Define an application individually
This topic explains how to manually define an individual application in Illumio Segmentation for the Cloud.
Tip
To automatically define an application with application discovery rules, edit application definitions, or export application definition reports, see Define an Application Automatically.
Prerequisites
Before you define an application, you must onboard at least one cloud account. Defining a deployment is optional. See Define a Deployment.
Define Applications Individually (Manually)
Select Application Discovery > Application Definitions.
Click Add.
A page with the fields to define the application appears.
Enter a name and description (optional) for the application.
This name is what appears in Illumio Segmentation for the Cloud. The name should be descriptive so that you can easily identify it.
Though optional, providing a description helps other members of your organization understand the purpose of this application.
Click Add Resources Using Cloud Metadata.
Cloud metadata contains information about your running cloud resources, including subnets and virtual networks. Cloud obtains your cloud tags directly from your cloud accounts. This data is the label that you assigned to a cloud resource along with an optional tag value.
You do not define your application instances using Illumio Cloud labels. Your applications are defined for Cloud purely based on cloud properties.
The Application Definition dialog box appears.
Choose whether to use cloud tags, virtual networks and subnets, or accounts to define the application.
In the Filter By Cloud Accounts field, select the accounts that are hosting the application resources. Continue selecting accounts until you've specified them all. To clear an account from the field, click backspace or click the X to clear them all.
In the Select field, select the specific tags or metadata (depending on the type you chose) that define the application.
Tip
The list is pre-populated with values that Cloud discovered after you onboarded your cloud accounts. Scroll the list to locate the values you want or type a value in the Select field to filter the list. The list refreshes to show values that match your search criteria.
Add as many tags or metadata to define this application.
Click Add to Selection.
Add as many tags or metadata as needed to define this application.
Important
When adding multiple tags, tag matching between resources and application definitions is performed using logical OR. A resource matches an application definition when it shares one or more tags.
Click Confirm Selection.
The dialog box closes, and your selected tags or metadata appear in the Selected section.
If you restart the steps to add a definition, the existing definition is cleared.
Click the Auto Approve Setting toggle to ON if you want Illumio Segmentation for the Cloud to automatically approve all discovered deployments and resources for this application. This skips the manual approval process for applications.
If you click the toggle to OFF, you must approve the application definition manually. See View and Approve an Application.
Click Save.
The Application Definitions page refreshes and includes the new application: The Deployments column indicates that Illumio Segmentation for the Cloud is discovering any defined deployments that host this application.
When the discovery process finishes, the list includes any deployments where Illumio Segmentation for the Cloud discovered matching cloud tags or metadata.
Illumio Segmentation for the Cloud does not populate the Deployments column if you choose not to define any for that application.
When it finishes discovering your saved application definition, and your application is listed as pending approval, you can still modify the resources defined for the application. For instance, you can add or drop cloud tags in the application definition in such a way that it applies to an additional resource, and Illumio Segmentation for the Cloud the applicationautomatically re-synchronizes to include the new resource. Once an application is approved i.e., no longer pending, any subsequent resource modifications could trigger a new pending approval state for the application deployment.
Edit an Application Definition
You can update or otherwise edit an application you have already defined.
From the Application Discovery > Application Definitions tab, find the application label for which you want to edit the definition.
Click View Details.
Click Edit.
Note
If you change the Auto Approve Setting toggle, you must confirm and save to retain the toggle change.
Delete Individually Created Application Definitions
When you delete applications that are pending approval, Illumio Segmentation for the Cloud deletes the application definitions.
When you delete approved applications, Illumio Segmentation for the Cloud deletes the application definitions and the rulesets (policies) associated with the application definitions and the application instances. Illumio Segmentation for the Cloud also disassociates any related resources from the application definitions being removed.
Delete Individually Created Application Definitions
Select Application Discovery > Application Definitions.
The Applications Definitions page appears and the Application Definitions tab is selected.
Select all the application definitions that you want to delete and click Remove.
Verify that you are deleting the correct applications and click Remove.
Delete Application Discovery Rule-Created Application Definitions
Note
Deleting a discovery rule automatically deletes all application definitions associated with the rule. You can manually delete associated application definitions.
Select Application Discovery > Discovery Rules.
The Application Discovery page appears and the Discovery Rules tab is selected.
For the Application Discovery Rule, select the View Details link.
The Details page for that rule appears.
In the Discovered Application Definitions section of the Details page, select all the application definitions that you want to delete and click Remove.
Verify that you are deleting the correct applications and click Remove.
Note
Illumio recognizes GCP labels under Illumio cloud tags. This means that when you use the tag-to-label mapping feature for GCP, cloud tags appear in the dropdown menu with the relevant prefix indicating they are GCP tags or labels. For example, cloud tags for GCP may have values like label/gcp-key:gcp-value.
Illumio supports GCP resource manager tags and labels at this time. Because GCP label values are optional, you may see empty tag values.
What's Next?
To understand application definitions and how they relate to deployments, see Deployments and Applications.
To approve your application, where each instance of the application in different deployments requires approval, see View and Approve an Application .
To begin creating policy for your application, see Writing Application Policy.