[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Foperators\u002Fpolicies":3,"docs:nav":151,"docs:surround:\u002Fdocs\u002Foperators\u002Fpolicies":363},{"id":4,"title":5,"body":6,"description":141,"extension":142,"launchGate":143,"meta":144,"navigation":145,"path":146,"seo":147,"stem":148,"stub":149,"__hash__":150},"docs_en\u002Fdocs\u002F4.operators\u002F13.policies.md","Policies",{"type":7,"value":8,"toc":132},"minimark",[9,17,24,29,42,45,49,52,80,92,96,111,118,122],[10,11,12,13,16],"p",{},"The ",[14,15,5],"strong",{}," app in the Manager shows the policies of every part of Velrix: how updates start, the release channel, maintenance windows, who may sign up and sign in, password reset, how well new passkeys must be protected, the security profile, whether project networks reach the internet, backup schedules, hardware thresholds, what happens when an account runs out of money, account limits, how long audit records and logs are kept, and more. An organisation’s page has the same app for that organisation.",[10,18,19,20,23],{},"Each part of Velrix keeps and enforces its own policies. The app only shows them and sends your changes to the part they belong to. If a part is not answering, its section says ",[14,21,22],{},"Unavailable","; its policies still apply.",[25,26,28],"h2",{"id":27},"choosing-the-level","Choosing the level",[10,30,31,34,35,38,39,41],{},[14,32,33],{},"Level"," chooses the whole realm or one of your organisations. With an organisation chosen, ",[14,36,37],{},"Project"," chooses the whole organisation or one of its projects. On an organisation’s page, only ",[14,40,37],{}," is shown.",[10,43,44],{},"Some policies exist only at some levels: hardware thresholds and the sign-in rules apply to the whole realm, account limits and log retention to an organisation. A project shows its organisation’s limits and retention, which it is held to.",[25,46,48],{"id":47},"reading-a-policy","Reading a policy",[10,50,51],{},"Every row shows the value that applies and where it was set:",[53,54,55,62,68,74],"ul",{},[56,57,58,61],"li",{},[14,59,60],{},"Here",": set at the level you are looking at.",[56,63,64,67],{},[14,65,66],{},"For the realm",": set for the whole installation, and inherited below it.",[56,69,70,73],{},[14,71,72],{},"From …",": set on an organisation or project above this one.",[56,75,76,79],{},[14,77,78],{},"Default",": nothing is set, so the built-in value applies.",[10,81,82,83,86,87,91],{},"A value that differs from its default is marked. ",[14,84,85],{},"Differs from default"," shows only those. Search finds a policy by its name, its id (",[88,89,90],"code",{},"updates.windows",") or the part it belongs to.",[25,93,95],{"id":94},"changing-a-policy","Changing a policy",[10,97,98,99,102,103,106,107,110],{},"Choose ",[14,100,101],{},"Change"," on a row. The form opens under the table. ",[14,104,105],{},"Save"," sends it to the part the policy belongs to, which checks it and records the change in the audit trail, with who made it. ",[14,108,109],{},"History"," opens those records.",[10,112,113,114,117],{},"Where a value is inherited, ",[14,115,116],{},"Use the value above"," removes the one set here.",[25,119,121],{"id":120},"copying-policies-to-another-installation","Copying policies to another installation",[10,123,124,127,128,131],{},[14,125,126],{},"Export"," saves the policies set at this level as one JSON file. ",[14,129,130],{},"Import"," on another installation, or later on this one, sets each of them through its own part, as you. A policy that is already the same is left alone. One that installation does not have, or that you may not change, is skipped, and one its part refuses is reported; the rest still apply.",{"title":133,"searchDepth":134,"depth":135,"links":136},"",2,3,[137,138,139,140],{"id":27,"depth":134,"text":28},{"id":47,"depth":134,"text":48},{"id":94,"depth":134,"text":95},{"id":120,"depth":134,"text":121},"Every module's policies in one place, where each value was set, and how to copy them to another installation.","md",null,{},true,"\u002Fdocs\u002Foperators\u002Fpolicies",{"title":5,"description":141},"docs\u002F4.operators\u002F13.policies",false,"0WFrwzvQfXULnEKk7zNuNIKGEOi_mGaQ7-nnWjj1kzQ",[152],{"title":153,"path":154,"stem":155,"children":156,"page":-1},"Docs","\u002Fdocs","docs",[157,161,191,218,252,320,334,356],{"title":158,"path":154,"stem":159,"stub":149,"launchGate":143,"icon":160},"Overview","docs\u002Findex","i-lucide-house",{"title":162,"stub":149,"launchGate":143,"icon":163,"path":164,"stem":165,"children":166,"page":149},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[167,171,175,179,183,187],{"title":168,"path":169,"stem":170,"stub":149,"launchGate":143},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":172,"path":173,"stem":174,"stub":149,"launchGate":143},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":176,"path":177,"stem":178,"stub":149,"launchGate":143},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":180,"path":181,"stem":182,"stub":149,"launchGate":143},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":184,"path":185,"stem":186,"stub":149,"launchGate":143},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":188,"path":189,"stem":190,"stub":149,"launchGate":143},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":192,"stub":149,"launchGate":143,"icon":193,"path":194,"stem":195,"children":196,"page":149},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[197,201,205,209,213],{"title":198,"path":199,"stem":200,"stub":145,"launchGate":143},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":202,"path":203,"stem":204,"stub":145,"launchGate":143},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":206,"path":207,"stem":208,"stub":145,"launchGate":143},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":210,"path":211,"stem":212,"stub":145,"launchGate":143},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":214,"path":215,"stem":216,"stub":145,"launchGate":217},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":219,"stub":149,"launchGate":143,"icon":220,"path":221,"stem":222,"children":223,"page":149},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[224,228,232,236,240,244,248],{"title":225,"path":226,"stem":227,"stub":149,"launchGate":143},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":229,"path":230,"stem":231,"stub":145,"launchGate":143},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":233,"path":234,"stem":235,"stub":145,"launchGate":143},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":237,"path":238,"stem":239,"stub":149,"launchGate":143},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":241,"path":242,"stem":243,"stub":145,"launchGate":143},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":245,"path":246,"stem":247,"stub":149,"launchGate":143},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":249,"path":250,"stem":251,"stub":145,"launchGate":143},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":253,"stub":149,"launchGate":143,"icon":254,"path":255,"stem":256,"children":257,"page":149},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[258,262,266,270,274,275,279,283,287,291,296,300,304,308,312,316],{"title":259,"path":260,"stem":261,"stub":149,"launchGate":143},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":263,"path":264,"stem":265,"stub":149,"launchGate":143},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":267,"path":268,"stem":269,"stub":149,"launchGate":143},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":271,"path":272,"stem":273,"stub":149,"launchGate":143},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":5,"path":146,"stem":148,"stub":149,"launchGate":143},{"title":276,"path":277,"stem":278,"stub":149,"launchGate":143},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":280,"path":281,"stem":282,"stub":149,"launchGate":143},"Public address and app hostnames","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":284,"path":285,"stem":286,"stub":149,"launchGate":143},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":288,"path":289,"stem":290,"stub":149,"launchGate":143},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":292,"path":293,"stem":294,"stub":145,"launchGate":295},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":297,"path":298,"stem":299,"stub":145,"launchGate":143},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":301,"path":302,"stem":303,"stub":145,"launchGate":143},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":305,"path":306,"stem":307,"stub":145,"launchGate":143},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":309,"path":310,"stem":311,"stub":145,"launchGate":143},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":313,"path":314,"stem":315,"stub":145,"launchGate":143},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":317,"path":318,"stem":319,"stub":149,"launchGate":143},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":321,"stub":149,"launchGate":143,"icon":322,"path":323,"stem":324,"children":325,"page":149},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[326,330],{"title":327,"path":328,"stem":329,"stub":149,"launchGate":143},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":331,"path":332,"stem":333,"stub":149,"launchGate":143},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":335,"stub":149,"launchGate":143,"icon":336,"path":337,"stem":338,"children":339,"page":149},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[340,344,348,352],{"title":341,"path":342,"stem":343,"stub":145,"launchGate":143},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":345,"path":346,"stem":347,"stub":145,"launchGate":143},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":349,"path":350,"stem":351,"stub":145,"launchGate":143},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":353,"path":354,"stem":355,"stub":145,"launchGate":143},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":357,"path":358,"stem":359,"children":360,"stub":149,"launchGate":143,"icon":362},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[361],{"title":357,"path":358,"stem":359,"stub":149,"launchGate":143},"i-lucide-scroll-text",[364,366],{"title":271,"path":272,"stem":273,"description":365,"children":-1},"The company that invoices, the details its country requires on an invoice, and the invoice footer.",{"title":276,"path":277,"stem":278,"description":367,"children":-1},"See every module on every server, restart, stop or move one, run several edges, and reach your servers when the web client can't be reached."]