Repository navigation
Document connector auth types and policies - #1202
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
danbarr
left a comment
There was a problem hiding this comment.
Editorial review assessed against the final stack at #1208 (a9c7827), so this excludes issues later PRs already fix.
Two points remain:
- Distinguish current console choices from API-only authentication types. In
docs/connector-gateway/connector-authentication.mdx, the authentication table calls all eight entries "Console label", including AWS STS, OBO, and XAA. The console selector at both the cited upstreame3da43246and freshly fetcheda11e15735contains only the other five types. Please identify the three API-only types explicitly, avoid presenting prospective labels as current UI, and link to the Enterprise Manager API for configuring them. - Make the policy page an actionable, canonical guide.
docs/connector-gateway/connector-policies.mdxadvertises both structured and Cedar policies, but only explains structured grants. Please add a direct API reference route for Cedar policy management, or narrow the page's stated scope. Coordinate with #1206 so this page owns the complete grant/revoke procedure and connector management links to it. The assembled stack currently repeats grants, inheritance, and Cedar-mode read-only behavior in both pages, while only the connector page covers revocation.
The authentication prerequisite order is useful and should stay.
d5f83bf to
fff0091
Compare
|
Thanks for the review. Both points are addressed, and the stack is restacked on the updated base:
|
|
/update-snapshots |
|
📸 Regenerated visual baselines per your |
Add connector authentication and connector policy pages, and cover transports, private endpoints, API-only fields, and advertised tool names on the connectors page. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses #1202 review comments: - MEDIUM body:auth-labels: identify AWS STS, OBO, and XAA as API-only and link to the Enterprise Manager API Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses #1202 review comments: - MEDIUM body:policy-page: narrow the page to directory group grants, add revoke steps and current console labels, and keep Cedar mode to the console's read-only behavior Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses #1202 review: - body (5419969477): add a direct API route for Cedar policy management Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6a09b5f to
aa5fcc7
Compare
danbarr
left a comment
There was a problem hiding this comment.
Approved from an editorial and information-architecture perspective. The findings from the stack review are addressed in the assembled result: administrator/owner audience, coherent navigation and credential-guide ownership, canonical access instructions, explicit API-only authentication, qualified usage reporting, and lowercase experience descriptions in prose. This approval does not assert live end-to-end validation of the deployment or examples.
Visual regression screenshots
Auto-generated by CI from
scripts/pr-screenshot-summary.mjs— edits inside this block are overwritten on the next push.🟡 Changed
/connector-gatewaydiff
diff
Description
Documents Connector Gateway connector authentication, connector policies, and connector fields, as described in #1178. Stacked on #1201; retarget to
mainafter it merges.New: Configure connector authentication (
connector-gateway/connector-authentication.mdx)awsSts,obo, andxaaare marked API-only, with a link to the Enterprise Manager API.New: Grant and revoke connector access (
connector-gateway/connector-policies.mdx)connectors.mdxCross-links
The sidebar now includes both pages.
two-group-models.mdxlinks to the policy page from its prose and related information. The Connector Gateway index lists auth configuration, and the identity providers page's next steps point to the auth page.Verification
Checked against
stacklok-enterprise-platformorigin/main:ConnectorAuthRequestand arm schemas,ConnectorWriteRequest, policy routes), plusdirectory/domain/models/connector.gofor required fields and constraintsconnector-gateway/internal/infra/vmcp/directory_translate.go(all eight auth types and both transports are servable),docs/architecture.md(SSE deprecation, credential fingerprint), and ADRs 0008, 0012, and 0013connector_policy_service.go(mode switch seeding and reset, 16 KiB limit),policycedar/(schema,claim_prefix, guard rule), anddocs/customer/migrations/connector-policy-directory-evaluation.mdconnector-auth-fields.tsx,create-connector-form-schema.ts,configuration-tab.tsx(locked form),access-tab.tsx,connector-form-fields.tsx, anddiscovered_server.go/mapper.go(private IP recommendation)npm run buildpasses, and Prettier and ESLint are cleanFollow-up, out of scope
This PR leaves out the issue's API-only connector metadata fields (
icon_url,repository_url,support_url,version,draft,origin) and the advertised tool-name format with its rename warning.The console labels connector states Verified, Draft, Verifying, and Broken.
connectors.mdxstill says Available and Failure.Type of change
Related issues/PRs
Part of #1178 and #1175. Stacked on #1201.
Submitter checklist
Content and formatting
Reviewer checklist
Content
🤖 Generated with Claude Code