Change a rule safely across levels
A child ruleset overrides what it inherits, within the parent's policy. Tightening loads; loosening is refused at load time.
Large organisations write rules at several levels: the organisation, a business unit, a project.
A child ruleset extends its parent and may change what it inherits through overrides, but only
as the parent allows. A tighten-only parameter may only move in its tightenDirection, and a
tighten-only rule may only get stricter. The check refuses anything else, before it ships.
Hands-on
-
The organisation sets the limit and lets children only lower it:
orders.ruleset.yaml (the parent) params: maxQuantity: type: integer default: 10 overridePolicy: tighten-only tightenDirection: lower -
The EU business unit lowers it to 5. Its scope is the parent's scope plus one level:
orders-eu.ruleset.yaml (the child) scope: - { level: organization, id: shop } - { level: businessUnit, id: eu } extends: - { ruleset: shop.orders, version: ^1.0.0 } overrides: params: maxQuantity: 5Check both. The child's golden tests prove the new limit:
rcas check (real output) $ rcas check orders.ruleset.yaml orders-eu.ruleset.yaml shop.orders@1.0.0 sha256:4583c90bbfca... 2 rules (1 client-safe), 1 params 3 golden tests, 0 failed shop.orders.eu@1.0.0 sha256:b31b76fa5a5b... 2 rules (1 client-safe), 1 params 2 golden tests, 0 failed [exit status 0] -
Try to loosen the limit to 20:
orders-eu.ruleset.yaml (loosened) overrides: params: maxQuantity: 20PARAM_LOOSENED (real output) $ rcas check orders-eu.ruleset.yaml orders-eu.ruleset.yaml: LOAD FAILED PARAM_LOOSENED: shop.orders.eu: param maxQuantity may only move lower [exit status 1] -
Try to lower the severity of the inherited rule to a warning:
orders-eu.ruleset.yaml (rule loosened) overrides: rules: - rule: order.quantity.max set: { severity: warning } reason: The EU team wants large orders to go through with a warning.RULE_LOOSENED (real output) $ rcas check orders-eu.ruleset.yaml orders-eu.ruleset.yaml: LOAD FAILED RULE_LOOSENED: order.quantity.max shop.orders.eu: rule order.quantity.max is tighten-only [exit status 1]Both are refused:
PARAM_LOOSENEDfor the parameter andRULE_LOOSENEDfor the rule. To allow a child to change them, the owner of the parent must change itsoverridePolicy, in a pull request of its own.
Done when
- The child loads and its golden tests pass with the tightened value.
- A loosening override fails the check with
PARAM_LOOSENEDorRULE_LOOSENED. - A change to the parent is followed by a check of every child, because a child's checksum changes with its parent's.
Go deeper
- Multi-level inheritance playbook.
- The lessons Parameters and Rule overrides.