CLI integration example
The Alibaba Cloud Command Line Interface (CLI) is a general-purpose command-line tool built on OpenAPI. You can use the Alibaba Cloud CLI to automate the management and maintenance of Cloud Single Sign-On (CloudSSO). This topic describes the procedure and provides examples for a CloudSSO administrator to use the Alibaba Cloud CLI to call CloudSSO.
Prerequisites
If you are unfamiliar with the Alibaba Cloud CLI, see What is Alibaba Cloud CLI?.
Install the Alibaba Cloud CLI
You must install the Alibaba Cloud CLI before you can use it. Installation methods are available for Windows, Linux, and macOS. Choose the installation guide for your operating system.
Windows: Install the CLI (Windows).
Linux: Install the CLI (Linux).
macOS: Install the CLI (macOS).
You can also use Cloud Shell to debug Alibaba Cloud CLI commands. For more information about Cloud Shell, see What is Cloud Shell?.
Configure the Alibaba Cloud CLI
For more information, see Log on to CloudSSO and access Alibaba Cloud resources using the CLI.
Generate a sample CLI command
Go to the CloudSSO API debugging list.
On the API debugging page, search for the API you want to use in the search box on the left. In the Parameter Settings section, enter the parameters according to the API documentation. Click the CLI Example tab to the right of the Parameter Settings section to generate a sample command with the parameters.
Click the Run Command
button to open Cloud Shell and quickly debug the command.Click the Copy
button to copy the sample CLI command to the clipboard. Then, paste the command into a local shell tool to run it.When you copy the sample CLI command to a local shell tool for debugging, note the parameter format. For more information about the format of Alibaba Cloud CLI command parameters, see Parameter format.
The sample command generated by the OpenAPI Portal includes the
--regionoption by default. When you run the command locally, the Alibaba Cloud CLI uses the specified region and ignores the region settings in your default identity credentials and environment variables. You can keep or remove this option as needed.
Call an API
Command structure
The general command structure for the Alibaba Cloud CLI is as follows. For more information, see Generate and call a command.
aliyun <command> <subcommand> [options and parameters]Common command options
In the Alibaba Cloud CLI, you can use command-line options to change the default behavior of a command or add features. Common command options are as follows:
--profile <profileName>: If you use the--profileoption and specify a valid configuration nameprofileName, the Alibaba Cloud CLI ignores the default identity credentials and environment variables. The CLI uses the specified configuration to run the command.--help: To get help information for a command, enter the--helpoption at the command level. For more information, see Get help information.
For more information, see Command-line options.
Examples
Example 1: The following code example shows how to use the --help option to get a list of CloudSSO APIs that you can call using the Alibaba Cloud CLI. You can also view the supported APIs in API overview.
Run the command.
aliyun cloudsso --helpThe output is displayed.
Usage: aliyun cloudsso <ApiName> --parameter1 value1 --parameter2 value2 ... Product: cloudsso (云SSO) Version: 2021-05-15 Available Api List: AddExternalSAMLIdPCertificate Adds a Security Assertion Markup Language (SAML) signing certificate. AddPermissionPolicyToAccessConfiguration Adds a policy to an access configuration. AddUserToGroup Adds a user to a group. ClearExternalSAMLIdentityProvider Clears the configurations of a Security Assertion Markup Language (SAML) identity provider (IdP). CreateAccessAssignment Assigns access permissions on an account in your resource directory to a user or a group by using access configuration. CreateAccessConfiguration Creates an access configuration. CreateDirectory Creates a directory. CreateGroup Creates a group.
Example 2: The following code example shows how to use the Alibaba Cloud CLI to call the CreateUser command in CloudSSO to create a CloudSSO user named Alice.
Run the command.
aliyun cloudsso CreateUser --region cn-shanghai --DirectoryId 'd-00fc2p61****' --UserName AliceThe output is displayed.
{ "User": { "Status": "Enabled", "UserName": "Alice", "Email": "", "Description": "", "UserId": "u-004ds*************", "FirstName": "", "CreateTime": "2024-05-16T10:49:27Z", "ProvisionType": "Manual", "DisplayName": "", "UpdateTime": "2024-05-16T10:49:27Z", "LastName": "" }, "RequestId": "E5D5256C-3981-5EB8-AB9C-30DF641D4DC9" }NoteIf a CloudSSO API call returns an error, check whether the request parameters and their values are correct based on the returned error code.
You can also record the RequestID or the SDK error message from the response and use the Alibaba Cloud OpenAPI Diagnostic Platform for self-service diagnosis.