Skip to main content

group_memberships

Creates, updates, deletes or gets a group_membership resource or lists group_memberships in a region

Overview

Namegroup_memberships
TypeResource
DescriptionResource Type Definition for AWS:IdentityStore::GroupMembership
Idaws.identitystore.group_memberships

Fields

NameDatatypeDescription
group_idstringThe unique identifier for a group in the identity store.
identity_store_idstringThe globally unique identifier for the identity store.
member_idobjectAn object containing the identifier of a group member.
membership_idstringThe identifier for a GroupMembership in the identity store.
regionstringAWS region.

Methods

NameAccessible byRequired Params
create_resourceINSERTIdentityStoreId, GroupId, MemberId, region
delete_resourceDELETEdata__Identifier, region
list_resourcesSELECTregion
get_resourceSELECTdata__Identifier, region

SELECT examples

Gets all group_memberships in a region.

SELECT
region,
group_id,
identity_store_id,
member_id,
membership_id
FROM aws.identitystore.group_memberships
WHERE region = 'us-east-1';

Gets all properties from an individual group_membership.

SELECT
region,
group_id,
identity_store_id,
member_id,
membership_id
FROM aws.identitystore.group_memberships
WHERE region = 'us-east-1' AND data__Identifier = '<MembershipId>|<IdentityStoreId>';

INSERT example

Use the following StackQL query and manifest file to create a new group_membership resource, using stack-deploy.

/*+ create */
INSERT INTO aws.identitystore.group_memberships (
GroupId,
IdentityStoreId,
MemberId,
region
)
SELECT
'{{ GroupId }}',
'{{ IdentityStoreId }}',
'{{ MemberId }}',
'{{ region }}';

DELETE example

/*+ delete */
DELETE FROM aws.identitystore.group_memberships
WHERE data__Identifier = '<MembershipId|IdentityStoreId>'
AND region = 'us-east-1';

Permissions

To operate on the group_memberships resource, the following permissions are required:

Create

identitystore:CreateGroupMembership,
identitystore:DescribeGroupMembership

Read

identitystore:DescribeGroupMembership

Delete

identitystore:DeleteGroupMembership,
identitystore:DescribeGroupMembership

List

identitystore:ListGroupMemberships