Shared policy attributes
Each policy resource requires exactly one match representation.module uses
Policy-as-code. conditions uses the complete native condition language as
native HCL objects, tuples, and values. No JSON encoding or escaping is needed.
Shared attributes are:
Native condition language
Every condition is one HCL object. A predicate compares one typed field:all when every child must match, any when at least one must match, and
not to invert one child. all and any each accept 1–64 condition objects.
Trees may contain at most 512 nodes and 16 levels.
Field catalog
Terraform accepts the same native-condition fields as the policy engine. The catalog is grouped by namespace so plans remain readable:
See Conditions for every accepted field, its exact type,
meaning, availability, and family. A field from another policy family is
rejected.
Content and Resource Policies additionally support history-aware operators:
within must be a positive integer followed by s, m, h, or d, such as
30s, 15m, 12h, or 7d, and cannot exceed 30 days. Count op is eq,
gt, gte, lt, or lte; count value is an integer from 0 through
1,024.
Content evaluates these predicates over the bounded current agent-session
history. Resource evaluates them over bounded, policy-safe facts ordered within
the same authenticated Resource connection. Resource backtests group retained
facts by connection ID. These forms do not currently express a rate limit
across Resource connections, users, devices, or the organization.
forge_content_policy
The
response checkpoint is endpoint- and capability-dependent. The LLM
Gateway does not provide it.
Timing constraints still apply: approval is pre_tool only, filtering is
post_tool only, and path redaction is pre_tool or post_tool only.
forge_access_policy
Access, Content, and Resource expose only their own family attributes. Terraform rejects
cross-family fields instead of silently discarding or retaining them as null
state.
forge_resource
The generated forge_resource reference
is the source of truth for its schema, validation, import format, and examples.
forge_resource manages one HTTP, HTTPS, PostgreSQL, MySQL, or Redis
destination separately from its policies and credentials:
protocol is http, postgres, mysql, or redis. upstream_tls defaults
to true; PostgreSQL, MySQL, and Redis require it. For a destination using a private certificate authority, set
upstream_ca_pem = trimspace(file("private-ca.pem")). There is no insecure
certificate-verification setting. transparent_routing defaults to false;
turning it on publishes the Resource to managed endpoint routes. A
gateway_id is required for direct access and automatic routing.
forge_resource_credential
The generated
forge_resource_credential reference
is the source of truth for supported credential kinds, assignments, rotation,
import format, and examples.
Credentials have a separate lifecycle so rotation and identity assignments do
not rewrite the Resource or its policies. Terraform 1.11 or newer is required
because secret is sensitive and write-only. Supply it through an ephemeral
variable:
kind is username_password, bearer_token, header,
aws_rds_iam, oauth2_client_credentials, or oauth2_token_exchange, subject
to Resource protocol validation. The generated reference lists the required
and incompatible fields for each kind.
Assignments use users, groups, and service_accounts; default applies
only when no identity-specific assignment exists. With no matching or default
credential, Forge rejects the connection instead of passing through caller
credentials. Increment secret_version and provide a replacement secret in
the same change to rotate it. Plan, state, refresh, API responses, and imports
never recover the secret.
Import a credential with <resource-id>/<credential-id>.
forge_resource_policy
The generated
forge_resource_policy reference is
the source of truth for its schema, validation, import format, and examples.
forge_resource_policy is a peer of forge_access_policy and
forge_content_policy over the shared policy engine. It uses the same native
condition tree and operators, named exceptions, outcomes and precedence,
messages, immutable revisions, forge.rego.v1, backtests, validation tokens,
and Terraform authority. Its distinct Resource scope, enforcement mode,
protocol field catalog, and actions are checked against the selected Resources.
Resource Policies have no
evaluate_on or enforcement_surfaces attribute.
The referenced Resource fields determine whether the rule runs before
connection, on each HTTP request, or before each database or Redis command. Forge
validates native and Rego field compatibility against every Resource listed in
resources.
HTTP request bodies support redaction. HTTP response bodies and PostgreSQL or
MySQL results support redaction and filtering. Resource transformations use the same
typed strategy, path, predicate, and unavailable-data attributes documented for
Content policies, with data_target replacing Content checkpoints. Approval
uses approval_mode; Resource policies do not use
auto_approve_on_request.
Content Rego example
forge_content_policy. Invalid
cross-field combinations fail planning or server validation.
Access destination block example
Usedestination.domain for simple endpoint-route network policy. It is the
right field for blocking a hostname or AI API domain. Do not use process.id
for local network route enforcement; use process.name only as a narrowing
condition with a route anchor such as destination.domain,
destination.ip, or exact destination.port.
Block, Endpoint route, and Destination domain equals api.deepseek.com.
Run a final connected terraform plan -detailed-exitcode; no changes confirms
Terraform state and the Forge policy revision match.
Resource command block example
This Resource Policy blocksDELETE commands for one PostgreSQL Resource and
returns useful guidance to the client. It monitors first so the initial rollout
does not interrupt traffic; change enforcement to enforce after reviewing
Resource Activity and a backtest.
Resource data and approval examples
Redact selected JSON fields before an HTTP request is forwarded:Readable references
Use exact user email and exact group, product, agent, route, MCP server/tool, or skill name/slug. Forge resolves names authoritatively. Missing and ambiguous matches fail apply rather than choosing arbitrarily. Forge retains the resolved bindings while refresh preserves readable configuration. Every policy resource with user or group subjects can disambiguate duplicate directory labels without putting a Forge object ID in configuration:group_directory_ids works the same way for configured group names. Every map
key must also appear in its matching users or groups set; empty qualifiers
and unsupported names fail before mutation. Most organizations should omit
these maps and use the concise unique email/name form. The same fields are
available on MCP ACLs and skill ACLs.
Policy id is different: it is a user-chosen durable key, immutable after
creation and never reusable after deletion. Choose a stable, descriptive slug.
Import
Policy resources import by their durable policy ID:forge_policy_authority resource
at the exact reviewed revision, then import the policy into the same Terraform
manager.
After import, run a connected terraform plan and reproduce the complete
remote scope, condition or module, action, and action-specific configuration in
HCL. Omitted attributes are desired changes, not instructions to preserve
unknown remote configuration.
Move existing Resource policy state
Resource rules previously declared asforge_access_policy must move to the
dedicated Terraform resource. Update the HCL to
forge_resource_policy, remove Access-only attributes such as
enforcement_surfaces, and move state before planning: