Software Secure Workload
Activity Configure

Fine-Tune External Dependencies for a Workspace

Use this procedure to create policies between specified subsets of workloads within scopes (rather than between entire scopes) during automatic policy discovery, when the provider of a policy belongs to a different scope than the scope in which policies are being discovered.

Fine-tuning External Dependencies
Figure 1: Fine-tuning External Dependencies

Before you begin

  • Configure an inventory filter for each subset of workloads for which you want to generate specific policies. You can create any number of inventory filters, in any scope.

    There are several ways to create inventory filters:

    These filters must have the following options enabled:

    • Restrict query to ownership scope

      Provides a service external of its scope

  • See also Tips for Exploring External Dependencies.

Procedure

1

Navigate to the workspace in which you will discover policies.

2

Click Automatically Discover Policies.

3

Click External Dependencies.

4

If necessary, click Show All scopes.

5

(Optional) Leverage previous configurations:

  • To reuse the changes you made to the list the last time you discovered policies, click Previous Config.

  • If you have set up external dependencies in the global “Default Policy Discovery Config”, you can use the global list by clicking Default Config. Or, after obtaining the default list, you can modify it as desired (for that workspace only), and then use the customized version on subsequent runs by clicking Previous Config once.

6

Reorder scopes (and inventory filters, if applicable) as needed.

Policy is applied based on the first scope or inventory filter in the list (starting from the top) that matches the traffic. For this purpose, you generally want to apply the most specific policy that matches traffic, so you want child scopes (more specific) above their parents (less specific).

  • If you have recently created new child scopes, which by default are added to the bottom of the list, reorder the entire list to place child scopes above their parents:

    (Recommended) Click Reorder Naturally.

    Reorder naturally
    Figure 2: Reorder naturally
  • (If you have a specific reason) To reorder the list manually:

    • Click Drag and Drop.

    • Click By Number:

      The external dependencies will be assigned priority values in multiples of 10. Change the values to change the order.

      Once numbers are modified, click View to update the list order and reassign multiples of 10 to each of the priorities.

7

Specify granularity for each row:

  • Click Fine for each row for which you want to generate policies specific to configured inventory filters or clusters.

    Click Coarse to generate policies that apply to the entire scope.

  • To apply granularity to all subscopes of a scope: Click the Button with three dots button at the end of the scope's row.