更新聯合規則
POST/v1/organizations/federation_rules/{federation_rule_id}
需要具有 org:admin 範圍的 OAuth 存取權杖,可透過 ant auth login --scope org:admin 或工作負載身分聯合規則取得;不接受 Admin API 金鑰。請參閱使用 Admin API 管理 WIF。
部分更新聯合規則。
issuer_id 不可變更。match 和 target 在設定時會以整個物件取代。
所參照的服務帳戶與工作區必須存在於您的組織中;無效的參照會以
400 錯誤拒絕。已封存的規則無法更新;這會傳回 400。請改為建立新規則。
針對知名共用簽發者(GitHub Actions、GitLab、Buildkite、Terraform Cloud、
Google)的規則必須透過帶有身分的宣告、固定租用戶的主體前綴(例如
repo:YOUR_ORG/...),或參照其中一個身分宣告的 CEL 條件(例如
claims.repository_owner)來限制租用戶身分。在這些簽發者上,每次更新
都會重新檢查此要求;若現有規則所儲存的 match 尚未限制租用戶身分,
則任何更新(即使是重新命名或描述變更)也必須在同一請求中提供
符合規定的 match。OAuth 呼叫者只能管理 oauth_scope 為
workspace:developer 或 workspace:inference 的規則;其他範圍需要
Console 工作階段。
Path parameters
Headers
Body
Returns
更新聯合規則
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{}'Response 200
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}Returns Examples
Response 200
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}