Skip to content
Stackship documentation Svenska

PoliciesUsers

Policies

Rules a boundary sets for what may run in it — which compute plans, labels, image registries and image tags its workloads may use.

A policy is a rule a boundary sets for its own workloads. It belongs to one boundary, applies to every cluster the boundary spans or to one cluster you pick, and is either Enforcing or Disabled. Policies are managed on the Policies page, under Security in the portal's sidebar.

The four rules

Rule What it stops
Allowed compute plans Creating a resource, or moving one to another compute plan, on a plan the policy does not list
Required labels Workloads that lack a label, or carry the wrong value for it
Allowed registries Workloads with an image from a registry the policy does not list
Disallow the latest tag Workloads with an image tagged latest, or with no tag at all

Each rule is described in detail, with examples of what it refuses, in Rule reference.

Where a policy is enforced

The rules are enforced in two different places, and that decides what a policy can see:

  • Allowed compute plans is checked by the platform when a resource is created or its plan changed — in the portal, the CLI and the API alike. The portal also greys out plans a policy does not allow. Nothing about it is written to a cluster.
  • The other three are admission rules in each cluster. When a policy is saved, the platform writes it to every cluster it applies to, and each cluster's operator turns it into a Kubernetes admission policy that checks pods and the objects that create them in the boundary's namespaces. They check what is created or changed from then on; what already runs keeps running.

A policy only ever applies to the boundary it belongs to: an admission rule is bound to the namespaces labelled with that boundary, and a compute-plan rule is read only for that boundary's resources.

Enforcing and disabled

A disabled policy stays stored and stays installed in its clusters, but blocks nothing. Switching it back on puts it in force again without re-creating it. Deleting a policy removes it from every cluster it was installed in.

Pages