Zpa Create Server Group

作者 zscaler809f68d6c921无许可证收录于 2026年10月8日更新于 2026年10月8日

Create a ZPA server group with all required dependencies. Server groups require app connector groups to exist first. This skill walks through the dependency chain: (1) Check for existing app connector groups, (2) Create an app connector group if none exist, (3) Create the server group referencing the connector group IDs, (4) Verify the server group was created correctly. Use when an administrator needs to set up a new server group for application access.

仅含说明DevOps & Cloud
AI 生成的概览

指导管理员创建 ZPA 服务器组,包括其必需的应用程序连接器组依赖项。

功能
按五个步骤执行:收集需求、选择服务器组模式、检查现有应用程序连接器组、按需创建连接器组,然后创建并验证服务器组。它为每个步骤提供 ZPA 工具调用和参数,并涵盖多个连接器组、微租户范围和静态服务器分配等边缘情况。最终产出已创建的服务器组,以及其 ID、设置和关联连接器组的摘要。
适用场景
适用于管理员需要创建新的 ZPA 服务器组,或为应用程序访问搭建 ZPA 基础设施的场景。也用于说明应用程序连接器组、服务器组、应用程序段和访问策略规则之间的依赖链。
运行要求
需要访问 ZPA 工具,包括 zpa_list_app_connector_groups、zpa_create_app_connector_group、zpa_get_app_connector_group、zpa_create_server_group 和 zpa_get_server_group 等函数。该技能不附带脚本,需要管理员提供名称、位置和可选设置。

ZPA: Create Server Group

Keywords

create server group, new server group, zpa server group, add server group, connector group dependency, server group setup, zpa infrastructure

Overview

Create a ZPA server group by first ensuring its required dependency -- an app connector group -- exists. Server groups are fundamental building blocks in ZPA that define which application connectors serve traffic for specific applications.

Use this skill when: An administrator asks to create a new server group, set up ZPA infrastructure, or needs help understanding server group dependencies.


Workflow

Follow this 5-step process to create a server group with its dependencies.

Step 1: Gather Requirements

Ask the administrator for the following information:

Required:

  • Server group name
  • Whether to use an existing app connector group or create a new one

Optional:

  • Server group description
  • Whether IP anchoring is needed (ip_anchored)
  • Whether dynamic discovery should be enabled (dynamic_discovery)
  • Specific application server IDs to associate (server_ids)
  • Microtenant ID (for multi-tenant environments)

Step 1.5: Pick the Server Group Pattern (baseline alignment)

Reference: ZPA Baseline Recommendations v1.0 §Server Group Definition. Pick one of the five patterns before you choose app_connector_group_ids:

PatternWhen to useAC group binding
Dedicated per location (default for most apps)Apps hosted in one DC / cloud regionThe single location AC group only
Secure enclaveSensitive / regulated apps (Finance, HR, Legal, PCI)The isolated enclave AC group only — never co-mingle with general traffic
GlobalApps reachable from anywhere (AD DCs, NTP, internally LB'd web)All location AC groups
SIPAThird-party apps that require fixed source IPDedicated SIPA AC group(s) only — separate from general traffic so heavy general load can't degrade SIPA performance
RegionalSingle-DC app that needs cross-DC failoverMultiple AC groups in a region (e.g. "US-East" SG bound to all US-East AC groups)
DiscoveryWildcard segment for unknown apps (*.corp.example.com)All communal AC groups, plus dynamic_discovery=True

Once you've picked the pattern, the AC group selection in Step 2 / 3 is determined.

Dynamic Discovery — when to disable it

The baseline doc recommends dynamic_discovery=True for almost all server groups. Disable it only when:

  • Strict per-server segmentation is required (specific server IDs must be served by specific connectors).
  • You need destination NAT for overlapping networks across multi-DC / multi-cloud or partner environments served by ZPA Extranet.

Important — dynamic discovery ≠ application health checks. Dynamic discovery only learns server reachability from connector lookups. Application health (TCP probes, HTTP checks, port polling) is configured separately on the application segment via the health_reporting field. See the application_segment-onboard skill for health_reporting defaults.


Step 2: Check for Existing App Connector Groups

Before creating anything, list existing app connector groups to avoid duplicates.

text
zpa_list_app_connector_groups()```text
**Evaluate results:**
- If a suitable connector group already exists, note its `id` for use in Step 4- If no connector groups exist or none are suitable, proceed to Step 3- Present the list to the administrator and ask which to use (or confirm creating a new one)
#### Example Response
```textI found the following existing app connector groups:
1. **US-East Connectors** (ID: 72058304567890)   - Location: New York, US   - Enabled: Yes   - Connectors: 3
2. **EU-West Connectors** (ID: 72058304567891)   - Location: Dublin, IE   - Enabled: Yes   - Connectors: 2
Would you like to use one of these, or should I create a new app connector group?```text
---
### Step 3: Create App Connector Group (if needed)
If a new app connector group is required:
```textzpa_create_app_connector_group(  name="<connector_group_name>",  description="<description>",  enabled=True,  latitude="<latitude>",  longitude="<longitude>",  location="<location_name>",  city_country="<city>, <country>",  country_code="<ISO_country_code>")```text
**Important notes:**
- `country_code` accepts full names (e.g., "United States") or ISO codes ("US")- `latitude` and `longitude` help with geo-proximity routing- Save the returned `id` -- it is required in the next step
#### Confirm creation
```textzpa_get_app_connector_group(group_id="<returned_id>")```text
---
### Step 4: Create the Server Group
With the app connector group ID(s) in hand, create the server group:
```textzpa_create_server_group(  name="<server_group_name>",  app_connector_group_ids=["<connector_group_id>"],  description="<description>",  enabled=True,  ip_anchored=False,  dynamic_discovery=True)```text
**Parameter guidance:**
- `app_connector_group_ids` (required): List of one or more app connector group IDs from Step 2 or Step 3- `dynamic_discovery`: Set to `True` when application servers are discovered automatically; `False` when specifying servers manually via `server_ids`- `ip_anchored`: Set to `True` only when source IP anchoring is required (advanced use case)
---
### Step 5: Verify and Summarize
Confirm the server group was created successfully:
```textzpa_get_server_group(group_id="<returned_server_group_id>")```text
#### Present Summary
```textServer group created successfully.
**Server Group:**- Name: <name>- ID: <id>- Enabled: Yes- Dynamic Discovery: Yes/No- IP Anchored: Yes/No
**Associated App Connector Group(s):**- <connector_group_name> (ID: <connector_group_id>)
**Next Steps:**- You can now reference this server group (ID: <id>) when creating  application segments using `zpa_create_application_segment`- To create a complete application, see the "application_segment-onboard" skill```text
---
## Dependency Chain Reference
```textApp Connector Group (no dependencies)        │        ▼   Server Group (requires app_connector_group_ids)        │        ▼Application Segment (requires segment_group_id, optionally server_group_ids)        │        ▼ Access Policy Rule (references application segments, groups, users)```text
---
## Edge Cases
### Multiple Connector Groups
A server group can reference multiple app connector groups for redundancy:
```textzpa_create_server_group(  name="Multi-Region Servers",  app_connector_group_ids=["<us_east_id>", "<eu_west_id>"],  dynamic_discovery=True)```text
### Microtenant Scoping
In multi-tenant environments, pass `microtenant_id` to both the connector group and server group:
```textzpa_create_app_connector_group(  name="Tenant-A Connectors",  microtenant_id="<tenant_id>",  ...)
zpa_create_server_group(  name="Tenant-A Servers",  app_connector_group_ids=["<id>"],  microtenant_id="<tenant_id>")```text
### Static Server Assignment
When dynamic discovery is disabled, associate specific application servers:
```textzpa_list_application_servers()
zpa_create_server_group(  name="Static Servers",  app_connector_group_ids=["<connector_group_id>"],  server_ids=["<server_id_1>", "<server_id_2>"],  dynamic_discovery=False)```text
---
## Quick Reference
**Dependency:** App Connector Group must exist before creating a Server Group.
**Tools used:**
- `zpa_list_app_connector_groups()` -- find existing connector groups- `zpa_create_app_connector_group(name, ...)` -- create if needed- `zpa_get_app_connector_group(group_id)` -- verify connector group- `zpa_create_server_group(name, app_connector_group_ids, ...)` -- create server group- `zpa_get_server_group(group_id)` -- verify server group
**Remember:**
- Always check for existing resources before creating new ones- The `app_connector_group_ids` parameter on server groups is required- Present the dependency chain to the administrator so they understand the relationship

来源与署名

来源:zscaler/zscaler-mcp-server位于skills/zpa/create-server-group提交809f68d

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架