@@ -153,7 +153,7 @@ Policies define severity thresholds that govern whether a stack can deploy. A po
See [Deploy Enforcement](/features/deploy-enforcement) for the full pre-flight flow, admin bypass path, and audit-log behavior.
-
+
### Creating a policy
@@ -246,6 +246,10 @@ Full scans take longer than vulnerability-only scans because Trivy reads every f
Beyond package CVEs, Sencho can run `trivy config` against a stack's Compose file to flag insecure defaults before you deploy. Typical checks cover privileged containers, missing resource limits, host networking, mounted Docker sockets, and overly broad capabilities.
+- Manage enforcement policies on the Policies tab. This is a read-only posture for the active node. + {isPaid ? 'Manage enforcement policies on the Policies tab. ' : ''}This is a read-only posture for the active node.
- Policy packs could not be loaded. -
- ); - } - - if (!packs) { - return ( -- Policy packs are curated security expectations for a deployment posture. Packs are advisory in - Community: they explain what good looks like. Block-on-deploy enforcement is an Admiral capability. -
- -{pack.tierCopy}
-