Resource → Configure
The Configure tab renders and pushes device configuration to this resource. It appears on resources whose type supports configuration push, once an administrator has bound a configuration stack to the resource with a Config Policy. If no policy targets the resource, the tab reads “No configuration policy targets this resource.”
The templates, stacks, and policies themselves are authored centrally under Govern → Config Policy. This tab is the operator’s side: fill in the per-device values, preview the result, and push.
What you see
The tab lists one card per stack bound to this resource. Each card shows the stack name, the policy it comes from (via {policy name}), and the stack’s description, followed by a form for that stack’s variables — the values the templates leave open (an interface name, an address, a hostname, and so on).
Common tasks
Set the variables
Fill in the variable form on the card. Click Save variables — the button stays disabled until you change something, and enables once there are edits. Saved values persist and are reused on the next push.
Preview the rendered configuration
Click Preview. MisterShell renders the stack against this resource — using its saved variables, facts, and current configuration — and opens a Preview — {stack name} dialog showing the fully rendered configuration exactly as it will be sent, read-only. Any rendering error is shown inline so you can fix a variable or the template before pushing.
Push to the device
From the preview dialog, click Push. (Push is unavailable while variables are unsaved — save them first.) A Pushing — {stack name} dialog opens with a live progress bar that advances as the configuration is applied to the device line by line, with a status message tracking each phase — connecting, enabling (privilege escalation), sending, and settling.
The rendered lines are sent to the device verbatim — exactly what you saw in the preview, nothing added. MisterShell does not enter or leave configuration mode for you: the template itself must include any mode-entry, mode-exit, and save commands the device needs (the template editor’s own hint says the same).
Privilege escalation is automatic when three things hold: the resource type uses an enable mode, the credential carries an enable password, and the device lands on an unprivileged prompt. If the type uses enable mode but the credential has no enable password, the push fails with a clear error before any configuration line is sent.
When the push finishes, expand Device output to read exactly what the device returned, with line breaks preserved. If the push fails, the technical failure details are shown inline in the same dialog, and the card’s status chip reflects the failure.
Review past pushes
Every push is recorded. It appears in this resource’s History timeline as a configuration-push entry; open it to see the stack, status, timestamp, and the configuration that was applied.
Licensing
Configuration workflows are an Enterprise-tier feature. Without the entitlement, the Save variables, Preview, and Push buttons stay visible but disabled, marked with a small lock whose tooltip explains what the license is missing.
Permissions
- Open and use the tab:
app.configure.executecovering the resource’s location. This includes bound stacks, variables, rendering, previews, push and push-result details. There is no read-only Configure tab. - Navigating to the resource still requires
app.resources.read. - Configuration operators do not need
app.configure.read, which controls access to template, stack and policy definitions in Govern. Editing those definitions requiresapp.configure.write.