Cluster Policy
The QHxClusterPolicy is a singleton, non-namespaced Kubernetes resource used
to define policy for an entire QHx cluster. At most one such policy can be
created.
- Resource Type Names & Abbreviations
QHxClusterPolicy,qhxcp- API Version
qhx.dev/v1- Namespaced
- No
QHx can operate without a QHxClusterPolicy being created. A
QHxClusterPolicy is only needed if it is desired to define an MLS mapping.
Reference
Section titled “Reference”spec.sealed (bool)
Section titled “spec.sealed (bool)”Default: false
Example:
spec: sealed: falseIf set to true, the QHxClusterPolicy becomes permanently immutable without
Kubernetes control plane-level intervention or uninstalling QHx. This can be
used to provide permanent assurance of a specific MLS policy.
spec.groupToLevelMapping (map)
Section titled “spec.groupToLevelMapping (map)”Default: {}
Example:
spec: groupToLevelMapping: - "level:c": "us:c" - "level:s": "us:s" - "level:ts": "us:ts"This mapping maps Kubernetes groups to QHx MLS level descriptors. See the QHx labelling specification for detalis on QHx MLS level descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.
spec.groupToReleasabilityMapping (map)
Section titled “spec.groupToReleasabilityMapping (map)”Default: {}
Example:
spec: groupToReleasabilityMapping: - "rel:fvey": "us,uk,ca,au,nz"This mapping maps Kubernetes groups to QHx MLS releasability descriptors. See the QHx labelling specification for detalis on QHx MLS releasability descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.
spec.groupToCompartmentMapping (map)
Section titled “spec.groupToCompartmentMapping (map)”Default: {}
Example:
spec: groupToCompartmentMapping: - "compartment:quantum": "us:quantum" - "compartment:marble": "us:marble"This mapping maps Kubernetes groups to QHx MLS compartment descriptors. See the QHx labelling specification for detalis on QHx MLS compartment descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.
Example
Section titled “Example”An annotated example QHxClusterPolicy is as follows:
---apiVersion: qhx.dev/v1kind: QHxClusterPolicy
metadata: name: qhx-cluster-policy
spec: ## This defaults to false. If set to true, the QHxClusterPolicy becomes permanently ## immutable without Kubernetes control plane-level intervention or uninstalling QHx. ## This can be used to provide permanent assurance of a specific MLS policy. sealed: false
## This mapping maps Kubernetes groups to QHx MLS level descriptors. ## See the QHx labelling specification for details on QHx MLS level descriptors. ## Groups may be chosen arbitrarily according to the Kubernetes environment. groupToLevelMapping: - "level:c": "us:c" - "level:s": "us:s" - "level:ts": "us:ts"
## This mapping maps Kubernetes groups to QHx MLS releasability descriptors. ## See the QHx labelling specification for details on QHx MLS releasability descriptors. groupToReleasabilityMapping: - "rel:fvey": "us,uk,ca,au,nz"
## This mapping maps Kubernetes groups to QHx MLS compartment descriptors. ## See the QHx labelling specification for details on QHx MLS compartment descriptors. groupToCompartmentMapping: - "compartment:quantum": "us:quantum" - "compartment:marble": "us:marble"