Operate Policies with the CLI

Deploy, inspect, and evaluate immutable Policies before attaching them to operational boundaries.

Before you begin

Prepare an executable Policy package or existing Policy CRN, representative allowed and denied inputs, and policy:evaluate authority. Keep principal and customer context faithful to production. Put the Resource kind and selector in constal.policy.json; use protected constal.ai/crn rather than a display name when selecting one exact Resource.

Steps

  1. Deploy an executable Policy package through constal deployments create policy.zip and poll publication.
  2. Put the normalized test input in a reviewed file containing action, resource, and optional bounded context.
  3. Evaluate it through the public Policy endpoint:
sh
constal policies evaluate ticket-boundary --body @policy-input.json --output json
  1. Repeat with a negative case and confirm explicit denial and expected constraints.
  2. Inspect the exact Resource set selected by the deployed manifest. Change and redeploy the Policy package when the selector changes; do not create a separate Resource-pattern or attach-everywhere path.
  3. Start a controlled Run and compare its pinned Policy hash with the currently deployed Policy.

The CLI does not provide an “attach everywhere” shortcut. An empty label selector intentionally selects every Resource of the declared kind inside the trusted environment, tenant, and namespace boundary.

Verify

Confirm denied operations stop before external dispatch. Verify an existing Run retains its accepted Policy snapshot unless an authenticated safe-point Policy control changes it. Record the deployment and evaluation output for review.

Next steps

Use Author Policies with the SDK, Operate Policies, and the generated Policies command reference.