建立企業管理的可信設定檔範本

在擁有許多子帳戶的企業中,在每個帳戶中手動設定可信設定檔可能既費時又容易出錯。 使用受信任的設定檔範本,動態授予聯合使用者存取企業中帳戶的權限。

當您使用企業管理的信任設定檔範本時,您可以只與聯盟使用者建立信任。 若要為子帳戶設定用於運算資源、IBM Cloud 服務及服務ID的可信賴設定檔,請參閱 《建立可信賴設定檔》

使用者不需要成為帳號的會員就可以套用信任的設定檔。 如果使用者與受信任的設定檔有相同的身分提供者 ( IdP ),而且他們符合信任條件,使用者就可以套用設定檔。 例如,企業目錄中的使用者需要存取一組帳戶才能完成特定任務。 建立具有信任條件的信任設定檔範本,以該使用者及其所需的政策為目標。 然後,將受信任的設定檔範本指定給需要存取的帳戶。 現在,使用者只要在每個帳戶套用受信任的設定檔,就可以在不同帳戶之間切換,而且他們在不同帳戶之間擁有一致的存取權限。

身分服務的管理員可以在其帳戶中的企業管理信任設定檔中新增信任關係和政策,但不能修改您在範本中定義的信任關係和政策。

開始之前

  • 在開始之前,您需要 啟用外部身分提供者的驗證

  • 若要瞭解企業變更 IAM 模版如何讓您的企業更安全,請參閱 企業管理 IAM 存取如何運作

  • 您必須是企業帳戶的成員,才能建立和指派企業管理的 IAM 模版。

  • 若要建立企業管理的 IAM 模版,請確定您已被指派下列存取權限:

    • 所有 IAM 帳戶管理服務上具有範本管理員角色的政策
  • 若要將企業管理的 IAM 模版指定給子帳戶,請確認已指定下列存取權限:

    • 所有 IAM 帳戶管理服務上具有範本指定管理員角色的政策
    • 企業服務上至少具有 Viewer 角色的政策

    預設情況下,沒有使用者擁有模板管理員或模板指定管理員的角色,包括帳戶擁有者。

  • 企業中的新帳戶和現有帳戶必須選擇加入企業管理的 IAM。 如需詳細資訊,請參閱 選擇加入企業管理式 IAM

建立可信賴的個人資料範本

當使用者需要存取許多子帳戶,或一組使用者需要臨時存取多個子帳戶時,請考慮使用受信任的設定檔範本。

若要建立受信任的設定檔範本,請完成下列步驟:

  1. 移至管理 > 存取 (IAM) > 範本,然後在 IBM Cloud 主控台中選擇受信任的設定檔

  2. 按一下建立

  3. 輸入可信設定檔範本的名稱和描述,說明其對企業使用者的用途。

  4. 為企業管理的受信任設定檔輸入名稱、電子郵件及描述,說明其對子帳戶使用者的用途,並務必在描述中列出此受信任設定檔可執行的操作清單。

    在電子郵件中,您可以添加個人電子郵件帳號或郵件分發清單。

    您可以在設定檔名稱中使用取代變數,為每個帳戶自訂設定檔。 支援以下變數:

    • ${template_id}:將被可信設定檔模板的唯一識別碼取代。
    • ${template_name}:將被可信設定檔模板的目前名稱取代。
    • ${template_version}:將被目前版本的可信設定檔範本取代。
    • ${account_id}:將被指定可信設定檔模板的帳戶識別碼取代。
    • ${account_name}:將被指定可信設定檔模板的帳戶名稱取代。

    帳戶名稱等值的變更不會導致受信任設定檔名稱的更新。 設定檔名稱會在您將範本指定給帳戶或升級範本版本時設定。 這表示如果帳戶名稱稍後變更,個人資料名稱不會自動更新。 新帳戶名稱只會在下次指定範本或升級時使用。

  5. 按一下建立

(選用)新增信任關係

個別使用者

透過 IBM Cloud IAM ID,與帳戶內外的個別使用者建立信任。

要建立信任,請完成下列步驟:

  1. 按一下信任關係 > 個別使用者
  2. 按一下新增,然後選擇帳戶使用者外部使用者來邀請企業成員,並指定範本。
    1. 按一下帳戶使用者,在帳戶中新增使用者。
      1. 選取一位使用者或多位使用者。
      2. 按一下 [ 新增 ],將使用者新增至關聯的設定檔。
    2. 按一下外部使用者,新增不在您帳戶中的使用者。
      1. 輸入 IAM ID。
      2. 輸入相關的帳戶 ID。 您可以新增一個以上的帳號,而且可以包含一個與使用者目前正在使用的帳號不同的帳號。
      3. (選用)輸入說明。
      4. 按一下 [ 新增 ],將使用者新增至關聯的設定檔。

點擊要編輯或刪除的使用者旁邊的操作圖標操作圖標,選擇新增刪除

聯合使用者

根據企業目錄中的屬性建立條件,藉此與聯邦使用者建立信任關係。 當聯邦使用者符合您定義的條件時,他們就可以套用設定檔。

要建立信任,請完成下列步驟:

  1. 按一下信任關係 > 聯邦使用者
  2. 點選新增,選擇按 IBMid 聯合的使用者按 IBM Cloud AppID 聯合的使用者作為驗證方法,並輸入預設身分提供者( IdP )。
  3. 根據您的 IdP 資料新增條件,以定義聯合使用者如何以及何時可以套用設定檔。
    1. 按一下新增條件,以定義多個條件。 聯邦使用者必須符合所有條件,才能套用受信任的設定檔。 關於用於建立條件的欄位的詳細資訊,請參閱 IAM 條件屬性
    2. 檢視身分提供者資料,從您的 IdP 搜尋個人資料中的屬性名和值。 如需詳細資訊,請參閱 使用 IdP 資料建立可信的設定檔
  4. 定義使用者在必須重新驗證之前,可以套用設定檔多久的階段持續時間。
  5. 按一下新增

點擊要編輯或刪除的聯合用戶旁邊的操作圖標操作圖標,選擇新增刪除

運算資源

與運算資源建立信任,讓在特定群集中執行的程式能安全存取必要的資源。

要建立信任,請完成下列步驟:

  1. 按一下信任關係 > 運算資源
  2. 按一下新增,然後選擇一個運算服務。
  3. 按一下新增條件,以定義多個條件。 關於用於建立條件的欄位的詳細資訊,請參閱 IAM 條件屬性
  4. 按一下新增

按一下您要編輯或刪除的計算資源旁的操作圖示“操作圖示”,選擇 「新增」「刪除」

IBM Cloud 服務

透過允許以雲端資源名稱辨識的雲端服務實體,與 IBM Cloud 服務建立信任。

要建立信任,請完成下列步驟:

  1. 按一下信任關係 > IBM Cloud 服務
  2. 按一下新增,然後輸入 CRN。
  3. (選用)輸入說明。
  4. 按一下新增

點擊要編輯或刪除的 IBM Cloud 服務旁邊的操作圖標操作圖標,選擇新增刪除

服務 ID

透過驗證服務,以服務 ID 建立信任。 可為特定服務建立服務 ID,並附帶 API 金鑰,以安全地驗證服務。 此外,服務 ID 可以假定為受信任的設定檔,繼承權限並在需要時存取資源。

要建立信任,請完成下列步驟:

  1. 按一下信任關係 > 服務 ID
  2. 按一下新增,然後輸入服務 ID。
  3. (選用)輸入說明。
  4. 按一下新增

點擊要編輯或刪除的服務 ID 旁邊的操作圖標操作圖標,方法是選擇新增刪除

(選用)新增存取政策

存取政策將子帳戶中的存取權授予可套用設定檔的聯合使用者。

  1. 按一下存取 > 新增

  2. 輸入名稱並說明要指定的政策。

    您為可信設定檔範本設定的每個政策都會建立一個政策範本。 您可以參考政策範本,在其他企業 IAM 範本中指派存取權限。

  3. 選取服務或服務群組,然後按一下下一步

  4. 將存取範圍設定為所有資源,或根據屬性選擇特定資源,然後按一下下一步

  5. 角色和動作部分,選擇定義存取範圍的角色。 您可以在政策範本流程中建立自訂角色範本,也可以從選取服務的現有自訂角色範本中選取自訂角色。

    1. 按一下建立自訂角色,以定義自訂的動作組合。
    2. 輸入範本名稱。
    3. (可選)輸入範本說明。
    4. 請輸入自訂角色的名稱。
    5. 請輸入自訂角色的 ID。
    6. (可選)為自訂角色輸入描述。
    7. 選取動作,然後按一下「建立」。 自訂角色會與其他已為政策選取的角色一起列出和選取。

    使用搜尋列尋找支援特定動作的角色。 例如,搜尋讀取編輯檢視,即可顯示這些動作適用的角色清單。

  6. (可選)新增條件,指定何時要政策授予存取權限。

  7. 按一下新增

移除存取政策

您可以在範本提交和指定之前移除政策。

更新範本詳細資料

您可以在提交範本之前隨時更新範本名稱、信任的設定檔名稱和說明。 若要更新範本詳細資訊,請依照以下步驟操作:

  1. 請前往 「管理」>「存取權限 (IAM)」>「範本」
  2. 選取您要更新的信任設定檔範本。
  3. 按一下詳細資料區段中的 編輯 圖示 編輯圖示
  4. 對模板名稱、信任的設定檔名稱和描述進行必要的更新。
  5. 按一下儲存

如果您需要在提交範本後進行更新,請建立新版本。

檢視您的「值得信賴」個人資料範本

檢閱並提交受信任的設定檔範本,使版本不能再變更。 如此一來,範本指派管理員就可以確定,他們只會在您確認版本已準備就緒時才指派版本。

  1. 按一下總覽 > 檢閱
  2. 驗證可信設定檔範本的設定是否符合您的期望。
  3. 按一下核取方塊,確認您無法變更版本。
  4. 按一下 確認

為子帳戶指定受信任的設定檔範本

將受信任的設定檔範本指定給企業中的子帳戶。

您只能將 IAM 模版指定給子帳戶和帳戶群組,而不能指定給執行帳戶。

  1. 按一下指定帳戶

  2. 選擇要指定範本的帳戶和帳戶群組。

    在您指定範本的每個子帳戶中,您都會建立企業管理的受信任設定檔。 子帳戶中的使用者可以透過設定檔上的企業管理{: tag-cyan} 標籤,判斷可信設定檔來自企業[管理]的 IAM 模版。

  3. 按一下指派

如果指派失敗,請按一下重試

建立新版本

如果要變更已提交或指定的受信任設定檔範本,請建立新版本。 您可以根據最新版本或您選擇的不同版本建立新版本。

若要建立新版本的受信任設定檔範本,請完成下列步驟:

  1. 移至 IBM Cloud 主控台中的管理 > 存取 (IAM) > 範本

  2. 請選擇您信賴的個人檔案範本。

  3. 點擊新版本圖標新版本圖標

  4. 選擇您想要的版本作為新版本的基礎。

  5. 輸入新的範本名稱和說明,或保留您已在使用的名稱和說明。

    輸入新的範本名稱會更新此版本及之前所有版本的範本名稱。 每個版本的範本說明都會單獨儲存。

  6. 輸入新的受信任個人資料名稱和描述,或保留您已在使用的名稱和描述。

    輸入新的「受信任的個人資料」名稱後,系統會將子帳戶中顯示的先前「受信任的個人資料」名稱替換為新版本。

  7. 選取要轉移到新版本的物件。

    1. (可選)選擇信任關係
    2. (可選)選擇存取
  8. 按一下建立

  9. 對設定進行其他調整。

  10. 按一下「檢閱」並提交新版本。 如需詳細資訊,請參閱 檢閱您的信任設定檔模板

若要指定受信任設定檔範本的新版本,請完成下列步驟:

  1. 移至 IBM Cloud 主控台中的管理 > 存取 (IAM) > 範本
  2. 按一下 Trusted profiles(受信任的設定檔 )。
  3. 按一下表展開圖示 表展開圖示 您要使用的範本。
  4. 選擇目前指定給子帳戶的版本。
  5. 按一下作業
  6. 按一下要指派不同版本的帳戶或帳戶群組指派上的 Update(更新 )。
  7. 請點擊「選擇版本」。
    1. 選取您要取代目前版本的版本。
  8. 按一下更新
  9. 對於要指定不同版本的每個帳戶或帳戶群組,重複這些步驟。

您指定的新模板版本會取代舊版本。 進一步瞭解「指定新版本」。

移除任務

您可以從指定範本的一個或多個帳戶中移除範本指定。 如果範本無法如預期般運作,您可能需要這樣做。 從帳戶移除範本指定時,預設會恢復先前版本的範本。 如果您移除的指定是範本的第一個或唯一版本,則會移除子帳戶中的受信任設定檔。

若要移除一項指派,請依照以下步驟操作:

  1. 移至 IBM Cloud 主控台中的管理 > 存取 (IAM) > 範本
  2. 按一下受信任的設定檔,然後選擇您的受信任設定檔範本。
  3. 按一下更新工作分配
    1. 若要從一個或幾個帳戶移除指派,請取消選擇要移除範本指派的帳戶。
    2. 若要從已指派範本的所有帳戶中移除指派,請按一下全部解除指派

使用 CLI 建立受信任的設定檔範本

當您有許多需要相同受信任設定檔的子帳戶時,請考慮使用受信任設定檔範本。 舉例來說,您的組織可能有內部標準或要求符合產業法規。

若要透過 CLI 建立受信任的設定檔範本,請完成以下步驟:

  1. 建立 JSON 檔案,設定可信設定檔範本定義。 有關您可以在 JSON 檔案中使用的屬性的詳細資訊,請參閱 IAM Identity API

    以下 JSON 檔案範例指定了企業帳戶的 account_id、範本的 name 以及 profile 設定。 此受信任的設定檔適用於資料庫管理員。 允許特定使用者套用 identities 中定義的範本。還定義了 rules,根據 SAML 屬性授予對設定檔的存取權。

       {
       "account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
       "name": "dbadmintemplate",
       "profile": {
          "name": "Profile for DB Admins",
          "description": "allows users to admin db instances",
          "identities": [
                {
                   "type": "user",
                   "identifier": "IBMid-123456789",
                   "accounts": [
                      "5bbe28be34524sdbdaa34d37d1f2294a"
                   ]
                }
          ],
          "rules": [
                {
                   "type": "Profile",
                   "realm_name": "${IDP_REALM_NAME}",
                   "expiration": 43200,
                   "conditions": [
                      {
                            "claim": "group",
                            "operator": "EQUALS",
                            "value": "\"admins\""
                      }
                   ]
                }
          ]
       },
       "policy_template_references": [
          {
                "id": "Policy Template-12345",
                "version": 1
          }
       ]
    }
    
  2. 使用 trusted-profile-template-create 指令建立受信任的設定檔範本,如以下範例請求所示:

    ibmcloud iam trustedprofile-template-create dbadmintemplate --file /path/to/db_trusted-profile_template.json
    

使用 CLI 更新受信任的設定檔範本

您可以在提交之前隨時更新受信任的設定檔範本。 若要更新可信設定檔模板的特定版本,請完成下列步驟:

  1. 使用新的可信設定檔模板定義更新您的 JSON 檔案。 有關您可以在 JSON 檔案中使用的屬性的詳細資訊,請參閱 IAM Identity API

      {
      "account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
      "name": "DBAdministrator",
      "profile": {
         "name": "Profile for DB Admins",
         "description": "allows users to admin db instances",
         "identities": [
               {
                  "type": "user",
                  "identifier": "IBMid-123456789",
                  "accounts": [
                     "5bbe28be34524sdbdaa34d37d1f2294a"
                  ]
               }
         ],
         "rules": [
               {
                  "type": "Profile",
                  "realm_name": "${IDP_REALM_NAME}",
                  "expiration": 43200,
                  "conditions": [
                     {
                           "claim": "group",
                           "operator": "EQUALS",
                           "value": "\"admins\""
                     }
                  ]
               }
         ]
      },
      "policy_template_references": [
         {
               "id": "Policy Template-12345",
               "version": 1
         }
      ]
    }
    
 當您更新範本名稱時,這會更新每個版本的名稱。
 {: note}

  1. 若要更新可信設定檔模板的特定版本,請使用 `trusted-profile-template-version-update` 指令,如下列範例請求所示:

 ```bash {: codeblock}
 ibmcloud iam trustedpprofile-template-version-update DBAdministrator 1 --file /path/to/db_trusted-profile_template.json
## 使用 CLI 提交受信任的設定檔範本
{: #commit-trusted-profile-template-cli cli}

檢閱受信任的設定檔範本,並將其提交,這樣就不能再對版本進行任何變更。 在您將版本指派給子帳戶之前,提交版本是必要的步驟。 如此一來,範本指派管理員就可以確定,他們只會在您確認版本已準備就緒時才指派版本。

以下示例請求提交了名為 `DBAdministrator` 的可信設定檔模板的 `1` 版本:

```bash {: codeblock}

ibmcloud iam trusted-profile-template-version-commit DBAdministrator 1

  ## 使用 CLI 為子帳戶指定受信任的設定檔範本
  {: #assign-trusted-profile-template-cli cli}

  將受信任的設定檔範本指定給企業中的子帳戶。

  您只能將 IAM 模版指定給子帳戶和帳戶群組,而不能指定給執行帳戶。
  {: note}

  若要為受信任的設定檔範本建立指派,請完成下列步驟:
  1. 列出企業帳戶中受信任的設定檔模板,並註記要指定給子帳戶的受信任設定檔模板的模板名稱和版本號:

 ```bash {: codeblock}
 ibmcloud iam trusted-profile-templates
1. 使用 `account-trusted profile-assignment-create` 指令將範本指定給 `Account` 或 `AccountGroup`。
ibmcloud iam trusted-profile-assignment-create DBAdministrator 1 AccountGroup 955fc2274567474f8da802d5c376504b
如果指派失敗,請使用 `trusted-profile-assignment-update` 方法重試。
{: tip}

## 使用 CLI 建立新版本
{: #new-version-trusted-profile-template cli}

如果要變更已提交或指定的受信任設定檔範本,請建立新版本。

1. 使用新的可信設定檔模板定義更新您的 JSON 檔案。 有關您可以在 JSON 檔案中使用的屬性的詳細資訊,請參閱 [IAM Identity API](/docs/apis/iam-identity-token-api#create-profile-template-version)。
1. 使用 `trusted-profile-template-version-create` 方法建立新版本。 以下範例請求會建立新版本的範本 `DBAdministrator`。
ibmcloud iam trusted-profile-template-version-create DBAdministrator --file /path/to/db_trusted-profile_template.json
## 使用 CLI 更新指派
{: #update-assignment-trusted-profile-cli cli}

更新作業以轉換到新版本或重試失敗的作業。

您指定的新模板版本會取代舊版本。 進一步瞭解「[指定新版本](/docs/enterprise-management?topic=enterprise-management-working-with-versions#new-version)」。
{: note}

1. 列出企業帳戶中受信任的設定檔工作分配,並註記要更新的工作分配的 `template_id`:
ibmcloud iam trusted-profile-assignments
1. 更新受信任的設定檔指派。 如果您要重試作業,請使用相同的版本號碼。 以下範例請求將指派 `ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d` 移轉到版本 2。
ibmcloud iam trusted-profile-assignment-update ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d 2
## 使用 CLI 移除指派
{: #remove-assignment-trusted-profile-cli cli}

您可以從已指定範本的帳戶或帳戶群組移除範本指定。 如果範本無法如預期般運作,您可能需要這樣做。 從帳戶移除範本指定時,預設會恢復先前版本的範本。 如果您移除的指定是範本的第一個或唯一版本,則會移除子帳戶中的企業管理受信任設定檔。

若要移除一項指派,請依照以下步驟操作:

1. 使用 `account-trusted profile-assignments` 方法列出帳戶中的工作分配。 記下您要移除的工作的 `ASSIGNMENT_ID`。
1. 使用 `account-trusted profile-assigment-delete` 方法移除指定。 以下範例請求移除指派 `AccountSettingsAssignment-63d65ed159ff463b8ec09ea77d22a05b`。
ibmcloud iam account-trusted profile-assignment-delete AccountSettingsAssignment-63d65ed159ff463b8ec09ea77d22a05b
## 使用 CLI 刪除版本
{: #delete-trusted-profile-template-version-cli cli}

在刪除受信任的設定檔模板版本之前,您必須移除該模板版本的所有指定。 完成以下步驟刪除特定版本:

1. 列出企業帳戶中受信任的設定檔模板,並註記要刪除版本的模板名稱和版本號:
ibmcloud iam account-trusted profile-templates
1. 刪除版本:
ibmcloud iam account-trusted profile-template-delete AccountSettingsTemplateUpdated 2
1. 若要刪除所有版本,請重複這些步驟。 確保您先移除每個版本的工作分配。

## 使用 API 建立受信任的設定檔範本
{: #create-trusted-profile-template-api api}

當您有許多需要相同受信任設定檔的子帳戶時,請考慮使用受信任設定檔範本。 舉例來說,您的組織可能有內部標準或要求符合產業法規。

若要使用 API 建立受信任的設定檔範本,請完成下列步驟:

1. 設定可信設定檔範本定義。 有關您可以使用的屬性的詳細資訊,請參閱 [IAM Identity API](/docs/apis/iam-identity-token-api#create-profile-template)。

以下範例指定企業帳戶的 account_id、範本的 name 以及 profile 設定。 此受信任的設定檔適用於資料庫管理員。 允許特定使用者套用 identities 中定義的範本。還定義了 rules,根據 SAML 屬性授予對設定檔的存取權。

   {
   "account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
   "name": "dbadmintemplate",
   "profile": {
      "name": "Profile for DB Admins",
      "description": "allows users to admin db instances",
      "identities": [
            {
               "type": "user",
               "identifier": "IBMid-123456789",
               "accounts": [
                  "5bbe28be34524sdbdaa34d37d1f2294a"
               ]
            }
      ],
      "rules": [
            {
               "type": "Profile",
               "realm_name": "${IDP_REALM_NAME}",
               "expiration": 43200,
               "conditions": [
                  {
                        "claim": "group",
                        "operator": "EQUALS",
                        "value": "\"admins\""
                  }
               ]
            }
      ]
   },
   "policy_template_references": [
      {
            "id": "Policy Template-12345",
            "version": 1
      }
   ]
}
   ProfileClaimRuleConditions condition = new ProfileClaimRuleConditions.Builder()
      .claim("blueGroups")
      .operator("EQUALS")
      .value("\"cloud-docs-dev\"")
      .build();
   List<ProfileClaimRuleConditions> conditions = new ArrayList<>();
   conditions.add(condition);
   TrustedProfileTemplateClaimRule claimRule = new TrustedProfileTemplateClaimRule.Builder()
      .name("My Rule")
      .realmName(realmName)
      .type(claimRuleType)
      .expiration(43200)
      .conditions(conditions)
      .build();
   TemplateProfileComponentRequest profile = new TemplateProfileComponentRequest.Builder()
      .addRules(claimRule)
      .name(profileTemplateProfileName)
      .description("Trusted profile created from a template")
      .build();
   CreateProfileTemplateOptions createProfileTemplateOptions = new CreateProfileTemplateOptions.Builder()
      .name(profileTemplateName)
      .description("IAM enterprise trusted profile template example")
      .accountId(enterpriseAccountId)
      .profile(profile)
      .build();
   Response<TrustedProfileTemplateResponse> response = service.createProfileTemplate(createProfileTemplateOptions).execute();
   TrustedProfileTemplateResponse trustedProfileTemplateResult = response.getResult();
   // Save the id for use by other test methods.
   profileTemplateId = trustedProfileTemplateResult.getId();
   profileTemplateVersion = trustedProfileTemplateResult.getVersion().longValue();
   System.out.println(trustedProfileTemplateResult);
   ```
   ```javascript {: javascript codeblock}
   const condition = {
   claim: "blueGroups",
   operator: "EQUALS",
   value: "\"cloud-docs-dev\"",
   }
   const claimRule = {
      name: "My Rule",
      realm_name: realmName,
      type: 'Profile-SAML',
      expiration: 43200,
      conditions: [condition],
   }
   const profile = {
   rules: [claimRule],
   name: "Profile-From-Example-Template",
   description: "Trusted profile created from a template",
   }
   const templateParams = {
   name: "Example-Profile-Template",
   description: "IAM enterprise trusted profile template example",
   accountId: enterpriseAccountId,
   profile: profile,
   }
   try {
   const res = await iamIdentityService.createProfileTemplate(templateParams);
   profileTemplateEtag = res.headers.etag;
   const { result } = res;
   profileTemplateId = result.id;
   profileTemplateVersion = result.version;
   console.log(JSON.stringify(result, null, 2));
   } catch (err) {
   console.warn(err);
   }
   ```
   ```python {: python codeblock}
   profile_claim_rule_conditions = {}
   profile_claim_rule_conditions['claim'] = 'blueGroups'
   profile_claim_rule_conditions['operator'] = 'EQUALS'
   profile_claim_rule_conditions['value'] = '\"cloud-docs-dev\"'
   profile_claim_rule = {}
   profile_claim_rule['name'] = 'My Rule'
   profile_claim_rule['realm_name'] = 'https://sdk.test.realm/1234'
   profile_claim_rule['type'] = 'Profile-SAML'
   profile_claim_rule['expiration'] = 43200
   profile_claim_rule['conditions'] = [profile_claim_rule_conditions]
   profile = {}
   profile['name'] = 'Profile-From-Example-Template'
   profile['description'] = 'Trusted profile created from a template'
   profile['rules'] = [profile_claim_rule]
   create_response = iam_identity_service.create_profile_template(
   name='Example-Profile-Template',
   description='IAM enterprise trusted profile template example',
   account_id=enterprise_account_id,
   profile=profile,
   )
   profile_template = create_response.get_result()
   print('\ncreate_profile_template() response: ', json.dumps(profile_template, indent=2))
   global profile_template_id
   profile_template_id = profile_template['id']
   global profile_template_version
   profile_template_version = profile_template['version']
   ```
   ```go {: go codeblock}
   profileClaimRuleConditions := new(iamidentityv1.ProfileClaimRuleConditions)
   profileClaimRuleConditions.Claim = core.StringPtr("blueGroups")
   profileClaimRuleConditions.Operator = core.StringPtr("EQUALS")
   profileClaimRuleConditions.Value = core.StringPtr("\"cloud-docs-dev\"")
   profileTemplateClaimRule := new(iamidentityv1.TrustedProfileTemplateClaimRule)
   profileTemplateClaimRule.Name = core.StringPtr("My Rule")
   profileTemplateClaimRule.RealmName = &realmName
   profileTemplateClaimRule.Type = &claimRuleType
   profileTemplateClaimRule.Expiration = core.Int64Ptr(int64(43200))
   profileTemplateClaimRule.Conditions = []iamidentityv1.ProfileClaimRuleConditions{*profileClaimRuleConditions}
   profile := new(iamidentityv1.TemplateProfileComponentRequest)
   profile.Name = &profileTemplateProfileName
   profile.Description = core.StringPtr("Example Profile created from Profile Template")
   profile.Rules = []iamidentityv1.TrustedProfileTemplateClaimRule{*profileTemplateClaimRule}
   createOptions := &iamidentityv1.CreateProfileTemplateOptions{
   Name:        &profileTemplateName,
   Description: core.StringPtr("Example Profile Template"),
   AccountID:   &enterpriseAccountID,
   Profile:     profile,
   }
   createResponse, response, err := iamIdentityService.CreateProfileTemplate(createOptions)
   b, _ := json.MarshalIndent(createResponse, "", "  ")
   fmt.Println(string(b))
   // Grab the ID and Etag value from the response for use in the update operation
   profileTemplateId = *createResponse.ID
   profileTemplateVersion = *createResponse.Version
   profileTemplateEtag = response.GetHeaders().Get("Etag")
   ```
 儲存回應中的 ProfileTemplate ID 和 entity_tag 值,以便在更新作業中使用。
 { tip}

 ## 使用 API 更新受信任的個人資料範本
 {: #update-trusted-profile-template-api api}

 您可以在提交之前隨時更新受信任的設定檔範本。 有關您可以在 JSON 檔案中使用的屬性的詳細資訊,請參閱 [IAM Identity API](/docs/apis/iam-identity-token-api#update-profile-template-version)。 若要更新可信設定檔模板的特定版本,請完成下列步驟:

 1. 列出您的 enteprise 帳戶中受信任的設定檔範本,並在回應中記下您要更新的範本版本的 `ProfileTemplate` ID 和 ETag。

```bash {: curl codeblock}
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
   .accountId(enterpriseAccountId)
   .build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", "  ")
fmt.Println(string(b))
1. 更新受信任的設定檔範本定義。

```bash {: curl codeblock}

curl -X PUT 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{ "account_id": "5bbe28be34524sdbdaa34d37d1f2294a", "name": "db admin template", "profile": { "name": "Profile for DB Admins", "description": "allows users to admin db instances", "rules": [ { "type": "Profile", "realm_name": "${IDP_REALM_NAME}", "expiration": 43200, "conditions": [ { "claim": "name", "operator": "EQUALS", "value": ""My Name"" } ] } ] }, "policy_template_references": [ { "id": "Policy Template-12345", "version": 1 } ] }'

 ```java {: java codeblock}
 UpdateProfileTemplateVersionOptions updateOptions = new UpdateProfileTemplateVersionOptions.Builder()
    .accountId(enterpriseAccountId)
    .templateId(profileTemplateId)
    .version(Long.toString(profileTemplateVersion))
    .ifMatch(profileTemplateEtag)
    .name(profileTemplateName)
    .description("IAM enterprise trusted profile template example - updated")
    .build();
 Response<TrustedProfileTemplateResponse> updateResponse = service.updateProfileTemplateVersion(updateOptions).execute();
 TrustedProfileTemplateResponse updateResult = updateResponse.getResult();
 // Grab the Etag value from the response for use in the update operation.
 profileTemplateEtag = updateResponse.getHeaders().values("Etag").get(0);
 System.out.println(updateResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
version: profileTemplateVersion,
ifMatch: profileTemplateEtag,
name: "Example-Profile-Template",
description: "IAM enterprise trusted profile template example - updated",
}
try {
const res = await iamIdentityService.updateProfileTemplateVersion(params);
profileTemplateEtag = res.headers.etag;
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
{
"id": "ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9",
"version": 1,
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "db admin template",
"committed": false,
"profile": {
   "name": "Profile for DB Admins",
   "description": "allows users to admin db instances",
   "rules": [
      {
      "type": "Profile-SAML",
      "realm_name": "${IDP_REALM_NAME}",
      "expiration": 43200,
      "conditions": [
         {
            "claim": "name",
            "operator": "EQUALS",
            "value": "\"My Name\""
         }
      ]
      }
   ]
},
"policy_template_references": [
   {
      "id": "Policy Template-12345",
      "version": "1"
   }
],
"created_at": "2023-03-07T13:55:33:428+0000",
"created_by_id": "IBMid-12345678901",
"last_modified_at": "2023-03-07T13:55:33:428+0000",
"last_modified_by_id": "IBMid-12345678901",
"entity_tag": "1-2da85a8f1172fc3527378318d3182778",
"crn": "crn:v1:staging:public:iam-identity::a/5bbe28be34524sdbdaa34d37d1f2294a::template:ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9"
}
{
"id": "ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9",
"version": 1,
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "db admin template",
"committed": false,
"profile": {
   "name": "Profile for DB Admins",
   "description": "allows users to admin db instances",
   "rules": [
      {
      "type": "Profile-SAML",
      "realm_name": "${IDP_REALM_NAME}",
      "expiration": 43200,
      "conditions": [
         {
            "claim": "name",
            "operator": "EQUALS",
            "value": "\"My Name\""
         }
      ]
      }
   ]
},
"policy_template_references": [
   {
      "id": "Policy Template-12345",
      "version": "1"
   }
],
"created_at": "2023-03-07T13:55:33:428+0000",
"created_by_id": "IBMid-12345678901",
"last_modified_at": "2023-03-07T13:55:33:428+0000",
"last_modified_by_id": "IBMid-12345678901",
"entity_tag": "1-2da85a8f1172fc3527378318d3182778",
"crn": "crn:v1:staging:public:iam-identity::a/5bbe28be34524sdbdaa34d37d1f2294a::template:ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9"
}

當您更新範本名稱時,這會更新每個版本的名稱。

使用 API 提交受信任的設定檔範本

檢閱受信任的設定檔範本並將其提交,這樣您就不能再對版本進行任何變更。 在您將版本指派給子帳戶之前,提交版本是必要的步驟。 如此一來,範本指派管理員就可以確定,他們只會在您確認版本已就緒時才指派版本。

  1. 取得您要檢閱和提交的可信設定檔範本版本。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
GetProfileTemplateVersionOptions getProfileTemplateOptions = new GetProfileTemplateVersionOptions.Builder()
   .templateId(profileTemplateId)
   .version(Long.toString(profileTemplateVersion))
   .build();
Response<TrustedProfileTemplateResponse> response = service.getProfileTemplateVersion(getProfileTemplateOptions).execute();
TrustedProfileTemplateResponse profileTemplateResult = response.getResult();
profileTemplateEtag = response.getHeaders().values("Etag").get(0);
System.out.println(profileTemplateResult);
const params = {
templateId: profileTemplateId,
version: profileTemplateVersion,
}
try {
const res = await iamIdentityService.getProfileTemplateVersion(params);
profileTemplateEtag = res.headers.etag;
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
get_response = iam_identity_service.get_profile_template_version(
template_id=profile_template_id, version=str(profile_template_version)
)
profile_template = get_response.get_result()
print('\nget_profile_template response: ', json.dumps(profile_template, indent=2))
global profile_template_etag
profile_template_etag = get_response.get_headers()['Etag']
profile_template_etag is not None
getOptions := &iamidentityv1.GetProfileTemplateVersionOptions{
TemplateID: &profileTemplateId,
Version:    core.StringPtr(strconv.FormatInt(profileTemplateVersion, 10)),
}
getResponse, response, err := iamIdentityService.GetProfileTemplateVersion(getOptions)
b, _ := json.MarshalIndent(getResponse, "", "  ")
fmt.Println(string(b))
profileTemplateEtag = response.GetHeaders().Get("Etag")
  1. 檢閱回應,確認已準備好提交。
  2. 提交可信設定檔範本的版本。
curl -X POST 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/{version}/commit' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
CommitProfileTemplateOptions commitOptions = new CommitProfileTemplateOptions.Builder()
   .templateId(profileTemplateId)
   .version(Long.toString(profileTemplateVersion))
   .build();
Response<Void> commitResponse = service.commitProfileTemplate(commitOptions).execute();
const commitParams = {
templateId: profileTemplateId,
version: profileTemplateVersion,
}
try {
const res = await iamIdentityService.commitProfileTemplate(commitParams);
} catch (err) {
console.warn(err);
}
commit_response = iam_identity_service.commit_profile_template(
template_id=profile_template_id, version=str(profile_template_version)
)
commitOptions := &iamidentityv1.CommitProfileTemplateOptions{
TemplateID: &profileTemplateId,
Version:    core.StringPtr(strconv.FormatInt(profileTemplateVersion, 10)),
}
response, err := iamIdentityService.CommitProfileTemplate(commitOptions)

使用 API 為子帳戶指定受信任的設定檔模板

將受信任的設定檔範本指定給企業中的子帳戶。

您只能將 IAM 模版指定給子帳戶和帳戶群組,而不能指定給執行帳戶。

若要為受信任的設定檔範本建立指派,請完成下列步驟:

  1. 列出您的 enteprise 帳戶中受信任的設定檔範本,並在回應中記下您要指定的範本版本的 ProfileTemplate ID 和版本。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
   .accountId(enterpriseAccountId)
   .build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", "  ")
fmt.Println(string(b))
ibmcloud iam trusted-profile-templates
  1. 將範本指定給 AccountAccountGroup
curl -X POST 'https://iam.cloud.ibm.com/v1/profile_assignments' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
   "template_id": "ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d",
   "template_version": 1,
   "target_type": "Account",
   "target": "5bbe28be34524e88a34d37d1f2294a8a"
}'
CreateTrustedProfileAssignmentOptions assignOptions = new CreateTrustedProfileAssignmentOptions.Builder()
   .templateId(profileTemplateId)
   .templateVersion(profileTemplateVersion)
   .targetType("Account")
   .target(enterpriseSubAccountId)
   .build();
Response<TemplateAssignmentResponse> assignResponse = service.createTrustedProfileAssignment(assignOptions).execute();
TemplateAssignmentResponse assignmentResponseResult = assignResponse.getResult();
// Save the id for use by other test methods.
profileTemplateAssignmentId = assignmentResponseResult.getId();
// Grab the Etag value from the response for use in the update operation.
profileTemplateAssignmentEtag = assignResponse.getHeaders().values("Etag").get(0);
System.out.println(assignmentResponseResult);
const assignParams = {
templateId: profileTemplateId,
templateVersion: profileTemplateVersion,
targetType: "Account",
target: enterpriseSubAccountId,
}
try {
const assRes = await iamIdentityService.createTrustedProfileAssignment(assignParams);
const { result } = assRes;
profileTemplateAssignmentId = result.id;
profileTemplateAssignmentEtag= assRes.headers.etag;
console.log(JSON.stringify(result, null, 2));
} catch (err) {
console.warn(err);
}
assign_response = iam_identity_service.create_trusted_profile_assignment(
template_id=profile_template_id,
template_version=profile_template_version,
target_type='Account',
target=enterprise_subaccount_id,
)
assignment = assign_response.get_result()
print('\ncreate_trusted_profile_assignment() response: ', json.dumps(assignment, indent=2))
global profile_template_assignment_id
profile_template_assignment_id = assignment['id']
global profile_template_assignment_etag
profile_template_assignment_etag = assign_response.get_headers()['Etag']
assignOptions := &iamidentityv1.CreateTrustedProfileAssignmentOptions{
TemplateID:      &profileTemplateId,
TemplateVersion: &profileTemplateVersion,
TargetType:      core.StringPtr("Account"),
Target:          &enterpriseSubAccountID,
}
assignResponse, response, err := iamIdentityService.CreateTrustedProfileAssignment(assignOptions)
b, _ := json.MarshalIndent(assignResponse, "", "  ")
fmt.Println(string(b))
// Grab the Etag and id for use by other test methods.
profileTemplateAssignmentEtag = response.GetHeaders().Get("Etag")
profileTemplateAssignmentId = *assignResponse.ID

如果指派失敗,請使用 更新指派作業 重試。

使用 API 建立新版本

如果要變更已提交或指定的受信任設定檔範本,請建立新版本。

curl -X POST 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
   "account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
   "name": "db admin template",
   "profile": {
      "name": "Profile for DB Admins",
      "description": "allows users to admin db instances",
      "rules": [
            {
               "type": "Profile",
               "realm_name": "${IDP_REALM_NAME}",
               "expiration": 43200,
               "conditions": [
                  {
                        "claim": "name",
                        "operator": "EQUALS",
                        "value": "\"My Name\""
                  }
               ]
            }
      ]
   },
   "policy_template_references": [
      {
            "id": "Policy Template-12345",
            "version": 1
      }
   ]
}'
ProfileClaimRuleConditions condition = new ProfileClaimRuleConditions.Builder()
   .claim("blueGroups")
   .operator("EQUALS")
   .value("\"cloud-docs-dev\"")
   .build();
List<ProfileClaimRuleConditions> conditions = new ArrayList<>();
conditions.add(condition);
TrustedProfileTemplateClaimRule claimRule = new TrustedProfileTemplateClaimRule.Builder()
   .name("My Rule")
   .realmName(realmName)
   .type(claimRuleType)
   .expiration(43200)
   .conditions(conditions)
   .build();
List<String> accounts = new ArrayList<String>();
accounts.add(enterpriseAccountId);
ProfileIdentityRequest profileIdentity = new ProfileIdentityRequest.Builder()
   .identifier(iamId)
   .accounts(accounts)
   .type("user")
   .description("Identity description")
   .build();
List<ProfileIdentityRequest> identities = new ArrayList<ProfileIdentityRequest>();
identities.add(profileIdentity);
TemplateProfileComponentRequest profile = new TemplateProfileComponentRequest.Builder()
   .addRules(claimRule)
   .name(profileTemplateProfileName)
   .description("Trusted profile created from a template - new version")
   .identities(identities)
   .build();
CreateProfileTemplateVersionOptions createOptions = new CreateProfileTemplateVersionOptions.Builder()
   .accountId(enterpriseAccountId)
   .templateId(profileTemplateId)
   .name(profileTemplateName)
   .description("IAM enterprise trusted profile template example - new version")
   .profile(profile)
   .build();
Response<TrustedProfileTemplateResponse> createResponse = service.createProfileTemplateVersion(createOptions).execute();
TrustedProfileTemplateResponse createResult = createResponse.getResult();
// Save the version for use by other test methods.
profileTemplateVersion = createResult.getVersion().longValue();
System.out.println(createResult);
const condition = {
   claim: "blueGroups",
   operator: "EQUALS",
   value: "\"cloud-docs-dev\"",
}
const claimRule = {
   name: "My Rule",
   realm_name: realmName,
   type: 'Profile-SAML',
   expiration: 43200,
   conditions: [condition],
}
const identity = {
   identifier: iamId,
   accounts: [enterpriseAccountId],
   type: "user",
   description: "Identity description",
}
const profile = {
   rules: [claimRule],
   name: "Profile-From-Example-Template",
   description: "Trusted profile created from a template - new version",
   identities: [identity],
}
const templateParams = {
   templateId: profileTemplateId,
   name: "Example-Profile-Template",
   description: "IAM enterprise trusted profile template example - new version",
   accountId: enterpriseAccountId,
   profile: profile,
}
try {
   const res = await iamIdentityService.createProfileTemplateVersion(templateParams);
   const { result } = res;
   profileTemplateVersion = result.version;
   console.log(JSON.stringify(result, null, 2));
} catch (err) {
   console.warn(err);
}
profile_claim_rule_conditions = {}
profile_claim_rule_conditions['claim'] = 'blueGroups'
profile_claim_rule_conditions['operator'] = 'EQUALS'
profile_claim_rule_conditions['value'] = '\"cloud-docs-dev\"'
profile_claim_rule = {}
profile_claim_rule['name'] = 'My Rule'
profile_claim_rule['realm_name'] = 'https://sdk.test.realm/1234'
profile_claim_rule['type'] = 'Profile-SAML'
profile_claim_rule['expiration'] = 43200
profile_claim_rule['conditions'] = [profile_claim_rule_conditions]
profile_identity = {}
profile_identity['identifier'] = iam_id
profile_identity['accounts'] = [enterprise_account_id]
profile_identity['type'] = 'user'
profile_identity['description'] = 'Identity description'
profile = {}
profile['name'] = 'Profile-From-Example-Template'
profile['description'] = 'Trusted profile created from a template - new version'
profile['rules'] = [profile_claim_rule]
profile['identities'] = [profile_identity]
create_response = iam_identity_service.create_profile_template_version(
template_id=profile_template_id,
name='Example-Profile-Template',
description='IAM enterprise trusted profile template example - new version',
account_id=enterprise_account_id,
profile=profile,
)
profile_template = create_response.get_result()
print('\ncreate_profile_template_version() response: ', json.dumps(profile_template, indent=2))
global profile_template_version
profile_template_version = profile_template['version']
profileClaimRuleConditions := new(iamidentityv1.ProfileClaimRuleConditions)
profileClaimRuleConditions.Claim = core.StringPtr("blueGroups")
profileClaimRuleConditions.Operator = core.StringPtr("EQUALS")
profileClaimRuleConditions.Value = core.StringPtr("\"cloud-docs-dev\"")
profileTemplateClaimRule := new(iamidentityv1.TrustedProfileTemplateClaimRule)
profileTemplateClaimRule.Name = core.StringPtr("My Rule")
profileTemplateClaimRule.RealmName = &realmName
profileTemplateClaimRule.Type = &claimRuleType
profileTemplateClaimRule.Expiration = core.Int64Ptr(int64(43200))
profileTemplateClaimRule.Conditions = []iamidentityv1.ProfileClaimRuleConditions{*profileClaimRuleConditions}
profile := new(iamidentityv1.TemplateProfileComponentRequest)
profile.Name = &profileTemplateProfileName
profile.Description = core.StringPtr("Example Profile created from Profile Template - new version")
profile.Rules = []iamidentityv1.TrustedProfileTemplateClaimRule{*profileTemplateClaimRule}
createOptions := &iamidentityv1.CreateProfileTemplateVersionOptions{
Name:        &profileTemplateName,
Description: core.StringPtr("Example Profile Template - new version"),
AccountID:   &enterpriseAccountID,
TemplateID:  &profileTemplateId,
Profile:     profile,
}
createResponse, response, err := iamIdentityService.CreateProfileTemplateVersion(createOptions)
b, _ := json.MarshalIndent(createResponse, "", "  ")
fmt.Println(string(b))
// save the new version to be used in subsequent calls
profileTemplateVersion = *createResponse.Version

使用 API 更新指派

更新作業以轉換到新版本或重試失敗的作業。

您指定的新模板版本會取代舊版本。 進一步瞭解「指定新版本」。

  1. 列出企業帳戶中的受信任設定檔指定,並註明 TemplateAssignment ID 和您要更新的指定的版本:
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_assignments?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListTrustedProfileAssignmentsOptions listOptions = new ListTrustedProfileAssignmentsOptions.Builder()
   .accountId(enterpriseAccountId)
   .templateId(profileTemplateId)
   .build();
Response<TemplateAssignmentListResponse> listResponse = service.listTrustedProfileAssignments(listOptions).execute();
TemplateAssignmentListResponse listResult = listResponse.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.listTrustedProfileAssignments(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_trusted_profile_assignments(
account_id=enterprise_account_id, template_id=profile_template_id
)
assignment_list = list_response.get_result()
print('\nlist_trusted_profile_assignments() response: ', json.dumps(assignment_list, indent=2))
listOptions := &iamidentityv1.ListTrustedProfileAssignmentsOptions{
AccountID:  &enterpriseAccountID,
TemplateID: &profileTemplateId,
}
listResponse, response, err := iamIdentityService.ListTrustedProfileAssignments(listOptions)
b, _ := json.MarshalIndent(listResponse, "", "  ")
fmt.Println(string(b))
  1. 更新受信任的設定檔指派。 如果您要重試作業,請使用相同的版本號碼。 以下範例請求將指派遷移到版本 2。
curl -X PATCH 'https://iam.cloud.ibm.com/v1/profile_assignments/<assignment_id>' -H 'Authorization: Bearer $TOKEN' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
   "template_version": 2
}'
UpdateTrustedProfileAssignmentOptions updateOptions = new UpdateTrustedProfileAssignmentOptions.Builder()
   .assignmentId(profileTemplateAssignmentId)
   .templateVersion(profileTemplateVersion)
   .ifMatch(profileTemplateAssignmentEtag)
   .build();
Response<TemplateAssignmentResponse> updateResponse = service.updateTrustedProfileAssignment(updateOptions).execute();
TemplateAssignmentResponse updateResult = updateResponse.getResult();
// Grab the Etag value from the response for use in the update operation.
profileTemplateAssignmentEtag = updateResponse.getHeaders().values("Etag").get(0);
System.out.println(updateResult);
const assignParams = {
assignmentId: profileTemplateAssignmentId,
templateVersion: profileTemplateVersion,
ifMatch: profileTemplateAssignmentEtag,
}
try {
const assRes = await iamIdentityService.updateTrustedProfileAssignment(assignParams);
console.log(JSON.stringify(assRes.result, null, 2));
} catch (err) {
console.warn(err);
}
assign_response = iam_identity_service.update_trusted_profile_assignment(
assignment_id=profile_template_assignment_id,
template_version=profile_template_version,
if_match=profile_template_assignment_etag,
)
assignment = assign_response.get_result()
print('\nupdate_profile_template_assignment response: ', json.dumps(assignment, indent=2))
profile_template_assignment_etag = assign_response.get_headers()['Etag']
updateOptions := &iamidentityv1.UpdateTrustedProfileAssignmentOptions{
AssignmentID:    &profileTemplateAssignmentId,
TemplateVersion: &profileTemplateVersion,
IfMatch:         &profileTemplateAssignmentEtag,
}
updateResponse, response, err := iamIdentityService.UpdateTrustedProfileAssignment(updateOptions)
b, _ := json.MarshalIndent(updateResponse, "", "  ")
fmt.Println(string(b))
// Grab the Etag and id for use by other test methods.
profileTemplateAssignmentEtag = response.GetHeaders().Get("Etag")

使用 API 移除指派

您可以從已指定範本的帳戶或帳戶群組移除範本指定。 如果範本無法如預期般運作或不再需要,您可能會想這麼做。 當您從帳戶移除範本指定時,預設會恢復先前版本的範本 (如果存在的話)。 如果您移除的指定是範本的第一個或唯一版本,則會移除子帳戶中的企業管理受信任設定檔。

若要移除一項指派,請依照以下步驟操作:

  1. 列出企業帳戶中受信任的設定檔指定,並註記要移除的指定的 TemplateAssignment ID。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_assignments?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListTrustedProfileAssignmentsOptions listOptions = new ListTrustedProfileAssignmentsOptions.Builder()
   .accountId(enterpriseAccountId)
   .templateId(profileTemplateId)
   .build();
Response<TemplateAssignmentListResponse> listResponse = service.listTrustedProfileAssignments(listOptions).execute();
TemplateAssignmentListResponse listResult = listResponse.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.listTrustedProfileAssignments(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_trusted_profile_assignments(
account_id=enterprise_account_id, template_id=profile_template_id
)
assignment_list = list_response.get_result()
print('\nlist_trusted_profile_assignments() response: ', json.dumps(assignment_list, indent=2))
listOptions := &iamidentityv1.ListTrustedProfileAssignmentsOptions{
AccountID:  &enterpriseAccountID,
TemplateID: &profileTemplateId,
}
listResponse, response, err := iamIdentityService.ListTrustedProfileAssignments(listOptions)
b, _ := json.MarshalIndent(listResponse, "", "  ")
fmt.Println(string(b))
  1. 移除任務。

移除任務可能會導致先前的任務變為活動。 如需詳細資訊,請參閱 使用範本版本

curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_assignments/<assignment_id>' -H 'Authorization: Bearer $TOKEN' }'
DeleteTrustedProfileAssignmentOptions deleteOptions = new DeleteTrustedProfileAssignmentOptions.Builder()
   .assignmentId(profileTemplateAssignmentId)
   .build();
Response<ExceptionResponse> deleteResponse = service.deleteTrustedProfileAssignment(deleteOptions).execute();
const params = {
assignmentId: profileTemplateAssignmentId,
}
try {
const res = await iamIdentityService.deleteTrustedProfileAssignment(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_trusted_profile_assignment(
assignment_id=profile_template_assignment_id
)
deleteOptions := &iamidentityv1.DeleteTrustedProfileAssignmentOptions{
AssignmentID: &profileTemplateAssignmentId,
}
excResponse, response, err := iamIdentityService.DeleteTrustedProfileAssignment(deleteOptions)

使用 API 刪除版本

在刪除受信任的設定檔模板版本之前,您必須移除該模板版本的所有指定。 完成以下步驟刪除特定版本:

  1. 列出您的 enteprise 帳戶中受信任的設定檔範本,並在回應中記下您要刪除的範本版本的 ProfileTemplate ID 和版本。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
   .accountId(enterpriseAccountId)
   .build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", "  ")
fmt.Println(string(b))
  1. 刪除版本:
curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
DeleteProfileTemplateVersionOptions deleteOptions = new DeleteProfileTemplateVersionOptions.Builder()
   .templateId(profileTemplateId)
   .version("1")
   .build();
Response<Void> deleteResponse = service.deleteProfileTemplateVersion(deleteOptions).execute();
const params = {
templateId: profileTemplateId,
version: 1,
}
try {
const res = await iamIdentityService.deleteProfileTemplateVersion(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_profile_template_version(
template_id=profile_template_id, version='1'
)
deleteOptions := &iamidentityv1.DeleteProfileTemplateVersionOptions{
TemplateID: &profileTemplateId,
Version:    core.StringPtr("1"),
}
response, err := iamIdentityService.DeleteProfileTemplateVersion(deleteOptions)

使用 API 刪除所有版本

確保您先移除每個版本的工作分配。

curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_templates/ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
DeleteAllVersionsOfProfileTemplateOptions deleteTeplateOptions = new DeleteAllVersionsOfProfileTemplateOptions.Builder()
   .templateId(profileTemplateId)
   .build();
Response<Void> deleteResponse = service.deleteAllVersionsOfProfileTemplate(deleteTeplateOptions).execute();
const params = {
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.deleteAllVersionsOfProfileTemplate(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_all_versions_of_profile_template(
template_id=profile_template_id
)
deleteOptions := &iamidentityv1.DeleteAllVersionsOfProfileTemplateOptions{
TemplateID: &profileTemplateId,
}
response, err := iamIdentityService.DeleteAllVersionsOfProfileTemplate(deleteOptions)