@@ -41,40 +41,12 @@ network_middlewares: { ... } # Additional traffic processing.
4141Refer to the [Policy Schema Reference](/reference/policy-schema) for every
4242accepted field.
4343
44- ## Understand Policy Sources
44+ ## Apply Policy Changes
4545
4646Every sandbox runs under a policy, but you do not have to supply a policy file
47- when creating one. OpenShell selects a policy from its configured sources,
48- falling back to its restrictive default when no other source supplies one.
49-
50- The base policy is the policy configured for the sandbox. The effective policy
51- includes rules contributed by attached providers, unless a gateway-global policy
52- replaces normal sandbox and provider selection.
53-
54- The gateway selects one policy source and, when allowed, adds rules from
55- attached providers:
56-
57- ` ` ` mermaid
58- flowchart TD
59- A["Gateway-global policy configured?"] -->|Yes| B["Use the gateway-global policy"]
60- A -->|No| C["Saved sandbox policy available?"]
61- C -->|Yes| D["Add rules from attached providers"]
62- C -->|No| E["Look for a policy in the image"]
63- E -->|Valid| D
64- E -->|Missing| F["Use the default restrictive policy"]
65- E -->|Invalid| G["Wait for a repaired policy<br/>before starting the workload"]
66- F --> D
67- B --> H["Validate permissions<br/>and credential access"]
68- D --> H
69- H --> I["Make the configuration active"]
70- ```
71-
72- At creation, an explicit ` --policy ` file takes precedence over
73- ` OPENSHELL_SANDBOX_POLICY ` . OpenShell looks inside the image only when the sandbox
74- has no saved policy. A gateway-global policy replaces
75- normal sandbox policy selection and prevents provider rules from being added.
76-
77- ## Apply Policy Changes
47+ when creating one. OpenShell uses an existing policy or falls back to its
48+ restrictive default. See [How OpenShell Selects a Policy](#how-openshell-selects-a-policy)
49+ for the selection order.
7850
7951You can update network rules while a sandbox is running. Changes to filesystem
8052permissions and process identity require recreating the sandbox to take effect.
@@ -93,9 +65,11 @@ configuration:
9365
9466# ## Inspect the Current Policy
9567
96- The base and effective views show the result of policy selection. The base view
97- excludes provider-contributed rules, making it the starting point for sandbox
98- policy edits. The effective view includes permissions from all selected sources.
68+ The base policy is the policy configured for the sandbox. Attached providers can
69+ contribute additional network rules; the effective policy includes those rules
70+ alongside the base policy. Start sandbox policy edits from the base view so you
71+ do not copy provider-owned rules into your configuration.
72+
9973In the command examples, replace `my-sandbox` with the name of your sandbox :
10074
10175` ` ` shell
@@ -246,6 +220,25 @@ existing access depends on the failure stage and the configured runtime failure
246220mode. [Troubleshoot Sandbox Policies](/sandboxes/troubleshoot-policies) explains
247221how to identify that stage and repair the configuration.
248222
223+ # # How OpenShell Selects a Policy
224+
225+ When more than one policy is available, OpenShell uses the first applicable
226+ policy in this order :
227+
228+ 1. A gateway-global policy set by an administrator.
229+ 2. The sandbox's saved policy. At creation, `--policy` takes precedence over
230+ ` OPENSHELL_SANDBOX_POLICY` ; subsequent policy changes update the saved policy.
231+ 3. A policy included in the sandbox image.
232+ 4. OpenShell's [restrictive default policy](/reference/default-policy).
233+
234+ OpenShell then adds network rules from attached providers, unless a
235+ gateway-global policy is active. A global policy replaces the sandbox's policy
236+ and suppresses provider-added rules, as described below.
237+
238+ An invalid image policy must be repaired before the workload can start;
239+ OpenShell does not skip it and use the default. See
240+ [Troubleshoot Sandbox Policies](/sandboxes/troubleshoot-policies) for repair guidance.
241+
249242# # Global Policy Override
250243
251244A gateway administrator can apply one policy across the gateway's sandboxes.
0 commit comments