Skip to content

Carry edge policy from the control plane out to the edges#227

Draft
scotwells wants to merge 1 commit into
mainfrom
feat/federation-policy-delivery
Draft

Carry edge policy from the control plane out to the edges#227
scotwells wants to merge 1 commit into
mainfrom
feat/federation-policy-delivery

Conversation

@scotwells

Copy link
Copy Markdown
Contributor

What this delivers

The protections customers configure — firewall and connector rules — are authored in one place, the control plane. For them to take effect, they have to reach every edge. This describes how that delivery happens: which policies travel out to the edges, and how each edge should read them once they arrive.

Why it's framed around responsibility

The configuration here is named for what it does — carrying policy from the center out to the edges — rather than the specific tool that moves it. That keeps the intent readable on its own terms, even if the mechanism underneath it changes later.

Scope

Delivery wiring for the test environment. It mirrors how policy reaches the edge in production so tests see the same propagation behavior customers depend on.

Describes how firewall and connector policy authored centrally is delivered
to each edge, and how each edge reads it on arrival. Named for what it does
rather than the tool that moves it, so the intent stays legible if the
mechanism changes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JbCy8vy66RdNYzGSgqH6P6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant