kosa8 docs

Commands / kosa8 label

kosa8 label

Show classification labels and relabel sandboxes

Every sandbox and snapshot can carry a classification label — a level from the org policy's ordered list (UNCLASSIFIED < CUI by default) plus caveats: CUI//SP-EXPT//NOFORN. A label is inherited by every snapshot, restore and fork, can be raised on the way and never lowered, decides which host directories may be mounted and where a snapshot may be pushed or exported, and is marked on kosa8 desk and on every export.

Set one with kosa8 sandbox create --label CUI. See docs/design/labels-and-cui.md for what is enforced and what kosa8 is not.

Subcommands