Closed rfum closed 3 months ago
@rfum please refer to the previous issue. You need to add the following block into your main.tf:
existing_sso_groups = { testgroup : { group_name = "testgroup" # this must be the name of a group that already exists in your AWS account }, }
Hi @rfum, yes @a1mops is correct - please review the example for referencing existing users/groups: https://github.com/aws-ia/terraform-aws-iam-identity-center/blob/main/examples/existing-users-and-groups/main.tf
Also on your account assignments - principal_idp
should be "INTERNAL"
only if you are using IAM Identity Store (the native IdP for IAM Identity Center). If you are syncing users/groups to IAM IdC via SCIM, this should be set to either "EXTERNAL"
or "GOOGLE"
(if using Google Workspace specifically). Let me know if this resolves your issue or if you need further help.
thanks!
Hi, I'm trying to use an existing group with the module, but I'm encountering the error mentioned in issue #36. Upgrading to version 0.0.5 didn't resolve the problem. Could this be related to the naming of my group? The group name contains a
'-'
character. I am following the rules defined in the README, ensuring that the same name is used for both the object and the principal in theaccount_assignments
block. I have confirmed thatfoo-read
is an existing SCIM group in my account. What might be causing the issue with my configuration?My code is :
Response is :