Skip to content
NebulaCtrldocs
Guides

Set a cluster's tenant policy

Choose which private LAN and tailnet destinations a proxy process may publish from a cluster, and which extra storage classes its volumes may use, in the console or through the API.

A cluster refuses two things until an administrator allows them: a proxy process that publishes a private destination, and a volume on an unfamiliar storage class. The cluster's tenant policy holds both allowlists.

Before you begin

  • You have the admin role or higher to change the policy. The viewer role can read it.
  • An API token limited to specific projects can't read or write it, because a cluster belongs to the whole organization. See API tokens.
  • The cluster is connected. The storage classes it offers appear after its agent reports them.

What the two lists do

ListAn entry isWhat it allows
Upstream allowlistA CIDR such as 192.168.1.0/24, an address, a host name such as nas.example.lan, or a *.suffix wildcard such as *.tail1234.ts.netA proxy process may publish a private LAN, CGNAT or tailnet destination that the entry names. Public addresses need no entry.
Storage class allowlistA storage class nameA volume may use that class, besides the cluster's default class and the classes its volumes already use.

Each list holds at most 256 entries. Saving replaces both lists.

The control plane refuses an entry it can never accept, and the console shows its message as written:

  • An address or range that is reserved: loopback, link-local, the metadata address, or the cluster's own pod and service ranges.
  • A range broader than /8.
  • A host name inside the cluster, such as *.svc or *.cluster.local.
  • An entry that is not an address, a CIDR range, a host name or a *.suffix wildcard.

A host inside the cluster, loopback, link-local and metadata addresses and the cluster's own nodes are refused for every proxy upstream, whatever the allowlist says. See Proxy upstreams.

Edit the policy

Open Clusters, select the cluster, then open Settings > Tenant policy.

Under Upstream allowlist, type an entry and select Add, or press Enter. Remove an entry with the X button beside it.

Under Storage class allowlist, add a class the same way. The classes the agent reported appear under Reported by the agent; select one to add it. Default class and Classes in use are always allowed and need no entry.

Select Save policy. A toast reads Tenant policy saved. If an entry is refused, the alert The tenant policy was not saved shows the reason and the lists in force stay unchanged.

What happens after you save

  • A proxy upstream that the new list no longer allows is withdrawn at its next check, within a minute. Its domain answers 503 and the release shows the policy blocker. See When an upstream is refused.
  • The storage class check applies when a volume is created. A new volume on a class that the list no longer allows is refused.

Verify

Open Settings > Tenant policy again. Both lists show your entries. A proxy service whose upstream you allowed publishes it at the next check, and its domain stops answering 503. A volume on an allowed class is created without the refusal. If either still fails, see Blocked by a cluster's policy.

Next steps

On this page