Govern → Config Policy
Config Policy is where you author device configuration once and push it to many resources. You write reusable configuration templates, group them into ordered stacks, and bind a stack to a set of resources with a policy. The values that differ per device are declared as variables and filled in on each resource’s Configure tab before you push.
Config Policy is one tab of the Policies area, alongside Session Policy, Fact Policy, Syslog Policy, and IDS Policy. The tab has three views, selected with the toggle in its toolbar:
- Rules — bind a stack to resources (the default view).
- Templates — author individual configuration templates.
- Stacks — group templates into an ordered set that is pushed as one.
The natural authoring order is the reverse: build Templates, group them into a Stack, then bind that stack with a Rule.
Author a template (Templates view)
- Click Create Template. In Create Config Template, give it a Name and choose a Renderer engine (currently Jinja2). The renderer is fixed once the template is created — it determines which resources the template can render against and push to.
- The template opens in the authoring workspace. At the top are the Name, the read-only Renderer, and a Description of what the template configures. The workspace has two panes.
Template body (left pane) is the editor for the configuration itself.
Rendered lines are sent to the device verbatim, so include any mode or save
commands the device needs — for example conf t … end, then write memory.
Privileged (enable) mode is entered automatically when the resource’s
credential provides an enable password.
The right pane has three tabs:
- Preview — pick a Reference resource (only configuration-capable resources appear) and click Render to see the Rendered output for that device. If the template defines variables, a Variable values for this preview form lets you try values. Errors are reported inline.
- Variables — declare the values that differ per device. Click Add
variable and set its Variable name (used in the body as
vars.<name>), Type (String, Integer, Boolean, IP address, or Choice), Display label, Default value, Help text, and a Required toggle. Choice variables also take a comma-separated Choices list. Variables prompt for a value before preview and push. - Inputs — a catalog of the data you can reference in the body, grouped as
Resource info (
info.*), Facts (facts.*), Current config (config.*), and Variables (vars.*). Clicking an entry inserts its{{ … }}token at the cursor. You can drill into facts with dot notation, e.g.{{ facts.system_ntp.servers }}.
Click Save to store the template. The Templates table lists each template’s name, description, renderer, and variable count. A template that a stack references cannot be deleted.
Group templates into a stack (Stacks view)
A stack is an ordered set of templates pushed as one configuration.
- Click Create Stack and give it a Name and optional Description.
- Under Member templates (rendered top to bottom), add templates and drag them into the order you want them applied. All members of a stack must share the same renderer — the first member you add fixes it.
The Stacks table lists each stack’s name, description, and member count. A stack that a policy references cannot be deleted.
Bind a stack to resources (Rules view)
A policy binds one stack to the resources it should apply to.
- Click Create Policy and set a Name, the Stack to push, and the Enabled toggle.
- Narrow the target with three selectors — Resource Types, Locations, and Tags. Leave a selector empty to match any value for that dimension; an empty selector shows an Any chip. With every selector empty, the policy targets any configuration-capable resource.
Each matching resource then shows the stack on its Configure tab, where an operator fills in the variables and pushes. Every push is recorded in the resource’s History timeline, and an automation action can push a stack in response to an event.
Permissions
- View template, stack and policy definitions:
app.configure.read. - Render or preview against a resource:
app.configure.executefor that resource’s location, including previews in the template editor. - Create / edit / delete templates, stacks, and policies:
app.configure.write. - Push a rendered stack to a device:
app.configure.execute— see the Configure tab.
Config Policy is an Enterprise feature: without that edition the create/edit buttons on all three views show a lock. Existing templates, stacks, and policies remain visible.