Create a new federation in NetApp Console local deployment
POST /organizations/{organization_id}/federations
Creates a new federation.
Parameters
| Name | Type | In | Required | Description |
|---|---|---|---|---|
organization_id |
string |
path |
True |
Identifier for an organization. |
Request Body
Creates a new federation.
| Name | Type | Required | Description |
|---|---|---|---|
autoAssignDefaultRoleIds |
array[string] |
False |
Role IDs assigned on JIT first-login provision. View-only roles only - Max 5. |
autoAssignUsersEnabled |
boolean |
False |
When true, Console auto-creates (JIT) a user identity and org membership |
domains |
array[string] |
False |
Array of email domain names that are associated with the federation. If a domain matches the user's email address or is an Entra ID |
expirationNotificationPeriod |
string |
False |
The time period when expiration notifications are generated. Defined values are:
|
expirationTimestamp |
string |
False |
Not applicable for LDAP federations. |
ldapOptions |
False |
Lightweight Directory Access Protocol (LDAP) configuration options when |
|
name |
string |
True |
The name of the federation. |
providerType |
string |
False |
The type of the identity provider. Defined values are:
|
state |
string |
True |
The state of the federation. Defined values are:
|
type |
string |
True |
Media type of the resource. |
version |
string |
True |
Version of the resource. |
Example request
{
"domains": [
"example.com",
"example2.com"
],
"name": "Draft Federation",
"state": "DRAFT",
"type": "application/vnd.netapp.bxp.federation",
"version": "1.0"
}
Response
Status: 201, Returns the newly created federation in the JSON response body.
| Name | Type | Required | Description |
|---|---|---|---|
auth0Id |
string |
False |
The ID of the connection in Auth0. |
auth0Name |
string |
False |
The name of the connection in Auth0. |
autoAssignDefaultRoleIds |
array[string] |
False |
Identifier of roles assigned to first-time users automatically added to the organization |
autoAssignUsersEnabled |
boolean |
False |
Whether first-time users should be automatically added to the organization when using this federation for SSO. |
domains |
array[string] |
False |
Array of email domain names that are associated with the federation. |
expirationNotificationPeriod |
string |
False |
The time period when expiration notifications are generated. Defined values are:
|
expirationTimestamp |
string |
False |
The date that the credentials or certificate expires. When a certificate is provided, the value is set to the certificate's expiration timestamp. |
id |
string |
False |
Globally unique identifier of the resource conforming to the UUIDv4 schema. |
keycloakComponentId |
string |
False |
Keycloak component identifier for LDAP provider. |
keycloakComponentName |
string |
False |
Keycloak component name for LDAP provider. |
ldapOptions |
False |
Lightweight Directory Access Protocol (LDAP) configuration options when |
|
metadata |
False |
Metadata associated with the resource. |
|
name |
string |
False |
The name of the federation. |
organizationId |
string |
False |
Identifier for an organization. |
providerType |
string |
False |
The type of the identity provider. Defined values are:
|
resourceId |
string |
False |
Identifier for the resource. |
state |
string |
False |
The state of the federation. Defined values are:
|
type |
string |
False |
Media type of the resource. |
version |
string |
False |
Version of the resource. |
Example response
{
"domains": [
"example.com",
"example2.com"
],
"id": "645eae30-ea32-4542-af58-1d9012fed81a",
"metadata": {
"createdBy": "666a3f38-d4fa-5b62-a391-a69029758d32",
"creationTimestamp": "2022-10-06T20:58:16.305662Z",
"modificationTimestamp": "2022-10-06T20:58:16.305662Z",
"modifiedBy": "666a3f38-d4fa-5b62-a391-a69029758d32"
},
"name": "Draft Federation",
"organizationId": "9b0ee210-70a0-4158-b025-0decde66e4de",
"resourceId": "862b6f03-58ac-479b-9ca5-5cb4429d8996",
"state": "DRAFT",
"type": "application/vnd.netapp.bxp.federation",
"version": "1.0"
}
Error
Status: 400, Bad request
| Name | Type | Required | Description |
|---|---|---|---|
correlationId |
string |
False |
Internal UUID representing the request or trace ID related. |
detail |
string |
False |
Details about the problem. |
invalidParams |
array[invalidParams] |
False |
List of invalid parameters. |
status |
string |
True |
HTTP error code related to the problem. |
title |
string |
True |
Title description of the problem. |
type |
string |
True |
Content-type of the object. |
Example error response
{
"detail": "The supplied query parameters are invalid.",
"status": "400",
"title": "Invalid query parameters",
"type": "https://bluexp.netapp.io/problems/1"
}
Error
Status: 401, Unauthorized
| Name | Type | Required | Description |
|---|---|---|---|
correlationId |
string |
False |
Internal UUID representing the request or trace ID related. |
detail |
string |
False |
Details about the problem. |
invalidParams |
array[invalidParams] |
False |
List of invalid parameters. |
status |
string |
True |
HTTP error code related to the problem. |
title |
string |
True |
Title description of the problem. |
type |
string |
True |
Content-type of the object. |
Example error response
{
"detail": "The request is missing the required bearer token.",
"status": "401",
"title": "Missing bearer token",
"type": "https://bluexp.netapp.io/problems/1"
}
Error
Status: 403, Forbidden
| Name | Type | Required | Description |
|---|---|---|---|
correlationId |
string |
False |
Internal UUID representing the request or trace ID related. |
detail |
string |
False |
Details about the problem. |
invalidParams |
array[invalidParams] |
False |
List of invalid parameters. |
status |
string |
True |
HTTP error code related to the problem. |
title |
string |
True |
Title description of the problem. |
type |
string |
True |
Content-type of the object. |
Example error response
{
"detail": "The requested operation isn't permitted.",
"status": "403",
"title": "Operation not permitted",
"type": "https://bluexp.netapp.io/problems/11"
}
Error
Status: 404, Not found
| Name | Type | Required | Description |
|---|---|---|---|
correlationId |
string |
False |
Internal UUID representing the request or trace ID related. |
detail |
string |
False |
Details about the problem. |
invalidParams |
array[invalidParams] |
False |
List of invalid parameters. |
status |
string |
True |
HTTP error code related to the problem. |
title |
string |
True |
Title description of the problem. |
type |
string |
True |
Content-type of the object. |
Example error response
{
"detail": "The collection specified in the request URI wasn't found.",
"status": "404",
"title": "Collection not found",
"type": "https://bluexp.netapp.io/problems/2"
}
Error
Status: 409, Conflict
| Name | Type | Required | Description |
|---|---|---|---|
correlationId |
string |
False |
Internal UUID representing the request or trace ID related. |
detail |
string |
False |
Details about the problem. |
invalidParams |
array[invalidParams] |
False |
List of invalid parameters. |
status |
string |
True |
HTTP error code related to the problem. |
title |
string |
True |
Title description of the problem. |
type |
string |
True |
Content-type of the object. |
Example error response
{
"detail": "The request body JSON contains a field that conflicts with an idempotent value.",
"status": "409",
"title": "JSON resource conflict",
"type": "https://bluexp.netapp.io/problems/10"
}
Definitions
See Definitions
federation_1.0_ldap_post_request_options
Lightweight Directory Access Protocol (LDAP) configuration options when providerType=LDAP.
| Name | Type | Required | Description |
|---|---|---|---|
bindCredential |
string |
True |
Password for the bind DN. |
bindDn |
string |
True |
Distinguished Name (DN) or UPN to bind to the LDAP server. |
connectionTimeout |
integer |
True |
LDAP connection timeout, in milliseconds. |
connectionUrl |
string |
True |
LDAP connection URL. |
importUsers |
boolean |
False |
Indicates whether to import users from LDAP. |
pagination |
boolean |
False |
Indicates whether to use LDAP pagination for user searches. |
rdnLdapAttribute |
string |
False |
LDAP attribute used as Relative Distinguished Name (RDN). |
searchScope |
string |
False |
LDAP search scope. |
syncRegistrations |
boolean |
False |
Indicates whether to synchronize user registrations from LDAP. |
userObjectClasses |
string |
False |
LDAP object class for users. |
usernameLdapAttribute |
string |
False |
LDAP attribute used as username. |
usersDn |
string |
True |
Base DN for user searches. |
uuidLdapAttribute |
string |
False |
LDAP attribute used as universally unique identifier (UUID). |
federation_1.0_ldap_response_options
Lightweight Directory Access Protocol (LDAP) configuration options when providerType=LDAP.
| Name | Type | Required | Description |
|---|---|---|---|
bindCredential |
string |
False |
Password for the bind DN. |
bindDn |
string |
False |
Distinguished Name (DN) or UPN to bind to the LDAP server. |
connectionTimeout |
integer |
False |
LDAP connection timeout, in milliseconds. |
connectionUrl |
string |
False |
LDAP connection URL. |
importUsers |
boolean |
False |
Indicates whether to import users from LDAP. |
pagination |
boolean |
False |
Indicates whether to use LDAP pagination for user searches. |
rdnLdapAttribute |
string |
False |
LDAP attribute used as Relative Distinguished Name (RDN). |
searchScope |
string |
False |
LDAP search scope. |
syncRegistrations |
boolean |
False |
Indicates whether to synchronize user registrations from LDAP. |
userObjectClasses |
string |
False |
LDAP object class for users. |
usernameLdapAttribute |
string |
False |
LDAP attribute used as username. |
usersDn |
string |
False |
Base DN for user searches. |
uuidLdapAttribute |
string |
False |
LDAP attribute used as universally unique identifier (UUID). |
type_bxp_label
Name/value pair.
| Name | Type | Required | Description |
|---|---|---|---|
name |
string |
True |
Name of the label. |
value |
string |
True |
Value of the label. |
type_bxp_metadata
Metadata associated with the resource.
| Name | Type | Required | Description |
|---|---|---|---|
createdBy |
string |
False |
UUID of the user who created the resource. |
creationTimestamp |
string |
False |
Resource creation date. |
labels |
array[type_bxp_label] |
False |
Array of name/value pairs representing additional information for the resource. |
modificationTimestamp |
string |
False |
Resource modification date. |
modifiedBy |
string |
False |
UUID of the user who modified the resource. |
invalidParams
| Name | Type | Required | Description |
|---|---|---|---|
name |
string |
True |
Name of the invalid parameter. |
reason |
string |
True |
Reason why the parameter is invalid. |