Skip to content

Cluster Policy

The QHxClusterPolicy is a singleton, non-namespaced Kubernetes resource used to define policy for an entire QHx cluster. At most one such policy can be created.

Resource Type Names & Abbreviations
QHxClusterPolicy, qhxcp
API Version
qhx.dev/v1
Namespaced
No

QHx can operate without a QHxClusterPolicy being created. A QHxClusterPolicy is only needed if it is desired to define an MLS mapping.

Default: false

Example:

spec:
sealed: false

If set to true, the QHxClusterPolicy becomes permanently immutable without Kubernetes control plane-level intervention or uninstalling QHx. This can be used to provide permanent assurance of a specific MLS policy.

Default: {}

Example:

spec:
groupToLevelMapping:
- "level:c": "us:c"
- "level:s": "us:s"
- "level:ts": "us:ts"

This mapping maps Kubernetes groups to QHx MLS level descriptors. See the QHx labelling specification for detalis on QHx MLS level descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

Default: {}

Example:

spec:
groupToReleasabilityMapping:
- "rel:fvey": "us,uk,ca,au,nz"

This mapping maps Kubernetes groups to QHx MLS releasability descriptors. See the QHx labelling specification for detalis on QHx MLS releasability descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

Default: {}

Example:

spec:
groupToCompartmentMapping:
- "compartment:quantum": "us:quantum"
- "compartment:marble": "us:marble"

This mapping maps Kubernetes groups to QHx MLS compartment descriptors. See the QHx labelling specification for detalis on QHx MLS compartment descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

An annotated example QHxClusterPolicy is as follows:

---
apiVersion: qhx.dev/v1
kind: QHxClusterPolicy
metadata:
name: qhx-cluster-policy
spec:
## This defaults to false. If set to true, the QHxClusterPolicy becomes permanently
## immutable without Kubernetes control plane-level intervention or uninstalling QHx.
## This can be used to provide permanent assurance of a specific MLS policy.
sealed: false
## This mapping maps Kubernetes groups to QHx MLS level descriptors.
## See the QHx labelling specification for details on QHx MLS level descriptors.
## Groups may be chosen arbitrarily according to the Kubernetes environment.
groupToLevelMapping:
- "level:c": "us:c"
- "level:s": "us:s"
- "level:ts": "us:ts"
## This mapping maps Kubernetes groups to QHx MLS releasability descriptors.
## See the QHx labelling specification for details on QHx MLS releasability descriptors.
groupToReleasabilityMapping:
- "rel:fvey": "us,uk,ca,au,nz"
## This mapping maps Kubernetes groups to QHx MLS compartment descriptors.
## See the QHx labelling specification for details on QHx MLS compartment descriptors.
groupToCompartmentMapping:
- "compartment:quantum": "us:quantum"
- "compartment:marble": "us:marble"