AWS SDK 또는 CLI로 UpdateAccessKey 사용하기

AWS SDK 또는 CLI로 UpdateAccessKey 사용하기

다음 코드 예시는 UpdateAccessKey을(를) 사용하는 방법을 보여줘요.

액션 예시는 더 큰 프로그램에서 발췌한 코드 조각이라, 실제 프로그램 컨텍스트 안에서 실행돼야 해요.

출처: 문서

본문

AWS CLI with Bash script

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

###############################################################################
# function iam_update_access_key
#
# This function can activate or deactivate an IAM access key for the specified IAM user.
#
# Parameters:
#       -u user_name  -- The name of the user.
#       -k access_key -- The access key to update.
#       -a            -- Activate the selected access key.
#       -d            -- Deactivate the selected access key.
#
# Example:
#       # To deactivate the selected access key for IAM user Bob
#       iam_update_access_key -u Bob -k AKIAIOSFODNN7EXAMPLE -d
#
# Returns:
#       0 - If successful.
#       1 - If it fails.
###############################################################################
function iam_update_access_key()
{

  local user_name access_key status response
  local option OPTARG # Required to use getopts command in a function.
  local activate_flag=false deactivate_flag=false

  # bashsupport disable=BP5008
  function usage()
{

    echo "function iam_update_access_key"
    echo "Updates the status of an AWS Identity and Access Management (IAM) access key for the specified IAM user"
    echo "  -u user_name    The name of the user."
    echo "  -k access_key   The access key to update."
    echo "  -a              Activate the access key."
    echo "  -d              Deactivate the access key."
    echo ""
  }

  # Retrieve the calling parameters.
    while getopts "u:k:adh" option; do
      case "$
{
option}" in
        u) user_name="$
{
OPTARG}" ;;
        k) access_key="$
{
OPTARG}" ;;
        a) activate_flag=true ;;
        d) deactivate_flag=true ;;
        h)
          usage
          return 0
          ;;
        \?)
          echo "Invalid parameter"
          usage
          return 1
          ;;
      esac
    done
    export OPTIND=1

   # Validate input parameters
    if [[ -z "$user_name" ]]; then
      errecho "ERROR: You must provide a username with the -u parameter."
      usage
      return 1
    fi

    if [[ -z "$access_key" ]]; then
      errecho "ERROR: You must provide an access key with the -k parameter."
      usage
      return 1
    fi

    # Ensure that only -a or -d is specified
    if [[ "$activate_flag" == true && "$deactivate_flag" == true ]]; then
      errecho "ERROR: You cannot specify both -a (activate) and -d (deactivate) at the same time."
      usage
      return 1
    fi

    # If neither -a nor -d is provided, return an error
    if [[ "$activate_flag" == false && "$deactivate_flag" == false ]]; then
      errecho "ERROR: You must specify either -a (activate) or -d (deactivate)."
      usage
      return 1
    fi

    # Determine the status based on the flag
    if [[ "$activate_flag" == true ]]; then
      status="Active"
    elif [[ "$deactivate_flag" == true ]]; then
      status="Inactive"
    fi

    iecho "Parameters:\n"
    iecho "    Username:   $user_name"
    iecho "    Access key: $access_key"
    iecho "    New status: $status"
    iecho ""

    # Update the access key status
    response=$(aws iam update-access-key \
      --user-name "$user_name" \
      --access-key-id "$access_key" \
      --status "$status" 2>&1)

    local error_code=$
{
?}

    if [[ $error_code -ne 0 ]]; then
      aws_cli_error_log $error_code
      errecho "ERROR: AWS reports update-access-key operation failed.\n$response"
      return 1
    fi

    iecho "update-access-key response: $response"
    iecho

    return 0
}

API 상세 내용은 AWS CLI Command Reference의 UpdateAccessKey 문서를 참고하세요.

SDK for C++

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

bool AwsDoc::IAM::updateAccessKey(const Aws::String &userName,
                                  const Aws::String &accessKeyID,
                                  Aws::IAM::Model::StatusType status,
                                  const Aws::Client::ClientConfiguration &clientConfig)
{

    Aws::IAM::IAMClient iam(clientConfig);
    Aws::IAM::Model::UpdateAccessKeyRequest request;
    request.SetUserName(userName);
    request.SetAccessKeyId(accessKeyID);
    request.SetStatus(status);

    auto outcome = iam.UpdateAccessKey(request);
    if (outcome.IsSuccess())
{

        std::cout << "Successfully updated status of access key "
                  << accessKeyID << " for user " << userName << std::endl;
    }
    else
{

        std::cerr << "Error updated status of access key " << accessKeyID <<
                  " for user " << userName << ": " <<
                  outcome.GetError().GetMessage() << std::endl;
    }

    return outcome.IsSuccess();
}

API 상세 내용은 AWS SDK for C++ API Reference의 UpdateAccessKey 문서를 참고하세요.

AWS CLI

IAM 사용자의 액세스 키를 활성화하거나 비활성화하려면

다음 update-access-key 명령은 Bob IAM 사용자의 지정 액세스 키(액세스 키 ID와 비밀 액세스 키)를 비활성화해요.

aws iam update-access-key \
    --access-key-id
AKIAIOSFODNN7EXAMPLE
 \
    --status
Inactive
 \
    --user-name
Bob

이 명령은 출력이 없어요.

키를 비활성화하면 AWS에 대한 프로그래매틱(API) 액세스에 더 이상 쓸 수 없어요. 하지만 키 자체는 남아 있어 다시 활성화할 수 있어요.

더 자세한 내용은 AWS IAM 사용자 가이드의 'IAM 사용자의 액세스 키 관리' 문서를 참고하세요.

API 상세 내용은 AWS CLI Command Reference의 UpdateAccessKey 문서를 참고하세요.

SDK for Java 2.x

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

import software.amazon.awssdk.services.iam.model.IamException;
import software.amazon.awssdk.services.iam.model.StatusType;
import software.amazon.awssdk.services.iam.model.UpdateAccessKeyRequest;
import software.amazon.awssdk.regions.Region;
import software.amazon.awssdk.services.iam.IamClient;

/**
 * Before running this Java V2 code example, set up your development
 * environment, including your credentials.
 *
 * For more information, see the following documentation topic:
 *
 * https://docs.aws.amazon.com/sdk-for-java/latest/developer-guide/get-started.html
 */
public class UpdateAccessKey
{


    private static StatusType statusType;

    public static void main(String[] args)
{

        final String usage = """

                Usage:
                    <username> <accessId> <status>\s

                Where:
                    username - The name of the user whose key you want to update.\s
                    accessId - The access key ID of the secret access key you want to update.\s
                    status - The status you want to assign to the secret access key.\s
                """;

        if (args.length != 3)
{

            System.out.println(usage);
            System.exit(1);
        }

        String username = args[0];
        String accessId = args[1];
        String status = args[2];
        Region region = Region.AWS_GLOBAL;
        IamClient iam = IamClient.builder()
                .region(region)
                .build();

        updateKey(iam, username, accessId, status);
        System.out.println("Done");
        iam.close();
    }

    public static void updateKey(IamClient iam, String username, String accessId, String status)
{

        try
{

            if (status.toLowerCase().equalsIgnoreCase("active"))
{

                statusType = StatusType.ACTIVE;
            } else if (status.toLowerCase().equalsIgnoreCase("inactive"))
{

                statusType = StatusType.INACTIVE;
            } else
{

                statusType = StatusType.UNKNOWN_TO_SDK_VERSION;
            }

            UpdateAccessKeyRequest request = UpdateAccessKeyRequest.builder()
                    .accessKeyId(accessId)
                    .userName(username)
                    .status(statusType)
                    .build();

            iam.updateAccessKey(request);
            System.out.printf("Successfully updated the status of access key %s to" +
                    "status %s for user %s", accessId, status, username);

        } catch (IamException e)
{

            System.err.println(e.awsErrorDetails().errorMessage());
            System.exit(1);
        }
    }
}

API 상세 내용은 AWS SDK for Java 2.x API Reference의 UpdateAccessKey 문서를 참고하세요.

SDK for JavaScript (v3)

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

액세스 키를 업데이트해요.

import
{

  UpdateAccessKeyCommand,
  IAMClient,
  StatusType,
} from "@aws-sdk/client-iam";

const client = new IAMClient(
{
});

/**
 *
 * @param
{
string} userName
 * @param
{
string} accessKeyId
 */
export const updateAccessKey = (userName, accessKeyId) =>
{

  const command = new UpdateAccessKeyCommand(
{

    AccessKeyId: accessKeyId,
    Status: StatusType.Inactive,
    UserName: userName,
  });

  return client.send(command);
};

더 자세한 내용은 AWS SDK for JavaScript 개발자 가이드를 참고하세요.

API 상세 내용은 AWS SDK for JavaScript API Reference의 UpdateAccessKey 문서를 참고하세요.

SDK for JavaScript (v2)

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

// Load the AWS SDK for Node.js
var AWS = require("aws-sdk");
// Set the region
AWS.config.update(
{
 region: "REGION" });

// Create the IAM service object
var iam = new AWS.IAM(
{
 apiVersion: "2010-05-08" });

var params =
{

  AccessKeyId: "ACCESS_KEY_ID",
  Status: "Active",
  UserName: "USER_NAME",
};

iam.updateAccessKey(params, function (err, data)
{

  if (err)
{

    console.log("Error", err);
  } else
{

    console.log("Success", data);
  }
});

더 자세한 내용은 AWS SDK for JavaScript 개발자 가이드를 참고하세요.

API 상세 내용은 AWS SDK for JavaScript API Reference의 UpdateAccessKey 문서를 참고하세요.

Tools for PowerShell V4

예시 1: 이 예시는 Bob IAM 사용자의 액세스 키 AKIAIOSFODNN7EXAMPLE 상태를 Inactive로 변경해요.

Update-IAMAccessKey -UserName Bob -AccessKeyId AKIAIOSFODNN7EXAMPLE -Status Inactive

API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V4)의 UpdateAccessKey 문서를 참고하세요.

Tools for PowerShell V5

예시 1: 이 예시는 Bob IAM 사용자의 액세스 키 AKIAIOSFODNN7EXAMPLE 상태를 Inactive로 변경해요.

Update-IAMAccessKey -UserName Bob -AccessKeyId AKIAIOSFODNN7EXAMPLE -Status Inactive

API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V5)의 UpdateAccessKey 문서를 참고하세요.

SDK for Python (Boto3)

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

def update_key(user_name, key_id, activate):
    """
    Updates the status of a key.

    :param user_name: The user that owns the key.
    :param key_id: The ID of the key to update.
    :param activate: When True, the key is activated. Otherwise, the key is deactivated.
    """

    try:
        key = iam.User(user_name).AccessKey(key_id)
        if activate:
            key.activate()
        else:
            key.deactivate()
        logger.info("%s key %s.", "Activated" if activate else "Deactivated", key_id)
    except ClientError:
        logger.exception(
            "Couldn't %s key %s.", "Activate" if activate else "Deactivate", key_id
        )
        raise

API 상세 내용은 AWS SDK for Python (Boto3) API Reference의 UpdateAccessKey 문서를 참고하세요.

SDK for SAP ABAP

참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.

    TRY.
        lo_iam->updateaccesskey(
          iv_accesskeyid = iv_access_key_id
          iv_status = iv_status
          iv_username = iv_user_name ).
        MESSAGE 'Access key updated successfully.' TYPE 'I'.
      CATCH /aws1/cx_iamnosuchentityex.
        MESSAGE 'Access key or user does not exist.' TYPE 'E'.
    ENDTRY.

API 상세 내용은 AWS SDK for SAP ABAP API reference의 UpdateAccessKey 문서를 참고하세요.

더 알아보기 (Learn more)