← all policies/chhhee10/cost-guard
━━ data
block-whole-bucket-recursive-copy
Refuse a recursive copy or sync whose source is a whole bucket
━━ when it runs
PreToolUsebefore the tool call runs. a denial here means the command never executes at all.
watchesevery tool the event fires for — not narrowed to particular tools
this pack enforces: a match returns a real denial rather than being recorded and discarded. what the denial then does depends on the event above.
━━ install
this one is on by default — taking the pack without flags turns it on, and the picker shows it pre-ticked.
- just this policy
- the whole pack
- turn just this off
- pick from a list
- uninstall the pack
ships in chhhee10/cost-guard · v4e133099d12a · source ↗
━━ also in data
- block-cross-region-bucket-transferRefuse a bucket-to-bucket copy whose two ends are in different regions
- block-whole-database-export-or-restoreRefuse a full dump of a managed database, or a snapshot restore into a new instance
- block-unbounded-storage-retentionRefuse multi-year log retention and replication rules; flag versioning with no expiry rule