Set a cluster's tenant policy
Choose which private LAN and tailnet destinations a proxy process may publish from a cluster, and which extra storage classes its volumes may use, in the console or through the API.
A cluster refuses two things until an administrator allows them: a proxy process that publishes a private destination, and a volume on an unfamiliar storage class. The cluster's tenant policy holds both allowlists.
Before you begin
- You have the admin role or higher to change the policy. The viewer role can read it.
- An API token limited to specific projects can't read or write it, because a cluster belongs to the whole organization. See API tokens.
- The cluster is connected. The storage classes it offers appear after its agent reports them.
What the two lists do
| List | An entry is | What it allows |
|---|---|---|
| Upstream allowlist | A CIDR such as 192.168.1.0/24, an address, a host name such as nas.example.lan, or a *.suffix wildcard such as *.tail1234.ts.net | A proxy process may publish a private LAN, CGNAT or tailnet destination that the entry names. Public addresses need no entry. |
| Storage class allowlist | A storage class name | A volume may use that class, besides the cluster's default class and the classes its volumes already use. |
Each list holds at most 256 entries. Saving replaces both lists.
The control plane refuses an entry it can never accept, and the console shows its message as written:
- An address or range that is reserved: loopback, link-local, the metadata address, or the cluster's own pod and service ranges.
- A range broader than
/8. - A host name inside the cluster, such as
*.svcor*.cluster.local. - An entry that is not an address, a CIDR range, a host name or a
*.suffixwildcard.
A host inside the cluster, loopback, link-local and metadata addresses and the cluster's own nodes are refused for every proxy upstream, whatever the allowlist says. See Proxy upstreams.
Edit the policy
Open Clusters, select the cluster, then open Settings > Tenant policy.
Under Upstream allowlist, type an entry and select Add, or press Enter. Remove an entry with the X button beside it.
Under Storage class allowlist, add a class the same way. The classes the agent reported appear under Reported by the agent; select one to add it. Default class and Classes in use are always allowed and need no entry.
Select Save policy. A toast reads Tenant policy saved. If an entry is refused, the alert The tenant policy was not saved shows the reason and the lists in force stay unchanged.
What happens after you save
- A proxy upstream that the new list no longer allows is withdrawn at its next check, within a minute. Its domain answers
503and the release shows thepolicyblocker. See When an upstream is refused. - The storage class check applies when a volume is created. A new volume on a class that the list no longer allows is refused.
Verify
Open Settings > Tenant policy again. Both lists show your entries. A proxy service whose upstream you allowed publishes it at the next check, and its domain stops answering 503. A volume on an allowed class is created without the refusal. If either still fails, see Blocked by a cluster's policy.
Next steps
Set up an edge cluster
Prepare a publicly reachable cluster to serve domains for services that run on another cluster, such as a home-lab cluster behind NAT.
Update a cluster agent
Update the agent that runs in a cluster from the console, roll it back, and re-apply the install manifest when an older cluster needs new permissions.