AAC Docs

aac sso request-idp-repair

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Sign and submit one exact IdP connection repair request.

Tenant Ops signs the exact replacement intent with the offline recovery key. No AAC session is required. The CLI saves a mode-0600 non-secret request record before transmission so an identical retry reuses the same request ID.

Synopsis

aac sso request-idp-repair
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  [--tenant-id TENANT_ID]
  --connection-id CONNECTION_ID
  --revision REVISION
  --file FILE
  --recovery-key-file RECOVERY_KEY_FILE

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--tenant-id value no —
--connection-id value yes —
--revision value yes —
--file value yes — Exact corrected full connection document.
--recovery-key-file value yes — Offline Ed25519 private key (must be a regular mode-0600 file).

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.