Name

Set-JS7IAMPermission

SYNOPSIS

Stores a permission to a role in the a Cockpit Identity Service

SYNTAX

Set-JS7IAMPermission [-Service] <String> [-Role] <String> [-Permission] <String[]> [-Excluded] [[-ControllerId] <String>] [[-AuditComment] <String>] [[-AuditTimeSpent] <Int32>] [[-AuditTicketLink] <Uri>] [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

This cmdlet stores a permission for a role in a JOC Cockpit Identity Service.

The following REST Web Service API resources are used:

* /iam/permissions/store

PARAMETERS

Service

-Service <String>
Specifies the unique name of the Identity Service.

Required?true
Position?1
Default value
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

Role

-Role <String>
Specifies the unique name of the role that permissions should be assigned.

Required?true
Position?2
Default value
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

Permission

-Permission <String[]>
Specifies one or more permissions for the role. Permissions are specified by identifiers like this:

* sos:products:controller:view
* sos:products:controller:agents:view
* sos:products:controller:deployment:manage

If more than one permission is used then they can be specified as an array or separated by comma:

* -Permissions @( "sos:products:controller:view", "sos:products:controller:agents:view" )
* -Permissions "sos:products:controller:view","sos:products:controller:agents:view"

Required?true
Position?3
Default value
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

Excluded

-Excluded <SwitchParameter>
Specifies if the permissions should be excluded. By default specified permissions are included.

Required?false
Position?named
Default valueFalse
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

ControllerId

-ControllerId <String>
Specifies the unique identifier of the Controller that related permissions are assigned.

Required?false
Position?4
Default valuedefault
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

AuditComment

-AuditComment <String>
Specifies a free text that indicates the reason for the current intervention,
e.g. "business requirement", "maintenance window" etc.

The Audit Comment is visible from the Audit Log view of the JOC Cockpit.
This argument is not mandatory, however, JOC Cockpit can be configured
to enforce Audit Log comments for any interventions.

Required?false
Position?5
Default value
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

AuditTimeSpent

-AuditTimeSpent <Int32>
Specifies the duration in minutes that the current intervention required.

This information is shown in the Audit Log view. It can be useful when integrated
with a ticket system that logs the time spent on interventions with JS7.

Required?false
Position?6
Default value0
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

-AuditTicketLink <Uri>
Specifies a URL to a ticket system that keeps track of any interventions performed for JS7.

This information is shown in the Audit Log view of JOC Cockpit.
It can be useful when integrated with a ticket system that logs interventions with JS7.

Required?false
Position?7
Default value
Accept pipeline input?true (ByPropertyName)
Accept wildcard characters?false

WhatIf

-WhatIf <SwitchParameter>

Required?false
Position?named
Default value
Accept pipeline input?false
Accept wildcard characters?false

Confirm

-Confirm <SwitchParameter>

Required?false
Position?named
Default value
Accept pipeline input?false
Accept wildcard characters?false

about_JS7

EXAMPLES

-------------------------- EXAMPLE 1 --------------------------

PS > Set-JS7IAMPermission -Service 'JOC' -Role 'application_manager' -Permission @( 'sos:products:controller:view', 'sos:products:controller:agents:view' )

Stores the indicated permissions with the role.

-------------------------- EXAMPLE 2 --------------------------

PS > Set-JS7IAMPermission -Service 'JOC' -Role 'application_manager' -Permission @( 'sos:products:controller:view', 'sos:products:controller:agents:view' ) -ControllerId 'testsuite'

Stores the indicated permissions with the role for access to the indicated Controller.

  • No labels