Control Plane
Aserto Edge Authorizers can connect to the Aserto Control Plane to receive policy and directory updates and commands. Edge authorizers must use client certificates from Edge Authorizer connections to connect to the Control Plane.
Configuration
The Aserto CLI can be used to configure certificates. The list connections
sub-command lists a tenant's existing
Edge Authorizer connections:
aserto control-plane list connections
Each of the listed connections has an id
field, which can be used to retrieve certificate data, including the
certificate and private key:
aserto control-plane get certificates <edge-authorizer-connection-id>
For more details on how to configure the certificate see the edge authorizers section of this documentation.
Commands
To list the Edge Authorizer instances connected to the Control Plane:
aserto control-plane list instances
Each entry in the resulting list will have an id
field, a policy-id
field indicating what policy instance the edge
is configured to run and a remote_host
field which can be used to identify the individual edge instance. The value of
the latter is the $HOSTNAME
environment variable of the edge host, and will be overridden with the $ASERTO_HOSTNAME
environment variable, if it exists.
The discovery
sub-command causes an Edge Authorizer to immediately fetch configuration from the Control Plane.
aserto control-plane exec discovery <instance-registration-id>
The exec edge-sync
sub-command causes an Edge Authorizer to immediately synchronize its local directory state (if
synchronization is enabled).
aserto control-plane exec edge-sync <instance-registration-id>