Manage connector policies
Each connector has a connector policy that decides which users can reach it. The Connector Gateway evaluates the policy on every request, so a change takes effect on the caller's next request.
A connector policy has two authoring modes:
| Mode | Grants access by | Managed in |
|---|---|---|
| Structured | Directory group membership | Console or API |
| Cedar | A Cedar policy document that matches directory groups, token claims, or both | API only |
Every connector starts in structured mode.
Grant access to directory groups
In structured mode, the policy lists the directory groups that can reach the connector. A connector with no groups is unreachable.
- In the console, open the connector and select the Access tab.
- Use Grant access to add one or more groups.
Membership is inherited, so granting to a parent group reaches every subgroup beneath it. Directory groups are separate from the OpenID Connect (OIDC) claim groups that cluster authorization policy matches. See Directory groups and OIDC claim groups.
For a Cedar-mode connector, the console shows a notice on the Access tab and disables group editing.
Next steps
- Configure connector authentication to set the credential the gateway sends to the backend.
- Tool usage to confirm the right users are calling the connector.
Related information
- Directory groups and OIDC claim groups - how connector policies relate to cluster authorization groups
- Users and groups - manage the directory groups that policies reference