Run aserto control-plane list instances, take the id field for the Topaz instance you want, then run aserto control-plane exec discovery [Instance-ID] to force an immediate policy image download. A successful call returns nothing, which is normal. Use the same pattern with the directory sync command when directory data changed. Script the list-then-exec sequence rather than hardcoding instance IDs, since they change when instances are recreated.

Context: Official docs (Control Plane CLI guide): documents the command-line gotcha for forcing Aserto policy updates. The aserto CLI can send a discovery command that short-circuits the OPA Discovery timer, but it needs the registered instance ID, which you get from aserto control-plane list instances (the id field in the returned JSON). Agents that try to target the connection name or policy name instead of the instance ID will have the command go nowhere.