idp_group_mappings
Creates, updates, deletes, gets or lists an idp_group_mappings resource.
Overview​
| Name | idp_group_mappings |
| Type | Resource |
| Id | oci.identity.idp_group_mappings |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The mapping is being retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the IdpGroupMapping. |
compartmentId | string | The OCID of the tenancy containing the IdentityProvider. |
groupId | string | The OCID of the IAM Service group that is mapped to the IdP group. |
idpGroupName | string | The name of the IdP group that is mapped to the IAM Service group. |
idpId | string | The OCID of the IdentityProvider this mapping belongs to. |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The mapping's current state. After creating a mapping object, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
timeCreated | string (date-time) | Date and time the mapping was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
A mapping between a single group defined by the identity provider (IdP) you're federating with<br />and a single IAM Service [group](#/en/identity/20160918/Group/) in Oracle Cloud Infrastructure.<br />For more information about group mappings and what they're for, see<br />[Identity Providers and Federation](/Content/Identity/Concepts/federation.htm).<br /><br />A given IdP group can be mapped to zero, one, or multiple IAM Service groups, and vice versa.<br />But each IdPGroupMapping object is between only a single IdP group and IAM Service group.<br />Each IdPGroupMapping object has its own OCID.<br /><br />Note: Any users who are in more than 50 IdP groups cannot be authenticated to use the Oracle<br />Cloud Infrastructure Console.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the IdpGroupMapping. |
compartmentId | string | The OCID of the tenancy containing the IdentityProvider. |
groupId | string | The OCID of the IAM Service group that is mapped to the IdP group. |
idpGroupName | string | The name of the IdP group that is mapped to the IAM Service group. |
idpId | string | The OCID of the IdentityProvider this mapping belongs to. |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The mapping's current state. After creating a mapping object, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
timeCreated | string (date-time) | Date and time the mapping was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | identityProviderId, mappingId, region | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Gets the specified group mapping.<br /> | |
list | select | identityProviderId, region | page, limit | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Lists the group mappings for the specified identity provider.<br /> |
create | insert | identityProviderId, region, idpGroupName, groupId | opc-retry-token | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Creates a single mapping between an IdP group and an IAM Service<br />[group](#/en/identity/20160918/Group/).<br /> |
update | update | identityProviderId, mappingId, region | if-match | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Updates the specified group mapping.<br /> |
delete | delete | identityProviderId, mappingId, region | if-match | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Deletes the specified group mapping.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
identityProviderId | string | The OCID of the identity provider. |
mappingId | string | The OCID of the group mapping. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
SELECT examples​
- get
- list
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Gets the specified group mapping.<br />
SELECT
id,
compartmentId,
groupId,
idpGroupName,
idpId,
inactiveStatus,
lifecycleState,
timeCreated
FROM oci.identity.idp_group_mappings
WHERE identityProviderId = '{{ identityProviderId }}' -- required
AND mappingId = '{{ mappingId }}' -- required
AND region = '{{ region }}' -- required
;
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Lists the group mappings for the specified identity provider.<br />
SELECT
id,
compartmentId,
groupId,
idpGroupName,
idpId,
inactiveStatus,
lifecycleState,
timeCreated
FROM oci.identity.idp_group_mappings
WHERE identityProviderId = '{{ identityProviderId }}' -- required
AND region = '{{ region }}' -- required
AND page = '{{ page }}'
AND limit = '{{ limit }}'
;
INSERT examples​
- create
- Manifest
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Creates a single mapping between an IdP group and an IAM Service<br />[group](#/en/identity/20160918/Group/).<br />
INSERT INTO oci.identity.idp_group_mappings (
groupId,
idpGroupName,
identityProviderId,
region,
opc-retry-token
)
SELECT
'{{ groupId }}' /* required */,
'{{ idpGroupName }}' /* required */,
'{{ identityProviderId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
groupId,
idpGroupName,
idpId,
inactiveStatus,
lifecycleState,
timeCreated
;
# Description fields are for documentation purposes
- name: idp_group_mappings
props:
- name: identityProviderId
value: "{{ identityProviderId }}"
description: Required parameter for the idp_group_mappings resource.
- name: region
value: "{{ region }}"
description: Required parameter for the idp_group_mappings resource.
- name: groupId
value: "{{ groupId }}"
description: |
The OCID of the IAM Service [group](#/en/identity/20160918/Group/)
you want to map to the IdP group.
- name: idpGroupName
value: "{{ idpGroupName }}"
description: |
The name of the IdP group you want to map.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Updates the specified group mapping.<br />
UPDATE oci.identity.idp_group_mappings
SET
groupId = '{{ groupId }}',
idpGroupName = '{{ idpGroupName }}'
WHERE
identityProviderId = '{{ identityProviderId }}' --required
AND mappingId = '{{ mappingId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
compartmentId,
groupId,
idpGroupName,
idpId,
inactiveStatus,
lifecycleState,
timeCreated;
DELETE examples​
- delete
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Deletes the specified group mapping.<br />
DELETE FROM oci.identity.idp_group_mappings
WHERE identityProviderId = '{{ identityProviderId }}' --required
AND mappingId = '{{ mappingId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;