Integrations Overview
How NetSeed connects to identity providers, device trust signals, and security event pipelines. Covers the integration model and what each connection point does.
Contact engineeringThree tracks: product reference for understanding how each component works, guides for common deployment and integration tasks, and API reference for building on top of the control plane.
These docs explain how each part of NetSeed works — integration points, configuration model, and the behavior of each component.
How NetSeed connects to identity providers, device trust signals, and security event pipelines. Covers the integration model and what each connection point does.
Contact engineeringOIDC configuration, group-based policy mapping, user lifecycle, and directory sync. How identity flows from your IdP into access decisions.
Contact engineeringHow device trust signals are evaluated as part of access decisions. Managed device conditions, compliant device requirements, and device-based policy rules.
Contact engineeringPer-flow audit record format, streaming destinations, HTTP endpoint configuration, object storage export, and SIEM integration patterns.
Contact engineeringCloud-managed, self-hosted, and hybrid deployment options. Component placement, control plane configuration, and operational requirements for each model.
Contact engineeringGuides cover the most frequent deployment and integration workflows — each one takes you from start to a working configuration.
Configure OIDC federation between your IdP and NetSeed. Map directory groups to access policies. Verify that authentication and group sync work end to end.
Contact engineeringDeploy NSN alongside a private service. Configure the service record in NSD. Verify that authenticated clients can reach the service by name and that unauthorized flows are dropped.
Contact engineeringConfigure scoped access for an engineering group. Install NSC on developer machines. Walk through the full authentication and service resolution flow.
Contact engineeringIssue a workload identity for an agent or CI job. Scope access to the required service endpoints. Verify access boundaries and audit record output.
Contact engineeringConfigure per-flow audit records to stream to an HTTP collector, SIEM, or object storage bucket. Verify record format and delivery against a sample flow.
Contact engineeringEvery lifecycle operation — user enrollment, service publishing, policy management, key rotation, temporary access — is available through the API. All endpoints return structured JSON.
API token issuance, scope, and rotation. How to authenticate requests to the control plane API from scripts, CI, or internal tooling.
Contact engineeringList, inspect, and manage user and workload identities. Enrollment, deactivation, and session state endpoints.
Contact engineeringCreate and manage groups. Assign identities to groups. Groups are the primary unit for policy attachment in NetSeed.
Contact engineeringCreate, update, and distribute access policies. Policy objects bind identities or groups to services with optional device trust conditions.
Contact engineeringPublish, update, and retire service records. Service objects define what is reachable, at which site node, and under which access policy.
Contact engineeringQuery historical audit records. Filter by identity, service, policy, time range, or outcome. Export endpoints for bulk retrieval.
Contact engineeringIssue, inspect, and revoke time-limited access grants. Grant objects support approval state, expiry timestamps, and scoped service binding.
Contact engineering这些文档说明 NetSeed 各部分的工作方式——集成点、配置模型,以及每个组件的行为。
NetSeed 如何对接身份提供商、设备信任信号与安全事件管道。涵盖集成模型以及各连接点的作用。
联系工程师OIDC 配置、基于组的策略映射、用户生命周期与目录同步。身份如何从你的 IdP 流入访问决策。
联系工程师设备信任信号如何作为访问决策的一部分被评估。受管设备条件、合规设备要求,以及基于设备的策略规则。
联系工程师逐流审计记录格式、流式传输目的地、HTTP 端点配置、对象存储导出,以及 SIEM 集成模式。
联系工程师云托管、自托管与混合部署选项。各模型的组件布放、控制面配置与运维要求。
联系工程师指南涵盖最常见的部署与集成工作流——每一篇都带你从起步走到一套可用的配置。
在你的 IdP 与 NetSeed 之间配置 OIDC 联邦。将目录组映射到访问策略。端到端验证认证与组同步是否生效。
联系工程师在私有服务旁部署 NSN。在 NSD 中配置服务记录。验证已认证客户端能按名称访问该服务,且未授权流量被丢弃。
联系工程师为一个工程团队配置按范围授权的访问。在开发者机器上安装 NSC。走通完整的认证与服务解析流程。
联系工程师为一个 agent 或 CI 任务签发工作负载身份。将访问范围限定到所需的服务端点。验证访问边界与审计记录输出。
联系工程师配置逐流审计记录流式传输到 HTTP 采集器、SIEM 或对象存储桶。以一个样例流验证记录格式与投递。
联系工程师每一项生命周期操作——用户注册、服务发布、策略管理、密钥轮换、临时访问——都可通过 API 完成。所有端点均返回结构化 JSON。
API token 的签发、范围与轮换。如何从脚本、CI 或内部工具向控制面 API 认证请求。
联系工程师列出、查看并管理用户与工作负载身份。注册、停用与会话状态端点。
联系工程师创建并管理组。将身份分配到组。在 NetSeed 中,组是策略挂载的主要单元。
联系工程师创建、更新并下发访问策略。策略对象将身份或组绑定到服务,并可附带设备信任条件。
联系工程师发布、更新并下线服务记录。服务对象定义什么可被访问、位于哪个站点节点,以及适用哪条访问策略。
联系工程师查询历史审计记录。按身份、服务、策略、时间范围或结果过滤。提供用于批量拉取的导出端点。
联系工程师签发、查看并撤销限时访问授权。授权对象支持审批状态、过期时间戳,以及按范围绑定服务。
联系工程师