Before you can create clusters using Tanzu Kubernetes Grid (TKG), you must connect to your standalone management cluster.
To connect to the standalone management cluster, you integrate the cluster with an OIDC or LDAP identity provider or use the build-in authentication mechanism provided by TKG. For instructions, see Identity and Access Management.
After you create a cluster, you can connect to the cluster using the Tanzu CLI, with or without an external OIDC or LDAP identity provider. For instructions, see Configure RBAC.
For conceptual information about identity and access management in TKG, see About Identity and Access Management.