AAC Docs

aac tenant assign-hosted-domain

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Request the AAC-assigned trust domain for your tenant and save it in the bound profile; repeated calls reuse it.

Synopsis

aac tenant assign-hosted-domain
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--field {trust-domain} | --output {json,table}]
  [--tenant-id TENANT_ID]
  [--bootstrap-token BOOTSTRAP_TOKEN]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--field trust-domain no — Print only the selected server-returned value; cannot combine with --output.
--output json | table no json Output mode: json (the default) or table.
--tenant-id value no — Tenant (defaults to the selected profile).
--bootstrap-token value no — Explicit platform ceremony; otherwise use the tenant-admin session.

At most one of --field, --output may be given.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

--field prints one unquoted value followed by a newline instead. It cannot be combined with an explicit --output. A missing or invalid value fails without scalar output; diagnostics go to standard error.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

What this command does

  Requests the AAC-assigned trust domain for your tenant. The name is your
  tenant id plus a suffix the control plane selects for its environment;
  no DNS record or proof of ownership is needed. The first call allocates
  the name permanently and every later call returns the same one. Use the
  name the command returns rather than building it yourself:

      on stage       <tenant_id>.tenants.stage.cascadeauth.dev
      on production  <tenant_id>.tenants.cascadeauth.com

Where the domain is saved

  On success it is written into the selected profile as hosted_trust_domain,
  if that profile is bound to this tenant; a profile bound to another tenant
  is left unchanged. Signing in with `aac sso login` does not write it, so a
  profile bound that way has no such line until this command or
  `aac init` runs. Replace main with your profile name:

      aac tenant assign-hosted-domain --profile main
      aac profile show main

To use a custom domain you own instead

  Prove control of it with a DNS TXT record, then bind it. A domain you
  own is recorded on the server and never written to the profile:

      aac tenant issue-domain-challenge --profile main --domain example.com
      aac tenant verify-domain --profile main --domain example.com
      aac tenant bind-trust-domain --profile main --trust-domain example.com