Skip to main content

Security Policy Guide 25.1

Use a Label Group in a Rule

When you use a label group in a rule, it is expanded into multiple rules. Cross-communication is allowed.

For example, the Non-Prod label group is used again here, but in the rule, not the scope, which allows for cross-communication.

Scope:

  • App: HRM

  • Env: All

  • Loc: US

Rule:

  • Providers: Non-prod DB

  • Services: MySQL

  • Consumers: Non-prod DB

This means “allow MySQL from Non-Prod DB to Non-Prod DB for the HRM application in All environments located in the US" and would allow the following communication:

  • HRM | Dev | US | DB ← HRM | Dev | US | DB

  • HRM | Dev | US | DB ← HRM | QA | US | DB

  • HRM | Dev | US | DB ← HRM | Stage | US | DB

  • HRM | QA | US | DB ← HRM | Dev | US | DB

  • HRM | QA | US | DB ← HRM | Stage | US | DB