almaforge_user Data Source
Read an AlmaForge User resource by name.
This data source reads existing cluster resources. It does not create, change, or delete them. Authenticate using the Terraform setup guide. Your identity needs permission to read the selected resources.
Users and their role assignments come from SSO. The provider exposes users only as data sources. Use the username shown by alma status, which may be an email address. See the RBAC guide to interpret the user's roles.
See the configuration reference for the resource manifest and field context.
Set name to the existing object's metadata.name. The result is available in metadata and spec. A missing object produces an error.
Example Usage
Save this configuration in a new directory. Replace the example name with the existing object you want to read. Review the plan before applying it. Applying this data-only configuration saves the outputs without changing cluster resources.
terraform initterraform plan -out=plan.tfplanterraform apply plan.tfplanterraform outputterraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}
provider "almaforge" {}
data "almaforge_user" "existing" {
name = "[email protected]"
}
output "name" {
value = data.almaforge_user.existing.metadata.name
}
Schema
Required
name(String) Name of the resource to read.
Read-Only
metadata(Attributes) (see below for nested schema)spec(Attributes) Spec contains the resource configuration. (see below for nested schema)
Nested Schema for metadata
Read-Only:
labels(Map of String) Labels attached to the resource.name(String) Resource name. Changing this name replaces the resource.resource_version(String) Server revision used to detect concurrent changes.
Nested Schema for spec
Read-Only:
created_by(Attributes) CreatedBy holds information about who created this user. (see below for nested schema)expires_at(String) ExpiresAt, if set, places a TTL on the user.identities(List of Object) Identities lists associated external identities that let the user log in using an externally verified identity. (see below for nested schema)roles(List of String) Roles is a list of roles assigned to the user.status(Attributes) Status is the login status. (see below for nested schema)traits(Map of List of String) Traits are key/value pairs received from an identity provider or set by an administrator. Used to populate role variables.
Nested Schema for spec.created_by
Read-Only:
connector(Attributes) Connector identifies the SSO connector if the user was created automatically via SSO. (see below for nested schema)created_at(String) CreatedAt is when the user was created.user(Attributes) User holds information about the user that created this user. (see below for nested schema)
Nested Schema for spec.created_by.connector
Read-Only:
id(String) ID is the connector ID.identity(String) Identity is the external identity of the user.subject(String) Subject is the immutable identifier the provider assigned to this user, taken from the OIDC sub claim. A cluster account is bound to it on the first login through a connector, and a later login through the same connector presenting a different subject is refused rather than allowed to take the account over. Connector types whose provider does not supply a stable subject leave it empty.type(String) Type is the connector type (for example, KindOIDC or KindGithub).
Nested Schema for spec.created_by.user
Read-Only:
name(String) Name is the name of the user.
Nested Schema for spec.identities
Read-Only:
id(String)identity(String)subject(String)type(String)
Nested Schema for spec.status
Read-Only:
is_locked(Boolean) IsLocked is true if the user is locked.lock_expires_at(String) LockExpiresAt is when this lock will expire.locked_at(String) LockedAt is when the user was locked.locked_message(String) LockedMessage describes the lock reason.