Target Clusters
ACM Foil uses ACM Placement to select managed clusters.
The active placement is:
Placement/acm-spo-policies/placement-spo-test
Selection Label
Clusters opt in with:
spo=true
Label a managed cluster:
oc label managedcluster <cluster-name> spo=true --overwrite
Remove a cluster from placement:
oc label managedcluster <cluster-name> spo-
Cluster Set Binding
The overlay binds the default ACM ManagedClusterSet into the policy namespace:
ManagedClusterSetBinding/acm-spo-policies/default
If a target cluster is in another cluster set, either move the cluster or add a matching ManagedClusterSetBinding.
Check a cluster set:
oc get managedcluster <cluster-name> \
-o jsonpath='{.metadata.labels.cluster\.open-cluster-management\.io/clusterset}{"\n"}'
Validate Placement
oc get placementdecision -n acm-spo-policies -o yaml
The decision should include the clusters that have spo=true and belong to a bound cluster set.