Skip to main content

group_memberships

Creates, updates, deletes, gets or lists a group_memberships resource.

Overview​

Namegroup_memberships
TypeResource
Idaws.identitystore.group_memberships

Fields​

The following fields are returned by SELECT queries:

NameDatatypeDescription
created_atstring (date-time)The date and time the group membership was created.
created_bystringThe identifier of the user or system that created the group membership.
group_idstringThe identifier for a group in the identity store. (pattern: <code>([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}</code>)
identity_store_idstringThe globally unique identifier for the identity store. (pattern: <code>d-[0-9a-f]{10}$|^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}</code>)
member_idobjectAn object containing the identifier of a group member.
membership_idstringThe identifier for a GroupMembership in an identity store. (pattern: <code>([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}</code>)
updated_atstring (date-time)The date and time the group membership was last updated.
updated_bystringThe identifier of the user or system that last updated the group membership.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
describe_group_membershipselectregionRetrieves membership metadata and attributes from MembershipId in an identity store. If you have access to a member account, you can use this API operation from the member account. For more information, see Limiting access to the identity store from member accounts in the IAM Identity Center User Guide.
list_group_membershipsselectregionFor the specified group in the specified identity store, returns the list of all GroupMembership objects and returns results in paginated form. If you have access to a member account, you can use this API operation from the member account. For more information, see Limiting access to the identity store from member accounts in the IAM Identity Center User Guide.
create_group_membershipinsertregion, IdentityStoreId, GroupId, MemberIdCreates a relationship between a member and a group. The following identifiers must be specified: GroupId, IdentityStoreId, and MemberId.
delete_group_membershipdeleteregionDelete a membership within a group given MembershipId.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringAWS region (default: us-east-1)

SELECT examples​

Retrieves membership metadata and attributes from MembershipId in an identity store. If you have access to a member account, you can use this API operation from the member account. For more information, see Limiting access to the identity store from member accounts in the IAM Identity Center User Guide.

SELECT
created_at,
created_by,
group_id,
identity_store_id,
member_id,
membership_id,
updated_at,
updated_by
FROM aws.identitystore.group_memberships
WHERE region = '{{ region }}' -- required
;

INSERT examples​

Creates a relationship between a member and a group. The following identifiers must be specified: GroupId, IdentityStoreId, and MemberId.

INSERT INTO aws.identitystore.group_memberships (
IdentityStoreId,
GroupId,
MemberId,
region
)
SELECT
'{{ IdentityStoreId }}' /* required */,
'{{ GroupId }}' /* required */,
'{{ MemberId }}' /* required */,
'{{ region }}'
RETURNING
identity_store_id,
membership_id
;

DELETE examples​

Delete a membership within a group given MembershipId.

DELETE FROM aws.identitystore.group_memberships
WHERE region = '{{ region }}' --required
;