Manage policies
See a boundary's policies, switch one between enforcing and disabled, change it, or delete it.
Requires: policies/write
The Policies page, under Security in the sidebar, lists the boundary's policies to everyone
with policies/read. Changing them needs policies/write; without it the switches and buttons are
unavailable.
The list
| Column | Shows |
|---|---|
| Name | The policy's name |
| Rule | Which of the four rules it holds |
| Scope | The one cluster it is limited to, or All clusters |
| State | A switch and Enforcing or Disabled |
Enforce or disable a policy
Use the switch in the State column. Switching a policy off keeps it stored and installed in its clusters, but it no longer blocks anything; switching it on puts it back in force. The change is written to each cluster at once and takes effect when that cluster's operator has processed it, normally within moments. A disabled Allowed compute plans policy is simply not counted when the platform checks a plan.
Change a policy
Choose Edit on the policy's row. The Edit policy dialog has the same fields as Create a policy, and everything but the name can be changed — the rule too. Choose Save changes.
The saved policy is written to its clusters straight away. Narrowing the scope from All clusters to one cluster removes the policy from the others. Workloads that already run are not checked again; the new rule applies to what is created or changed from then on.
Delete a policy
Choose the delete button on the row, then Delete policy in Delete this policy?. The platform first removes the policy from every cluster it was installed in, and deletes it only when all of them have done so; each cluster's operator then removes the admission rule, normally within moments.
If a cluster cannot be reached, nothing is deleted and Could not delete the policy appears. The policy keeps applying in every cluster it is still installed in. Try again when the cluster is back.
With the CLI and API
stsh policy lists the boundary's policies and stsh policy <name> shows one; add -o json to see
every field.
The routes are under /boundaries/<boundary-id>/resources/policies:
| Method and path | Does |
|---|---|
GET …/policies |
Lists the policies |
GET …/policies/<name> |
Shows one, with where it was written to (projections) |
PUT …/policies/<name> |
Replaces the policy |
DELETE …/policies/<name> |
Deletes it; 204 when done |
A PUT replaces the whole policy with the body, which has the same fields as a create. A field
left out is not kept: an omitted description becomes empty and an omitted enabled turns the
policy on. A different name in the body renames the policy.