Repository navigation
Correct Connector Gateway claims and stale API spec - #1201
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
danbarr
left a comment
There was a problem hiding this comment.
Approving from an editorial/IA POV; technical updates could use peer review.
danbarr
left a comment
There was a problem hiding this comment.
Reviewed editorially as part of the seven-PR stack, including the assembled result at #1208 (a9c7827). My earlier editorial/IA assessment still stands: correcting the Connector Gateway feature claims and explaining the real discovery and policy behavior are useful improvements.
I also verified that the published Connector Gateway API spec is a byte-for-byte match for the upstream file at the cited e3da43246 revision. I have no additional editorial findings specific to this PR. This is not a blanket technical validation of the Helm deployment instructions; I did not run them against a live cluster.
The remaining page-level findings are on their owning PRs, with the combined navigation and reader-journey assessment on #1208.
f2d72be to
ede5fc7
Compare
Replace vMCP features in the platform landing table, describe the discovery admit flow, document structured and Cedar connector policy modes, and regenerate the Connector Gateway API spec from upstream without the retired per-user connector routes. Add the spec to the release-sync assets so it doesn't drift again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ede5fc7 to
c7edaaa
Compare
danbarr
left a comment
There was a problem hiding this comment.
Approved from an editorial and information-architecture perspective. The findings from the stack review are addressed in the assembled result: administrator/owner audience, coherent navigation and credential-guide ownership, canonical access instructions, explicit API-only authentication, qualified usage reporting, and lowercase experience descriptions in prose. This approval does not assert live end-to-end validation of the deployment or examples.
Description
Fixes public Connector Gateway pages that contradicted current product behavior, and the stale published API spec.
Platform landing page (
docs/platform/index.mdx)The Connector Gateway feature table listed composite tools, tool filtering, and context-bloat reduction, which are vMCP features. Replaced them with gateway features: per-user connector access with directory groups or Cedar policies, credentials brokered on each user's behalf, and cluster discovery.
Connector Gateway API spec
static/api-specs/connector-gateway-api.jsonis now a byte-for-byte copy of upstreamenterprise/connector-gateway/docs/openapi/swagger.json. That drops the four retired per-user connector-config routes (GET /v1/users/me/gateway/connectorsandGET/PUT/DELETE .../connectors/{connector_id}) and their schemas.api-reference.mdx: the blurb now describes what remains (the caller's gateway view, connection status, connect flow, tools) and points to the Enterprise Manager's/v1/me/connectionsroutes for enabling connectors..github/upstream-projects.yaml: added the spec as asource:asset on thestacklok-enterprise-platformproject, matching how its CRDs are sourced. Tested withsync-assets.mjs --cloneagainst a local clone. Since that project has noversion:pin yet, the workflow won't trigger on its own until the platform ships releases.Discovery (
connectors.mdx)Replaced "picks up MCP servers running in your cluster automatically" with the actual flow. Add connector opens a chooser (Import from registry, Discover in Kubernetes, Configure manually). Discovery lists every
MCPServeras a candidate, marks ones already Already added as a connector, and registers nothing until the admin chooses Add to catalog. Admitted servers become drafts with no backend auth, which publish on first save.Connector access (
connectors.mdx,two-group-models.mdx, plus one-line fixes inconnector-gateway/index.mdxandenterprise-directory/index.mdx)Connector access was described as directory-groups only. The pages now explain the structured and Cedar policy modes, that Cedar documents can match
UserGroupmembership orprincipal.claim_*token claims, and that the console doesn't edit Cedar-mode policies (it shows a notice and disables group editing). The group-models table splits connector access by mode, and that page has a note that Cedar-mode policies are API-only. Full policy docs are left to #1178.Verification
Checked against
stacklok-enterprise-platformorigin/main:discover-connectors-dialog.tsx,add-connector-dialog.tsx,admitDiscoveredServersinconnectors-admin/actions.ts, anddiscovered_server_service.godocs/customer/migrations/connector-policy-directory-evaluation.md,directory/app/claims.go(theclaim_prefix), andaccess-tab.tsx(Cedar-managed notice)npm run buildpasses, and Prettier and ESLint are clean on the changed filesType of change
Related issues/PRs
Closes #1177 (part of #1175). Follows #1180.
Submitter checklist
Content and formatting
Reviewer checklist
Content
🤖 Generated with Claude Code