Pattern-based policies
Converged Bridge Access Management supports attribute-based policies, policies that apply to all resources and resource pattern-based policies. Patter-based policies can be assigned directly to users, access group and Service IDs, providing flexible control over resource access.
Resource pattern-based policies allow administrators to define a resource pattern (resource CRN) and apply one policy across multiple resources that match the specified pattern. Administrators can also configure a policy for an individual resource when more granular control is required.
Administrators can create, view, assign, update and validate resource pattern-based policies through the Assign Access Policy workflow.
During authorization, access evaluation includes the resource pattern-based policies associated with the user or the access group to which the user belongs. The OKTA FGA authorization engine evaluates these policies to determine whether access is allowed for resources that match the configured pattern.
Resource pattern definitions
A resource pattern identifies the resources that a policy applies to. When a wildcard (*) is included in part of the pattern, all values are accepted in that position.
Example resource pattern:
- crn:v1:dx:local:iam:global:delivery:public:domain:*
Example individual resource identifier:
- crn:v1:dx:local:insights:global:5c306798dec5.1:public:dashboard:1aeb4e99-2c80-43f1-93bf-b55c2953d346
Pattern validation rules and allowed characters
Consider the following guidelines when creating pattern definitions to ensure values comply with the required validation rules and contain only supported characters:
- Only the following characters are allowed in the pattern: uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), colon (:), asterisk (*), underscore (_), period (.), forward slash (/), and hyphen (-).
- Spaces are not allowed in the pattern.
- The colon (:) acts as a separator between pattern segments.
- When the wildcard character (*) is specified between colons (for example, :*:), no other characters can appear between the colons. The colon character (:) is used only as a part separator and cannot be included as a value within any part of the pattern.
- The wildcard character (*) cannot be combined with any other character.
- The API validates the pattern and rejects any value that contains characters outside the allowed character set.
- The allowed character pattern is: [A-Za-z0-9:.*_/-].*
- A part value may be empty (for example, ...::...).
Assign a pattern-based policy
The steps for assigning a pattern-based policy are the same for Users, Access Groups, and Service IDs. The only difference is the entry point used to access the entity.
Follow the steps below to assign a Resource based on patterns policy:
- From the Kyndryl Bridge main menu
, go to Administration → Access Management → Bridge Access Management.
- From the left navigation menu, select Users, Access Groups or Service IDs, depending on the entity.
Learn more:
Users: To learn more about how to assign policies to a user, see UsersUsers.
Access groups: To learn more about how to assign policies to an access group, see Access GroupsAccess Groups.
Service IDs: To learn more about how to assign policies to a Service ID, see Service IDsService IDs
- Locate the user, access group or Service ID, you want to configure and click on +Assign Access Policy workflow.
- When assigning the policy, select Resource based on patterns in the Scope field.
- Enter the resource pattern definition. The resource pattern must use the required colon-separated format. Invalid patterns cannot be saved and an error message is displayed.
- To verify the assignment, open the Access Policies tab and confirm that the policy is displayed with the Resources based on patterns scope.
Once the policy is assigned, access is granted according to the configured resource pattern and authorization is evaluated against the matching resources.
Editing access group pattern-based policies
Policies assigned to an access group can be edited when policy settings need to be updated. Changes to an access group policy can affect all users who inherit access through that access group.
- From the Kyndryl Bridge main menu
, go to Administration → Bridge Access Management → Access Groups.
- On the Access Groups page, locate the access group whose policy you want to modify and select the access group name.
- Select the Access Policies tab.
- Locate the policy under the Access Policy Name column and select the policy name.
- Select Edit.
- Update the policy configuration as required and save your changes.