페더레이션 규칙 업데이트
org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.
페더레이션 규칙을 부분적으로 업데이트합니다.
issuer_id는 변경할 수 없습니다. match와 target은 설정 시 전체 객체로
교체됩니다. 참조된 서비스 계정과 워크스페이스는 조직에 존재해야 하며,
잘못된 참조는 400 오류로 거부됩니다. 보관된 규칙은 업데이트할 수 없으며
400을 반환합니다. 대신 새 규칙을 생성하세요. 잘 알려진 공유 발급자(GitHub Actions,
GitLab, Buildkite, Terraform Cloud, Google)에 대한 규칙은 ID를 담은 클레임,
테넌트를 고정하는 subject 접두사(예: repo:YOUR_ORG/...), 또는 이러한 ID 클레임 중
하나를 참조하는 CEL 조건(예: claims.repository_owner)을 통해 테넌트 ID를
제한해야 합니다. 이러한 발급자에서는 업데이트할 때마다 이 요구 사항이 다시
확인됩니다. 기존 규칙에 저장된 match가 아직 테넌트 ID를 제한하지 않는 경우,
모든 업데이트(이름 변경이나 설명 변경 포함)는 동일한 요청에서 요건을 충족하는
match도 함께 제공해야 합니다. OAuth 호출자는 oauth_scope가
workspace:developer 또는 workspace:inference인 규칙만 관리할 수 있으며,
다른 범위는 Console 세션이 필요합니다.
Path parameters
Headers
Body
Returns
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
-d '{}'{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}Returns Examples
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}