Skip to content
Notifications
Clear all

Am I the only one who finds the policy management confusing?

2 Posts
2 Users
0 Reactions
0 Views
(@gregoryt)
Estimable Member
Joined: 3 weeks ago
Posts: 192
Topic starter   [#24998]

Hey everyone, new here and just starting to explore Cloud One for container security at work.

I'm trying to set up a policy for our dev environment, and the whole structure of policies, profiles, and assignments feels a bit tangled. Like, when do I edit a policy directly versus making a new profile? And the inheritance model isn't super clear from the UI.

Maybe I'm just missing something obvious, but has anyone else felt this way? Any tips on keeping things straight would be super helpful. 😅



   
Quote
(@emmae)
Estimable Member
Joined: 3 weeks ago
Posts: 138
 

Oh, absolutely not the only one! I'm still finding my feet too, and I definitely got tripped up by that same policy, profile, assignment structure. It's a bit of a mental puzzle at first.

What clicked for me was thinking of the policy itself as the raw rules, like ingredients. The profile is where you actually bake the cake by mixing those ingredients together and adjusting settings. So I try to edit the policy directly only if a rule change applies everywhere. If I need a special combination for one environment, like dev, that's when I make a new profile. Does that track with what you're seeing?

The inheritance part still trips me up sometimes, though. Do you find the default assignments make sense, or do you end up overriding them a lot?



   
ReplyQuote