企業管理の信頼できるプロファイルテンプレートの作成
子アカウントを多数抱える企業では、各アカウントで信頼されたプロファイルを手動で設定するのは時間がかかり、エラーが発生しやすいものです。 信頼できるプロファイルテンプレートを使用して、企業内のアカウントへのフェデレーションユーザーのアクセスを動的に許可します。
企業管理の信頼済みプロファイルテンプレートを使用すると、フェデレーションユーザーとのみ信頼関係を構築できます。 アカウントアカウントでコンピューティングリソース、 IBM Cloud サービス、およびサービスID用の信頼済みプロファイルを設定するには、「 信頼済みプロファイルの作成 」を参照してください。
信頼済みプロファイルを適用するには、ユーザーはアカウントのメンバーである必要はありません。 ユーザーが信頼されたプロファイルと同じアイデンティティプロバイダー( IdP )を所有しており、信頼の条件を満たしている場合、ユーザーはプロファイルを適用することができます。 例えば、企業ディレクトリ内のユーザーが特定のタスクを実行するために、アカウントのグループへのアクセスが必要な場合などです。 そのユーザーと必要なポリシーをターゲットとした信頼条件付きの信頼プロファイルテンプレートを作成します。 次に、アクセスが必要なアカウントに信頼されたプロファイルテンプレートを割り当てます。 現在、ユーザーは各アカウントで信頼されたプロファイルを適用することでアカウントを切り替えることができ、アカウント間で一貫したアクセスが可能になっています。
ID サービスの管理者は、アカウント内の企業管理の信頼済みプロファイルに信頼関係とポリシーを追加できますが、テンプレートで定義したものを変更することはできません。
開始前に
-
始める前に、 外部アイデンティティプロバイダーからの認証を有効にする 必要があります。
-
企業管理のIAMテンプレートが企業をより安全にする仕組みについては 、「企業管理のIAMアクセス機能の仕組み」 を参照してください。
-
企業管理のIAMテンプレートを作成し、割り当てるには、エンタープライズアカウントのメンバーである必要があります。
-
企業管理のIAMテンプレートを作成するには、次のアクセス権が割り当てられていることを確認してください
- すべての アカウントにおいて、「テンプレート管理者」ロールを付与されたポリシー
-
企業管理のIAMテンプレートを子アカウントに割り当てるには、次のアクセス権が割り当てられていることを確認してください
- すべてのIAMアカウント管理サービスにおけるテンプレート割り当て管理者の役割を持つポリシー
- エンタープライズサービスで少なくともビューアーの役割を持つポリシー
デフォルトでは、アカウント所有者を含め、テンプレート管理者またはテンプレート割当管理者のロールを持つユーザーはいません。
-
企業内の新規および既存のアカウントは、エンタープライズ管理IAMにオプトインする必要があります。 詳細については 、「企業管理のIAMへのオプトイン 」を参照してください。
信頼できるプロファイルテンプレートの作成
ユーザーが多数の子アカウントへのアクセスを必要とする場合、またはユーザーグループが複数の子アカウントへの一時的なアクセスを必要とする場合には、信頼されたプロファイルテンプレートの使用を検討してください。
信頼済みプロファイルテンプレートを作成するには、以下の手順を実行してください
-
Manage > Access (IAM) > Templates と進み、 IBM Cloud コンソールで Trusted profiles を選択する。
-
「作成」 をクリックします。
-
企業ユーザー向けの信頼済みプロファイルテンプレートの目的を説明する名前と説明を入力してください。
-
エンタープライズ管理の信頼済みプロファイルについて、 アカウントユーザー向けの目的を説明する名前、メールアドレス、説明を入力してください。説明には、この信頼済みプロファイルで利用可能な操作の一覧を必ず含めてください。
メールには、個人用メールアドレスまたは配布リストのいずれかを追加できます。
プロファイル名の置換変数を使用して、アカウントごとにカスタマイズすることができます。 以下の変数がサポートされています:
${template_id}:信頼されたプロファイルテンプレートの一意な識別子に置き換えられます。${template_name}:信頼されたプロファイルテンプレートの現在の名前に置き換えられます。${template_version}:信頼されたプロファイルテンプレートの現在のバージョンに置き換えられます。${account_id}:信頼されたプロファイルテンプレートが割り当てられているアカウントの識別子に置き換えられます。${account_name}:信頼されたプロファイル・テンプレートが割り当てられているアカウントの名前に置き換えられます。
アカウント名などの値を変更しても、信頼済みプロファイル名は更新されません。 プロファイル名は、テンプレートをアカウントに割り当てたり、テンプレートのバージョンをアップグレードしたりするときに設定されます。 つまり、アカウント名が後で変更されても、プロフィール名は自動的に更新されません。 新しいアカウント名は、次にテンプレートを割り当てたりアップグレードするときにのみ使用されます。
-
「作成」 をクリックします。
(オプション)信頼関係を追加する
個別ユーザー
IBM Cloud IAM ID を使用して、アカウント内外の個々のユーザーとの信頼関係を確立します。
信頼を確立するには、以下の手順を完了してください
- 信頼関係]>[個人ユーザー ]をクリックします。
- Add(追加)」をクリックし、「 Account users(アカウントユーザー) 」または「 External users(外部ユーザー) 」を選択して企業メンバーを招待し、テンプレートを割り当てます。
- アカウントにユーザーを追加するには、 「アカウント ユーザー」 をクリックします。
- ユーザーまたは複数のユーザーを選択します。
- Add(追加 )をクリックして、ユーザーを関連プロファイルに追加します。
- アカウントに登録されていないユーザーを追加するには、[ 外部ユーザー ]をクリックします。
- IAM IDを入力します。
- 関連するアカウントIDを入力する。 複数のアカウントを追加することができ、ユーザーが現在作業しているアカウントとは別のアカウントを追加することもできます。
- (オプション) 説明を入力します。
- Add(追加 )をクリックして、ユーザーを関連プロファイルに追加します。
- アカウントにユーザーを追加するには、 「アカウント ユーザー」 をクリックします。
追加または削除を選択して、編集または削除したいユーザーの横にある 「アクション アイコンをクリックします。
フェデレーテッド・ユーザー
企業のディレクトリにある属性に基づいて条件を設定し、フェデレーションユーザーとの信頼関係を構築します。 あなたが定義した条件を満たす連邦政府職員は、プロファイルを申請することができます。
信頼を確立するには、以下の手順を完了してください
- Trust relationship(信頼関係)]>[Federated users(連携ユーザー) ]をクリックします。
- Add をクリックし、認証方法として Users federated by IBMid または **Users federated by IBM Cloud AppID を選択し、デフォルトの ID プロバイダ(**IdP )を入力する。
- IdP のデータに基づく条件を追加して、いつ、どのようにフェデレーテッド・ユーザーがプロファイルを適用できるかを定義します。
- 複数の条件を定義するには、 Add a conditionをクリックする。 フェデレーションユーザーは、信頼済みプロファイルを適用するために、すべての条件を満たしている必要があります。 条件の作成に使用されるフィールドについて詳しくは、IAM 条件プロパティーを参照してください。
- IdP から、ご自身の個人データに含まれる属性名や値を検索するには、 IDプロバイダーのデータを表示してください。 詳しくは、IdP データを使用したトラステッド・プロファイルの作成を参照してください。
- ユーザーがプロファイルを適用できる期間のセッション期間を定義します。この期間を過ぎると、ユーザーは再認証を行う必要があります。
- 追加 をクリックします。
追加または削除を選択して、編集または削除する連携ユーザーの横にあるアクションアイコン クリックします。
コンピュート・リソース
特定のクラスタで実行されるプログラムが必要なリソースに安全にアクセスできるように、計算リソースとの信頼関係を確立する。
信頼を確立するには、以下の手順を完了してください
- Trust relationship > Compute resourcesをクリックする。
- Addをクリックし、コンピュート・サービスを選択する。
- 複数の条件を定義するには、 Add a conditionをクリックする。 条件の作成に使用されるフィールドについて詳しくは、IAM 条件プロパティーを参照してください。
- 追加 をクリックします。
[追加] または[削除]を選択して、編集または削除するコンピューティング リソースの横にある [アクション]アイコン クリックします。
IBM Cloud サービス
クラウド・リソース名で識別されるクラウド・サービスのインスタンスを許可することで、 IBM Cloud サービスとの信頼関係を確立する。
信頼を確立するには、以下の手順を完了してください
- 信頼関係 > IBM Cloud サービスをクリックします。
- Addをクリックし、CRNを入力します。
- (オプション) 説明を入力します。
- 追加 をクリックします。
Add(追加) または Remove(削除 )を選択して、編集または削除したい IBM Cloud サービスの横にある Actions( アイコンをクリックします。
サービス ID
サービスを認証することで、サービスIDとの信頼関係を確立する。 サービスIDは特定のサービス用に作成することができ、APIキーはそのサービスを安全に認証するために生成される。 さらに、サービスIDは信頼されたプロファイルを想定し、必要に応じて権限を継承し、リソースにアクセスすることができる。
信頼を確立するには、以下の手順を完了してください
- 信頼関係]>[サービスID ]をクリックします。
- Addをクリックし、サービスIDを入力する。
- (オプション) 説明を入力します。
- 追加 をクリックします。
編集または削除したいサービスIDの横にある 「Actions アイコンをクリックし、「 Add」 または「 Remove 」を選択します。
(オプション)アクセスポリシーを追加する
アクセスポリシーにより、プロファイルを適用できるフェデレーションユーザーに子アカウントへのアクセス権が付与されます。
-
アクセス > 追加をクリックします。
-
名前を入力し、割り当てたいポリシーを説明してください。
信頼されたプロファイルテンプレートに設定するすべてのポリシーで、ポリシーテンプレートを作成します。 他のエンタープライズIAMテンプレートでアクセス権を割り当てるために、ポリシーテンプレートを参照することができます。
-
サービスまたはサービスのグループを選択し、[ 次へ] をクリックします。
-
アクセス範囲を「 すべてのリソース 」にするか、属性に基づいて 「特定のリソース 」を選択し、「 次へ 」をクリックします。
-
ロールとアクション 」セクションで、アクセス範囲を定義するロールを選択します。 ポリシーテンプレートフロー内でカスタムロールテンプレートを作成し、選択したサービスの既存のカスタムロールテンプレートからカスタムロールを選択することもできます。
- アクションのカスタムの組み合わせを定義するには、 カスタムロールの作成をクリックします。
- テンプレート名を入力します。
- (任意)テンプレートの説明を入力してください。
- カスタムロールの名前を入力してください。
- カスタムロールのIDを入力してください。
- (任意)カスタムロールの説明を入力してください。
- アクションを選択し、 作成をクリックする。 カスタムロールは、ポリシーで既に選択されている他のロールと一緒に一覧表示され、選択されます。
検索バーを使用して、特定のアクションをサポートするロールを検索します。 例えば、 read、 edit、 viewを検索すると、これらのアクションが適用されるロールのリストが表示されます。
-
(オプション)ポリシーでアクセスを許可したい場合を指定する条件を追加します。
-
追加 をクリックします。
アクセスポリシーを削除する
テンプレートがコミットされ、割り当てられる前にポリシーを削除することができます。
テンプレートの詳細を更新する
テンプレートをコミットする前であれば、いつでもテンプレート名、信頼済みプロファイル名、説明を更新することができます。 テンプレートの詳細を更新するには、以下の手順に従ってください:
- [管理] > [アクセス (IAM)] > [テンプレート] に移動します。
- 更新したい信頼済みプロファイルテンプレートを選択します。
- 詳細セクションの 編集 アイコン
をクリックします。
- テンプレート名、信頼済みプロファイル名、説明文を必要に応じて更新します。
- 保存 をクリックします。
テンプレートをコミットした後で更新が必要な場合は、新しいバージョンを作成してください。
信頼できるプロフィールテンプレートの確認
信頼できるプロファイルテンプレートをレビューし、コミットすることで、そのバージョンにこれ以上の変更が加えられないようにする。 これにより、テンプレート割り当て管理者が、お客様が準備完了を確認したときにのみバージョンを割り当てていることを確実にすることができます。
- 概要 > レビュー をクリックします。
- 信頼されたプロファイルテンプレートが期待通りに設定されていることを確認してください。
- バージョンを変更できないことを確認するために、チェックボックスをクリックします。
- **「コミット」**をクリックします。
子アカウントに信頼されたプロファイルテンプレートを割り当てる
信頼されたプロファイルテンプレートを企業内の子アカウントに割り当てます。
IAMテンプレートは、エンタープライズアカウントではなく、子アカウントとアカウントグループのみに割り当てることができます。
-
「アカウントの割り当て 」をクリックします。
-
テンプレートを割り当てるアカウントおよびアカウントグループを選択します。
テンプレートを割り当てる各子アカウントで、企業管理の信頼済みプロファイルを作成します。 子アカウントのユーザーは、信頼されたプロファイルが企業管理のIAMテンプレートから作成されたものであることを、プロファイルに付された企業管理の タグによって確認することができます。
-
割り当て をクリックします。
割り当てに失敗した場合は、 [再試行] をクリックします。
新しいバージョンを作成する
コミット済みまたは割り当て済みの信頼済みプロファイルテンプレートを変更したい場合は、新しいバージョンを作成してください。 最新のバージョンを基に新しいバージョンを作成したり、選択した別のバージョンを作成したりすることができます。
信頼済みプロファイルテンプレートの新しいバージョンを作成するには、以下の手順を実行してください
-
IBM Cloud コンソールの 「管理」>「アクセス (IAM)」>「テンプレート」 に移動します。
-
信頼できるプロフィールテンプレートを選択してください。
-
新しいバージョンアイコンをクリック
。
-
新しいバージョンのベースとして使用したいバージョンを選択します。
-
新しいテンプレート名と説明を入力するか、現在使用中のものをそのまま使用します。
新しいテンプレート名を入力すると、このバージョンとそれ以前のすべてのバージョンのテンプレート名が更新されます。 テンプレートの説明は、各バージョンごとに個別に保存されます。
-
新しい信頼済みプロファイル名と説明を入力するか、現在使用中のものをそのまま使用します。
新しい信頼済みプロファイル名を入力すると、新しいバージョンをアカウント表示される以前の信頼済みプロファイル名が置き換えられます。
-
新しいバージョンに引き継ぎたいオブジェクトを選択します。
- (オプション) 信頼関係を選択します。
- (オプション )「アクセス」 を選択します。
-
「作成」 をクリックします。
-
設定について、その他必要な調整を行ってください。
-
「レビュー」 をクリックし、新しいバージョンをコミットします。 詳細については 、「信頼済みプロファイルテンプレートの確認 」を参照してください。
信頼済みプロファイルテンプレートの新しいバージョンを割り当てるには、以下の手順に従います
- IBM Cloud コンソールの 「管理」>「アクセス (IAM)」>「テンプレート」 に移動します。
- 信頼済みプロファイルをクリックします。
- 作業するテンプレートの テーブルが拡張する アイコン
をクリックします。
- 現在子アカウントに割り当てられているバージョンを選択します。
- 「割り当て」 をクリックします。
- 別のバージョンを割り当てたいアカウントまたはアカウントグループの割り当てで 、「更新」 をクリックします。
- 「 バージョンを選択 」をクリックしてください。
- 現在のバージョンを置き換えたいバージョンを選択します。
- 更新 をクリックします。
- 異なるバージョンを割り当てたい各アカウントまたはアカウントグループに対して、これらの手順を繰り返します。
割り当てた新しいテンプレートバージョンが古いバージョンに置き換わります。 新しいバージョンの割り当てについて、さらに詳しく知る。
割り当ての削除
テンプレートが割り当てられている1つ以上のアカウントから、テンプレート割り当てを削除することができます。 テンプレートが意図したように動作していない場合は、そうした方が良いでしょう。 アカウントからテンプレート割り当てを削除すると、デフォルトではテンプレートの以前のバージョンが復元されます。 削除した割り当てがテンプレートの最初のバージョンまたは唯一のバージョンの場合、子アカウントの信頼されたプロファイルが削除されます。
割り当てを削除するには、以下の手順に従ってください
- IBM Cloud コンソールの 「管理」>「アクセス (IAM)」>「テンプレート」 に移動します。
- 信頼済みプロファイルをクリックし、信頼済みプロファイルテンプレートを選択します。
- 「更新 」をクリックします。
- 1つまたは少数のアカウントから割り当てを削除するには、テンプレート割り当てを削除したいアカウントの選択を解除します。
- テンプレートが割り当てられているすべてのアカウントから割り当てを解除するには 、「すべて解除」 をクリックします。
CLI を使用して信頼されたプロファイルテンプレートを作成する
同じ信頼済みプロファイルを必要とする子アカウントを多数お持ちの場合は、信頼済みプロファイルテンプレートのご利用をご検討ください。 例えば、貴社には社内基準があるかもしれませんし、業界規制への準拠が求められる場合もあるでしょう。
CLI を使用して信頼済みプロファイルテンプレートを作成するには、以下の手順を実行してください
-
信頼されたプロファイルテンプレートの定義を設定するJSONファイルを作成します。 JSONファイルで使用できる属性の詳細については 、IAM Identity API を参照してください。
次の例のJSONファイルでは、エンタープライズアカウントの
account_id、テンプレートのname、およびprofile構成を指定しています。 この信頼されたプロファイルはデータベース管理者用です。identitiesrulesも定義されており、 の属性に基づいてプロファイルへのアクセスを許可します。 SAML{ "account_id": "5bbe28be34524sdbdaa34d37d1f2294a", "name": "dbadmintemplate", "profile": { "name": "Profile for DB Admins", "description": "allows users to admin db instances", "identities": [ { "type": "user", "identifier": "IBMid-123456789", "accounts": [ "5bbe28be34524sdbdaa34d37d1f2294a" ] } ], "rules": [ { "type": "Profile", "realm_name": "${IDP_REALM_NAME}", "expiration": 43200, "conditions": [ { "claim": "group", "operator": "EQUALS", "value": "\"admins\"" } ] } ] }, "policy_template_references": [ { "id": "Policy Template-12345", "version": 1 } ] } -
次のサンプルリクエストに示されているように、
trusted-profile-template-createコマンドを使用して信頼されたプロファイルテンプレートを作成しますibmcloud iam trustedprofile-template-create dbadmintemplate --file /path/to/db_trusted-profile_template.json
CLI を使用して信頼されたプロファイルテンプレートを更新する
コミットする前に、信頼されたプロファイルテンプレートをいつでも更新することができます。 信頼済みプロファイルテンプレートの特定のバージョンを更新するには、以下の手順に従います
-
新しい信頼済みプロファイルテンプレートの定義をJSONファイルに追加します。 JSONファイルで使用できる属性の詳細については 、IAM Identity API を参照してください。
{ "account_id": "5bbe28be34524sdbdaa34d37d1f2294a", "name": "DBAdministrator", "profile": { "name": "Profile for DB Admins", "description": "allows users to admin db instances", "identities": [ { "type": "user", "identifier": "IBMid-123456789", "accounts": [ "5bbe28be34524sdbdaa34d37d1f2294a" ] } ], "rules": [ { "type": "Profile", "realm_name": "${IDP_REALM_NAME}", "expiration": 43200, "conditions": [ { "claim": "group", "operator": "EQUALS", "value": "\"admins\"" } ] } ] }, "policy_template_references": [ { "id": "Policy Template-12345", "version": 1 } ] }
テンプレート名を更新すると、すべてのバージョンの名前が更新されます。
{: note}
1. 信頼済みプロファイルテンプレートの特定のバージョンを更新するには、次のサンプルリクエストに示されているように、 `trusted-profile-template-version-update` コマンドを使用します
```bash {: codeblock}
ibmcloud iam trustedpprofile-template-version-update DBAdministrator 1 --file /path/to/db_trusted-profile_template.json
## CLI を使用して信頼されたプロファイルテンプレートをコミットする
{: #commit-trusted-profile-template-cli cli}
信頼できるプロファイルテンプレートを確認し、そのバージョンにこれ以上の変更が加えられないようにコミットします。 バージョンをコミットすることは、子アカウントに割り当てる前に必要なステップです。 これにより、テンプレート割り当て管理者が、お客様が準備完了を確認したときにのみバージョンを割り当てていることを確実にすることができます。
以下のサンプルリクエストは、 `DBAdministrator` という名前の信頼済みプロファイルテンプレートのバージョン `1` をコミットします
```bash {: codeblock}
ibmcloud iam trusted-profile-template-version-commit DBAdministrator 1
## CLI を使用して信頼されたプロファイルテンプレートを子アカウントに割り当てる
{: #assign-trusted-profile-template-cli cli}
信頼されたプロファイルテンプレートを企業内の子アカウントに割り当てます。
IAMテンプレートは、エンタープライズアカウントではなく、子アカウントとアカウントグループのみに割り当てることができます。
{: note}
信頼済みプロファイルテンプレートに割り当てを作成するには、以下の手順に従います
1. 企業アカウントで信頼されたプロファイルテンプレートをリストアップし、子アカウントに割り当てる信頼されたプロファイルテンプレートのテンプレート名とバージョン番号をメモします
```bash {: codeblock}
ibmcloud iam trusted-profile-templates
1. `account-trusted profile-assignment-create` コマンドを使用して、テンプレートを `Account` または `AccountGroup` に割り当てます。
ibmcloud iam trusted-profile-assignment-create DBAdministrator 1 AccountGroup 955fc2274567474f8da802d5c376504b
割り当てに失敗した場合は、 `trusted-profile-assignment-update` メソッドを使用して再試行してください。
{: tip}
## CLI を使用して新しいバージョンを作成する
{: #new-version-trusted-profile-template cli}
コミット済みまたは割り当て済みの信頼済みプロファイルテンプレートを変更したい場合は、新しいバージョンを作成してください。
1. 新しい信頼済みプロファイルテンプレートの定義をJSONファイルに追加します。 JSONファイルで使用できる属性の詳細については [、IAM Identity API](/docs/apis/iam-identity-token-api#create-profile-template-version) を参照してください。
1. `trusted-profile-template-version-create` メソッドを使用して新しいバージョンを作成します。 次のサンプルリクエストは、テンプレートの新しいバージョンを作成します。 `DBAdministrator`。
ibmcloud iam trusted-profile-template-version-create DBAdministrator --file /path/to/db_trusted-profile_template.json
## CLI を使用して課題を更新する
{: #update-assignment-trusted-profile-cli cli}
新しいバージョンへの移行や、失敗した割り当ての再試行などの割り当てを更新します。
割り当てた新しいテンプレートバージョンが古いバージョンに置き換わります。 [新しいバージョンの割り当てについて](/docs/enterprise-management?topic=enterprise-management-working-with-versions#new-version)、さらに詳しく知る。
{: note}
1. 企業アカウントで信頼されたプロファイルの割り当てをリストアップし、更新したい割り当てについて `template_id` にメモしてください
ibmcloud iam trusted-profile-assignments
1. 信頼済みプロファイルの割り当てを更新します。 課題を再提出する場合は、同じバージョン番号を使用してください。 次のサンプルリクエストは、課題 `ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d` をバージョン2に移行します。
ibmcloud iam trusted-profile-assignment-update ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d 2
## CLI を使用して割り当てを削除する
{: #remove-assignment-trusted-profile-cli cli}
テンプレートが割り当てられているアカウントまたはアカウントグループから、テンプレート割り当てを削除することができます。 テンプレートが意図したように動作していない場合は、そうした方が良いでしょう。 アカウントからテンプレート割り当てを削除すると、デフォルトではテンプレートの以前のバージョンが復元されます。 削除した割り当てがテンプレートの最初のバージョンまたは唯一のバージョンの場合、子アカウントの企業管理の信頼済みプロファイルが削除されます。
割り当てを削除するには、以下の手順に従ってください
1. `account-trusted profile-assignments` の方法でアカウント内の割り当てをリストアップします。 削除したい課題の `ASSIGNMENT_ID` をメモしてください。
1. `account-trusted profile-assigment-delete` メソッドを使用して割り当てを解除します。 次のサンプルリクエストは、 `AccountSettingsAssignment-63d65ed159ff463b8ec09ea77d22a05b` の割り当てを削除します。
ibmcloud iam account-trusted profile-assignment-delete AccountSettingsAssignment-63d65ed159ff463b8ec09ea77d22a05b
## CLI を使用してバージョンを削除する
{: #delete-trusted-profile-template-version-cli cli}
信頼されたプロファイルテンプレートのバージョンを削除する前に、そのバージョンのテンプレートへのすべての割り当てを削除する必要があります。 特定のバージョンを削除するには、以下の手順に従ってください
1. 企業アカウントで信頼するプロファイルテンプレートをリストアップし、削除するバージョンのテンプレート名とバージョン番号をメモします
ibmcloud iam account-trusted profile-templates
1. バージョンを削除する:
ibmcloud iam account-trusted profile-template-delete AccountSettingsTemplateUpdated 2
1. すべてのバージョンを削除するには、これらの手順を繰り返します。 各バージョンの割り当てを最初に削除することを確認してください。
## APIを使用して信頼性の高いプロファイルテンプレートを作成する
{: #create-trusted-profile-template-api api}
同じ信頼済みプロファイルを必要とする子アカウントを多数お持ちの場合は、信頼済みプロファイルテンプレートのご利用をご検討ください。 例えば、貴社には社内基準があるかもしれませんし、業界規制への準拠が求められる場合もあるでしょう。
APIを使用して信頼されたプロファイルテンプレートを作成するには、以下の手順に従います
1. 信頼済みプロファイルテンプレートの定義を設定します。 使用できる属性の詳細については [、IAM Identity API](/docs/apis/iam-identity-token-api#create-profile-template) を参照してください。
次の例では、エンタープライズアカウントの account_id 、テンプレートの name 、および profile の設定を指定しています。 この信頼されたプロファイルはデータベース管理者用です。 identities rules も定義されており、 の属性に基づいてプロファイルへのアクセスを許可します。 SAML
{
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "dbadmintemplate",
"profile": {
"name": "Profile for DB Admins",
"description": "allows users to admin db instances",
"identities": [
{
"type": "user",
"identifier": "IBMid-123456789",
"accounts": [
"5bbe28be34524sdbdaa34d37d1f2294a"
]
}
],
"rules": [
{
"type": "Profile",
"realm_name": "${IDP_REALM_NAME}",
"expiration": 43200,
"conditions": [
{
"claim": "group",
"operator": "EQUALS",
"value": "\"admins\""
}
]
}
]
},
"policy_template_references": [
{
"id": "Policy Template-12345",
"version": 1
}
]
}
ProfileClaimRuleConditions condition = new ProfileClaimRuleConditions.Builder()
.claim("blueGroups")
.operator("EQUALS")
.value("\"cloud-docs-dev\"")
.build();
List<ProfileClaimRuleConditions> conditions = new ArrayList<>();
conditions.add(condition);
TrustedProfileTemplateClaimRule claimRule = new TrustedProfileTemplateClaimRule.Builder()
.name("My Rule")
.realmName(realmName)
.type(claimRuleType)
.expiration(43200)
.conditions(conditions)
.build();
TemplateProfileComponentRequest profile = new TemplateProfileComponentRequest.Builder()
.addRules(claimRule)
.name(profileTemplateProfileName)
.description("Trusted profile created from a template")
.build();
CreateProfileTemplateOptions createProfileTemplateOptions = new CreateProfileTemplateOptions.Builder()
.name(profileTemplateName)
.description("IAM enterprise trusted profile template example")
.accountId(enterpriseAccountId)
.profile(profile)
.build();
Response<TrustedProfileTemplateResponse> response = service.createProfileTemplate(createProfileTemplateOptions).execute();
TrustedProfileTemplateResponse trustedProfileTemplateResult = response.getResult();
// Save the id for use by other test methods.
profileTemplateId = trustedProfileTemplateResult.getId();
profileTemplateVersion = trustedProfileTemplateResult.getVersion().longValue();
System.out.println(trustedProfileTemplateResult);
```
```javascript {: javascript codeblock}
const condition = {
claim: "blueGroups",
operator: "EQUALS",
value: "\"cloud-docs-dev\"",
}
const claimRule = {
name: "My Rule",
realm_name: realmName,
type: 'Profile-SAML',
expiration: 43200,
conditions: [condition],
}
const profile = {
rules: [claimRule],
name: "Profile-From-Example-Template",
description: "Trusted profile created from a template",
}
const templateParams = {
name: "Example-Profile-Template",
description: "IAM enterprise trusted profile template example",
accountId: enterpriseAccountId,
profile: profile,
}
try {
const res = await iamIdentityService.createProfileTemplate(templateParams);
profileTemplateEtag = res.headers.etag;
const { result } = res;
profileTemplateId = result.id;
profileTemplateVersion = result.version;
console.log(JSON.stringify(result, null, 2));
} catch (err) {
console.warn(err);
}
```
```python {: python codeblock}
profile_claim_rule_conditions = {}
profile_claim_rule_conditions['claim'] = 'blueGroups'
profile_claim_rule_conditions['operator'] = 'EQUALS'
profile_claim_rule_conditions['value'] = '\"cloud-docs-dev\"'
profile_claim_rule = {}
profile_claim_rule['name'] = 'My Rule'
profile_claim_rule['realm_name'] = 'https://sdk.test.realm/1234'
profile_claim_rule['type'] = 'Profile-SAML'
profile_claim_rule['expiration'] = 43200
profile_claim_rule['conditions'] = [profile_claim_rule_conditions]
profile = {}
profile['name'] = 'Profile-From-Example-Template'
profile['description'] = 'Trusted profile created from a template'
profile['rules'] = [profile_claim_rule]
create_response = iam_identity_service.create_profile_template(
name='Example-Profile-Template',
description='IAM enterprise trusted profile template example',
account_id=enterprise_account_id,
profile=profile,
)
profile_template = create_response.get_result()
print('\ncreate_profile_template() response: ', json.dumps(profile_template, indent=2))
global profile_template_id
profile_template_id = profile_template['id']
global profile_template_version
profile_template_version = profile_template['version']
```
```go {: go codeblock}
profileClaimRuleConditions := new(iamidentityv1.ProfileClaimRuleConditions)
profileClaimRuleConditions.Claim = core.StringPtr("blueGroups")
profileClaimRuleConditions.Operator = core.StringPtr("EQUALS")
profileClaimRuleConditions.Value = core.StringPtr("\"cloud-docs-dev\"")
profileTemplateClaimRule := new(iamidentityv1.TrustedProfileTemplateClaimRule)
profileTemplateClaimRule.Name = core.StringPtr("My Rule")
profileTemplateClaimRule.RealmName = &realmName
profileTemplateClaimRule.Type = &claimRuleType
profileTemplateClaimRule.Expiration = core.Int64Ptr(int64(43200))
profileTemplateClaimRule.Conditions = []iamidentityv1.ProfileClaimRuleConditions{*profileClaimRuleConditions}
profile := new(iamidentityv1.TemplateProfileComponentRequest)
profile.Name = &profileTemplateProfileName
profile.Description = core.StringPtr("Example Profile created from Profile Template")
profile.Rules = []iamidentityv1.TrustedProfileTemplateClaimRule{*profileTemplateClaimRule}
createOptions := &iamidentityv1.CreateProfileTemplateOptions{
Name: &profileTemplateName,
Description: core.StringPtr("Example Profile Template"),
AccountID: &enterpriseAccountID,
Profile: profile,
}
createResponse, response, err := iamIdentityService.CreateProfileTemplate(createOptions)
b, _ := json.MarshalIndent(createResponse, "", " ")
fmt.Println(string(b))
// Grab the ID and Etag value from the response for use in the update operation
profileTemplateId = *createResponse.ID
profileTemplateVersion = *createResponse.Version
profileTemplateEtag = response.GetHeaders().Get("Etag")
```
更新処理で使用するために、レスポンスから ProfileTemplate IDとentity_tagの値を保存します。
{ tip}
## APIを使用して信頼済みプロファイルテンプレートを更新する
{: #update-trusted-profile-template-api api}
コミットする前に、信頼されたプロファイルテンプレートをいつでも更新することができます。 JSONファイルで使用できる属性の詳細については [、IAM Identity API](/docs/apis/iam-identity-token-api#update-profile-template-version) を参照してください。 信頼済みプロファイルテンプレートの特定のバージョンを更新するには、以下の手順に従います
1. 企業アカウントで信頼するプロファイルテンプレートをリストアップし、更新したいテンプレートバージョンの応答に含まれる `ProfileTemplate` IDとETagをメモします。
```bash {: curl codeblock}
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
.accountId(enterpriseAccountId)
.build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", " ")
fmt.Println(string(b))
1. 信頼済みプロファイルテンプレートの定義を更新します。
```bash {: curl codeblock}
curl -X PUT 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{ "account_id": "5bbe28be34524sdbdaa34d37d1f2294a", "name": "db admin template", "profile": { "name": "Profile for DB Admins", "description": "allows users to admin db instances", "rules": [ { "type": "Profile", "realm_name": "${IDP_REALM_NAME}", "expiration": 43200, "conditions": [ { "claim": "name", "operator": "EQUALS", "value": ""My Name"" } ] } ] }, "policy_template_references": [ { "id": "Policy Template-12345", "version": 1 } ] }'
```java {: java codeblock}
UpdateProfileTemplateVersionOptions updateOptions = new UpdateProfileTemplateVersionOptions.Builder()
.accountId(enterpriseAccountId)
.templateId(profileTemplateId)
.version(Long.toString(profileTemplateVersion))
.ifMatch(profileTemplateEtag)
.name(profileTemplateName)
.description("IAM enterprise trusted profile template example - updated")
.build();
Response<TrustedProfileTemplateResponse> updateResponse = service.updateProfileTemplateVersion(updateOptions).execute();
TrustedProfileTemplateResponse updateResult = updateResponse.getResult();
// Grab the Etag value from the response for use in the update operation.
profileTemplateEtag = updateResponse.getHeaders().values("Etag").get(0);
System.out.println(updateResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
version: profileTemplateVersion,
ifMatch: profileTemplateEtag,
name: "Example-Profile-Template",
description: "IAM enterprise trusted profile template example - updated",
}
try {
const res = await iamIdentityService.updateProfileTemplateVersion(params);
profileTemplateEtag = res.headers.etag;
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
{
"id": "ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9",
"version": 1,
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "db admin template",
"committed": false,
"profile": {
"name": "Profile for DB Admins",
"description": "allows users to admin db instances",
"rules": [
{
"type": "Profile-SAML",
"realm_name": "${IDP_REALM_NAME}",
"expiration": 43200,
"conditions": [
{
"claim": "name",
"operator": "EQUALS",
"value": "\"My Name\""
}
]
}
]
},
"policy_template_references": [
{
"id": "Policy Template-12345",
"version": "1"
}
],
"created_at": "2023-03-07T13:55:33:428+0000",
"created_by_id": "IBMid-12345678901",
"last_modified_at": "2023-03-07T13:55:33:428+0000",
"last_modified_by_id": "IBMid-12345678901",
"entity_tag": "1-2da85a8f1172fc3527378318d3182778",
"crn": "crn:v1:staging:public:iam-identity::a/5bbe28be34524sdbdaa34d37d1f2294a::template:ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9"
}
{
"id": "ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9",
"version": 1,
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "db admin template",
"committed": false,
"profile": {
"name": "Profile for DB Admins",
"description": "allows users to admin db instances",
"rules": [
{
"type": "Profile-SAML",
"realm_name": "${IDP_REALM_NAME}",
"expiration": 43200,
"conditions": [
{
"claim": "name",
"operator": "EQUALS",
"value": "\"My Name\""
}
]
}
]
},
"policy_template_references": [
{
"id": "Policy Template-12345",
"version": "1"
}
],
"created_at": "2023-03-07T13:55:33:428+0000",
"created_by_id": "IBMid-12345678901",
"last_modified_at": "2023-03-07T13:55:33:428+0000",
"last_modified_by_id": "IBMid-12345678901",
"entity_tag": "1-2da85a8f1172fc3527378318d3182778",
"crn": "crn:v1:staging:public:iam-identity::a/5bbe28be34524sdbdaa34d37d1f2294a::template:ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9"
}
テンプレート名を更新すると、すべてのバージョンの名前が更新されます。
APIを使用して信頼されたプロファイルテンプレートをコミットする
信頼できるプロファイルテンプレートを確認し、そのバージョンにこれ以上変更を加えられないようにコミットします。 バージョンをコミットすることは、子アカウントに割り当てる前に必要なステップです。 これにより、テンプレート割り当て管理者が、お客様が準備完了を確認したときにのみバージョンを割り当てていることを確認できます。
- レビューとコミットを行いたい信頼済みプロファイルテンプレートのバージョンを取得します。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
GetProfileTemplateVersionOptions getProfileTemplateOptions = new GetProfileTemplateVersionOptions.Builder()
.templateId(profileTemplateId)
.version(Long.toString(profileTemplateVersion))
.build();
Response<TrustedProfileTemplateResponse> response = service.getProfileTemplateVersion(getProfileTemplateOptions).execute();
TrustedProfileTemplateResponse profileTemplateResult = response.getResult();
profileTemplateEtag = response.getHeaders().values("Etag").get(0);
System.out.println(profileTemplateResult);
const params = {
templateId: profileTemplateId,
version: profileTemplateVersion,
}
try {
const res = await iamIdentityService.getProfileTemplateVersion(params);
profileTemplateEtag = res.headers.etag;
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
get_response = iam_identity_service.get_profile_template_version(
template_id=profile_template_id, version=str(profile_template_version)
)
profile_template = get_response.get_result()
print('\nget_profile_template response: ', json.dumps(profile_template, indent=2))
global profile_template_etag
profile_template_etag = get_response.get_headers()['Etag']
profile_template_etag is not None
getOptions := &iamidentityv1.GetProfileTemplateVersionOptions{
TemplateID: &profileTemplateId,
Version: core.StringPtr(strconv.FormatInt(profileTemplateVersion, 10)),
}
getResponse, response, err := iamIdentityService.GetProfileTemplateVersion(getOptions)
b, _ := json.MarshalIndent(getResponse, "", " ")
fmt.Println(string(b))
profileTemplateEtag = response.GetHeaders().Get("Etag")
- 回答を確認し、コミットする準備ができていることを確認します。
- 信頼済みプロファイルテンプレートのバージョンをコミットする。
curl -X POST 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/{version}/commit' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
CommitProfileTemplateOptions commitOptions = new CommitProfileTemplateOptions.Builder()
.templateId(profileTemplateId)
.version(Long.toString(profileTemplateVersion))
.build();
Response<Void> commitResponse = service.commitProfileTemplate(commitOptions).execute();
const commitParams = {
templateId: profileTemplateId,
version: profileTemplateVersion,
}
try {
const res = await iamIdentityService.commitProfileTemplate(commitParams);
} catch (err) {
console.warn(err);
}
commit_response = iam_identity_service.commit_profile_template(
template_id=profile_template_id, version=str(profile_template_version)
)
commitOptions := &iamidentityv1.CommitProfileTemplateOptions{
TemplateID: &profileTemplateId,
Version: core.StringPtr(strconv.FormatInt(profileTemplateVersion, 10)),
}
response, err := iamIdentityService.CommitProfileTemplate(commitOptions)
APIを使用して信頼されたプロファイルテンプレートを子アカウントに割り当てる
信頼されたプロファイルテンプレートを企業内の子アカウントに割り当てます。
IAMテンプレートは、エンタープライズアカウントではなく、子アカウントとアカウントグループのみに割り当てることができます。
信頼済みプロファイルテンプレートに割り当てを作成するには、以下の手順に従います
- 企業アカウントで信頼するプロファイルテンプレートをリストアップし、割り当てたいテンプレートバージョンの応答に記載されている
ProfileTemplateIDとバージョンをメモします。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
.accountId(enterpriseAccountId)
.build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", " ")
fmt.Println(string(b))
ibmcloud iam trusted-profile-templates
- テンプレートを
AccountまたはAccountGroupに割り当てます。
curl -X POST 'https://iam.cloud.ibm.com/v1/profile_assignments' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
"template_id": "ProfileTemplate-cac1b203-5956-4981-bdec-0a4af4feab4d",
"template_version": 1,
"target_type": "Account",
"target": "5bbe28be34524e88a34d37d1f2294a8a"
}'
CreateTrustedProfileAssignmentOptions assignOptions = new CreateTrustedProfileAssignmentOptions.Builder()
.templateId(profileTemplateId)
.templateVersion(profileTemplateVersion)
.targetType("Account")
.target(enterpriseSubAccountId)
.build();
Response<TemplateAssignmentResponse> assignResponse = service.createTrustedProfileAssignment(assignOptions).execute();
TemplateAssignmentResponse assignmentResponseResult = assignResponse.getResult();
// Save the id for use by other test methods.
profileTemplateAssignmentId = assignmentResponseResult.getId();
// Grab the Etag value from the response for use in the update operation.
profileTemplateAssignmentEtag = assignResponse.getHeaders().values("Etag").get(0);
System.out.println(assignmentResponseResult);
const assignParams = {
templateId: profileTemplateId,
templateVersion: profileTemplateVersion,
targetType: "Account",
target: enterpriseSubAccountId,
}
try {
const assRes = await iamIdentityService.createTrustedProfileAssignment(assignParams);
const { result } = assRes;
profileTemplateAssignmentId = result.id;
profileTemplateAssignmentEtag= assRes.headers.etag;
console.log(JSON.stringify(result, null, 2));
} catch (err) {
console.warn(err);
}
assign_response = iam_identity_service.create_trusted_profile_assignment(
template_id=profile_template_id,
template_version=profile_template_version,
target_type='Account',
target=enterprise_subaccount_id,
)
assignment = assign_response.get_result()
print('\ncreate_trusted_profile_assignment() response: ', json.dumps(assignment, indent=2))
global profile_template_assignment_id
profile_template_assignment_id = assignment['id']
global profile_template_assignment_etag
profile_template_assignment_etag = assign_response.get_headers()['Etag']
assignOptions := &iamidentityv1.CreateTrustedProfileAssignmentOptions{
TemplateID: &profileTemplateId,
TemplateVersion: &profileTemplateVersion,
TargetType: core.StringPtr("Account"),
Target: &enterpriseSubAccountID,
}
assignResponse, response, err := iamIdentityService.CreateTrustedProfileAssignment(assignOptions)
b, _ := json.MarshalIndent(assignResponse, "", " ")
fmt.Println(string(b))
// Grab the Etag and id for use by other test methods.
profileTemplateAssignmentEtag = response.GetHeaders().Get("Etag")
profileTemplateAssignmentId = *assignResponse.ID
割り当てに失敗した場合は、 割り当ての更新操作 を使用して再試行します。
API を使用して新しいバージョンを作成する
コミット済みまたは割り当て済みの信頼済みプロファイルテンプレートを変更したい場合は、新しいバージョンを作成してください。
curl -X POST 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
"account_id": "5bbe28be34524sdbdaa34d37d1f2294a",
"name": "db admin template",
"profile": {
"name": "Profile for DB Admins",
"description": "allows users to admin db instances",
"rules": [
{
"type": "Profile",
"realm_name": "${IDP_REALM_NAME}",
"expiration": 43200,
"conditions": [
{
"claim": "name",
"operator": "EQUALS",
"value": "\"My Name\""
}
]
}
]
},
"policy_template_references": [
{
"id": "Policy Template-12345",
"version": 1
}
]
}'
ProfileClaimRuleConditions condition = new ProfileClaimRuleConditions.Builder()
.claim("blueGroups")
.operator("EQUALS")
.value("\"cloud-docs-dev\"")
.build();
List<ProfileClaimRuleConditions> conditions = new ArrayList<>();
conditions.add(condition);
TrustedProfileTemplateClaimRule claimRule = new TrustedProfileTemplateClaimRule.Builder()
.name("My Rule")
.realmName(realmName)
.type(claimRuleType)
.expiration(43200)
.conditions(conditions)
.build();
List<String> accounts = new ArrayList<String>();
accounts.add(enterpriseAccountId);
ProfileIdentityRequest profileIdentity = new ProfileIdentityRequest.Builder()
.identifier(iamId)
.accounts(accounts)
.type("user")
.description("Identity description")
.build();
List<ProfileIdentityRequest> identities = new ArrayList<ProfileIdentityRequest>();
identities.add(profileIdentity);
TemplateProfileComponentRequest profile = new TemplateProfileComponentRequest.Builder()
.addRules(claimRule)
.name(profileTemplateProfileName)
.description("Trusted profile created from a template - new version")
.identities(identities)
.build();
CreateProfileTemplateVersionOptions createOptions = new CreateProfileTemplateVersionOptions.Builder()
.accountId(enterpriseAccountId)
.templateId(profileTemplateId)
.name(profileTemplateName)
.description("IAM enterprise trusted profile template example - new version")
.profile(profile)
.build();
Response<TrustedProfileTemplateResponse> createResponse = service.createProfileTemplateVersion(createOptions).execute();
TrustedProfileTemplateResponse createResult = createResponse.getResult();
// Save the version for use by other test methods.
profileTemplateVersion = createResult.getVersion().longValue();
System.out.println(createResult);
const condition = {
claim: "blueGroups",
operator: "EQUALS",
value: "\"cloud-docs-dev\"",
}
const claimRule = {
name: "My Rule",
realm_name: realmName,
type: 'Profile-SAML',
expiration: 43200,
conditions: [condition],
}
const identity = {
identifier: iamId,
accounts: [enterpriseAccountId],
type: "user",
description: "Identity description",
}
const profile = {
rules: [claimRule],
name: "Profile-From-Example-Template",
description: "Trusted profile created from a template - new version",
identities: [identity],
}
const templateParams = {
templateId: profileTemplateId,
name: "Example-Profile-Template",
description: "IAM enterprise trusted profile template example - new version",
accountId: enterpriseAccountId,
profile: profile,
}
try {
const res = await iamIdentityService.createProfileTemplateVersion(templateParams);
const { result } = res;
profileTemplateVersion = result.version;
console.log(JSON.stringify(result, null, 2));
} catch (err) {
console.warn(err);
}
profile_claim_rule_conditions = {}
profile_claim_rule_conditions['claim'] = 'blueGroups'
profile_claim_rule_conditions['operator'] = 'EQUALS'
profile_claim_rule_conditions['value'] = '\"cloud-docs-dev\"'
profile_claim_rule = {}
profile_claim_rule['name'] = 'My Rule'
profile_claim_rule['realm_name'] = 'https://sdk.test.realm/1234'
profile_claim_rule['type'] = 'Profile-SAML'
profile_claim_rule['expiration'] = 43200
profile_claim_rule['conditions'] = [profile_claim_rule_conditions]
profile_identity = {}
profile_identity['identifier'] = iam_id
profile_identity['accounts'] = [enterprise_account_id]
profile_identity['type'] = 'user'
profile_identity['description'] = 'Identity description'
profile = {}
profile['name'] = 'Profile-From-Example-Template'
profile['description'] = 'Trusted profile created from a template - new version'
profile['rules'] = [profile_claim_rule]
profile['identities'] = [profile_identity]
create_response = iam_identity_service.create_profile_template_version(
template_id=profile_template_id,
name='Example-Profile-Template',
description='IAM enterprise trusted profile template example - new version',
account_id=enterprise_account_id,
profile=profile,
)
profile_template = create_response.get_result()
print('\ncreate_profile_template_version() response: ', json.dumps(profile_template, indent=2))
global profile_template_version
profile_template_version = profile_template['version']
profileClaimRuleConditions := new(iamidentityv1.ProfileClaimRuleConditions)
profileClaimRuleConditions.Claim = core.StringPtr("blueGroups")
profileClaimRuleConditions.Operator = core.StringPtr("EQUALS")
profileClaimRuleConditions.Value = core.StringPtr("\"cloud-docs-dev\"")
profileTemplateClaimRule := new(iamidentityv1.TrustedProfileTemplateClaimRule)
profileTemplateClaimRule.Name = core.StringPtr("My Rule")
profileTemplateClaimRule.RealmName = &realmName
profileTemplateClaimRule.Type = &claimRuleType
profileTemplateClaimRule.Expiration = core.Int64Ptr(int64(43200))
profileTemplateClaimRule.Conditions = []iamidentityv1.ProfileClaimRuleConditions{*profileClaimRuleConditions}
profile := new(iamidentityv1.TemplateProfileComponentRequest)
profile.Name = &profileTemplateProfileName
profile.Description = core.StringPtr("Example Profile created from Profile Template - new version")
profile.Rules = []iamidentityv1.TrustedProfileTemplateClaimRule{*profileTemplateClaimRule}
createOptions := &iamidentityv1.CreateProfileTemplateVersionOptions{
Name: &profileTemplateName,
Description: core.StringPtr("Example Profile Template - new version"),
AccountID: &enterpriseAccountID,
TemplateID: &profileTemplateId,
Profile: profile,
}
createResponse, response, err := iamIdentityService.CreateProfileTemplateVersion(createOptions)
b, _ := json.MarshalIndent(createResponse, "", " ")
fmt.Println(string(b))
// save the new version to be used in subsequent calls
profileTemplateVersion = *createResponse.Version
API を使用して課題を更新する
新しいバージョンへの移行や、失敗した割り当ての再試行などの割り当てを更新します。
割り当てた新しいテンプレートバージョンが古いバージョンに置き換わります。 新しいバージョンの割り当てについて、さらに詳しく知る。
- 企業アカウントで信頼するプロファイルの割り当てをリストアップし、更新する割り当ての
TemplateAssignmentIDとバージョンをメモします
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_assignments?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListTrustedProfileAssignmentsOptions listOptions = new ListTrustedProfileAssignmentsOptions.Builder()
.accountId(enterpriseAccountId)
.templateId(profileTemplateId)
.build();
Response<TemplateAssignmentListResponse> listResponse = service.listTrustedProfileAssignments(listOptions).execute();
TemplateAssignmentListResponse listResult = listResponse.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.listTrustedProfileAssignments(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_trusted_profile_assignments(
account_id=enterprise_account_id, template_id=profile_template_id
)
assignment_list = list_response.get_result()
print('\nlist_trusted_profile_assignments() response: ', json.dumps(assignment_list, indent=2))
listOptions := &iamidentityv1.ListTrustedProfileAssignmentsOptions{
AccountID: &enterpriseAccountID,
TemplateID: &profileTemplateId,
}
listResponse, response, err := iamIdentityService.ListTrustedProfileAssignments(listOptions)
b, _ := json.MarshalIndent(listResponse, "", " ")
fmt.Println(string(b))
- 信頼済みプロファイルの割り当てを更新します。 課題を再提出する場合は、同じバージョン番号を使用してください。 次のサンプルリクエストは、割り当てをバージョン2に移行します。
curl -X PATCH 'https://iam.cloud.ibm.com/v1/profile_assignments/<assignment_id>' -H 'Authorization: Bearer $TOKEN' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN' -d '{
"template_version": 2
}'
UpdateTrustedProfileAssignmentOptions updateOptions = new UpdateTrustedProfileAssignmentOptions.Builder()
.assignmentId(profileTemplateAssignmentId)
.templateVersion(profileTemplateVersion)
.ifMatch(profileTemplateAssignmentEtag)
.build();
Response<TemplateAssignmentResponse> updateResponse = service.updateTrustedProfileAssignment(updateOptions).execute();
TemplateAssignmentResponse updateResult = updateResponse.getResult();
// Grab the Etag value from the response for use in the update operation.
profileTemplateAssignmentEtag = updateResponse.getHeaders().values("Etag").get(0);
System.out.println(updateResult);
const assignParams = {
assignmentId: profileTemplateAssignmentId,
templateVersion: profileTemplateVersion,
ifMatch: profileTemplateAssignmentEtag,
}
try {
const assRes = await iamIdentityService.updateTrustedProfileAssignment(assignParams);
console.log(JSON.stringify(assRes.result, null, 2));
} catch (err) {
console.warn(err);
}
assign_response = iam_identity_service.update_trusted_profile_assignment(
assignment_id=profile_template_assignment_id,
template_version=profile_template_version,
if_match=profile_template_assignment_etag,
)
assignment = assign_response.get_result()
print('\nupdate_profile_template_assignment response: ', json.dumps(assignment, indent=2))
profile_template_assignment_etag = assign_response.get_headers()['Etag']
updateOptions := &iamidentityv1.UpdateTrustedProfileAssignmentOptions{
AssignmentID: &profileTemplateAssignmentId,
TemplateVersion: &profileTemplateVersion,
IfMatch: &profileTemplateAssignmentEtag,
}
updateResponse, response, err := iamIdentityService.UpdateTrustedProfileAssignment(updateOptions)
b, _ := json.MarshalIndent(updateResponse, "", " ")
fmt.Println(string(b))
// Grab the Etag and id for use by other test methods.
profileTemplateAssignmentEtag = response.GetHeaders().Get("Etag")
API を使用して割り当てを削除する
テンプレートが割り当てられているアカウントまたはアカウントグループから、テンプレート割り当てを削除することができます。 テンプレートが意図したように機能していない場合や、もはや必要ない場合には、そうした方が良いでしょう。 アカウントからテンプレート割り当てを削除すると、デフォルトでは以前のバージョンのテンプレートが復元されます。 削除した割り当てがテンプレートの最初のバージョンまたは唯一のバージョンの場合、子アカウントの企業管理の信頼済みプロファイルが削除されます。
割り当てを削除するには、以下の手順に従ってください
- 企業アカウントで信頼されたプロファイルの割り当てをリストアップし、削除する割り当ての
TemplateAssignmentIDをメモします。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_assignments?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListTrustedProfileAssignmentsOptions listOptions = new ListTrustedProfileAssignmentsOptions.Builder()
.accountId(enterpriseAccountId)
.templateId(profileTemplateId)
.build();
Response<TemplateAssignmentListResponse> listResponse = service.listTrustedProfileAssignments(listOptions).execute();
TemplateAssignmentListResponse listResult = listResponse.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.listTrustedProfileAssignments(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_trusted_profile_assignments(
account_id=enterprise_account_id, template_id=profile_template_id
)
assignment_list = list_response.get_result()
print('\nlist_trusted_profile_assignments() response: ', json.dumps(assignment_list, indent=2))
listOptions := &iamidentityv1.ListTrustedProfileAssignmentsOptions{
AccountID: &enterpriseAccountID,
TemplateID: &profileTemplateId,
}
listResponse, response, err := iamIdentityService.ListTrustedProfileAssignments(listOptions)
b, _ := json.MarshalIndent(listResponse, "", " ")
fmt.Println(string(b))
- 割り当てを削除します。
割り当てを削除すると、以前の割り当てがアクティブになる可能性があります。 詳細は 、「テンプレートバージョンでの作業 」を参照してください。
curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_assignments/<assignment_id>' -H 'Authorization: Bearer $TOKEN' }'
DeleteTrustedProfileAssignmentOptions deleteOptions = new DeleteTrustedProfileAssignmentOptions.Builder()
.assignmentId(profileTemplateAssignmentId)
.build();
Response<ExceptionResponse> deleteResponse = service.deleteTrustedProfileAssignment(deleteOptions).execute();
const params = {
assignmentId: profileTemplateAssignmentId,
}
try {
const res = await iamIdentityService.deleteTrustedProfileAssignment(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_trusted_profile_assignment(
assignment_id=profile_template_assignment_id
)
deleteOptions := &iamidentityv1.DeleteTrustedProfileAssignmentOptions{
AssignmentID: &profileTemplateAssignmentId,
}
excResponse, response, err := iamIdentityService.DeleteTrustedProfileAssignment(deleteOptions)
API を使用してバージョンを削除する
信頼されたプロファイルテンプレートのバージョンを削除する前に、そのバージョンのテンプレートへのすべての割り当てを削除する必要があります。 特定のバージョンを削除するには、以下の手順に従ってください
- 企業アカウントで信頼するプロファイルテンプレートをリストアップし、削除したいテンプレートバージョンの応答に記載されている
ProfileTemplateIDとバージョンをメモします。
curl -X GET 'https://iam.cloud.ibm.com/v1/profile_templates?account_id=5bbe28be34524sdbdaa34d37d1f2294a' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
ListProfileTemplatesOptions listOptions = new ListProfileTemplatesOptions.Builder()
.accountId(enterpriseAccountId)
.build();
Response<TrustedProfileTemplateList> response = service.listProfileTemplates(listOptions).execute();
TrustedProfileTemplateList listResult = response.getResult();
System.out.println(listResult);
const params = {
accountId: enterpriseAccountId,
}
try {
const res = await iamIdentityService.listProfileTemplates(params);
console.log(JSON.stringify(res.result, null, 2));
} catch (err) {
console.warn(err);
}
list_response = iam_identity_service.list_profile_templates(account_id=enterprise_account_id)
profile_template_list = list_response.get_result()
print('\nlist_profile_templates response: ', json.dumps(profile_template_list, indent=2))
listOptions := &iamidentityv1.ListProfileTemplatesOptions{
AccountID: &enterpriseAccountID,
}
listResponse, response, err := iamIdentityService.ListProfileTemplates(listOptions)
b, _ := json.MarshalIndent(listResponse, "", " ")
fmt.Println(string(b))
- バージョンを削除する:
curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_templates/{template_id}/versions/{version}' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
DeleteProfileTemplateVersionOptions deleteOptions = new DeleteProfileTemplateVersionOptions.Builder()
.templateId(profileTemplateId)
.version("1")
.build();
Response<Void> deleteResponse = service.deleteProfileTemplateVersion(deleteOptions).execute();
const params = {
templateId: profileTemplateId,
version: 1,
}
try {
const res = await iamIdentityService.deleteProfileTemplateVersion(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_profile_template_version(
template_id=profile_template_id, version='1'
)
deleteOptions := &iamidentityv1.DeleteProfileTemplateVersionOptions{
TemplateID: &profileTemplateId,
Version: core.StringPtr("1"),
}
response, err := iamIdentityService.DeleteProfileTemplateVersion(deleteOptions)
APIを使用してすべてのバージョンを削除する
各バージョンの割り当てを最初に削除することを確認してください。
curl -X DELETE 'https://iam.cloud.ibm.com/v1/profile_templates/ProfileTemplate-767fc1f6-c77c-4196-b3d6-a009a5a536e9' -H 'Content-Type: application/json' -H 'Authorization: Bearer $TOKEN'
DeleteAllVersionsOfProfileTemplateOptions deleteTeplateOptions = new DeleteAllVersionsOfProfileTemplateOptions.Builder()
.templateId(profileTemplateId)
.build();
Response<Void> deleteResponse = service.deleteAllVersionsOfProfileTemplate(deleteTeplateOptions).execute();
const params = {
templateId: profileTemplateId,
}
try {
const res = await iamIdentityService.deleteAllVersionsOfProfileTemplate(params);
} catch (err) {
console.warn(err);
}
delete_response = iam_identity_service.delete_all_versions_of_profile_template(
template_id=profile_template_id
)
deleteOptions := &iamidentityv1.DeleteAllVersionsOfProfileTemplateOptions{
TemplateID: &profileTemplateId,
}
response, err := iamIdentityService.DeleteAllVersionsOfProfileTemplate(deleteOptions)