Prerequisites
- Web console
- CLI
- Terraform
- Go SDK
- Python SDK
- JavaScript SDK
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
- Install and configure the Nebius AI Cloud CLI.
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
- Install and configure the Nebius AI Cloud provider for Terraform.
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
- Install and initialize the Nebius SDK for Go.
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
- Install and initialize the Nebius SDK for Python.
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
- Install and initialize the Nebius SDK for JavaScript.
- Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Make sure that you have access to your IdP admin portal and can get the SAML application metadata (login URL, identifier, certificate) required to create a federation.
Creating a federation
- Web console
- CLI
- Terraform
- Go SDK
- Python SDK
- JavaScript SDK
-
In the web console, go to
Administration → IAM.
- Go to the Federations tab.
- Click Create entity → Federation.
-
Specify the IdP settings:
-
If you have an XML file with SAML metadata:
- Enter a federation name.
- Click Upload file and select the XML file with the SAML metadata from your IdP, then click Continue.
- On the page that opens, enter a name for the certificate in the Certificates section.
-
If you don’t have an XML file, enter the SAML metadata manually:
- Enable Manual mode and enter a federation name.
- Under Identity provider (IdP), specify the SSO URL and Issuer parameters from your IdP, then click Continue.
- On the page that opens, enter a certificate name, then either upload the PEM certificate file, or copy and paste the certificate body into the field.
-
If you have an XML file with SAML metadata:
- Click Create federation.
-
To create a federation, run the following command:
The command contains the following parameters:
nebius iam federation create \ --name <federation_name> \ --parent-id <tenant_ID> \ --saml-settings-sso-url <URL_to_log_in> \ --saml-settings-idp-issuer <application_identifier>--name: Federation name.--parent-id: ID of the tenant in which you create the federation.--saml-settings-sso-url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.--saml-settings-idp-issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Copy and save the federation ID. It is returned in the
metadata.idparameter of the command output. -
After you create a federation, attach a certificate to it. Prepare the
federation-cert.jsonfile:If the certificate body is split into several lines in the source, paste the body as a single line in{ "metadata": { "parent_id": "<federation_ID>", "name": "<certificate_name>" }, "spec": { "description": "certificate for a federation", "data": "-----BEGIN CERTIFICATE-----\n<certificate_body>\n-----END CERTIFICATE-----\n" } }federation-cert.json. -
Apply the certificate file:
nebius iam federation-certificate create --file federation-cert.json
-
Create a federation:
-
Prepare the following configuration file:
The file contains the following parameters:
resource "nebius_iam_v1_federation" "<federation_name>" { name = "<federation_name>" parent_id = "<tenant_ID>" saml_settings = { sso_url = "<URL_to_log_in>" idp_issuer = "<application_identifier>" } }name: Federation name.parent_id: ID of the tenant in which you create the federation.saml_settings.sso_url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.saml_settings.idp_issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Check that the configuration is correct:
terraform validate -
Apply the changes:
terraform apply
-
Prepare the following configuration file:
-
After you create a federation, attach a certificate to it:
-
Prepare a certificate manifest in the same file where you store the
nebius_iam_v1_federationresource:In the resource, specify the federation name. Save your PEM certificate asresource "nebius_iam_v1_federation_certificate" "certificate_for_<federation_name>" { parent_id = nebius_iam_v1_federation.<federation_name>.id name = "certificate" data = file("${path.module}/certificate.pem") description = "certificate for a federation" depends_on = [nebius_iam_v1_federation.<federation_name>] }certificate.pemin the Terraform working directory — thefile()function reads the certificate from that file. -
Check that the configuration is correct:
terraform validate -
Apply the changes:
terraform apply
-
Prepare a certificate manifest in the same file where you store the
-
To create a federation, run the following code:
The code contains the following parameters:
federationOperation, err := sdk.Services().IAM().V1(). Federation().Create( ctx, &iam.CreateFederationRequest{ Metadata: &common.ResourceMetadata{ ParentId: "<tenant_ID>", Name: "<federation_name>", }, Spec: &iam.FederationSpec{ Settings: &iam.FederationSpec_SamlSettings{ SamlSettings: &iam.SamlSettings{ SsoUrl: "<URL_to_log_in>", IdpIssuer: "<application_identifier>", }, }, }, }, ) if err != nil { return err } if _, err = federationOperation.Wait(ctx); err != nil { return err }Metadata.ParentId: ID of the tenant in which you create the federation.Metadata.Name: Federation name.Spec.Settings.SamlSettings.SsoUrl: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.Spec.Settings.SamlSettings.IdpIssuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Copy and save the federation ID. It’s returned by
federationOperation.ResourceID(). -
After you create a federation, attach a certificate to it:
In the code, set
certificateOperation, err := sdk.Services().IAM().V1(). FederationCertificate().Create( ctx, &iam.CreateFederationCertificateRequest{ Metadata: &common.ResourceMetadata{ ParentId: "<federation_ID>", }, Spec: &iam.FederationCertificateSpec{ Description: "certificate for a federation", Data: certificateData, }, }, ) if err != nil { return err } if _, err = certificateOperation.Wait(ctx); err != nil { return err }Metadata.ParentIdto the federation ID from the previous step, and assign your PEM-encoded certificate body to thecertificateDatavariable used inSpec.Data.
-
To create a federation, run the following code:
The code contains the following parameters:
federation_service = FederationServiceClient(sdk) federation_operation = await federation_service.create( CreateFederationRequest( metadata=ResourceMetadata( parent_id="<tenant_ID>", name="<federation_name>", ), spec=FederationSpec( saml_settings=SamlSettings( sso_url="<URL_to_log_in>", idp_issuer="<application_identifier>", ), ), ), ) await federation_operation.wait()metadata.parent_id: ID of the tenant in which you create the federation.metadata.name: Federation name.spec.saml_settings.sso_url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.spec.saml_settings.idp_issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Copy and save the federation ID. It’s returned by
federation_operation.resource_id. -
After you create a federation, attach a certificate to it:
In the code, set
cert_service = FederationCertificateServiceClient(sdk) certificate_operation = await cert_service.create( CreateFederationCertificateRequest( metadata=ResourceMetadata(parent_id="<federation_ID>"), spec=FederationCertificateSpec( description="certificate for a federation", data=certificate_data, ), ), ) await certificate_operation.wait()metadata.parent_idto the federation ID from the previous step, and assign your PEM-encoded certificate body to thecertificate_datavariable used inspec.data.
-
To create a federation, run the following code:
The code contains the following parameters:
const federationService = new FederationService(sdk); const federationOperation = await federationService.create( CreateFederationRequest.create({ metadata: ResourceMetadata.create({ parentId: "<tenant_ID>", name: "<federation_name>", }), spec: FederationSpec.create({ settings: { $case: "samlSettings", samlSettings: SamlSettings.create({ ssoUrl: "<URL_to_log_in>", idpIssuer: "<application_identifier>", }), }, }), }), ).result; await federationOperation.wait();metadata.parentId: ID of the tenant in which you create the federation.metadata.name: Federation name.spec.settings.samlSettings.ssoUrl: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.spec.settings.samlSettings.idpIssuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Copy and save the federation ID. It’s returned by
federationOperation.resourceId(). -
After you create a federation, attach a certificate to it:
In the code, set
const createCertificateService = new FederationCertificateService(sdk); const certificateOperation = await createCertificateService.create( CreateFederationCertificateRequest.create({ metadata: ResourceMetadata.create({ parentId: "<federation_ID>", }), spec: FederationCertificateSpec.create({ description: "certificate for a federation", data: certificateData, }), }), ).result; await certificateOperation.wait();metadata.parentIdto the federation ID from the previous step, and assign your PEM-encoded certificate body to thecertificateDatavariable used inspec.data.
Changing federation settings
- Web console
- CLI
- Terraform
- Go SDK
- Python SDK
- JavaScript SDK
-
In the sidebar, go to
Administration → IAM.
- Go to the Federations tab.
-
Next to the federation, click
→ Configure.
-
Update federation settings:
- Name: Federation name.
- SSO URL: Login URL from your IdP.
- Issuer: Your IdP identifier string.
- Click Save changes to apply the new settings.
To change federation settings, run the following command:You can change the following parameters:
The ID is specified in the
nebius iam federation update <federation_ID> \
--name <new_federation_name> \
--saml-settings-sso-url <URL_to_log_in> \
--saml-settings-idp-issuer <application_identifier>
--name: Federation name.--saml-settings-sso-url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.--saml-settings-idp-issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
How to get the federation ID
How to get the federation ID
nebius iam federation list --parent-id <tenant_ID>
.items.metadata.id parameter.-
Modify the manifest with the deployed federation:
You can change the following parameters:
resource "nebius_iam_v1_federation" "<federation_name>" { name = "<new_federation_name>" saml_settings = { sso_url = "<URL_to_log_in>" idp_issuer = "<application_identifier>" } }name: Federation name.saml_settings.sso_url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.saml_settings.idp_issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
-
Check that the configuration is correct:
terraform validate -
Apply the changes:
terraform apply
The SDK has no partial update call, so to change federation settings, get the federation, modify the parameters you want to change, then send the updated metadata and spec back:The code contains the following parameters:
The response returns the federation ID in each item’s metadata, accessible as
federationForUpdate, err := sdk.Services().IAM().V1().
Federation().Get(
ctx,
&iam.GetFederationRequest{Id: "<federation_ID>"},
)
if err != nil {
return err
}
federationForUpdate.GetMetadata().Name = "<new_federation_name>"
federationForUpdate.GetSpec().GetSamlSettings().SsoUrl =
"<URL_to_log_in>"
federationForUpdate.GetSpec().GetSamlSettings().IdpIssuer =
"<application_identifier>"
updateFederationOperation, err := sdk.Services().IAM().
V1().Federation().Update(
ctx,
&iam.UpdateFederationRequest{
Metadata: federationForUpdate.GetMetadata(),
Spec: federationForUpdate.GetSpec(),
},
)
if err != nil {
return err
}
if _, err = updateFederationOperation.Wait(ctx); err != nil {
return err
}
IdinGetFederationRequest: Federation ID. Use the ID you saved when creating the federation.Metadata.Name: Federation name.Spec.SamlSettings.SsoUrl: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.Spec.SamlSettings.IdpIssuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
How to get the federation ID
How to get the federation ID
listedFederations, err := sdk.Services().IAM().V1().
Federation().List(
ctx,
&iam.ListFederationsRequest{ParentId: "<tenant_ID>"},
)
if err != nil {
return err
}
fmt.Println(listedFederations)
listedFederations.GetItems()[i].GetMetadata().GetId().The SDK has no partial update call, so to change federation settings, get the federation, modify the parameters you want to change, then send the updated metadata and spec back:The code contains the following parameters:
The response returns the federation ID in each item’s metadata, accessible as
federation_service = FederationServiceClient(sdk)
federation = await federation_service.get(
GetFederationRequest(id="<federation_ID>"),
)
if federation.metadata is None or federation.spec is None:
raise ValueError("federation resource is incomplete")
if federation.spec.saml_settings is None:
raise ValueError("federation SAML settings are missing")
federation.metadata.name = "<new_federation_name>"
federation.spec.saml_settings.sso_url = "<URL_to_log_in>"
federation.spec.saml_settings.idp_issuer = "<application_identifier>"
update_federation_operation = await federation_service.update(
UpdateFederationRequest(
metadata=federation.metadata,
spec=federation.spec,
),
)
await update_federation_operation.wait()
idinGetFederationRequest: Federation ID. Use the ID you saved when creating the federation.metadata.name: Federation name.spec.saml_settings.sso_url: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.spec.saml_settings.idp_issuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
How to get the federation ID
How to get the federation ID
federation_service = FederationServiceClient(sdk)
listed_federations = await federation_service.list(
ListFederationsRequest(parent_id="<tenant_ID>"),
)
print(listed_federations)
listed_federations.items[i].metadata.id.The SDK has no partial update call, so to change federation settings, get the federation, modify the parameters you want to change, then send the updated metadata and spec back:The code contains the following parameters:
The response returns the federation ID in each item’s metadata, accessible as
const updateFederationService = new FederationService(sdk);
const federationForUpdate = await updateFederationService.get(
GetFederationRequest.create({
id: "<federation_ID>",
}),
);
if (!federationForUpdate.metadata ||
!federationForUpdate.spec) {
throw new Error("federation resource is incomplete");
}
if (federationForUpdate.spec.settings?.$case !==
"samlSettings") {
throw new Error("federation SAML settings are missing");
}
federationForUpdate.metadata.name = "<new_federation_name>";
federationForUpdate.spec.settings.samlSettings.ssoUrl =
"<URL_to_log_in>";
federationForUpdate.spec.settings.samlSettings.idpIssuer =
"<application_identifier>";
const updateFederationOperation =
await updateFederationService.update(
UpdateFederationRequest.create({
metadata: federationForUpdate.metadata,
spec: federationForUpdate.spec,
}),
).result;
await updateFederationOperation.wait();
idinGetFederationRequest: Federation ID. Use the ID you saved when creating the federation.metadata.name: Federation name.spec.settings.samlSettings.ssoUrl: URL of the page that opens when a federated user logs in. For example, Microsoft Entra ID calls it Login URL.spec.settings.samlSettings.idpIssuer: Identifier of your SAML application. For example, Microsoft Entra ID calls it Microsoft Entra Identifier.
How to get the federation ID
How to get the federation ID
const listFederationService = new FederationService(sdk);
const listedFederations = await listFederationService.list(
ListFederationsRequest.create({
parentId: "<tenant_ID>",
}),
);
console.log(listedFederations);
listedFederations.items[i].metadata?.id.Changing federation certificates
- Web console
- CLI
- Terraform
- Go SDK
- Python SDK
- JavaScript SDK
-
In the sidebar, go to
Administration → IAM.
- Go to the Federations tab and open the federation whose certificate you want to change.
-
On the Certificates tab, rename or delete a certificate.
A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
-
To add a new certificate:
- Click Attach certificate.
- Enter a certificate name, then either upload the PEM certificate file, or copy and paste the certificate body into the field.
- Click Attach certificates.
When changing federation certificates, you can rename, add or delete a certificate.
The ID is specified in the
-
Rename a certificate:
nebius iam federation-certificate update <certificate_ID> --name <new_certificate_name> -
Delete a certificate:
nebius iam federation-certificate delete <certificate_ID>A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
How to get the certificate ID
How to get the certificate ID
nebius iam federation-certificate list-by-federation --federation-id <federation_ID>
.items.metadata.id parameter.When changing federation certificates, you can rename, add or delete a certificate:
-
To rename a certificate, update the
nameparameter in thenebius_iam_v1_federation_certificateresource. -
To delete a certificate, remove the
nebius_iam_v1_federation_certificateresource from the configuration file.A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
When changing federation certificates, you can rename or delete a certificate.
The response returns the certificate ID in each item’s metadata, accessible as
-
Rename a certificate. The SDK has no partial update call, so get the certificate, change its
Metadata.Name, then send the updated metadata and spec back:certificate, err := sdk.Services().IAM().V1(). FederationCertificate().Get( ctx, &iam.GetFederationCertificateRequest{ Id: "<certificate_ID>", }, ) if err != nil { return err } certificate.GetMetadata().Name = "<new_certificate_name>" updateCertificateOperation, err := sdk.Services().IAM(). V1().FederationCertificate().Update( ctx, &iam.UpdateFederationCertificateRequest{ Metadata: certificate.GetMetadata(), Spec: certificate.GetSpec(), }, ) if err != nil { return err } if _, err = updateCertificateOperation.Wait(ctx); err != nil { return err } -
Delete a certificate:
deleteCertificateOperation, err := sdk.Services().IAM(). V1().FederationCertificate().Delete( ctx, &iam.DeleteFederationCertificateRequest{ Id: "<certificate_ID>", }, ) if err != nil { return err } if _, err = deleteCertificateOperation.Wait(ctx); err != nil { return err }A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
How to get the certificate ID
How to get the certificate ID
listedFederationCertificates, err := sdk.Services().IAM().
V1().FederationCertificate().ListByFederation(
ctx,
&iam.ListFederationCertificateByFederationRequest{
FederationId: "<federation_ID>",
},
)
if err != nil {
return err
}
fmt.Println(listedFederationCertificates)
listedFederationCertificates.GetItems()[i].GetMetadata().GetId().When changing federation certificates, you can rename or delete a certificate.
The response returns the certificate ID in each item’s metadata, accessible as
-
Rename a certificate. The SDK has no partial update call, so get the certificate, change its
metadata.name, then send the updated metadata and spec back:cert_service = FederationCertificateServiceClient(sdk) certificate = await cert_service.get( GetFederationCertificateRequest(id="<certificate_ID>"), ) if certificate.metadata is None or certificate.spec is None: raise ValueError("certificate resource is incomplete") certificate.metadata.name = "<new_certificate_name>" update_certificate_operation = await cert_service.update( UpdateFederationCertificateRequest( metadata=certificate.metadata, spec=certificate.spec, ), ) await update_certificate_operation.wait() -
Delete a certificate:
cert_service = FederationCertificateServiceClient(sdk) delete_certificate_operation = await cert_service.delete( DeleteFederationCertificateRequest(id="<certificate_ID>"), ) await delete_certificate_operation.wait()A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
How to get the certificate ID
How to get the certificate ID
cert_service = FederationCertificateServiceClient(sdk)
listed_federation_certificates = (
await cert_service.list_by_federation(
ListFederationCertificateByFederationRequest(
federation_id="<federation_ID>",
),
)
)
print(listed_federation_certificates)
listed_federation_certificates.items[i].metadata.id.When changing federation certificates, you can rename or delete a certificate.
The response returns the certificate ID in each item’s metadata, accessible as
-
Rename a certificate. The SDK has no partial update call, so get the certificate, change its
metadata.name, then send the updated metadata and spec back:const updateCertificateService = new FederationCertificateService(sdk); const certificateForUpdate = await updateCertificateService.get( GetFederationCertificateRequest.create({ id: "<certificate_ID>", }), ); if (!certificateForUpdate.metadata || !certificateForUpdate.spec) { throw new Error("certificate resource is incomplete"); } certificateForUpdate.metadata.name = "<new_certificate_name>"; const updateCertificateOperation = await updateCertificateService.update( UpdateFederationCertificateRequest.create({ metadata: certificateForUpdate.metadata, spec: certificateForUpdate.spec, }), ).result; await updateCertificateOperation.wait(); -
Delete a certificate:
const deleteCertificateService = new FederationCertificateService(sdk); const deleteCertificateOperation = await deleteCertificateService.delete( DeleteFederationCertificateRequest.create({ id: "<certificate_ID>", }), ).result; await deleteCertificateOperation.wait();A federation cannot function correctly without at least one valid certificate. If you need to delete the only certificate attached to the federation, be sure to replace it with a new one.
How to get the certificate ID
How to get the certificate ID
const listCertificateService =
new FederationCertificateService(sdk);
const listedFederationCertificates =
await listCertificateService.listByFederation(
ListFederationCertificateByFederationRequest.create({
federationId: "<federation_ID>",
}),
);
console.log(listedFederationCertificates);
listedFederationCertificates.items[i].metadata?.id.Deactivating a federation
When a federation is inactive, users who authenticate through that federation will not be able to sign in to Nebius AI Cloud until it’s reactivated.- Web console
- CLI
- Go SDK
- Python SDK
- JavaScript SDK
-
In the sidebar, go to
Administration → IAM.
- Go to the Federations tab.
-
Next to the federation you want to deactivate, click
→ Deactivate. To reactivate the federation, click
→ Activate.
To deactivate a federation, run the following command:To activate a federation again, run the following command:A federation is active by default after you create it. Run the
The ID is specified in the
nebius iam federation deactivate --federation-id <federation_ID>
nebius iam federation activate --federation-id <federation_ID>
activate command only if you deactivated the federation earlier.How to get the federation ID
How to get the federation ID
nebius iam federation list --parent-id <tenant_ID>
.items.metadata.id parameter.To deactivate a federation, run the following code:To activate a federation again, run the following code:A federation is active by default after you create it. Run the activation code only if you deactivated the federation earlier.
The response returns the federation ID in each item’s metadata, accessible as
deactivateFederationOperation, err := sdk.Services().IAM().
V1().Federation().Deactivate(
ctx,
&iam.DeactivateFederationRequest{
FederationId: "<federation_ID>",
},
)
if err != nil {
return err
}
if _, err = deactivateFederationOperation.Wait(ctx); err != nil {
return err
}
activateFederationOperation, err := sdk.Services().IAM().
V1().Federation().Activate(
ctx,
&iam.ActivateFederationRequest{
FederationId: "<federation_ID>",
},
)
if err != nil {
return err
}
if _, err = activateFederationOperation.Wait(ctx); err != nil {
return err
}
How to get the federation ID
How to get the federation ID
listedFederations, err := sdk.Services().IAM().V1().
Federation().List(
ctx,
&iam.ListFederationsRequest{ParentId: "<tenant_ID>"},
)
if err != nil {
return err
}
fmt.Println(listedFederations)
listedFederations.GetItems()[i].GetMetadata().GetId().To deactivate a federation, run the following code:To activate a federation again, run the following code:A federation is active by default after you create it. Run the activation code only if you deactivated the federation earlier.
The response returns the federation ID in each item’s metadata, accessible as
federation_service = FederationServiceClient(sdk)
deactivate_federation_operation = await federation_service.deactivate(
DeactivateFederationRequest(
federation_id="<federation_ID>",
),
)
await deactivate_federation_operation.wait()
federation_service = FederationServiceClient(sdk)
activate_federation_operation = await federation_service.activate(
ActivateFederationRequest(
federation_id="<federation_ID>",
),
)
await activate_federation_operation.wait()
How to get the federation ID
How to get the federation ID
federation_service = FederationServiceClient(sdk)
listed_federations = await federation_service.list(
ListFederationsRequest(parent_id="<tenant_ID>"),
)
print(listed_federations)
listed_federations.items[i].metadata.id.To deactivate a federation, run the following code:To activate a federation again, run the following code:A federation is active by default after you create it. Run the activation code only if you deactivated the federation earlier.
The response returns the federation ID in each item’s metadata, accessible as
const deactivateFederationService =
new FederationService(sdk);
const deactivateFederationOperation =
await deactivateFederationService.deactivate(
DeactivateFederationRequest.create({
federationId: "<federation_ID>",
}),
).result;
await deactivateFederationOperation.wait();
const activateFederationService =
new FederationService(sdk);
const activateFederationOperation =
await activateFederationService.activate(
ActivateFederationRequest.create({
federationId: "<federation_ID>",
}),
).result;
await activateFederationOperation.wait();
How to get the federation ID
How to get the federation ID
const listFederationService = new FederationService(sdk);
const listedFederations = await listFederationService.list(
ListFederationsRequest.create({
parentId: "<tenant_ID>",
}),
);
console.log(listedFederations);
listedFederations.items[i].metadata?.id.Deleting a federation
Deleting a federation cannot be reversed.
- CLI
- Go SDK
- Python SDK
- JavaScript SDK
To delete a federation, run the following command:
The ID is specified in the
nebius iam federation delete <federation_ID>
How to get the federation ID
How to get the federation ID
nebius iam federation list --parent-id <tenant_ID>
.items.metadata.id parameter.To delete a federation, run the following code:The code contains the following parameter:
The response returns the federation ID in each item’s metadata, accessible as
deleteFederationOperation, err := sdk.Services().IAM().
V1().Federation().Delete(
ctx,
&iam.DeleteFederationRequest{
Id: "<federation_ID>",
},
)
if err != nil {
return err
}
if _, err = deleteFederationOperation.Wait(ctx); err != nil {
return err
}
IdinDeleteFederationRequest: Federation ID. Use the ID you saved when creating the federation.
How to get the federation ID
How to get the federation ID
listedFederations, err := sdk.Services().IAM().V1().
Federation().List(
ctx,
&iam.ListFederationsRequest{ParentId: "<tenant_ID>"},
)
if err != nil {
return err
}
fmt.Println(listedFederations)
listedFederations.GetItems()[i].GetMetadata().GetId().To delete a federation, run the following code:The code contains the following parameter:
The response returns the federation ID in each item’s metadata, accessible as
federation_service = FederationServiceClient(sdk)
delete_federation_operation = await federation_service.delete(
DeleteFederationRequest(id="<federation_ID>"),
)
await delete_federation_operation.wait()
idinDeleteFederationRequest: Federation ID. Use the ID you saved when creating the federation.
How to get the federation ID
How to get the federation ID
federation_service = FederationServiceClient(sdk)
listed_federations = await federation_service.list(
ListFederationsRequest(parent_id="<tenant_ID>"),
)
print(listed_federations)
listed_federations.items[i].metadata.id.To delete a federation, run the following code:The code contains the following parameter:
The response returns the federation ID in each item’s metadata, accessible as
const deleteFederationService = new FederationService(sdk);
const deleteFederationOperation =
await deleteFederationService.delete(
DeleteFederationRequest.create({
id: "<federation_ID>",
}),
).result;
await deleteFederationOperation.wait();
idinDeleteFederationRequest: Federation ID. Use the ID you saved when creating the federation.
How to get the federation ID
How to get the federation ID
const listFederationService = new FederationService(sdk);
const listedFederations = await listFederationService.list(
ListFederationsRequest.create({
parentId: "<tenant_ID>",
}),
);
console.log(listedFederations);
listedFederations.items[i].metadata?.id.