Template name
ACS-RAM-BulkyUpdateLoginProfile
Template description
Modifies the settings of the specified RAM users to log on to the console.
Template type
Automated
Owner
Alibaba Cloud
Input parameters
Parameter | Description | Data type | Required | Default value | Limit |
userNames | The user names. | List | Yes | ||
regionId | The region ID. | String | No | {{ ACS::RegionId }} | |
MFABindRequired | Specifies whether a multi-factor authentication (MFA) device must be attached to the RAM user upon logon. | Boolean | No | True | |
passwordResetRequired | Specifies whether the RAM user has to change the password upon logon. | Boolean | No | False | |
rateControl | The rate control settings. | Json | No | {'Mode': 'Concurrency', 'MaxErrors': 0, 'Concurrency': 10} | |
OOSAssumeRole | The RAM role that is assumed by CloudOps Orchestration Service (OOS). | String | No | "" |
Output parameters
N/A.
Permission policy that is required to execute the template
{
"Version": "1",
"Statement": [
{
"Action": [
"ram:UpdateLoginProfile"
],
"Resource": "*",
"Effect": "Allow"
}
]
}
References
ACS-RAM-BulkyUpdateLoginProfile
Template content
FormatVersion: OOS-2019-06-01
Description:
en: Bulky modify the logon configurations of a RAM user
name-en: ACS-RAM-BulkyUpdateLoginProfile
categories:
- security
Parameters:
regionId:
Type: String
Label:
en: RegionId
AssociationProperty: RegionId
Default: '{{ ACS::RegionId }}'
userNames:
Type: List
Label:
en: UserNames
MFABindRequired:
Type: Boolean
Label:
en: MFABindRequired
Default: true
passwordResetRequired:
Type: Boolean
Label:
en: PasswordResetRequired
Specifies whether an MFA device must be attached to the RAM user upon logon.
Default: false
rateControl:
Label:
en: RateControl
Type: Json
AssociationProperty: RateControl
Default:
Mode: Concurrency
MaxErrors: 0
Concurrency: 10
OOSAssumeRole:
Label:
en: OOSAssumeRole
Type: String
Default: ''
RamRole: '{{ OOSAssumeRole }}'
Tasks:
- Name: updateLoginProfile
Action: 'ACS::ExecuteApi'
Description:
en: Modifies the logon configurations of a RAM user
Properties:
Service: RAM
API: UpdateLoginProfile
Parameters:
RegionId: '{{ regionId }}'
PasswordResetRequired: '{{ passwordResetRequired }}'
MFABindRequired: '{{ MFABindRequired }}'
UserName: '{{ ACS::TaskLoopItem }}'
Loop:
RateControl: '{{ rateControl }}'
Items: '{{ userNames }}'