Call the DeployPolicyInstance operation to deploy a policy instance to specified namespaces in an ACK cluster. To create a policy instance, select a security policy, configure a governance action (alert or deny), and specify the target namespaces for the policy.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cs:DeployPolicyInstance |
get |
*Cluster
|
None | None |
Request syntax
POST /clusters/{cluster_id}/policies/{policy_name} HTTP/1.1
Path Parameters
|
Parameter |
Type |
Required |
Description |
Example |
| cluster_id |
string |
Yes |
The ID of the target cluster. |
c8155823d057948c69a**** |
| policy_name |
string |
Yes |
The name of the policy governance rule. |
ACKAllowedRepos |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| body |
object |
No |
The request body. |
|
| action |
string |
No |
The governance action. Valid values:
|
deny |
| namespaces |
array |
No |
The namespaces where the policy applies. If you omit this parameter, the policy applies to all namespaces. |
|
|
string |
No |
A namespace where the policy applies. |
default |
|
| parameters |
object |
No |
For details on the parameters supported by each policy governance rule, see Container security policy rules. |
{ "repos": [ "registry-vpc.cn-hangzhou.aliyuncs.com/acs/", "registry.cn-hangzhou.aliyuncs.com/acs/" ] } |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| instances |
array |
The names of the deployed policy instances. |
|
|
string |
The name of a deployed policy instance. |
[ "allowed-repos-kqxnc" ] |
Examples
Success response
JSON format
{
"instances": [
"[ \"allowed-repos-kqxnc\" ]"
]
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.