Commands / kosa8 label
kosa8 label
Show classification labels and relabel sandboxes
Every sandbox and snapshot can carry a classification label — a level from
the org policy's ordered list (UNCLASSIFIED < CUI by default) plus caveats:
CUI//SP-EXPT//NOFORN. A label is inherited by every snapshot, restore and
fork, can be raised on the way and never lowered, decides which host
directories may be mounted and where a snapshot may be pushed or exported,
and is marked on kosa8 desk and on every export.
Set one with kosa8 sandbox create --label CUI. See
docs/design/labels-and-cui.md for what is enforced and what kosa8 is not.