Rule Cascade
LearnThe process, end to end

Change a rule safely across levels

A child ruleset overrides what it inherits, within the parent's policy. Tightening loads; loosening is refused at load time.

Large organisations write rules at several levels: the organisation, a business unit, a project. A child ruleset extends its parent and may change what it inherits through overrides, but only as the parent allows. A tighten-only parameter may only move in its tightenDirection, and a tighten-only rule may only get stricter. The check refuses anything else, before it ships.

Hands-on

  1. The organisation sets the limit and lets children only lower it:

    orders.ruleset.yaml (the parent)
    params:
      maxQuantity:
        type: integer
        default: 10
        overridePolicy: tighten-only
        tightenDirection: lower
  2. The EU business unit lowers it to 5. Its scope is the parent's scope plus one level:

    orders-eu.ruleset.yaml (the child)
    scope:
      - { level: organization, id: shop }
      - { level: businessUnit, id: eu }
    
    extends:
      - { ruleset: shop.orders, version: ^1.0.0 }
    
    overrides:
      params:
        maxQuantity: 5

    Check both. The child's golden tests prove the new limit:

    rcas check (real output)
    $ rcas check orders.ruleset.yaml orders-eu.ruleset.yaml
    shop.orders@1.0.0  sha256:4583c90bbfca...  2 rules (1 client-safe), 1 params
      3 golden tests, 0 failed
    shop.orders.eu@1.0.0  sha256:b31b76fa5a5b...  2 rules (1 client-safe), 1 params
      2 golden tests, 0 failed
    [exit status 0]
  3. Try to loosen the limit to 20:

    orders-eu.ruleset.yaml (loosened)
    overrides:
      params:
        maxQuantity: 20
    PARAM_LOOSENED (real output)
    $ rcas check orders-eu.ruleset.yaml
    orders-eu.ruleset.yaml: LOAD FAILED
      PARAM_LOOSENED: shop.orders.eu: param maxQuantity may only move lower
    [exit status 1]
  4. Try to lower the severity of the inherited rule to a warning:

    orders-eu.ruleset.yaml (rule loosened)
    overrides:
      rules:
        - rule: order.quantity.max
          set: { severity: warning }
          reason: The EU team wants large orders to go through with a warning.
    RULE_LOOSENED (real output)
    $ rcas check orders-eu.ruleset.yaml
    orders-eu.ruleset.yaml: LOAD FAILED
      RULE_LOOSENED: order.quantity.max shop.orders.eu: rule order.quantity.max is tighten-only
    [exit status 1]

    Both are refused: PARAM_LOOSENED for the parameter and RULE_LOOSENED for the rule. To allow a child to change them, the owner of the parent must change its overridePolicy, in a pull request of its own.

Done when

  • The child loads and its golden tests pass with the tightened value.
  • A loosening override fails the check with PARAM_LOOSENED or RULE_LOOSENED.
  • A change to the parent is followed by a check of every child, because a child's checksum changes with its parent's.

Go deeper

Course overview

On this page