Class AccessEntry
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<AccessEntry.Builder,AccessEntry>
An access entry allows an IAM principal (user or role) to access your cluster. Access entries can replace the need to
maintain the aws-auth ConfigMap for authentication. For more information about access
entries, see Access entries in the
Amazon EKS User Guide.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionfinal StringThe ARN of the access entry.static AccessEntry.Builderbuilder()final StringThe name of your cluster.final InstantThe Unix epoch timestamp at object creation.final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final inthashCode()final booleanFor responses, this returns true if the service returned a value for the KubernetesGroups property.final booleanhasTags()For responses, this returns true if the service returned a value for the Tags property.Anamethat you've specified in a KubernetesRoleBindingorClusterRoleBindingobject so that Kubernetes authorizes theprincipalARNaccess to cluster objects.final InstantThe Unix epoch timestamp for the last modification to the object.final StringThe ARN of the IAM principal for the access entry.static Class<? extends AccessEntry.Builder> tags()Metadata that assists with categorization and organization.Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.final Stringtype()The type of the access entry.final Stringusername()Thenameof a user that can authenticate to your cluster.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
clusterName
-
principalArn
The ARN of the IAM principal for the access entry. If you ever delete the IAM principal with this ARN, the access entry isn't automatically deleted. We recommend that you delete the access entry with an ARN for an IAM principal that you delete. If you don't delete the access entry and ever recreate the IAM principal, even if it has the same ARN, the access entry won't work. This is because even though the ARN is the same for the recreated IAM principal, the
roleIDoruserID(you can see this with the Security Token ServiceGetCallerIdentityAPI) is different for the recreated IAM principal than it was for the original IAM principal. Even though you don't see the IAM principal'sroleIDoruserIDfor an access entry, Amazon EKS stores it with the access entry.- Returns:
- The ARN of the IAM principal for the access entry. If you ever delete the IAM principal with this ARN,
the access entry isn't automatically deleted. We recommend that you delete the access entry with an ARN
for an IAM principal that you delete. If you don't delete the access entry and ever recreate the IAM
principal, even if it has the same ARN, the access entry won't work. This is because even though the ARN
is the same for the recreated IAM principal, the
roleIDoruserID(you can see this with the Security Token ServiceGetCallerIdentityAPI) is different for the recreated IAM principal than it was for the original IAM principal. Even though you don't see the IAM principal'sroleIDoruserIDfor an access entry, Amazon EKS stores it with the access entry.
-
hasKubernetesGroups
public final boolean hasKubernetesGroups()For responses, this returns true if the service returned a value for the KubernetesGroups property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
kubernetesGroups
A
namethat you've specified in a KubernetesRoleBindingorClusterRoleBindingobject so that Kubernetes authorizes theprincipalARNaccess to cluster objects.Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasKubernetesGroups()method.- Returns:
- A
namethat you've specified in a KubernetesRoleBindingorClusterRoleBindingobject so that Kubernetes authorizes theprincipalARNaccess to cluster objects.
-
accessEntryArn
The ARN of the access entry.
- Returns:
- The ARN of the access entry.
-
createdAt
The Unix epoch timestamp at object creation.
- Returns:
- The Unix epoch timestamp at object creation.
-
modifiedAt
The Unix epoch timestamp for the last modification to the object.
- Returns:
- The Unix epoch timestamp for the last modification to the object.
-
hasTags
public final boolean hasTags()For responses, this returns true if the service returned a value for the Tags property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
tags
Metadata that assists with categorization and organization. Each tag consists of a key and an optional value. You define both. Tags don't propagate to any other cluster or Amazon Web Services resources.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasTags()method.- Returns:
- Metadata that assists with categorization and organization. Each tag consists of a key and an optional value. You define both. Tags don't propagate to any other cluster or Amazon Web Services resources.
-
username
The
nameof a user that can authenticate to your cluster.- Returns:
- The
nameof a user that can authenticate to your cluster.
-
type
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<AccessEntry.Builder,AccessEntry> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-