Skip to main content

Security Policy Guide 25.2.10

Label Types

Label

Description

Role

role_label.png

This label type allows you to describe the “role” (or function) of a workload. In a simple two-tier application consisting of a web server and a database server, there would be two roles: Web and Database. You can use the same role as many times as you want in other rulesets for different applications.

Application

app_label.png

This label type allows you describe the application that a workload supports. When two servers in a two tier application have a relationship with one another because one provides a service (like a database) to another, they likely constitute an application.

If an organization has 100 applications, and each application has a separate web role and separate database role, the application role separates each one of the Web and Database role.

Environment

env_label.png

This label type allows you to describe a workload based upon its stage in the product development lifecycle, such as QA, staging and production.

Location

location_label.png

This label type allows you to describe a workload based on its location. For example, Germany, the US, Europe, and Asia. Or, Rack #3, Rack #4, Rack #5; or data center AWS-east1, AWS-east2, and so on.

Additional Dimensions

A given workload cannot have more than one label per type. It’s possible to allow a workload that uses a service or services or across boundaries to communicate; for example, if a server is playing multiple roles, such as a database server used by two different applications, Illumio recommends that you create different role labels for that workload.