How it works
Applications, environments and token scope
Tokens carry an application and environment, and rules and waivers can apply to just those.
Every token can belong to one application and one environment, like storefront in production. ForgeRepo™ reads the scope only from the token, never from anything the client sends, so it cannot be faked.
- A rule with an application or environment only applies to tokens in that scope. A rule with neither applies to everyone.
- At the same priority, a scoped rule beats a rule for everyone.
- A request with no token only gets rules that apply to everyone.
- Waivers can be scoped the same way, except license waivers, which always apply to everyone.
- The traffic log, Consumers and the SBOM export group downloads by application and environment.
- Open Settings, then the Applications tab, and add the applications and environments you use. Tick Production on production environments.
- On Tokens, set the application and environment of each pipeline token. Only admins can change these.
- Write scoped rules on Rules with Only for application and Only in environment.
Tip
Use one token per application per environment. A token shared by two applications can only name one of them, and the traffic log will blame the wrong team.
Lifecycle stages
With Enforce lifecycle stages on (Settings, Policy), a production environment only gets versions promoted to the production stage on the Artifacts page, and a version at the blocked stage is refused to everyone. Lifecycle can only take away an allow, never add one.