Skip to content

Bots

Create bots, non-human members of your organization that act through API keys.

Updated View as Markdown

A bot is a non-human member of your organization, for scripts and automation. A bot can’t sign in: it acts only through its API keys, and each key has exactly the bot’s access. A bot can do nothing until policies are attached to it, directly or through a group.

Use a bot when code needs less access than the person who runs it, or needs access that doesn’t depend on one person staying in the organization.

Each bot has a name (1 to 100 characters), a bot ID like bot_a1b2c3d4e5f6, and a resource name like ezgh::org_…:bot_a1b2c3d4e5f6.

Create a bot

Creating a bot needs bots.create.

  1. Open IAM > Bots and select Create bot.
  2. Enter a Name.
  3. Select the Groups and Policies to start with. These steps appear only if you may change group members and attach policies.
  4. Select Create bot.
ezgh iam bots create deployer
ezgh iam policies attach ProjectsFullAccess --bot deployer
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/bots \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "deployer"}'

See CreateBot. Attach policies with AttachBotPolicy.

Create an API key for a bot

Creating a key for a bot needs bots.createApiKey on the bot. Whoever has it can act with the bot’s access, so treat it like policies.attach. You create bot keys signed in, in the console or the CLI; an API key can’t create API keys.

  1. Open IAM > Bots and select the bot.
  2. On the API keys tab, select Create API key.
  3. Enter a Name, choose when it Expires, review, then select Create key.
  4. Copy the key. It isn’t shown again.
ezgh iam api-keys create ci --bot deployer --expires-in-days 90

The key is printed once, on standard output.

See API keys for key format, expiry and revocation.

Rename or delete a bot

On the bot’s page, select Rename (bots.update) or Delete (bots.delete). Deleting a bot deletes its API keys, which stop working at once, and removes it from its groups. With the CLI, use ezgh iam bots update <bot> --name <name> and ezgh iam bots delete <bot>.

The bot’s page also has a Groups tab and a Permissions tab, where you change its groups and directly attached policies as for a user.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close