2023-03-28 19:12:30 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
2023-08-11 13:12:13 +00:00
|
|
|
// SPDX-License-Identifier: BUSL-1.1
|
2023-03-28 19:12:30 +00:00
|
|
|
|
2019-04-26 17:49:28 +00:00
|
|
|
package authmethod
|
|
|
|
|
|
|
|
import (
|
|
|
|
"github.com/hashicorp/consul/command/flags"
|
|
|
|
"github.com/mitchellh/cli"
|
|
|
|
)
|
|
|
|
|
|
|
|
func New() *cmd {
|
|
|
|
return &cmd{}
|
|
|
|
}
|
|
|
|
|
|
|
|
type cmd struct{}
|
|
|
|
|
|
|
|
func (c *cmd) Run(args []string) int {
|
|
|
|
return cli.RunResultHelp
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *cmd) Synopsis() string {
|
|
|
|
return synopsis
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *cmd) Help() string {
|
|
|
|
return flags.Usage(help, nil)
|
|
|
|
}
|
|
|
|
|
2019-05-01 21:11:23 +00:00
|
|
|
const synopsis = "Manage Consul's ACL auth methods"
|
2019-04-26 17:49:28 +00:00
|
|
|
const help = `
|
|
|
|
Usage: consul acl auth-method <subcommand> [options] [args]
|
|
|
|
|
2019-05-01 21:11:23 +00:00
|
|
|
This command has subcommands for managing Consul's ACL auth methods.
|
2019-04-26 17:49:28 +00:00
|
|
|
Here are some simple examples, and more detailed examples are available in
|
|
|
|
the subcommands or the documentation.
|
|
|
|
|
|
|
|
Create a new auth method:
|
|
|
|
|
|
|
|
$ consul acl auth-method create -type "kubernetes" \
|
|
|
|
-name "my-k8s" \
|
|
|
|
-description "This is an example kube auth method" \
|
|
|
|
-kubernetes-host "https://apiserver.example.com:8443" \
|
2020-10-06 22:44:24 +00:00
|
|
|
-kubernetes-ca-cert @/path/to/kube.ca.crt \
|
2019-04-26 17:49:28 +00:00
|
|
|
-kubernetes-service-account-jwt "JWT_CONTENTS"
|
|
|
|
|
|
|
|
List all auth methods:
|
|
|
|
|
|
|
|
$ consul acl auth-method list
|
|
|
|
|
|
|
|
Update all editable fields of the auth method:
|
|
|
|
|
|
|
|
$ consul acl auth-method update -name "my-k8s" \
|
|
|
|
-description "new description" \
|
|
|
|
-kubernetes-host "https://new-apiserver.example.com:8443" \
|
2020-10-06 22:44:24 +00:00
|
|
|
-kubernetes-ca-cert @/path/to/new-kube.ca.crt \
|
2019-04-26 17:49:28 +00:00
|
|
|
-kubernetes-service-account-jwt "NEW_JWT_CONTENTS"
|
|
|
|
|
|
|
|
Read an auth method:
|
|
|
|
|
|
|
|
$ consul acl auth-method read -name my-k8s
|
|
|
|
|
|
|
|
Delete an auth method:
|
|
|
|
|
|
|
|
$ consul acl auth-method delete -name my-k8s
|
|
|
|
|
|
|
|
For more examples, ask for subcommand help or view the documentation.
|
|
|
|
`
|