Machine Groups Page
Machine Groups allow you to organize machine identities into logical collections for simplified policy management. Instead of creating connection rules for individual machines, you can apply policies to entire groups.
Overview
Machine Groups provide:
- Logical Organization: Group machines by function, security zone, application, or any organizational principle
- Simplified Policy Management: temporarily suspends its ability to generate Corsha credentials
- Visual Clarity: Groups appear as blue rectangles in Connection Canvas
- Scalability: Manage hundreds of machines through a few well-organized groups
Accessing Machine Groups
Navigate to the Machine Groups page by clicking the "Groups" option under the Machines section in the Console sidebar.
Creating a Machine Group
To create a new machine group:
- Click the New Group button
- Provide a Group Name that describes the group's purpose
- Optionally add a Description to document the group's purpose or membership criteria
- Click Create
Managing Group Membership
Machines can be assigned to groups in two ways:
During Machine Creation
When creating a new machine identity, you can assign it to a group in the machine creation wizard. See Creating Machines for details on creating machines.
Updating Existing Machines
From the Machine Details page, you can change a machine's group assignment:
- Navigate to the machine's detail page
- Click Edit or Change Group
- Select the new group from the dropdown
- Click Save
Machine Groups in Connection Canvas
In the Connection Canvas visualization:
- Groups appear as blue rectangles surrounding member machines
- Drag entire groups to reposition all member machines at once
- Border nodes appear in groups without Gatekeepers for visual clarity
See Connection Canvas for more on visualizing machine groups.
Best Practices
- Organize by Function: Group machines by their role or application (e.g., "Web Servers", "Database Cluster", "OT Controllers")
- Align with Security Zones: Create groups matching your network segmentation strategy
- Keep Groups Focused: Avoid overly broad groups that undermine policy granularity
- Document Purpose: Use group descriptions to clarify membership criteria
- Review Regularly: Audit group membership periodically to ensure it remains accurate