OptionalapiAPI version of the policy.
OptionaldescriptionDescription of the policy.
OptionaldisabledWhether the policy is ignored by the Cerbos engine.
OptionalmetadataMetadata about the policy.
The policy body.
OptionalvariablesVariable expressions defined for the policy.
Each variable is evaluated before any rule condition. A variable expression can contain anything that condition expression can have.
Define variables within the policy body instead, provided the Cerbos policy decision point server is at least v0.29 (DerivedRolesBody.variables, PrincipalPolicyBody.variables, or ResourcePolicyBody.variables).
A policy defining rules for actions that can be performed by a given role.