delonix policy
O tecto de admissão do nó (`kind: RuntimePolicy` / `<root>/policy.json`).
The node's admission ceiling (`kind: RuntimePolicy` / `<root>/policy.json`).
O tecto que este nó impõe no ponto de admissão — antes de um
container run/vm create sequer arrancar. Desde o M04 (ver
docs/roadmap/13-improvements-traceability.md) tem forma declarativa: um
stack apply pode subir ou apertá-lo como qualquer outro Kind convergente
(get runtimepolicies/describe runtimepolicy <nome> mostram o que
está em vigor). O que nunca é automático é BAIXÁ-LO — stack destroy/
apply --prune nunca lhe tocam, mesmo quando o manifesto deixa de o declarar, porque
isso reabriria o nó em silêncio. policy unset é o único verbo imperativo deste grupo, e
é a única forma de o remover.
The ceiling this node enforces at admission — before a
container run/vm create even starts. Since M04 (see
docs/roadmap/13-improvements-traceability.md) it has a declarative form: a
stack apply can raise or tighten it like any other converging Kind
(get runtimepolicies/describe runtimepolicy <name> show what is in
effect). What is never automatic is LOWERING it — stack destroy/
apply --prune never touch it, even when the manifest stops declaring it, because that
would silently reopen the node. policy unset is the group's only imperative verb, and
the only way to remove it.
📄 Implementação real em Rust: cmd/policy.rs
Usage: delonix policy [OPTIONS] <COMMAND>
Commands:
unset Remove the node's security ceiling (`<root>/policy.json`)
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle unset
EXAMPLES:
# what the node currently refuses, if anything
delonix get runtimepolicy
# the full detail — mode, every rule, the file it lives in
delonix describe runtimepolicy node-ceiling
# raise or tighten it declaratively, like any other Kind
delonix stack apply -f examples/full-runtimepolicy.yaml
SEE ALSO:
delonix policy unset · delonix get · delonix describe · delonix stack apply
delonix › policypolicy unset
Remove the node's security ceiling (<root>/policy.json).
The ONLY way it comes down: stack apply --prune/stack destroy never touch it, even when the manifest stops declaring kind: RuntimePolicy — see the module doc. Asks for confirmation on a terminal; --force for scripts.
Usage: delonix policy unset [OPTIONS]
Options:
-f, --force
Skip the confirmation prompt (REQUIRED when stdin is not a terminal)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove the ceiling on a terminal — asks for confirmation first
delonix policy unset
# in a script, where nobody can answer the prompt
delonix policy unset --force
SEE ALSO:
delonix policy · delonix get · delonix describe
delonix › policy › unsetExemplosExamples
delonix policy unsetdelonix policy unset --force