Skip to content

Commit c941bac

Browse files
committed
docs(policy): simplify policy selection guidance
Signed-off-by: Johnny Greco <jogreco@nvidia.com>
1 parent e3442c0 commit c941bac

2 files changed

Lines changed: 30 additions & 37 deletions

File tree

‎docs/reference/default-policy.mdx‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,8 +28,8 @@ repair; it does not silently select the fallback.
2828
An active gateway-global policy replaces sandbox policy selection and suppresses
2929
provider-added network grants. Otherwise, attached providers can add their
3030
network rules to the selected sandbox policy. Refer to
31-
[Configure Sandbox Policies](/sandboxes/policies#understand-policy-sources) for
32-
the selection diagram.
31+
[How OpenShell Selects a Policy](/sandboxes/policies#how-openshell-selects-a-policy) for
32+
the selection order.
3333

3434
## Fallback Filesystem Access
3535

‎docs/sandboxes/policies.mdx‎

Lines changed: 28 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -41,40 +41,12 @@ network_middlewares: { ... } # Additional traffic processing.
4141
Refer to the [Policy Schema Reference](/reference/policy-schema) for every
4242
accepted field.
4343
44-
## Understand Policy Sources
44+
## Apply Policy Changes
4545
4646
Every sandbox runs under a policy, but you do not have to supply a policy file
47-
when creating one. OpenShell selects a policy from its configured sources,
48-
falling back to its restrictive default when no other source supplies one.
49-
50-
The base policy is the policy configured for the sandbox. The effective policy
51-
includes rules contributed by attached providers, unless a gateway-global policy
52-
replaces normal sandbox and provider selection.
53-
54-
The gateway selects one policy source and, when allowed, adds rules from
55-
attached providers:
56-
57-
```mermaid
58-
flowchart TD
59-
A["Gateway-global policy configured?"] -->|Yes| B["Use the gateway-global policy"]
60-
A -->|No| C["Saved sandbox policy available?"]
61-
C -->|Yes| D["Add rules from attached providers"]
62-
C -->|No| E["Look for a policy in the image"]
63-
E -->|Valid| D
64-
E -->|Missing| F["Use the default restrictive policy"]
65-
E -->|Invalid| G["Wait for a repaired policy<br/>before starting the workload"]
66-
F --> D
67-
B --> H["Validate permissions<br/>and credential access"]
68-
D --> H
69-
H --> I["Make the configuration active"]
70-
```
71-
72-
At creation, an explicit `--policy` file takes precedence over
73-
`OPENSHELL_SANDBOX_POLICY`. OpenShell looks inside the image only when the sandbox
74-
has no saved policy. A gateway-global policy replaces
75-
normal sandbox policy selection and prevents provider rules from being added.
76-
77-
## Apply Policy Changes
47+
when creating one. OpenShell uses an existing policy or falls back to its
48+
restrictive default. See [How OpenShell Selects a Policy](#how-openshell-selects-a-policy)
49+
for the selection order.
7850
7951
You can update network rules while a sandbox is running. Changes to filesystem
8052
permissions and process identity require recreating the sandbox to take effect.
@@ -93,9 +65,11 @@ configuration:
9365

9466
### Inspect the Current Policy
9567

96-
The base and effective views show the result of policy selection. The base view
97-
excludes provider-contributed rules, making it the starting point for sandbox
98-
policy edits. The effective view includes permissions from all selected sources.
68+
The base policy is the policy configured for the sandbox. Attached providers can
69+
contribute additional network rules; the effective policy includes those rules
70+
alongside the base policy. Start sandbox policy edits from the base view so you
71+
do not copy provider-owned rules into your configuration.
72+
9973
In the command examples, replace `my-sandbox` with the name of your sandbox:
10074

10175
```shell
@@ -246,6 +220,25 @@ existing access depends on the failure stage and the configured runtime failure
246220
mode. [Troubleshoot Sandbox Policies](/sandboxes/troubleshoot-policies) explains
247221
how to identify that stage and repair the configuration.
248222

223+
## How OpenShell Selects a Policy
224+
225+
When more than one policy is available, OpenShell uses the first applicable
226+
policy in this order:
227+
228+
1. A gateway-global policy set by an administrator.
229+
2. The sandbox's saved policy. At creation, `--policy` takes precedence over
230+
`OPENSHELL_SANDBOX_POLICY`; subsequent policy changes update the saved policy.
231+
3. A policy included in the sandbox image.
232+
4. OpenShell's [restrictive default policy](/reference/default-policy).
233+
234+
OpenShell then adds network rules from attached providers, unless a
235+
gateway-global policy is active. A global policy replaces the sandbox's policy
236+
and suppresses provider-added rules, as described below.
237+
238+
An invalid image policy must be repaired before the workload can start;
239+
OpenShell does not skip it and use the default. See
240+
[Troubleshoot Sandbox Policies](/sandboxes/troubleshoot-policies) for repair guidance.
241+
249242
## Global Policy Override
250243

251244
A gateway administrator can apply one policy across the gateway's sandboxes.

0 commit comments

Comments
 (0)