CreateApplicationFederatedCredential - 创建应用联邦凭证

更新时间:
复制 MD 格式

创建应用联邦凭证。

调试

您可以在OpenAPI Explorer中直接运行该接口,免去您计算签名的困扰。运行成功后,OpenAPI Explorer可以自动生成SDK代码示例。

调试

授权信息

下表是API对应的授权信息,可以在RAM权限策略语句的Action元素中使用,用来给RAM用户或RAM角色授予调用此API的权限。具体说明如下:

  • 操作:是指具体的权限点。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

访问级别

资源类型

条件关键字

关联操作

eiam:CreateApplicationFederatedCredential

create

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/*

请求参数

名称

类型

必填

描述

示例值

InstanceId

string

实例 ID

idaas_ue2jvisn35ea5lmthk267xxxxx

ApplicationId

string

应用 ID

app_mkv7rgt4d7i4u7zqtzev2mxxxx

FederatedCredentialProviderId

string

联邦凭证提供方 ID

fcp_adasd

ApplicationFederatedCredentialType

string

应用联邦凭证类型

oidc

ApplicationFederatedCredentialName

string

应用联邦凭证名称

example_name

VerificationCondition

string

校验条件

IsNullOrEmpty("jwt.issuer")

Description

string

描述

description_text

AttributeMappings

array<object>

属性映射

object

SourceValueExpression

string

来源表达式

Append(client.applicationFederatedCredentialId, ":", cert.subject.CN, ":", cert.serialNumber)

TargetField

string

目标字段

client.activeSubjectUrn

VerificationMode

string

校验模式:freedom(默认)/ structured

freedom

OidcVerificationConfig

object

OIDC 结构化配置(structured 模式 + oidc 类型)

Profile

string

OIDC 场景 Profile:generic / kubernetes / gcp_vm / azure_vm

kubernetes

KubernetesConfig

object

Kubernetes 场景配置

Namespace

string

K8s 命名空间

default

ServiceAccountName

string

K8s 服务账号名称

my-sa

PodNamePrefix

string

Pod 名称前缀

my-pod-

GcpVmConfig

object

GCP VM 场景配置

ServiceAccountId

string

Service Account 对应 sub

123456789

InstanceIds

array

string

ProjectId

string

AzureVmConfig

object

Azure VM 场景配置

ResourceGroupName

string

VmNames

array

string

SubscriptionId

string

PrincipalId

string

GenericConfig

object

Subject

string

Pkcs7VerificationConfig

object

PKCS#7 结构化配置(structured 模式 + pkcs7 类型)

InstanceIds

array

string

返回参数

名称

类型

描述

示例值

object

RequestId

string

请求 ID

0441BD79-92F3-53AA-8657-F8CE4A2B912A

ApplicationFederatedCredentialId

string

应用联邦凭证 ID

afc_asd123daxxxx

示例

正常返回示例

JSON格式

{
  "RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A",
  "ApplicationFederatedCredentialId": "afc_asd123daxxxx"
}

错误码

访问错误中心查看更多错误码。

变更历史

更多信息,参考变更详情