Guardrail policies
Guardrail policies in Facets enforce security and compliance on blueprints using Rego, with Warning or Error severity that can gate releases.
Guardrail policies enforce your security, compliance, and operational standards on blueprints. You write the rules in Rego, scope them to the resources they apply to, and set a severity that decides whether a violation warns or blocks the release. This keeps blueprints aligned with best practices as they grow, without re-stating the same rule everywhere.
To create one, see Creating a guardrail policy.
Creating and managing policies
Manage guardrail policies from the Settings > Guardrails page: create, edit, and remove them there. Policy names are unique across the control plane.
A policy gets its enforcement logic one of two ways: write the Rego yourself, or start from a template, a policy framework the control plane ships with named inputs to fill in. raptor get policy-templates lists the templates available to you, and raptor get guardrail-policies lists the policies already in place.
Scoping a policy
Scope a policy to a single blueprint and to one or more environments, resource types, and resources. This gives you fine control: enforce a policy on a single resource in a blueprint, or on a chosen set of resources within a particular environment.
Severity
Every policy is Warning or Error. A Warning flags a violation but lets the release continue; an Error blocks the release until the violation is resolved. Alerts for both are on the Guardrails page.
Where violations surface
When a policy is broken, the violation appears as a GuardRails compliance issue in the Validation panel on the Releases page, alongside the other pre-release checks. An Error-severity violation blocks the release there until it is resolved; a Warning is reported but does not block. Policy enforcement is also recorded in logs that account for each violation and the action taken.
FAQ
What is Rego? Rego is a declarative language for expressing and enforcing policy. It evaluates queries against JSON data, which suits access control, data filtering, and resource-allocation rules.
Why Rego? It is the policy language of Open Policy Agent (OPA). Its declarative style prioritises query outcomes and reads well against structured documents like JSON, so you focus on the desired result rather than the execution steps.
How do I write and test Rego? See the Rego policy language reference, and experiment in the Rego Playground.
Where do I view guardrail validations? In the Validation panel on the Releases page, listed as GuardRails compliance issues.
Can I enable or disable a policy? Yes, with the toggle on the Settings > Guardrails page. From the CLI, raptor enable guardrail-policy NAME and raptor disable guardrail-policy NAME, both of which take more than one name at a time.
Can I clone a policy? Yes, with the clone icon under Actions on the Settings > Guardrails page.
What happens on a compliance issue during validation? Any issue with ERROR severity blocks the release until it is resolved. Warnings do not block.
Parallel releases
Parallel releases run multiple non-conflicting selective releases at once in the same environment, across every resource type, with queuing or state-lock handling.
Creating a Guardrail Policy
Step-by-step guide to creating a guardrail policy in Facets: set severity, scope it to blueprints and resources, and add Rego enforcement code.