Creating a Cluster Policy Using Policy Central

Use Policy Central for a smarter, rule-based approach to policy creation. Predefined templates make it quick and easy to create and manage policies.

Prerequisites:

To create a cluster policy:

  1. Go to menu > KUBE+ > GROUPS & POLICIES > Cluster Policy
    On the Cluster Policy page, the existing policies (if any) are listed.
  2. Click +Create Policy in the command bar.
    The Cluster Policy popup opens.
  3. Under the Policy Central section, click +Create Policy.
  4. In the Welcome to Policy Central popup, click Get Started.
  5. In the Create Policy window:
    1. Select Kube Cluster Policy from the Policy Type dropdown.
    2. Fill in the policy details:
      Table 1. Policy Details - Field and Description Table
      Field Description
      Policy Name* Enter a unique policy name to be associated with one or more clusters.
      Description Optionally, provide a brief description of the policy for clarity and reference.
      Select a Tag Choose a tag to categorize and manage the policy.
      *: Mandatory fields
  6. Click Configure Policy.
    The Create a Kube Cluster Policy in 3 Simple Steps popup displayed:
    • You may close it.
    • To avoid seeing it again, check Don’t Show Again, then click Close.
  7. Configuring the Policy as follows:
    1. In the Cluster Rules page:
      • A default template is displayed. You can:
        • Use the existing template.
        • Modify and save it.
        • Save it as a new template.
      • Templates are listed under Cluster Rule Templates in the right panel.

      • Select a template to apply it to your rule.

    2. The field in the Cluster Rules are:
      Table 2. Cluster Rules - Field and Description Table
      Policy Application Scope
      • Cluster Wide - Cluster wide global policy.

      • Namespace Wide - Policy to be applied for a specific namespace or a project within a cluster.

      Policy Rules Enable or disable the following rules as needed:
      • Onboarding Rule - Automatically map the policy by evaluating the configured rules when new clusters or namespaces are detected. If not enabled, the policy will not be mapped automatically but still can be mapped manually in KUBE+.
      • Namespace Exclusion for Certificate Discovery - Skip specified namespaces during the certificate discovery process.
      • Off-boarding Rule - Execute defined actions when clusters are removed from KUBE+
  8. Click Next.
  9. In the Issuance Template page:
    • Select a certificate template from the right panel.
    • In the Import Issuance Template popup, click Confirm.
    • (Optional) Click + Add CA to add more CAs, and fill in the required fields.
  10. Click Next.
  11. (Optional) Configure Notifications as follows:
    1. On the Notification page, click + Add Notification.
    2. In the Configure Notification panel, fill in the following:
      Notification Settings Tab
      Table 3. Notification Settings - Field and Description Table
      Field Description
      Recipient Select recipients. The options are:
      • User Group - select this checkbox and add user groups from the dropdown list.
      • User - select this checkbox and add users from the dropdown list.
      • Email - enter the email address with comma separated.
      Delivery Method Select delivery methods. The options are:
      • *Notify Via - Bydefault Email option is selected.
      • Notify Me - Enable this toggle button to notify you when the policy is executed.

      Message Template tab

      Table 4. Message Template - Field and Description Table
      Field Description
      Email Template Select a emal template from the dropdown list.
      Email Subject Enter the email subject. You can include variable to replace the value. To know about the variables, click Variables.
      Email Content Enter the email content for the bosy of the email. You can also use variables.
    3. Click Add.
  12. Click Finish.
  13. In the Submit Policy confirmation popup, click Confirm.
    The cluster policy is added to the Cluster Policy inventory.
Related Information