bm admin user svcacct info

Important

This command has been replaced and will be deprecated in a future Buckit Manager CLI release.

As of Buckit Manager CLI RELEASE.2024-10-08T09-37-26Z, use the bm admin accesskey info command to display information about access keys for built-in Buckit IDP users.

For access keys for AD/LDAP users, use the bm idp ldap accesskey info command.

Syntax

The bm admin user svcacct info command returns a description of the specified access key.

“Access Keys” have equivalent functionality to and replace the concept of “Service Accounts” in Buckit.

The description output includes the following details, as available:

  • Access Key

  • Parent user of the specified access key

  • Access key status (on or off)

  • Policy or policies

  • Comment

  • Expiration

Use --policy to view the attached policies.

The following command returns information on the specified access key:

bm admin user svcacct info mybuckit myuseraccesskey

The command has the following syntax:

bm [GLOBALFLAGS] admin user svcacct info           \
                                    [--policy]     \
                                    ALIAS          \
                                    ACCESSKEY
  • Brackets [] indicate optional parameters.

  • Parameters sharing a line are mutually dependent.

  • Parameters separated using the pipe | operator are mutually exclusive.

Copy the example to a text editor and modify as-needed before running the command in the terminal/shell.

Parameters

ALIAS
Required

The alias of the Buckit deployment.

ACCESSKEY
Required

The service account access key to display.

--policy
Optional

Displays policies attached to the specified service account.

Global Flags

This command supports any of the global flags.

Examples

Display Service Account Details

Use bm admin user svcacct info to display details of a service account on a Buckit deployment:

   bm admin user svcacct info ALIAS ACCESSKEY
  • Replace ALIAS with the alias of the Buckit deployment.

  • Replace ACCESSKEY with the service account access key.

The output resembles the following:

AccessKey: myuserserviceaccount
ParentUser: myuser
Status: on
Comment:
Policy: implied
Expiration: no-expiry

Display Service Account Policy Details

Use bm admin user svcacct info to display the policies attached to service account:

   bm admin user svcacct info --policy ALIAS ACCESSKEY
  • Replace ALIAS with the alias of the Buckit deployment.

  • Replace ACCESSKEY with the service account access key.

The output resembles the following:

{
 "Version": "2012-10-17",
 "Statement": [
  {
   "Effect": "Allow",
   "Action": [
    "s3:*"
   ],
   "Resource": [
    "arn:aws:s3:::*"
   ]
  }
 ]
}

Behavior

S3 Compatibility

The bm commandline tool is built for compatibility with the AWS S3 API and is tested with Buckit and AWS S3 for expected functionality and behavior.

Buckit provides no guarantees for other S3-compatible services, as their S3 API implementation is unknown and therefore unsupported. While bm commands may work as documented, any such usage is at your own risk.