Skip to content
Stackship documentation Svenska

PoliciesUsers

Manage policies

See a boundary's policies, switch one between enforcing and disabled, change it, or delete it.

Requires: policies/write

The Policies page, under Security in the sidebar, lists the boundary's policies to everyone with policies/read. Changing them needs policies/write; without it the switches and buttons are unavailable.

The list

Column Shows
Name The policy's name
Rule Which of the four rules it holds
Scope The one cluster it is limited to, or All clusters
State A switch and Enforcing or Disabled

Enforce or disable a policy

Use the switch in the State column. Switching a policy off keeps it stored and installed in its clusters, but it no longer blocks anything; switching it on puts it back in force. The change is written to each cluster at once and takes effect when that cluster's operator has processed it, normally within moments. A disabled Allowed compute plans policy is simply not counted when the platform checks a plan.

Change a policy

Choose Edit on the policy's row. The Edit policy dialog has the same fields as Create a policy, and everything but the name can be changed — the rule too. Choose Save changes.

The saved policy is written to its clusters straight away. Narrowing the scope from All clusters to one cluster removes the policy from the others. Workloads that already run are not checked again; the new rule applies to what is created or changed from then on.

Delete a policy

Choose the delete button on the row, then Delete policy in Delete this policy?. The platform first removes the policy from every cluster it was installed in, and deletes it only when all of them have done so; each cluster's operator then removes the admission rule, normally within moments.

If a cluster cannot be reached, nothing is deleted and Could not delete the policy appears. The policy keeps applying in every cluster it is still installed in. Try again when the cluster is back.

With the CLI and API

stsh policy lists the boundary's policies and stsh policy <name> shows one; add -o json to see every field.

The routes are under /boundaries/<boundary-id>/resources/policies:

Method and path Does
GET …/policies Lists the policies
GET …/policies/<name> Shows one, with where it was written to (projections)
PUT …/policies/<name> Replaces the policy
DELETE …/policies/<name> Deletes it; 204 when done

A PUT replaces the whole policy with the body, which has the same fields as a create. A field left out is not kept: an omitted description becomes empty and an omitted enabled turns the policy on. A different name in the body renames the policy.