Nomad
nomad acl auth-method update command reference
The acl auth-method update command is used to update existing ACL Auth
Methods.
Usage
nomad acl auth-method update [options] <auth-method_name>
The acl auth-method update command requires an existing method's name.
Options
- -name: Sets the human-readable name for the ACL Role. It is required and can contain alphanumeric characters and dashes. This name must be unique and must not exceed 128 characters.
- -description: A free form text description of the role that must not exceed 256 characters.
- -policy: Specifies a policy to associate with the role identified by their name. This flag can be specified multiple times and must be specified at least once.
- -no-merge: Do not merge the current role information with what is provided to the command. Instead, overwrite all fields with the exception of the role ID which is immutable.
- -type: Updates the type of the auth method. Supported types are- OIDCand- JWT.
- -max-token-ttl: Updates the duration of time all tokens created by this auth method should be valid for.
- -token-locality: Updates the kind of token that this auth method should produce. This can be either- localor- global.
- token-name-format: Sets the token format for the authenticated users. This can be lightly templated using HIL '${foo}' syntax. Defaults to '${auth_method_type}-${auth_method_name}'.
- -default: Specifies whether this auth method should be treated as a default one in case no auth method is explicitly specified for a login command.
- -config: Auth method configuration in JSON format. You may provide '-' to send the config through stdin, or prefix a file path with '@' to indicate that the config should be loaded from the file.
- -json: Output the ACL auth method in a JSON format.
- -t: Format and display the ACL auth method using a Go template.
Examples
Update an existing ACL auth method:
$ nomad acl auth-method update -token-locality "global" -token-name-format '${auth_method_name}-${value.user}' -config @config.json example-acl-auth-method
Name                = example-acl-auth-method
Type                = OIDC
Locality            = global
Max Token TTL       = 1h0m0s
Token Name Format   = ${auth_method_name}-${value.user}
Default             = false
Create Index        = 14
Modify Index        = 33
Auth Method Config
OIDC Discovery URL     = https://my-corp-app-name.auth0.com/
OIDC Client ID         = V1RPi2MYptMV1RPi2MYptMV1RPi2MYpt
OIDC Client Secret     = example-client-secret
Bound audiences        = V1RPi2MYptMV1RPi2MYptMV1RPi2MYpt
Allowed redirects URIs = http://localhost:4646/oidc/callback
Discovery CA pem       = <none>
Signing algorithms     = <none>
Claim mappings         = {http://example.com/first_name: first_name}; {http://example.com/last_name: last_name}
List claim mappings    = {http://nomad.com/groups: groups}
General options
- -address=<addr>: The address of the Nomad server. Overrides the- NOMAD_ADDRenvironment variable if set. Defaults to- http://127.0.0.1:4646.
- -region=<region>: The region of the Nomad server to forward commands to. Overrides the- NOMAD_REGIONenvironment variable if set. Defaults to the Agent's local region.
- -no-color: Disables colored command output. Alternatively,- NOMAD_CLI_NO_COLORmay be set. This option takes precedence over- -force-color.
- -force-color: Forces colored command output. This can be used in cases where the usual terminal detection fails. Alternatively,- NOMAD_CLI_FORCE_COLORmay be set. This option has no effect if- -no-coloris also used.
- -ca-cert=<path>: Path to a PEM encoded CA cert file to use to verify the Nomad server SSL certificate. Overrides the- NOMAD_CACERTenvironment variable if set.
- -ca-path=<path>: Path to a directory of PEM encoded CA cert files to verify the Nomad server SSL certificate. If both- -ca-certand- -ca-pathare specified,- -ca-certis used. Overrides the- NOMAD_CAPATHenvironment variable if set.
- -client-cert=<path>: Path to a PEM encoded client certificate for TLS authentication to the Nomad server. Must also specify- -client-key. Overrides the- NOMAD_CLIENT_CERTenvironment variable if set.
- -client-key=<path>: Path to an unencrypted PEM encoded private key matching the client certificate from- -client-cert. Overrides the- NOMAD_CLIENT_KEYenvironment variable if set.
- -tls-server-name=<value>: The server name to use as the SNI host when connecting via TLS. Overrides the- NOMAD_TLS_SERVER_NAMEenvironment variable if set.
- -tls-skip-verify: Do not verify TLS certificate. This is highly not recommended. Verification will also be skipped if- NOMAD_SKIP_VERIFYis set.
- -token: The SecretID of an ACL token to use to authenticate API requests with. Overrides the- NOMAD_TOKENenvironment variable if set.