Skip to main content

Policies

Policies are the directives the Enterprise Manager pushes to Stacklok clients. Each directive controls one aspect of client behavior: which MCP registry clients connect to, whether non-registry servers are allowed, where telemetry flows, and what certificates and environment variables MCP containers get.

Available directives

DirectiveUse it to
RegistryEnforce a specific MCP registry URL
Non-registry serversBlock or allow MCP servers that are not in the registry
TelemetryStandardize OpenTelemetry collector configuration
CA certificateInject a custom CA certificate into MCP containers
Build environmentInject environment variables into MCP containers

Enforcement levels

Every policy directive carries an enforcement field with one of two values:

EnforcementMeaning
enforcedMandatory. Clients must use the configured value and cannot override it locally.
defaultAdvisory. Clients use the configured value as a default but may override it locally.

Use enforced when a policy needs to hold firm across the organization, for example in regulated environments or when compliance requires it. Use default when you want to recommend a configuration while still letting individual teams or developers adjust for local needs.

Apply policy changes

After updating enterprise-manager.enterpriseConfig in your Helm values, upgrade the release to push the change to clients:

helm upgrade stacklok-enterprise \
oci://oci.stacklok.com/stacklok-enterprise/<CHANNEL>/stacklok-enterprise-platform \
--version <VERSION> \
--namespace stacklok-system \
--values values.yaml

Clients receive the updated policy the next time they connect to the Enterprise Manager.

Next steps

Pick a directive to configure:

Or read about degraded mode to control how clients behave when the Enterprise Manager is unreachable.