Use space labels to attach policies
Currently, we can only attach a policy to stacks directly, either manually or through autoattach labels. It would be great if the autoattach feature also applied to space level labels, for all of their stacks.
To explain our use case, we have a standard approval policy (on the root space) that we only want to apply to our production environment spaces, which are at the lowest level in our hierarchy. The only way for us to do this currently is to add a “prod” label to every stack under these spaces, which can be dangerous in case developers forget to add them. If we could just add that “prod” label to the production spaces, it would ensure that our policy always applies to all of their stacks.
- Workaround
Log in to comment and vote
Comments2
Amaranth Falcon
Aug 21
•Merged request
•4 votes
Autoattach for only stacks or only modules
At the moment when using
autoattach:*on a context or policy, it attached to both Stacks and Modules.It would be good to be able to to
autoattach:stack:*orautoattach:module:*in order to only target modules or stacks no matter what the naming of the resource is.Jade Elephant
Nov 14, 2024
In our case, to mitigate the problem, we place ‘the policy’ in every space we wanted (yep, duplications) with autoattach:* label. That way policy applied to all stacks in existing and all child spaces.