Files
Max Vojtkov a6d8aa8b52 A Terraform provider for Dokploy
Plugin-framework provider covering projects, environments, applications,
Compose stacks, managed databases, domains, mounts, ports, redirects,
basic auth, registries, SSH keys, certificates and backup destinations,
over Dokploy's tRPC-over-REST API.

The shim package exposes the provider to other Go modules, which is how
pulumi-dokploy bridges it.
2026-08-09 12:17:26 +03:00
..
2026-08-09 12:17:26 +03:00

CloudTrail Server-Side Encryption Enabled

Source Sentinel Policy

cloudtrail-server-side-encryption-enabled.sentinel

Conversion Quality

Good

Why this is Good

The Sentinel policy is config-oriented and checks whether kms_key_id is present as a configured value. tfpolicy can preserve the same enforcement intent by validating the planned end-state value for attrs.kms_key_id.

Key translation notes

  • tfconfig/v2 config inspection becomes a planned-value check in tfpolicy
  • The converted policy focuses on whether kms_key_id is ultimately present, not whether it originated as a constant in the config

Limitations encountered

The tfpolicy version does not preserve the config-level distinction between explicit constant values and other configuration forms. It validates the final planned attribute value instead.