Straza / snapshot distribution

Policy snapshot distribution timeline Activating a PolicySet compiles and signs a content-addressed snapshot; live clients adopt it by pull within about 30 seconds over three lanes: the post-decision pulse, the daemon tick, and checkin. A fail-closed grace boundary denies everything governed if no valid signed snapshot is available. activate admin API · strazactl compile < 2 s @ 10k rules sign ed25519 snapshot id 9f3a…c1 · CBOR store + serve GET /v1/snapshot · ETag CLIENT ADOPTION: PULL, ≤ 30 s t=0 10 s 20 s 30 s ≤ 30 s t=0.0 s busy session post-decision pulsepulse snap 41d2…8csnap 9f3a…c1 next decision after the throttle window idle session daemon tick ~30 sdaemon snap 41d2…8csnap 9f3a…c1 next daemon tick new session checkin · token refreshcheckin (no snapshot)snap 9f3a…c1 fetched at session start fail-closed boundary security layer unreachable + no valid signed snapshot within the grace TTL ⇒ deny everything governed grace TTL: enterprise 0 · standalone 15 min adoption is pull-based plus a push nudge: idle daemons adopt in < 5 s, the tick is the fallback; the < 2 s lever is the session kill switch
Press “activate a policy” to compile, sign and watch the three adoption lanes pick up the new snapshot. Hover any element for its facts.
What this shows

Activating a PolicySet compiles every active set into one snapshot (< 2 s at 10k rules), signs it with the ed25519 snapshot key, and stores it; the snapshot id is the content address of the CBOR blob, served over GET /v1/snapshot with an ETag. Distribution is pull-based, with a push nudge for idle sessions: a busy session adopts it via the detached post-decision pulse (a conditional GET throttled by the client's snapshotLagSeconds, default 30 s; a busy session lags at most one tool call plus that); an idle-but-connected session gets the policy-update push nudge and adopts in under 5 s, with the daemon tick (~30 s) as the fallback when no push reached it; new sessions and token refreshes fetch it at checkin. In every lane the blob is fetched and its signature verified before the session's snapshot id advances. An id alone would brick hooks. If the security layer is unreachable and no valid signed snapshot exists within the grace TTL (enterprise default 0, standalone 15 min), the client fails closed and denies everything governed. When a change must land in under 2 seconds, the lever is the session kill switch, not policy distribution.