Skip to main content

Use space labels to attach policies

Currently, we can only attach a policy to stacks directly, either manually or through autoattach labels. It would be great if the autoattach feature also applied to space level labels, for all of their stacks.

To explain our use case, we have a standard approval policy (on the root space) that we only want to apply to our production environment spaces, which are at the lowest level in our hierarchy. The only way for us to do this currently is to add a “prod” label to every stack under these spaces, which can be dangerous in case developers forget to add them. If we could just add that “prod” label to the production spaces, it would ensure that our policy always applies to all of their stacks.

Workaround
Status: ⬆️ Gathering votes2 comments

Log in to comment and vote

Comments2

  • Amaranth Falcon

    •

    Aug 21

    •

    Merged request

    •

    4 votes

    Autoattach for only stacks or only modules

    At the moment when using autoattach:* on a context or policy, it attached to both Stacks and Modules.

    It would be good to be able to to autoattach:stack:* or autoattach:module:* in order to only target modules or stacks no matter what the naming of the resource is.

  • Jade Elephant

    •

    Nov 14, 2024

    In our case, to mitigate the problem, we place ‘the policy’ in every space we wanted (yep, duplications) with autoattach:* label. That way policy applied to all stacks in existing and all child spaces.