Configuration ownership

Clearplane gives the UI/API model and Docker-label model equal importance. They feed the same persisted routing and policy model, but every resource keeps the source that owns it.

UI and REST API ownership

Resources created through the UI or REST API are UI/API-owned. They remain editable and removable through either interface, subject to authorization and validation.

The UI and REST API are two interfaces to the same ownership source. A resource created through one does not become a different kind of runtime resource when it is later edited through the other.

Management API grid responses contain list summaries. Retrieve the resource’s full configuration through its detail endpoint before editing; a grid row does not contain the complete configuration needed for an update.

Docker-label ownership

Container discovery creates label-owned routes, clusters, destinations, inline policies, and each route's policy states and assignments. These resources are visible in the UI with their source, but are read-only there. Edit the labels on the owning container instead. A label-owned WAF policy keeps its disabled rules, target exclusions and per-ruleset thresholds editable, because labels cannot address individual rules.

When discovery accepts a label change, it reconciles the complete owned resource graph. An invalid or conflicting candidate is reported as a discovery issue and the previous valid graph remains in place.

Removing every clearplane.* discovery label from a container deletes its label-owned proxy route or standalone redirect, cluster, destinations, and inline policies. An issued certificate remains available under UI/API ownership. Setting the route's enable label to false, removing only that enable label while other Clearplane labels remain, or stopping the container disables the route without deleting its owned graph.

Resource groups

Resource groups organize routes, clusters, certificates, ACME DNS profiles, access control policies and aliases, rate limit policies, auto-ban policies, CORS policies, authentication policies, request headers and response headers policies, WAF policies, and WAF rulesets.

Pages for these resources show one section per group that contains resources, followed by Ungrouped. The search box above the sections filters every section at once and hides sections without matches. Turn off Group by resource group to list the page's resources in one table instead. Clearplane saves that choice per page for your account, so it follows you across browsers.

Logs, bans, audit, metrics, background jobs, and settings are operational pages and do not use resource groups.

Hybrid configuration

You can use both models in one Clearplane installation. For example, application teams can publish services with Docker labels while operators manage shared policies through the UI or REST API.

Ownership remains per resource. Clearplane does not silently convert a label-owned resource into UI/API ownership, and recreating the same resource in another source does not override its owner. To change ownership, remove the original definition and create its replacement through the intended source.

Use the source badge and locked-field state in the UI to identify where a change belongs. Then follow Change and apply configuration to verify when it becomes effective.