mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 08:27:53 +00:00
Merge pull request #3585 from Infisical/ENG-2748
feat(docs): Self approval
This commit is contained in:
@@ -6,7 +6,7 @@ description: "Learn how to enable a set of policies to manage changes to sensiti
|
|||||||
<Info>
|
<Info>
|
||||||
Approval Workflows is a paid feature.
|
Approval Workflows is a paid feature.
|
||||||
|
|
||||||
If you're using Infisical Cloud, then it is available under the **Pro Tier** and **Enterprise Tire**.
|
If you're using Infisical Cloud, then it is available under the **Pro Tier** and **Enterprise Tier**.
|
||||||
If you're self-hosting Infisical, then you should contact [email protected] to purchase an enterprise license to use it.
|
If you're self-hosting Infisical, then you should contact [email protected] to purchase an enterprise license to use it.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
@@ -33,6 +33,10 @@ First, you would need to create a set of policies for a certain environment. In
|
|||||||
|
|
||||||
The enforcement level determines how strict the policy is. A **Hard** enforcement level means that any change that matches the policy will need full approval prior merging. A **Soft** enforcement level allows for break glass functionality on the request. If a change request is bypassed, the approvers will be notified via email.
|
The enforcement level determines how strict the policy is. A **Hard** enforcement level means that any change that matches the policy will need full approval prior merging. A **Soft** enforcement level allows for break glass functionality on the request. If a change request is bypassed, the approvers will be notified via email.
|
||||||
|
|
||||||
|
### Self approvals
|
||||||
|
|
||||||
|
If the **Self Approvals** option is enabled, users who are designated as approvers on the policy can approve requests that they themselves have submitted.
|
||||||
|
|
||||||
### Example of creating a change policy
|
### Example of creating a change policy
|
||||||
|
|
||||||
When creating a policy, you can choose the type of policy you want to create. In this case, we will be creating a `Change Policy`. Other types of policies include `Access Policy` that creates policies for **[Access Requests](/documentation/platform/access-controls/access-requests)**.
|
When creating a policy, you can choose the type of policy you want to create. In this case, we will be creating a `Change Policy`. Other types of policies include `Access Policy` that creates policies for **[Access Requests](/documentation/platform/access-controls/access-requests)**.
|
||||||
@@ -41,10 +45,18 @@ When creating a policy, you can choose the type of policy you want to create. In
|
|||||||
|
|
||||||
### Example of updating secrets with Approval workflows
|
### Example of updating secrets with Approval workflows
|
||||||
|
|
||||||
When a user submits a change to an enviropnment that is under a particular policy, a corresponsing change request will go to a predefined approver (or multiple approvers).
|
When a user submits a change to an environment that is under a particular policy, a corresponding change request will go to a predefined approver (or multiple approvers).
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Approvers are notified by email and/or Slack as soon as the request is initiated. In the Infisical Dashboard, they will be able to `approve` and `merge` (or `deny`) a request for a change in a particular environment. After that, depending on the workflows setup, the change will be automatically propagated to the right applications (e.g., using [Infisical Kubernetes Operator](https://infisical.com/docs/integrations/platforms/kubernetes)).
|
Approvers are notified by email and/or Slack as soon as the request is initiated. In the Infisical Dashboard, they will be able to `approve` and `merge` (or `deny`) a request for a change in a particular environment. After that, depending on the workflows setup, the change will be automatically propagated to the right applications (e.g., using [Infisical Kubernetes Operator](https://infisical.com/docs/integrations/platforms/kubernetes)).
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
## FAQ
|
||||||
|
|
||||||
|
<AccordionGroup>
|
||||||
|
<Accordion title="Is it possible to disable self-approval for policies?">
|
||||||
|
Yes, if you'd like to require an approval from an approver other than the one who created the request, then you can disable the **Self Approvals** feature inside of your target policy.
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 43 KiB After Width: | Height: | Size: 133 KiB |
Reference in New Issue
Block a user