Skip to content

aws.grafana.describe_workspace_authentication

Example SQL Queries

SELECT * FROM
aws.grafana.describe_workspace_authentication
WHERE
"workspace_id" = 'VALUE';

Description

Displays information about the authentication methods used in one Amazon Managed Grafana workspace.

Table Definition

Column NameColumn Data Type
workspace_id Required Input Column

The ID of the workspace to return authentication information about.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
authentication

A structure containing information about the authentication methods used in the workspace.

STRUCT(
"aws_sso" STRUCT(
"sso_client_id" VARCHAR
),
"providers" VARCHAR[],
"saml" STRUCT(
"configuration" STRUCT(
"allowed_organizations" VARCHAR[],
"assertion_attributes" STRUCT(
"email" VARCHAR,
"groups" VARCHAR,
"login" VARCHAR,
"name" VARCHAR,
"org" VARCHAR,
"role" VARCHAR
),
"idp_metadata" STRUCT(
"url" VARCHAR,
"xml" VARCHAR
),
"login_validity_duration" BIGINT,
"role_values" STRUCT(
"admin" VARCHAR[],
"editor" VARCHAR[]
)
),
"status" VARCHAR
)
)
Show child fields
authentication.aws_sso

A structure containing information about how this workspace works with IAM Identity Center.

Show child fields
authentication.aws_sso.sso_client_id

The ID of the IAM Identity Center-managed application that is created by Amazon Managed Grafana.

authentication.providers[]
authentication.saml

A structure containing information about how this workspace works with SAML, including what attributes within the assertion are to be mapped to user information in the workspace.

Show child fields
authentication.saml.configuration

A structure containing details about how this workspace works with SAML.

Show child fields
authentication.saml.configuration.allowed_organizations[]
authentication.saml.configuration.assertion_attributes

A structure that defines which attributes in the SAML assertion are to be used to define information about the users authenticated by that IdP to use the workspace.

Show child fields
authentication.saml.configuration.assertion_attributes.email

The name of the attribute within the SAML assertion to use as the email names for SAML users.

authentication.saml.configuration.assertion_attributes.groups

The name of the attribute within the SAML assertion to use as the user full "friendly" names for user groups.

authentication.saml.configuration.assertion_attributes.login

The name of the attribute within the SAML assertion to use as the login names for SAML users.

authentication.saml.configuration.assertion_attributes.name

The name of the attribute within the SAML assertion to use as the user full "friendly" names for SAML users.

authentication.saml.configuration.assertion_attributes.org

The name of the attribute within the SAML assertion to use as the user full "friendly" names for the users' organizations.

authentication.saml.configuration.assertion_attributes.role

The name of the attribute within the SAML assertion to use as the user roles.

authentication.saml.configuration.idp_metadata

A structure containing the identity provider (IdP) metadata used to integrate the identity provider with this workspace.

Show child fields
authentication.saml.configuration.idp_metadata.url

The URL of the location containing the IdP metadata.

authentication.saml.configuration.idp_metadata.xml

The full IdP metadata, in XML format.

authentication.saml.configuration.login_validity_duration

How long a sign-on session by a SAML user is valid, before the user has to sign on again.

authentication.saml.configuration.role_values

A structure containing arrays that map group names in the SAML assertion to the Grafana Admin and Editor roles in the workspace.

Show child fields
authentication.saml.configuration.role_values.admin[]
authentication.saml.configuration.role_values.editor[]
authentication.saml.status

Specifies whether the workspace's SAML configuration is complete.