UserGroupsArgs

data class UserGroupsArgs(val exhaustive: Output<Boolean>? = null, val groupIds: Output<List<String>>? = null, val realmId: Output<String>? = null, val userId: Output<String>? = null) : ConvertibleToJava<UserGroupsArgs>

Allows for managing a Keycloak user's groups. If exhaustive is true, this resource attempts to be an authoritative source over user groups: groups that are manually added to the user will be removed, and groups that are manually removed from the user group will be added upon the next run of pulumi up. If exhaustive is false, this resource is a partial assignation of groups to a user. As a result, you can get multiple keycloak.UserGroups for the same user_id.

Example Usage

Exhaustive Groups)

import * as pulumi from "@pulumi/pulumi";
import * as keycloak from "@pulumi/keycloak";
const realm = new keycloak.Realm("realm", {
realm: "my-realm",
enabled: true,
});
const group = new keycloak.Group("group", {
realmId: realm.id,
name: "foo",
});
const user = new keycloak.User("user", {
realmId: realm.id,
username: "my-user",
});
const userGroups = new keycloak.UserGroups("user_groups", {
realmId: realm.id,
userId: user.id,
groupIds: [group&#46;id],
});
import pulumi
import pulumi_keycloak as keycloak
realm = keycloak.Realm("realm",
realm="my-realm",
enabled=True)
group = keycloak.Group("group",
realm_id=realm.id,
name="foo")
user = keycloak.User("user",
realm_id=realm.id,
username="my-user")
user_groups = keycloak.UserGroups("user_groups",
realm_id=realm.id,
user_id=user.id,
group_ids=[group&#46;id])
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Keycloak = Pulumi.Keycloak;
return await Deployment.RunAsync(() =>
{
var realm = new Keycloak.Realm("realm", new()
{
RealmName = "my-realm",
Enabled = true,
});
var @group = new Keycloak.Group("group", new()
{
RealmId = realm.Id,
Name = "foo",
});
var user = new Keycloak.User("user", new()
{
RealmId = realm.Id,
Username = "my-user",
});
var userGroups = new Keycloak.UserGroups("user_groups", new()
{
RealmId = realm.Id,
UserId = user.Id,
GroupIds = new[]
{
@group.Id,
},
});
});
package main
import (
"github.com/pulumi/pulumi-keycloak/sdk/v5/go/keycloak"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
realm, err := keycloak.NewRealm(ctx, "realm", &keycloak.RealmArgs{
Realm: pulumi.String("my-realm"),
Enabled: pulumi.Bool(true),
})
if err != nil {
return err
}
group, err := keycloak.NewGroup(ctx, "group", &keycloak.GroupArgs{
RealmId: realm.ID(),
Name: pulumi.String("foo"),
})
if err != nil {
return err
}
user, err := keycloak.NewUser(ctx, "user", &keycloak.UserArgs{
RealmId: realm.ID(),
Username: pulumi.String("my-user"),
})
if err != nil {
return err
}
_, err = keycloak.NewUserGroups(ctx, "user_groups", &keycloak.UserGroupsArgs{
RealmId: realm.ID(),
UserId: user.ID(),
GroupIds: pulumi.StringArray{
group.ID(),
},
})
if err != nil {
return err
}
return nil
})
}
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.keycloak.Realm;
import com.pulumi.keycloak.RealmArgs;
import com.pulumi.keycloak.Group;
import com.pulumi.keycloak.GroupArgs;
import com.pulumi.keycloak.User;
import com.pulumi.keycloak.UserArgs;
import com.pulumi.keycloak.UserGroups;
import com.pulumi.keycloak.UserGroupsArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var realm = new Realm("realm", RealmArgs.builder()
.realm("my-realm")
.enabled(true)
.build());
var group = new Group("group", GroupArgs.builder()
.realmId(realm.id())
.name("foo")
.build());
var user = new User("user", UserArgs.builder()
.realmId(realm.id())
.username("my-user")
.build());
var userGroups = new UserGroups("userGroups", UserGroupsArgs.builder()
.realmId(realm.id())
.userId(user.id())
.groupIds(group.id())
.build());
}
}
resources:
realm:
type: keycloak:Realm
properties:
realm: my-realm
enabled: true
group:
type: keycloak:Group
properties:
realmId: ${realm.id}
name: foo
user:
type: keycloak:User
properties:
realmId: ${realm.id}
username: my-user
userGroups:
type: keycloak:UserGroups
name: user_groups
properties:
realmId: ${realm.id}
userId: ${user.id}
groupIds:
- ${group.id}

Constructors

Link copied to clipboard
constructor(exhaustive: Output<Boolean>? = null, groupIds: Output<List<String>>? = null, realmId: Output<String>? = null, userId: Output<String>? = null)

Properties

Link copied to clipboard
val exhaustive: Output<Boolean>? = null

Indicates if the list of the user's groups is exhaustive. In this case, groups that are manually added to the user will be removed. Defaults to true.

Link copied to clipboard
val groupIds: Output<List<String>>? = null

A list of group IDs that the user is member of.

Link copied to clipboard
val realmId: Output<String>? = null

The realm this group exists in.

Link copied to clipboard
val userId: Output<String>? = null

The ID of the user this resource should manage groups for.

Functions

Link copied to clipboard
open override fun toJava(): UserGroupsArgs