View Enforced Policies for a Specific Workload (Concrete Policies)
Use this procedure to view all enforced policies for a specific workload (that is, the concrete policies for that workload). This view is useful because all policies in a workspace may not apply to every workload in the workspace, and because policies in multiple workspaces may apply to a particular workload (for example, inherited policies in parent or ancestor scopes).
Concrete policies are listed in priority order. For more information about the effects of priority, see the Policy Priorities section.
Before you begin
|
Concrete policies include only policies in enforced workspaces. If a workspace is not enforced, any policies that would apply to the workload if the workspace were enforced do not appear in the list. |
Procedure
1 |
You can navigate to the Concrete Policies page for a workload from the Inventory page or from the workspace: To navigate from the Scopes and Inventory page: To navigate from the Segmentation page: |
2 |
From the menu on the left side of the Workload Profile page, click CONCRETE POLICIES. |
3 |
Click a row to view details. For more information, see the Concrete Policies tab.
|
4 |
To see the amount of traffic that has hit each policy: |
5 |
To view information about Kubernetes or OpenShift workloads, click CONTAINER POLICIES. |
What to do next
Choose Monitor > Enforcement Status for status of concrete policies, for example to see if any policies have been skipped. For details, see the Enforcement Status section.