Skip to content

Groups

Give a set of users and bots the same policies by attaching the policies to a group.

Updated View as Markdown

A group is a set of users and bots. Policies attached to a group apply to every member, in addition to the policies attached to the member directly. Groups don’t contain other groups.

Each group has a name (1 to 100 characters), an optional description (up to 1,000 characters), a group ID like grp_a1b2c3d4e5f6, and a resource name like ezgh::org_…:grp_a1b2c3d4e5f6.

Create a group

Creating a group needs groups.create.

  1. Open IAM > Groups and select Create group.
  2. Enter a Name and, optionally, a Description.
  3. Select the Members and Policies to start with. These steps appear only if you may change members and attach policies.
  4. Review, then select Create group.
ezgh iam groups create developers --description "Application developers"
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "developers", "description": "Application developers"}'

See CreateGroup.

Add and remove members

Members are users and bots in the organization. Changing a group’s members needs groups.updateMembers on the group.

  1. Open IAM > Groups and select the group.
  2. On the Members tab, select Edit members.
  3. Select the users and bots, then Save.
ezgh iam groups add-members developers user:ada@example.com bot:deployer
ezgh iam groups remove-members developers user:ada@example.com
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups/$GROUP_ID/members/$PRINCIPAL_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"

$PRINCIPAL_ID is a user ID or a bot ID. See AddGroupMember, RemoveGroupMember and SetGroupMembers, which replaces all members (up to 500 in one request).

You can also change a user’s or bot’s groups from their own page. See Change a user’s groups.

Attach policies to a group

Attaching or detaching policies needs policies.attach.

  1. Open IAM > Groups and select the group.
  2. On the Permissions tab, select Edit policies.
  3. Select the policies, then Save.
ezgh iam policies attach ReadOnlyAccess --group developers
ezgh iam policies detach ReadOnlyAccess --group developers
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups/$GROUP_ID/policies/ReadOnlyAccess \
  -H "Authorization: Bearer $EZGH_API_KEY"

See AttachGroupPolicy, DetachGroupPolicy and SetGroupPolicies.

Rename or delete a group

On the group’s page, select Edit to change its name or description (groups.update), or Delete to delete it (groups.delete). Deleting a group removes its memberships and policy attachments: its members lose the access its policies gave them. With the CLI, use ezgh iam groups update and ezgh iam groups delete.

Groups provisioned by SCIM

Groups your identity provider pushes over SCIM show Managed by SCIM. While SCIM is on, their name and members come from your identity provider, and renaming them, deleting them or changing their members here returns 409 with managed_by_scim. Their policies are yours: attach policies to them as to any group.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close