指定されたクラウドプロバイダーに対して 1 つのアクセス ロールを作成します。一部のMongoDB Cloud 機能では、認証にこれらのクラウドプロバイダーアクセス ロールを使用します。GCPプロバイダーの場合、プロジェクトフォルダーがまだプロビジョニングされていない場合、Atlas は非同期にロールを作成するようになります。ステータスが IN_PROGRESS の中間ロールが返され、最終サービス アカウントがプロビジョニングされます。GCPプロジェクトが設定されると、後続の リクエストによってサービス アカウントが同期的に作成されます。
- プロジェクトオーナー
path パラメータ
-
プロジェクトを識別する一意の 24 桁の 16 進数文字列。 認証済みユーザーがアクセスできるすべてのプロジェクトを取得するには、 /groups エンドポイントを使用します。
注: グループとプロジェクトは同義語です。そのため、グループ ID はプロジェクト ID と同じです。既存のグループの場合、グループ/プロジェクト ID は同じままです。リソースおよび対応するエンドポイントでは、グループという用語が使用されます。
形式は次のパターンと一致する必要があります:
^([a-f0-9]{24})$。
クエリ パラメータ
-
アプリケーションがレスポンスを
envelopeJSON オブジェクトにラップするかどうかを示すフラグ。一部の API クライアントは、HTTP レスポンス ヘッダーまたはステータス コードにアクセスできません。これを修正するには、クエリで envelope=true を設定します。結果のリストを返すエンドポイントは、結果オブジェクトをエンベロープとして使用します。アプリケーションは、レスポンス本体にステータス パラメータを追加します。デフォルト値は
falseです。 -
レスポンス本体を pretty-print 形式にするかどうかを示すフラグ。
デフォルト値は
falseです。Prettyprint
curl \
--request POST 'https://cloud.mongodb.com/api/atlas/v1.0/groups/32b6e34b3d91647abb20e7b8/cloudProviderAccess' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"providerName": "AWS"
}'
{
"providerName": "AWS"
}
{
"providerName": "AZURE",
"atlasAzureAppId": "string",
"servicePrincipalId": "string",
"tenantId": "string"
}
{
"providerName": "GCP"
}
{
"atlasAWSAccountArn": "arn:aws:iam::772401394250:role/my-test-aws-role",
"atlasAssumedRoleExternalId": "feb2dfc7-f760-4288-a403-01c7c2345005",
"authorizedDate": "2024-05-30T14:12:00Z",
"createdDate": "2024-05-30T14:11:00Z",
"featureUsages": [],
"iamAssumedRoleArn": "arn:aws:iam::123456789012:root",
"providerName": "AWS",
"roleId": "32b6e34b3d91647abb20e7b8"
}
{
"_id": "32b6e34b3d91647abb20e7b8",
"atlasAzureAppId": "da5dd062-f3ca-4cb5-b86a-05f82203ab67",
"createdDate": "2024-05-30T14:11:00Z",
"featureUsages": [],
"lastUpdatedDate": "2024-05-30T14:12:00Z",
"providerName": "AZURE",
"servicePrincipalId": "ec8e7844-912d-4869-86e9-6d0dfca4b8af",
"tenantId": "4297fc77-1592-4de8-a6d5-a8c32401df87"
}
{
"createdDate": "2024-05-30T14:11:00Z",
"featureUsages": [],
"gcpServiceAccountForAtlas": "mongodb-atlas-1234567890123456@p-111111111111111111111111.iam.gserviceaccount.com",
"providerName": "GCP",
"roleId": "32b6e34b3d91647abb20e7b8",
"status": "COMPLETE"
}
{
"detail": "(This is just an example, the exception may not be related to this endpoint)",
"error": 401,
"errorCode": "NOT_ORG_GROUP_CREATOR",
"reason": "Unauthorized"
}
{
"detail": "(This is just an example, the exception may not be related to this endpoint)",
"error": 403,
"errorCode": "CANNOT_CHANGE_GROUP_NAME",
"reason": "Forbidden"
}
{
"detail": "(This is just an example, the exception may not be related to this endpoint) Cannot find resource AWS",
"error": 404,
"errorCode": "RESOURCE_NOT_FOUND",
"reason": "Not Found"
}
{
"detail": "(This is just an example, the exception may not be related to this endpoint)",
"error": 500,
"errorCode": "UNEXPECTED_ERROR",
"reason": "Internal Server Error"
}