yandex_organizationmanager_saml_federation (Resource)
Статья создана
Обновлена 7 августа 2025 г.
Allows management of a single SAML Federation within an existing Yandex Cloud Organization.
Example usage
//
// Create a new OrganizationManager SAML Federation.
//
resource "yandex_organizationmanager_saml_federation" "saml_fed" {
name = "my-federation"
description = "My new SAML federation"
organization_id = "sdf4*********3fr"
sso_url = "https://my-sso.url"
issuer = "my-issuer"
sso_binding = "POST"
}
Schema
Required
issuer(String) The ID of the IdP server to be used for authentication. The IdP server also responds to IAM with this ID after the user authenticates.name(String) The resource name.organization_id(String) The organization to attach this SAML Federation to.sso_binding(String) Single sign-on endpoint binding type. Most Identity Providers support thePOSTbinding type. SAML Binding is a mapping of a SAML protocol message onto standard messaging formats and/or communications protocols.sso_url(String) Single sign-on (SSO) endpoint URL. Specify the link to the IdP login page here.
Optional
auto_create_account_on_login(Boolean) Add new users automatically on successful authentication. The user will get theresource-manager.clouds.memberrole automatically, but you need to grant other roles to them. If the value isfalse, users who aren't added to the cloud can't log in, even if they have authenticated on your server.case_insensitive_name_ids(Boolean) Use case-insensitive name IDs.cookie_max_age(String) The lifetime of a Browser cookie in seconds. If the cookie is still valid, the management console authenticates the user immediately and redirects them to the home page. The default value is8h.description(String) The resource description.labels(Map of String) A set of key/value label pairs which assigned to resource.security_settings(Block List, Max: 1) Federation security settings. (see below for nested schema)timeouts(Block, Optional) (see below for nested schema)
Read-Only
created_at(String) The creation timestamp of the resource.id(String) The ID of this resource.
Nested Schema for security_settings
Optional:
encrypted_assertions(Boolean) Enable encrypted assertions.force_authn(Boolean) Force authentication on session expiration
Nested Schema for timeouts
Optional:
create(String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).delete(String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs.read(String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled.update(String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).
Import
The resource can be imported by using their resource ID. For getting the resource ID you can use Yandex Cloud Web Console
# terraform import yandex_organizationmanager_saml_federation.<resource Name> <resource Id>
terraform import yandex_organizationmanager_saml_federation.saml_fed ...