Setting up automatic policy assignment

You can set up automatic assignment of policies to SaaS applications, Google Kubernetes Engine (GKE) applications, instances, or buckets.

Prerequisites

Considerations

  • Assigning policies automatically takes precedence over assigning policies manually or setting a default policy. This means that the auto-assignment conditions that are defined for the custom policy or the hycu-policy tag that is added to the preferred entity define which policy gets assigned, even if the entity already has a manually assigned policy.

  • If you want to assign a new policy to a SaaS application, a GKE application, an instance, or a bucket for which automatic policy assignment has been set up, define new tags, labels, or metadata as described in this topic.

  • An automatically assigned policy is not automatically unassigned, even if the auto-assignment conditions no longer apply (when you update the auto-assignment conditions for a policy, or when the tags, labels, or metadata of an entity change).

  • For methods 2 and 3: The exclude policy has the highest priority. If an entity matches the conditions for multiple policies and the exclude policy is one of them, the exclude policy is used, leaving the entity unprotected.

Methods

The corresponding policies are automatically assigned to entities during the next entity synchronization in R‑Cloud.