UIP Insights 组
“uip Insights Groups”的语法和选项,可读取活动租户的 Insights 组及其 Insights 角色名称。
uip insights groups 读取当前调用者可见的租户组及其 Insights 角色名称。这是一个只读表面,没有“创建”、“更新”或“删除”动词。
读取 Insights 组需要活动租户中的Insights Management 查看权限。没有用户身份的会话(例如,使用客户端凭据登录的会话)根本无法读取此数据,并会收到 403。
大纲
uip insights groups list [--include-email] [-l <n>] [-o <n>]
uip insights groups get <group-id> [--include-email]
uip insights groups list [--include-email] [-l <n>] [-o <n>]
uip insights groups get <group-id> [--include-email]
UIP Insights 组列表
列出当前调用者可见的租户组及其 Insights 角色名称。每一行都通过目录解析(每组一个,按顺序缓存调用),因此大型租户的第一个(冷缓存)列表可能慢于类似大小的 users list。
选项
| 标记 | 描述 |
|---|---|
--include-email | 在输出中包括电子邮件地址和嵌套角色 ID。默认情况下 — 默认视图忽略两者。 |
-l, --limit <number> | 要返回的最大行数。默认为 50。 |
-o, --offset <number> | 返回结果之前要跳过的行。 |
分页在客户端进行:后端返回完整的未分页列表,CLI 在获取后对其进行切片。
示例
uip insights groups list
uip insights groups list --include-email --limit 100
uip insights groups list
uip insights groups list --include-email --limit 100
数据形状 — 默认视图
{
"Code": "InsightsGroupsList",
"Data": [
{ "id": "d1e2f3a4-0000-0000-0000-000000000001", "name": "Automation Users", "roles": [{ "name": "Viewer" }] }
],
"Pagination": { "Returned": 1, "Limit": 50, "Offset": 0, "Total": 1, "HasMore": false },
"Instructions": "Roles shown are the group's Insights roles in the active tenant, by name; 'uip insights roles list' maps a role name to its role GUID and back. Directory filtering can omit unresolved groups, so a missing row is not proof the stored group does not exist. Listing groups resolves each row through the directory, one cached call per group in sequence. 'uip insights groups get' returns the same fields as a row here and can persist refreshed directory name and email fields for the group, so read the row here when it is enough."
}
{
"Code": "InsightsGroupsList",
"Data": [
{ "id": "d1e2f3a4-0000-0000-0000-000000000001", "name": "Automation Users", "roles": [{ "name": "Viewer" }] }
],
"Pagination": { "Returned": 1, "Limit": 50, "Offset": 0, "Total": 1, "HasMore": false },
"Instructions": "Roles shown are the group's Insights roles in the active tenant, by name; 'uip insights roles list' maps a role name to its role GUID and back. Directory filtering can omit unresolved groups, so a missing row is not proof the stored group does not exist. Listing groups resolves each row through the directory, one cached call per group in sequence. 'uip insights groups get' returns the same fields as a row here and can persist refreshed directory name and email fields for the group, so read the row here when it is enough."
}
数据形状 — with --include-email
{
"Code": "InsightsGroupsList",
"Data": [
{
"id": "d1e2f3a4-0000-0000-0000-000000000001",
"name": "Automation Users",
"email": "automation-users@example.com",
"roles": [{ "id": "c1d2e3f4-0000-0000-0000-000000000001", "name": "Viewer" }]
}
],
"Pagination": { "Returned": 1, "Limit": 50, "Offset": 0, "Total": 1, "HasMore": false }
}
{
"Code": "InsightsGroupsList",
"Data": [
{
"id": "d1e2f3a4-0000-0000-0000-000000000001",
"name": "Automation Users",
"email": "automation-users@example.com",
"roles": [{ "id": "c1d2e3f4-0000-0000-0000-000000000001", "name": "Viewer" }]
}
],
"Pagination": { "Returned": 1, "Limit": 50, "Offset": 0, "Total": 1, "HasMore": false }
}
目录筛选可能会删除行。后端目录查找无法解析的组会完全从列表中省略 — 缺少的组并不能证明它不存在;; groups get 仍可能直接解析此问题。在空列表上,上面的常备说明将被删除,因为未从零行中保留任何内容,但目录分辨率警告和每组的成本说明仍然适用。
uip Insights 组获取的收益
按 GUID 获取一个 Insights 组。与list不同,这可以将刷新的组目录名称和电子邮件字段保留下来,作为副作用——它是读取形状的读取,但不是纯读取。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<group-id> | 是 | 组 GUID。必须是真实的 GUID — 格式错误的值会在任何网络调用之前导致客户端失败,Run 'uip insights groups list' to find a group ID.。 |
选项
| 标记 | 描述 |
|---|---|
--include-email | 在输出中包括电子邮件地址和嵌套角色 ID。默认情况下为关闭。 |
示例
uip insights groups get d1e2f3a4-0000-0000-0000-000000000001
uip insights groups get d1e2f3a4-0000-0000-0000-000000000001
数据形状(--输出 json)
{
"Code": "InsightsGroupGet",
"Data": { "id": "d1e2f3a4-0000-0000-0000-000000000001", "name": "Automation Users", "roles": [{ "name": "Viewer" }] }
}
{
"Code": "InsightsGroupGet",
"Data": { "id": "d1e2f3a4-0000-0000-0000-000000000001", "name": "Automation Users", "roles": [{ "name": "Viewer" }] }
}
使用 --include-email 时,相同的形状将获得 email 和嵌套 roles[].id,与列表视图相同。
404 页面上的 Group <id> was not found in the active Insights tenant, or is not visible there. — 目录无法同时解析此处的 404 页的组,因此 404 页面本身并不能证明存储的组不存在。如果每个 Insights RBAC 命令都出现 404s,则租户可能没有配置 Insights 门户服务。
另请参阅
- Insights 概述
- 用户、角色— 其他 RBAC 读取的面;
roles将此处显示的角色名称映射到其 GUID,来回映射。