kubernetes_auth_backend_config`.

**Classification:** [`vault.concept.kubernetes-auth-integration`](#vault-concept-kubernetes-auth-integration).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.authenticates-kubernetes-cluster`](#vault-relation-authenticates-kubernetes-cluster): targets [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) through `source.kubernetes_host`.
- [`vault.relation.configures-auth-method`](#vault-relation-configures-auth-method): targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.kubernetes_host`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

**Relation through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kubernetes-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L555-L573">Source</a></summary>

<div id="rule-kubernetes-auth-backend-role"></div>

Matches `resource` instances of `vault_kubernetes_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kubernetes-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L527-L533">Source</a></summary>

<div id="rule-kubernetes-secret-backend-role"></div>

Matches `resource` instances of `vault_kubernetes_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.kubernetes-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L487-L525">Source</a></summary>

<div id="rule-kubernetes-secret-backend"></div>

Matches `resource` instances of `vault_kubernetes_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.issues-kubernetes-credentials-for`](#vault-relation-issues-kubernetes-credentials-for): targets [`rf.concept.kubernetes-cluster`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-kubernetes-cluster) through `source.kubernetes_host`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.kubernetes_host`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

</details>

</details>

<details>
<summary><code>vault.rule.kv-secret-backend-v2</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L543-L561">Source</a></summary>

<div id="rule-kv-secret-backend-v2"></div>

Matches `resource` instances of `vault_kv_secret_backend_v2`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.kv-secret-v2-read</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L580-L587">Source</a></summary>

<div id="rule-kv-secret-v2-read"></div>

Matches `data` instances of `vault_kv_secret_v2`.

**Classification:** [`vault.concept.secret-read`](#vault-concept-secret-read).

</details>

<details>
<summary><code>vault.rule.kv-secret-v2</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L572-L578">Source</a></summary>

<div id="rule-kv-secret-v2"></div>

Matches `resource` instances of `vault_kv_secret_v2`.

**Classification:** [`vault.concept.secret-definition`](#vault-concept-secret-definition).

</details>

<details>
<summary><code>vault.rule.kv-secret-read</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L563-L570">Source</a></summary>

<div id="rule-kv-secret-read"></div>

Matches `data` instances of `vault_kv_secret`.

**Classification:** [`vault.concept.secret-read`](#vault-concept-secret-read).

</details>

<details>
<summary><code>vault.rule.kv-secret</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L535-L541">Source</a></summary>

<div id="rule-kv-secret"></div>

Matches `resource` instances of `vault_kv_secret`.

**Classification:** [`vault.concept.secret-definition`](#vault-concept-secret-definition).

</details>

<details>
<summary><code>vault.rule.ldap-auth-backend-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L608-L626">Source</a></summary>

<div id="rule-ldap-auth-backend-group"></div>

Matches `resource` instances of `vault_ldap_auth_backend_group`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.ldap-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L575-L606">Source</a></summary>

<div id="rule-ldap-auth-backend"></div>

Matches `resource` instances of `vault_ldap_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.ldap-secret-backend-dynamic-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L622-L628">Source</a></summary>

<div id="rule-ldap-secret-backend-dynamic-role"></div>

Matches `resource` instances of `vault_ldap_secret_backend_dynamic_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.ldap-secret-backend-library-set</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L630-L636">Source</a></summary>

<div id="rule-ldap-secret-backend-library-set"></div>

Matches `resource` instances of `vault_ldap_secret_backend_library_set`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.ldap-secret-backend-static-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L638-L644">Source</a></summary>

<div id="rule-ldap-secret-backend-static-role"></div>

Matches `resource` instances of `vault_ldap_secret_backend_static_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.ldap-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L589-L620">Source</a></summary>

<div id="rule-ldap-secret-backend"></div>

Matches `resource` instances of `vault_ldap_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.managed-keys</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L221-L227">Source</a></summary>

<div id="rule-managed-keys"></div>

Matches `resource` instances of `vault_managed_keys`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.mfa-duo</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L285-L291">Source</a></summary>

<div id="rule-mfa-duo"></div>

Matches `resource` instances of `vault_mfa_duo`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.mfa-okta</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L293-L299">Source</a></summary>

<div id="rule-mfa-okta"></div>

Matches `resource` instances of `vault_mfa_okta`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.mfa-pingid</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L301-L307">Source</a></summary>

<div id="rule-mfa-pingid"></div>

Matches `resource` instances of `vault_mfa_pingid`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.mfa-totp</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L309-L315">Source</a></summary>

<div id="rule-mfa-totp"></div>

Matches `resource` instances of `vault_mfa_totp`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.mongodbatlas-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L646-L677">Source</a></summary>

<div id="rule-mongodbatlas-secret-backend"></div>

Matches `resource` instances of `vault_mongodbatlas_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.mongodbatlas-secret-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L679-L685">Source</a></summary>

<div id="rule-mongodbatlas-secret-role"></div>

Matches `resource` instances of `vault_mongodbatlas_secret_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.mount</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L687-L718">Source</a></summary>

<div id="rule-mount"></div>

Matches `resource` instances of `vault_mount`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.namespace</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L33-L64">Source</a></summary>

<div id="rule-namespace"></div>

Matches `resource` instances of `vault_namespace`.

**Classification:** [`vault.concept.namespace`](#vault-concept-namespace).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.nomad-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L720-L751">Source</a></summary>

<div id="rule-nomad-secret-backend"></div>

Matches `resource` instances of `vault_nomad_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["backend"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "backend"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.nomad-secret-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L753-L759">Source</a></summary>

<div id="rule-nomad-secret-role"></div>

Matches `resource` instances of `vault_nomad_secret_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.oauth-resource-server-config-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/identity/identity-oidc.rf.hcl#L317-L323">Source</a></summary>

<div id="rule-oauth-resource-server-config-profile"></div>

Matches `resource` instances of `vault_oauth_resource_server_config_profile`.

**Classification:** [`vault.concept.identity-configuration`](#vault-concept-identity-configuration).

</details>

<details>
<summary><code>vault.rule.oci-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L648-L666">Source</a></summary>

<div id="rule-oci-auth-backend-role"></div>

Matches `resource` instances of `vault_oci_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.oci-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L628-L646">Source</a></summary>

<div id="rule-oci-auth-backend"></div>

Matches `resource` instances of `vault_oci_auth_backend`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.path`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.path`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.okta-auth-backend-group</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L701-L719">Source</a></summary>

<div id="rule-okta-auth-backend-group"></div>

Matches `resource` instances of `vault_okta_auth_backend_group`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.path`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.path`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.okta-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L668-L699">Source</a></summary>

<div id="rule-okta-auth-backend"></div>

Matches `resource` instances of `vault_okta_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.os-secret-backend-account</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L781-L787">Source</a></summary>

<div id="rule-os-secret-backend-account"></div>

Matches `resource` instances of `vault_os_secret_backend_account`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.os-secret-backend-host</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L789-L795">Source</a></summary>

<div id="rule-os-secret-backend-host"></div>

Matches `resource` instances of `vault_os_secret_backend_host`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.os-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L761-L779">Source</a></summary>

<div id="rule-os-secret-backend"></div>

Matches `resource` instances of `vault_os_secret_backend`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.password-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L66-L72">Source</a></summary>

<div id="rule-password-policy"></div>

Matches `resource` instances of `vault_password_policy`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.pki-external-ca-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L125-L147">Source</a></summary>

<div id="rule-pki-external-ca-secret-backend-role"></div>

Matches `resource` instances of `vault_pki_external_ca_secret_backend_role`.

**Classification:** [`vault.concept.external-ca-integration`](#vault-concept-external-ca-integration).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-acme</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L149-L167">Source</a></summary>

<div id="rule-pki-secret-backend-config-acme"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_acme`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-auto-tidy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L169-L187">Source</a></summary>

<div id="rule-pki-secret-backend-config-auto-tidy"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_auto_tidy`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-cluster</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L189-L207">Source</a></summary>

<div id="rule-pki-secret-backend-config-cluster"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_cluster`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-cmpv2</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L209-L227">Source</a></summary>

<div id="rule-pki-secret-backend-config-cmpv2"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_cmpv2`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-est</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L229-L247">Source</a></summary>

<div id="rule-pki-secret-backend-config-est"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_est`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-issuers</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L249-L267">Source</a></summary>

<div id="rule-pki-secret-backend-config-issuers"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_issuers`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-scep</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L269-L287">Source</a></summary>

<div id="rule-pki-secret-backend-config-scep"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_scep`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-config-urls</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L289-L307">Source</a></summary>

<div id="rule-pki-secret-backend-config-urls"></div>

Matches `resource` instances of `vault_pki_secret_backend_config_urls`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-crl-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L309-L327">Source</a></summary>

<div id="rule-pki-secret-backend-crl-config"></div>

Matches `resource` instances of `vault_pki_secret_backend_crl_config`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-intermediate-set-signed</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L329-L347">Source</a></summary>

<div id="rule-pki-secret-backend-intermediate-set-signed"></div>

Matches `resource` instances of `vault_pki_secret_backend_intermediate_set_signed`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-issuer</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L349-L371">Source</a></summary>

<div id="rule-pki-secret-backend-issuer"></div>

Matches `resource` instances of `vault_pki_secret_backend_issuer`.

**Classification:** [`vault.concept.certificate-authority`](#vault-concept-certificate-authority).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L373-L404">Source</a></summary>

<div id="rule-pki-secret-backend-key"></div>

Matches `resource` instances of `vault_pki_secret_backend_key`.

**Classification:** [`vault.concept.encryption-key`](#vault-concept-encryption-key).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["key_name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "key_id", "key_name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L406-L424">Source</a></summary>

<div id="rule-pki-secret-backend-role"></div>

Matches `resource` instances of `vault_pki_secret_backend_role`.

**Classification:** [`vault.concept.pki-configuration`](#vault-concept-pki-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.pki-secret-backend-root-cert</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L426-L448">Source</a></summary>

<div id="rule-pki-secret-backend-root-cert"></div>

Matches `resource` instances of `vault_pki_secret_backend_root_cert`.

**Classification:** [`vault.concept.certificate-authority`](#vault-concept-certificate-authority).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.plugin-pinned-version</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/system/plugins.rf.hcl#L17-L23">Source</a></summary>

<div id="rule-plugin-pinned-version"></div>

Matches `resource` instances of `vault_plugin_pinned_version`.

**Classification:** [`vault.concept.plugin-configuration`](#vault-concept-plugin-configuration).

</details>

<details>
<summary><code>vault.rule.plugin-runtime</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/system/plugins.rf.hcl#L25-L47">Source</a></summary>

<div id="rule-plugin-runtime"></div>

Matches `resource` instances of `vault_plugin_runtime`.

**Classification:** [`vault.concept.plugin-runtime`](#vault-concept-plugin-runtime).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.plugin</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/system/plugins.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-plugin"></div>

Matches `resource` instances of `vault_plugin`.

**Classification:** [`vault.concept.plugin-configuration`](#vault-concept-plugin-configuration).

</details>

<details>
<summary><code>vault.rule.policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L74-L80">Source</a></summary>

<div id="rule-policy"></div>

Matches `resource` instances of `vault_policy`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.rabbitmq-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L830-L836">Source</a></summary>

<div id="rule-rabbitmq-secret-backend-role"></div>

Matches `resource` instances of `vault_rabbitmq_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.rabbitmq-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L797-L828">Source</a></summary>

<div id="rule-rabbitmq-secret-backend"></div>

Matches `resource` instances of `vault_rabbitmq_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.radius-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L721-L739">Source</a></summary>

<div id="rule-radius-auth-backend"></div>

Matches `resource` instances of `vault_radius_auth_backend`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.raft-autopilot</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L69-L75">Source</a></summary>

<div id="rule-raft-autopilot"></div>

Matches `resource` instances of `vault_raft_autopilot`.

**Classification:** [`vault.concept.operations-configuration`](#vault-concept-operations-configuration).

</details>

<details>
<summary><code>vault.rule.raft-snapshot-agent-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/operations/audit-continuity.rf.hcl#L77-L135">Source</a></summary>

<div id="rule-raft-snapshot-agent-config"></div>

Matches `resource` instances of `vault_raft_snapshot_agent_config`.

**Classification:** [`vault.concept.backup-plan`](#vault-concept-backup-plan).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.stores-snapshots-in`](#vault-relation-stores-snapshots-in): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.aws_s3_bucket`.
- [`vault.relation.stores-snapshots-in`](#vault-relation-stores-snapshots-in): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.azure_container_name`.
- [`vault.relation.stores-snapshots-in`](#vault-relation-stores-snapshots-in): targets [`rf.concept.object-storage-container`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-object-storage-container) through `source.google_gcs_bucket`.
- [`vault.relation.uses-encryption-key`](#vault-relation-uses-encryption-key): targets [`vault.concept.encryption-key`](#vault-concept-encryption-key) through `source.aws_s3_kms_key`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.aws_s3_bucket`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

**Relation through `source.azure_container_name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

**Relation through `source.google_gcs_bucket`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

**Relation through `source.aws_s3_kms_key`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.rgp-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L82-L88">Source</a></summary>

<div id="rule-rgp-policy"></div>

Matches `resource` instances of `vault_rgp_policy`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.rotation-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/governance/namespaces.rf.hcl#L90-L96">Source</a></summary>

<div id="rule-rotation-policy"></div>

Matches `resource` instances of `vault_rotation_policy`.

**Classification:** [`vault.concept.governance-configuration`](#vault-concept-governance-configuration).

</details>

<details>
<summary><code>vault.rule.saml-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L774-L792">Source</a></summary>

<div id="rule-saml-auth-backend-role"></div>

Matches `resource` instances of `vault_saml_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.path`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.path`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.saml-auth-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L741-L772">Source</a></summary>

<div id="rule-saml-auth-backend"></div>

Matches `resource` instances of `vault_saml_auth_backend`.

**Classification:** [`vault.concept.auth-method`](#vault-concept-auth-method).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["path"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "path"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.scep-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L794-L812">Source</a></summary>

<div id="rule-scep-auth-backend-role"></div>

Matches `resource` instances of `vault_scep_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-association</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L9-L27">Source</a></summary>

<div id="rule-secrets-sync-association"></div>

Matches `resource` instances of `vault_secrets_sync_association`.

**Classification:** [`vault.concept.secret-sync-configuration`](#vault-concept-secret-sync-configuration).

**Contributions**

- targets [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination) through `source.name`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.name`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.name`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-aws-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L29-L75">Source</a></summary>

<div id="rule-secrets-sync-aws-destination"></div>

Matches `resource` instances of `vault_secrets_sync_aws_destination`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-encryption-key`](#vault-relation-uses-encryption-key): targets [`vault.concept.encryption-key`](#vault-concept-encryption-key) through `source.kms_key_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.kms_key_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-azure-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L77-L115">Source</a></summary>

<div id="rule-secrets-sync-azure-destination"></div>

Matches `resource` instances of `vault_secrets_sync_azure_destination`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-cloud-identity`](#vault-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L117-L123">Source</a></summary>

<div id="rule-secrets-sync-config"></div>

Matches `resource` instances of `vault_secrets_sync_config`.

**Classification:** [`vault.concept.secret-sync-configuration`](#vault-concept-secret-sync-configuration).

</details>

<details>
<summary><code>vault.rule.secrets-sync-gcp-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L125-L193">Source</a></summary>

<div id="rule-secrets-sync-gcp-destination"></div>

Matches `resource` instances of `vault_secrets_sync_gcp_destination`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

**Relations**

- [`vault.relation.uses-cloud-identity`](#vault-relation-uses-cloud-identity): targets [`rf.concept.service-identity`](https://docs.rootform.dev/language/reference/rf-vocabulary/#rf-concept-service-identity) through `source.service_account_email`.
- [`vault.relation.uses-encryption-key`](#vault-relation-uses-encryption-key): targets [`vault.concept.encryption-key`](#vault-concept-encryption-key) through `source.kms_key_id`.
- [`vault.relation.uses-encryption-key`](#vault-relation-uses-encryption-key): targets [`vault.concept.encryption-key`](#vault-concept-encryption-key) through `source.global_kms_key`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

**Relation through `source.service_account_email`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`

**Relation through `source.kms_key_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.global_kms_key`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-gh-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L195-L226">Source</a></summary>

<div id="rule-secrets-sync-gh-destination"></div>

Matches `resource` instances of `vault_secrets_sync_gh_destination`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-github-apps</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L228-L259">Source</a></summary>

<div id="rule-secrets-sync-github-apps"></div>

Matches `resource` instances of `vault_secrets_sync_github_apps`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.secrets-sync-vercel-destination</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets-sync/destinations.rf.hcl#L261-L292">Source</a></summary>

<div id="rule-secrets-sync-vercel-destination"></div>

Matches `resource` instances of `vault_secrets_sync_vercel_destination`.

**Classification:** [`vault.concept.secret-sync-destination`](#vault-concept-secret-sync-destination).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.spiffe-auth-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L814-L832">Source</a></summary>

<div id="rule-spiffe-auth-backend-config"></div>

Matches `resource` instances of `vault_spiffe_auth_backend_config`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.spiffe-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L834-L852">Source</a></summary>

<div id="rule-spiffe-auth-backend-role"></div>

Matches `resource` instances of `vault_spiffe_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

**Contributions**

- targets [`vault.concept.auth-method`](#vault-concept-auth-method) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.spiffe-secret-backend-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L838-L856">Source</a></summary>

<div id="rule-spiffe-secret-backend-config"></div>

Matches `resource` instances of `vault_spiffe_secret_backend_config`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.mount`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.mount`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.spiffe-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L858-L864">Source</a></summary>

<div id="rule-spiffe-secret-backend-role"></div>

Matches `resource` instances of `vault_spiffe_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.ssh-secret-backend-ca</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/pki/certificate-authorities.rf.hcl#L450-L472">Source</a></summary>

<div id="rule-ssh-secret-backend-ca"></div>

Matches `resource` instances of `vault_ssh_secret_backend_ca`.

**Classification:** [`vault.concept.certificate-authority`](#vault-concept-certificate-authority).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.ssh-secret-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L866-L872">Source</a></summary>

<div id="rule-ssh-secret-backend-role"></div>

Matches `resource` instances of `vault_ssh_secret_backend_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.terraform-cloud-secret-backend</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L874-L905">Source</a></summary>

<div id="rule-terraform-cloud-secret-backend"></div>

Matches `resource` instances of `vault_terraform_cloud_secret_backend`.

**Classification:** [`vault.concept.secrets-engine`](#vault-concept-secrets-engine).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["backend"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "backend"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.terraform-cloud-secret-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/secrets/secrets-engines.rf.hcl#L907-L913">Source</a></summary>

<div id="rule-terraform-cloud-secret-role"></div>

Matches `resource` instances of `vault_terraform_cloud_secret_role`.

**Classification:** [`vault.concept.secrets-engine-configuration`](#vault-concept-secrets-engine-configuration).

</details>

<details>
<summary><code>vault.rule.token-auth-backend-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/authentication/auth-methods.rf.hcl#L854-L860">Source</a></summary>

<div id="rule-token-auth-backend-role"></div>

Matches `resource` instances of `vault_token_auth_backend_role`.

**Classification:** [`vault.concept.auth-configuration`](#vault-concept-auth-configuration).

</details>

<details>
<summary><code>vault.rule.transform-alphabet</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L229-L235">Source</a></summary>

<div id="rule-transform-alphabet"></div>

Matches `resource` instances of `vault_transform_alphabet`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.transform-key-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L237-L243">Source</a></summary>

<div id="rule-transform-key-configuration"></div>

Matches `resource` instances of `vault_transform_key_configuration`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.transform-role</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L245-L251">Source</a></summary>

<div id="rule-transform-role"></div>

Matches `resource` instances of `vault_transform_role`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.transform-template</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L253-L259">Source</a></summary>

<div id="rule-transform-template"></div>

Matches `resource` instances of `vault_transform_template`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

</details>

<details>
<summary><code>vault.rule.transform-transformation</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L261-L283">Source</a></summary>

<div id="rule-transform-transformation"></div>

Matches `resource` instances of `vault_transform_transformation`.

**Classification:** [`vault.concept.data-transformation`](#vault-concept-data-transformation).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.transit-secret-backend-key</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L285-L316">Source</a></summary>

<div id="rule-transit-secret-backend-key"></div>

Matches `resource` instances of `vault_transit_secret_backend_key`.

**Classification:** [`vault.concept.encryption-key`](#vault-concept-encryption-key).

**Contexts**

- [`vault.context.ownership`](#vault-context-ownership): targets [`vault.concept.namespace`](#vault-concept-namespace) through `source.namespace`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "name"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "name"]`

**Context through `source.namespace`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>vault.rule.transit-secret-cache-config</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/vault/encryption/key-management.rf.hcl#L318-L336">Source</a></summary>

<div id="rule-transit-secret-cache-config"></div>

Matches `resource` instances of `vault_transit_secret_cache_config`.

**Classification:** [`vault.concept.encryption-configuration`](#vault-concept-encryption-configuration).

**Contributions**

- targets [`vault.concept.secrets-engine`](#vault-concept-secrets-engine) through `source.backend`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.backend`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.path`
- `match.strategy`: `"exact"`

</details>

</details>
