Replies: 1 comment 1 reply
-
Applying that tag would open up DRS to ny domain, what I would do is change DRS in the landing project directly. And since org policies are not retroactive, we typically do this by hand via the console, set up the desired configuration, then put DRS back to its initial state. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Far as I can tell the networking stage doesnt have any support for tags?
We have two organizations; one historic, and a newer one where we're implementing FAST. As part of a longer term migration path we want to connect the landing VPC in the FAST org to a VPC in the non-FAST org. We're prevented by default by the DRS org policy (theres an SA in the non-FAST org that needs to read/use a few resources in the FAST org landing VPC).
If I'm reading it all correctly, the "right" approach would be to apply to the
allowed-policy-member-domains-all
tag value to the landing VPC?Beta Was this translation helpful? Give feedback.
All reactions