Policies
The Policies app in the Manager shows the policies of every part of Velrix: how updates start, maintenance windows, who may sign up and sign in, password reset, the security profile, backup schedules, hardware thresholds, what happens when an account runs out of money, account limits, how long audit records and logs are kept, and more. An organisation’s page has the same app for that organisation.
Each part of Velrix keeps and enforces its own policies. The app only shows them and sends your changes to the part they belong to. If a part is not answering, its section says Unavailable; its policies still apply.
Choosing the level
Level chooses the whole realm or one of your organisations. With an organisation chosen, Project chooses the whole organisation or one of its projects. On an organisation’s page, only Project is shown.
Some policies exist only at some levels: hardware thresholds and the sign-in rules apply to the whole realm, account limits and log retention to an organisation. A project shows its organisation’s limits and retention, which it is held to.
Reading a policy
Every row shows the value that applies and where it was set:
- Here: set at the level you are looking at.
- For the realm: set for the whole installation, and inherited below it.
- From …: set on an organisation or project above this one.
- Default: nothing is set, so the built-in value applies.
A value that differs from its default is marked. Differs from default shows only those. Search finds a policy by its name, its id (updates.windows) or the part it belongs to.
Changing a policy
Choose Change on a row. The form opens under the table. Save sends it to the part the policy belongs to, which checks it and records the change in the audit trail, with who made it. History opens those records.
Where a value is inherited, Use the value above removes the one set here.
Copying policies to another installation
Export saves the policies set at this level as one JSON file. Import on another installation, or later on this one, sets each of them through its own part, as you. A policy that is already the same is left alone. One that installation does not have, or that you may not change, is skipped, and one its part refuses is reported; the rest still apply.