View and approve an application
This topic explains how to approve an application definition after you've created it. See Define an Application.
Prerequisites
Before you begin, you must onboard your cloud accounts and create an application definition.
Why is Approval Required?
After you define an application, it appears in the Application Definitions list. First, if you have defined a deployment, Illumio discovers any environments where the application is running. See Illumio Discovers Your Application Environments.
When the discovery process finishes, the list will include any deployments where Illumio discovered matching cloud tags or metadata.
Note
The Application Definition page lets you toggle whether you want Illumio Segmentation for the Cloud to automatically approve all discovered applicable deployments and resources. Similarly, the Application Discovery Rule page lets you toggle whether you want Illumio Segmentation for the Cloud to automatically approve all discovered application definitions, as well as any updates made to their deployments and resources. See the Define an Application documentation on the portal.
Note
Either of these methods will skip the manual approval process for applications as described here.
For application definitions that are not automatically approved, you can see that each of the application instances needs to be approved; meaning, you've defined an application, but the status is still Pending Approval. In this way, Illumio ensures other key stakeholders are in the loop to approve your application definitions.
Illumio will not populate the Deployments column if you choose not to define any deployments for that application.
Approve a Given Application Definition
Select Application Discovery > Application Definitions.
The list of defined applications appears.
Select the application that you want to review and/or approve.
Note
If you select one application definition, it will allow you to approve it if it is pending approval. If you select more than one application, the Approve button will be grayed-out because bulk application approval is not supported.
Click Approve.
Verify that you are approving the correct application and click Confirm.
The Approval Status column updates to indicate that the application definition has been approved. The application is added to the applications displayed on the Applications page. You can create a policy for that application.
Approve Application Deployments and Resources in Bulk
You can have a single application that has multiple resources or deployments, such as staging and production. For example, you could have two application definitions associated with that application, one for each deployment. Illumio Segmentation for the Cloud lets you approve two or more such application deployments in bulk.
Select Application Discovery > Application Definitions.
Select the application that you want to review and/or approve.
Click Approve.
Select the checkboxes for the deployments and resources you want to approve.
For example, you can choose an AWS us-west -1 resource for staging and production, but not development.
Verify your selections and click Confirm.
Illumio will create the approved definitions for that application based on the deployments and resources you selected. Using the above example, you would have two approved definitions for the application, one using the staging deployment and the other using the production deployment.
Illumio Segmentation for the Cloud does not let you bulk-approve application definitions that are based on different applications.
Viewing Application Information
After you have approved an application, you can view details about the application. When you click on an application, you will see the following tabs for that application:
Summary: This provides general information about the application, such as the name, owners, the cloud accounts associated with the application, whether it was created manually or with a specific discovery rule, and resources by deployment.
This circle graph indicates service categories, service roles, resources, security controls, and firewall rules.
Click on the graph to see details, such as the security control count. The security control count for each resource is the total number of Security Groups, Network Security Groups, and Network ACLs associated directly with the resource and its subnet.
Inventory: An application-specific view of what you would see on the Inventory page.
See Inventory.
Traffic: An application-specific view of what you would see on the Traffic page.
See Traffic.
Map: An application-specific view of what you would see on the Cloud Map page.
See Cloud Map.
Policy: A list of active policies for the application.
See Cloud Policy Model.
Exporting an Application Report
Click Export on the Applications page.
Edit the report name and select the format.
Click the Scheduling Section toggle to the on position to schedule the export, unless you want to export the report immediately.
To schedule your report, select your recurrence and time.
Click Save.
Go to the Reports page to download the exported report.
Map your Cloud Tags
After you have approved an application, you can map your cloud tags to Illumio labels and write policy rules for it. Although mapping cloud tags to Illumio labels is not required to create policies, it will help you to make your policies specific.