delete_dfw_policy
Delete a DFW security policy after previewing its blast radius and obtaining confirmation. Refuses deletion if the policy still contains rules.
Instructions
[WRITE] Delete a DFW security policy; refuses while it still holds rules.
Without confirm=True this only previews: it returns blast_radius (the policy's name, category, sequence_number, rule_count and rule_ids, blockers, unmeasured) and deletes nothing. Show that to the user and get their decision. Do not set confirm=True on your own because the user asked to delete earlier: they have not seen the blast radius yet.
confirm=True refuses, deleting nothing, while the policy still holds rules — list them with list_dfw_rules and clear each with delete_dfw_rule first — or when its rules could not be read. Returns {"action": "preview" | "deleted", "blast_radius": ...}, else {"error", "hint", "blast_radius"?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | Optional NSX Manager target from config. | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| policy_id | Yes | ID of the policy to delete. |