You can call the CleanUserPermissions operation to delete the kubeconfig files of the specified users and revoke the relevant Role-Based Access Control (RBAC) permissions. This API operation is suitable for scenarios where employees have resigned or the accounts of employees are locked.
Operation description
To call this operation, make sure that you have the AliyunCSFullAccess permission.
You cannot revoke the permissions of an Alibaba Cloud account.
You cannot revoke the permissions of the account that you use to call this operation.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cs:CleanUserPermissions |
none |
*All Resource
|
None | None |
Request syntax
DELETE /users/{Uid}/permissions HTTP/1.1
Path Parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Uid |
string |
Yes |
The ID of the specified Resource Access Management (RAM) user or RAM role within the Alibaba Cloud account. |
26562443851650**** |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Force |
boolean |
No |
Specifies whether to forcefully delete the specified kubeconfig files. Valid values:
|
false |
| ClusterIds |
array |
No |
The cluster IDs. If you specify a list of cluster IDs, only the kubeconfig files and RBAC permissions of the clusters that belong to the current user in the list are revoked. |
|
|
string |
No |
The ID of the cluster. |
cd53c3a9ee12a494c9a0451e2ffc11c65 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| request_id |
string |
The request ID. |
687C5BAA-D103-4993-884B-C35E4314**** |
| task_id |
string |
The task ID. |
clean-user-permissions-2085266204********-6694c16e6ae07*********** |
Examples
Success response
JSON format
{
"request_id": "687C5BAA-D103-4993-884B-C35E4314****",
"task_id": "clean-user-permissions-2085266204********-6694c16e6ae07***********"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.