Skip to content

aws.eks.describe_identity_provider_config

Example SQL Queries

SELECT * FROM
aws.eks.describe_identity_provider_config
WHERE
"cluster_name" = 'VALUE'
AND "identity_provider_config" = 'VALUE';

Description

Describes an identity provider configuration.

Table Definition

Column NameColumn Data Type
cluster_name Required Input Column

The name of your cluster.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
_input_identity_provider_config Input Column
STRUCT(
"type" VARCHAR,
"name" VARCHAR
)
Show child fields
_input_identity_provider_config.name

The name of the identity provider configuration.

_input_identity_provider_config.type

The type of the identity provider configuration. The only type available is oidc.

identity_provider_config

The object that represents an OpenID Connect (OIDC) identity provider configuration.

STRUCT(
"oidc" STRUCT(
"identity_provider_config_name" VARCHAR,
"identity_provider_config_arn" VARCHAR,
"cluster_name" VARCHAR,
"issuer_url" VARCHAR,
"client_id" VARCHAR,
"username_claim" VARCHAR,
"username_prefix" VARCHAR,
"groups_claim" VARCHAR,
"groups_prefix" VARCHAR,
"required_claims" MAP(VARCHAR, VARCHAR),
"tags" MAP(VARCHAR, VARCHAR),
"status" VARCHAR
)
)
Show child fields
identity_provider_config.oidc

An object representing an OpenID Connect (OIDC) identity provider configuration.

Show child fields
identity_provider_config.oidc.client_id

This is also known as audience. The ID of the client application that makes authentication requests to the OIDC identity provider.

identity_provider_config.oidc.cluster_name

The name of your cluster.

identity_provider_config.oidc.groups_claim

The JSON web token (JWT) claim that the provider uses to return your groups.

identity_provider_config.oidc.groups_prefix

The prefix that is prepended to group claims to prevent clashes with existing names (such as system: groups). For example, the value oidc: creates group names like oidc:engineering and oidc:infra. The prefix can't contain system:

identity_provider_config.oidc.identity_provider_config_arn

The ARN of the configuration.

identity_provider_config.oidc.identity_provider_config_name

The name of the configuration.

identity_provider_config.oidc.issuer_url

The URL of the OIDC identity provider that allows the API server to discover public signing keys for verifying tokens.

identity_provider_config.oidc.required_claims

The key-value pairs that describe required claims in the identity token. If set, each claim is verified to be present in the token with a matching value.

identity_provider_config.oidc.status

The status of the OIDC identity provider.

identity_provider_config.oidc.tags

Metadata that assists with categorization and organization. Each tag consists of a key and an optional value. You define both. Tags don't propagate to any other cluster or Amazon Web Services resources.

identity_provider_config.oidc.username_claim

The JSON Web token (JWT) claim that is used as the username.

identity_provider_config.oidc.username_prefix

The prefix that is prepended to username claims to prevent clashes with existing names. The prefix can't contain system: