Deploy Policy Changes
Use web console, Admin SDK, or API. Runtime CLI does not manage policy.
Prerequisites
Section titled “Prerequisites”Record active version, allow/deny cases, Resources/scopes, Grants, Approval behavior, rollback version, and STS/Audit readiness.
Procedure
Section titled “Procedure”- Create version and compile merged bundle.
- Simulate allow, deny, missing-scope, revoked-Session, and Approval cases.
- Activate in a test zone/cohort.
- Poll activation status until
propagation_statusisloadedand STS version matches. - Run canaries and inspect audit.
- Expand only after pass.
Allow the configured STS poll interval for multi-replica convergence.
Verify
Section titled “Verify”Canaries match simulation, STS reports intended bundle, no compile/staleness alert fires, Gateway matches, and audit identifies determining policy.
Rollback or Recovery
Section titled “Rollback or Recovery”Activate the last known-good version and repeat convergence/canaries. Do not edit stored versions or weaken unrelated grants.
Next Step
Section titled “Next Step”Use Upgrade Caracal only for runtime/chart/schema changes.

