bm idp ldap policy detach

Description

The bm idp ldap policy detach command detaches one or more polices from an entity.

The following example detaches the policy userpolicy from the user bobfisher on the mybuckit deployment.

bm idp ldap policy detach mybuckit                                                  \
                          userpolicy                                               \
                          --user='uid=bobfisher,ou=people,ou=hwengg,dc=min,dc=io'

The command has the following syntax:

bm [GLOBALFLAGS] idp ldap policy detach             \
                                 POLICYNAME         \
                                 [POLICY2] ...      \
                                 ALIAS              \
                                 [--user=`USER`]    \
                                 [--group=`GROUP`]
  • Replace ALIAS with the alias of a Buckit deployment to configure for AD/LDAP integration.

  • Replace POLICYNAME with the policy to detach from the entity. You may list multiple policies to detach from the entity.

  • Use must use one of either the --user or --group flag. You may only use the flag once in the command. You cannot use both flags in the same command.

  • Brackets [] indicate optional parameters.

  • Parameters sharing a line are mutually dependent.

  • Parameters separated using the pipe | operator are mutually exclusive.

Copy the example to a text editor and modify as-needed before running the command in the terminal/shell.

Parameters

ALIAS
Required

The alias of the Buckit deployment with the entity from which to detach a policy.

For example:

bm idp ldap policy detach mybuckit                                                  \
                          userpolicy                                               \
                          --user='uid=bobfisher,ou=people,ou=hwengg,dc=min,dc=io'

Example

The following example detaches two policies, policy1 and policy2, from the projectb group on the mybuckit deployment:

bm idp ldap policy detach mybuckit                                                 \
                          policy1                                                 \
                          policy2                                                 \
                          --group='cn=projectb,ou=groups,ou=swengg,dc=min,dc=io'

Global Flags

This command supports any of the global flags.

Behavior

S3 Compatibility

The bm commandline tool is built for compatibility with the AWS S3 API and is tested with Buckit and AWS S3 for expected functionality and behavior.

Buckit provides no guarantees for other S3-compatible services, as their S3 API implementation is unknown and therefore unsupported. While bm commands may work as documented, any such usage is at your own risk.