AWS SDK 또는 CLI로 UpdateAccessKey 사용하기
AWS SDK 또는 CLI로 UpdateAccessKey 사용하기
다음 코드 예시는 UpdateAccessKey을(를) 사용하는 방법을 보여줘요.
액션 예시는 더 큰 프로그램에서 발췌한 코드 조각이라, 실제 프로그램 컨텍스트 안에서 실행돼야 해요.
출처: 문서
본문
AWS CLI with Bash script
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
###############################################################################
# function iam_update_access_key
#
# This function can activate or deactivate an IAM access key for the specified IAM user.
#
# Parameters:
# -u user_name -- The name of the user.
# -k access_key -- The access key to update.
# -a -- Activate the selected access key.
# -d -- Deactivate the selected access key.
#
# Example:
# # To deactivate the selected access key for IAM user Bob
# iam_update_access_key -u Bob -k AKIAIOSFODNN7EXAMPLE -d
#
# Returns:
# 0 - If successful.
# 1 - If it fails.
###############################################################################
function iam_update_access_key()
{
local user_name access_key status response
local option OPTARG # Required to use getopts command in a function.
local activate_flag=false deactivate_flag=false
# bashsupport disable=BP5008
function usage()
{
echo "function iam_update_access_key"
echo "Updates the status of an AWS Identity and Access Management (IAM) access key for the specified IAM user"
echo " -u user_name The name of the user."
echo " -k access_key The access key to update."
echo " -a Activate the access key."
echo " -d Deactivate the access key."
echo ""
}
# Retrieve the calling parameters.
while getopts "u:k:adh" option; do
case "$
{
option}" in
u) user_name="$
{
OPTARG}" ;;
k) access_key="$
{
OPTARG}" ;;
a) activate_flag=true ;;
d) deactivate_flag=true ;;
h)
usage
return 0
;;
\?)
echo "Invalid parameter"
usage
return 1
;;
esac
done
export OPTIND=1
# Validate input parameters
if [[ -z "$user_name" ]]; then
errecho "ERROR: You must provide a username with the -u parameter."
usage
return 1
fi
if [[ -z "$access_key" ]]; then
errecho "ERROR: You must provide an access key with the -k parameter."
usage
return 1
fi
# Ensure that only -a or -d is specified
if [[ "$activate_flag" == true && "$deactivate_flag" == true ]]; then
errecho "ERROR: You cannot specify both -a (activate) and -d (deactivate) at the same time."
usage
return 1
fi
# If neither -a nor -d is provided, return an error
if [[ "$activate_flag" == false && "$deactivate_flag" == false ]]; then
errecho "ERROR: You must specify either -a (activate) or -d (deactivate)."
usage
return 1
fi
# Determine the status based on the flag
if [[ "$activate_flag" == true ]]; then
status="Active"
elif [[ "$deactivate_flag" == true ]]; then
status="Inactive"
fi
iecho "Parameters:\n"
iecho " Username: $user_name"
iecho " Access key: $access_key"
iecho " New status: $status"
iecho ""
# Update the access key status
response=$(aws iam update-access-key \
--user-name "$user_name" \
--access-key-id "$access_key" \
--status "$status" 2>&1)
local error_code=$
{
?}
if [[ $error_code -ne 0 ]]; then
aws_cli_error_log $error_code
errecho "ERROR: AWS reports update-access-key operation failed.\n$response"
return 1
fi
iecho "update-access-key response: $response"
iecho
return 0
}
API 상세 내용은 AWS CLI Command Reference의 UpdateAccessKey 문서를 참고하세요.
SDK for C++
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
bool AwsDoc::IAM::updateAccessKey(const Aws::String &userName,
const Aws::String &accessKeyID,
Aws::IAM::Model::StatusType status,
const Aws::Client::ClientConfiguration &clientConfig)
{
Aws::IAM::IAMClient iam(clientConfig);
Aws::IAM::Model::UpdateAccessKeyRequest request;
request.SetUserName(userName);
request.SetAccessKeyId(accessKeyID);
request.SetStatus(status);
auto outcome = iam.UpdateAccessKey(request);
if (outcome.IsSuccess())
{
std::cout << "Successfully updated status of access key "
<< accessKeyID << " for user " << userName << std::endl;
}
else
{
std::cerr << "Error updated status of access key " << accessKeyID <<
" for user " << userName << ": " <<
outcome.GetError().GetMessage() << std::endl;
}
return outcome.IsSuccess();
}
API 상세 내용은 AWS SDK for C++ API Reference의 UpdateAccessKey 문서를 참고하세요.
AWS CLI
IAM 사용자의 액세스 키를 활성화하거나 비활성화하려면
다음 update-access-key 명령은 Bob IAM 사용자의 지정 액세스 키(액세스 키 ID와 비밀 액세스 키)를 비활성화해요.
aws iam update-access-key \
--access-key-id
AKIAIOSFODNN7EXAMPLE
\
--status
Inactive
\
--user-name
Bob
이 명령은 출력이 없어요.
키를 비활성화하면 AWS에 대한 프로그래매틱(API) 액세스에 더 이상 쓸 수 없어요. 하지만 키 자체는 남아 있어 다시 활성화할 수 있어요.
더 자세한 내용은 AWS IAM 사용자 가이드의 'IAM 사용자의 액세스 키 관리' 문서를 참고하세요.
API 상세 내용은 AWS CLI Command Reference의 UpdateAccessKey 문서를 참고하세요.
SDK for Java 2.x
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
import software.amazon.awssdk.services.iam.model.IamException;
import software.amazon.awssdk.services.iam.model.StatusType;
import software.amazon.awssdk.services.iam.model.UpdateAccessKeyRequest;
import software.amazon.awssdk.regions.Region;
import software.amazon.awssdk.services.iam.IamClient;
/**
* Before running this Java V2 code example, set up your development
* environment, including your credentials.
*
* For more information, see the following documentation topic:
*
* https://docs.aws.amazon.com/sdk-for-java/latest/developer-guide/get-started.html
*/
public class UpdateAccessKey
{
private static StatusType statusType;
public static void main(String[] args)
{
final String usage = """
Usage:
<username> <accessId> <status>\s
Where:
username - The name of the user whose key you want to update.\s
accessId - The access key ID of the secret access key you want to update.\s
status - The status you want to assign to the secret access key.\s
""";
if (args.length != 3)
{
System.out.println(usage);
System.exit(1);
}
String username = args[0];
String accessId = args[1];
String status = args[2];
Region region = Region.AWS_GLOBAL;
IamClient iam = IamClient.builder()
.region(region)
.build();
updateKey(iam, username, accessId, status);
System.out.println("Done");
iam.close();
}
public static void updateKey(IamClient iam, String username, String accessId, String status)
{
try
{
if (status.toLowerCase().equalsIgnoreCase("active"))
{
statusType = StatusType.ACTIVE;
} else if (status.toLowerCase().equalsIgnoreCase("inactive"))
{
statusType = StatusType.INACTIVE;
} else
{
statusType = StatusType.UNKNOWN_TO_SDK_VERSION;
}
UpdateAccessKeyRequest request = UpdateAccessKeyRequest.builder()
.accessKeyId(accessId)
.userName(username)
.status(statusType)
.build();
iam.updateAccessKey(request);
System.out.printf("Successfully updated the status of access key %s to" +
"status %s for user %s", accessId, status, username);
} catch (IamException e)
{
System.err.println(e.awsErrorDetails().errorMessage());
System.exit(1);
}
}
}
API 상세 내용은 AWS SDK for Java 2.x API Reference의 UpdateAccessKey 문서를 참고하세요.
SDK for JavaScript (v3)
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
액세스 키를 업데이트해요.
import
{
UpdateAccessKeyCommand,
IAMClient,
StatusType,
} from "@aws-sdk/client-iam";
const client = new IAMClient(
{
});
/**
*
* @param
{
string} userName
* @param
{
string} accessKeyId
*/
export const updateAccessKey = (userName, accessKeyId) =>
{
const command = new UpdateAccessKeyCommand(
{
AccessKeyId: accessKeyId,
Status: StatusType.Inactive,
UserName: userName,
});
return client.send(command);
};
더 자세한 내용은 AWS SDK for JavaScript 개발자 가이드를 참고하세요.
API 상세 내용은 AWS SDK for JavaScript API Reference의 UpdateAccessKey 문서를 참고하세요.
SDK for JavaScript (v2)
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
// Load the AWS SDK for Node.js
var AWS = require("aws-sdk");
// Set the region
AWS.config.update(
{
region: "REGION" });
// Create the IAM service object
var iam = new AWS.IAM(
{
apiVersion: "2010-05-08" });
var params =
{
AccessKeyId: "ACCESS_KEY_ID",
Status: "Active",
UserName: "USER_NAME",
};
iam.updateAccessKey(params, function (err, data)
{
if (err)
{
console.log("Error", err);
} else
{
console.log("Success", data);
}
});
더 자세한 내용은 AWS SDK for JavaScript 개발자 가이드를 참고하세요.
API 상세 내용은 AWS SDK for JavaScript API Reference의 UpdateAccessKey 문서를 참고하세요.
Tools for PowerShell V4
예시 1: 이 예시는 Bob IAM 사용자의 액세스 키 AKIAIOSFODNN7EXAMPLE 상태를 Inactive로 변경해요.
Update-IAMAccessKey -UserName Bob -AccessKeyId AKIAIOSFODNN7EXAMPLE -Status Inactive
API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V4)의 UpdateAccessKey 문서를 참고하세요.
Tools for PowerShell V5
예시 1: 이 예시는 Bob IAM 사용자의 액세스 키 AKIAIOSFODNN7EXAMPLE 상태를 Inactive로 변경해요.
Update-IAMAccessKey -UserName Bob -AccessKeyId AKIAIOSFODNN7EXAMPLE -Status Inactive
API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V5)의 UpdateAccessKey 문서를 참고하세요.
SDK for Python (Boto3)
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
def update_key(user_name, key_id, activate):
"""
Updates the status of a key.
:param user_name: The user that owns the key.
:param key_id: The ID of the key to update.
:param activate: When True, the key is activated. Otherwise, the key is deactivated.
"""
try:
key = iam.User(user_name).AccessKey(key_id)
if activate:
key.activate()
else:
key.deactivate()
logger.info("%s key %s.", "Activated" if activate else "Deactivated", key_id)
except ClientError:
logger.exception(
"Couldn't %s key %s.", "Activate" if activate else "Deactivate", key_id
)
raise
API 상세 내용은 AWS SDK for Python (Boto3) API Reference의 UpdateAccessKey 문서를 참고하세요.
SDK for SAP ABAP
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
TRY.
lo_iam->updateaccesskey(
iv_accesskeyid = iv_access_key_id
iv_status = iv_status
iv_username = iv_user_name ).
MESSAGE 'Access key updated successfully.' TYPE 'I'.
CATCH /aws1/cx_iamnosuchentityex.
MESSAGE 'Access key or user does not exist.' TYPE 'E'.
ENDTRY.
API 상세 내용은 AWS SDK for SAP ABAP API reference의 UpdateAccessKey 문서를 참고하세요.