New-UAPDatabaseTargetDefinition

New-UAPDatabaseTargetDefinition

SYNOPSIS

Defines a database instance target of a policy

SYNTAX

New-UAPDatabaseTargetDefinition -instanceName <String> -instanceType <String> -instanceId <String>
 -authenticationMethod <String> -profile <Hashtable> [-TargetDefinition <PSObject[]>]
 [<CommonParameters>]

DESCRIPTION

Defines a database instance target and the profile - the permissions - policy members receive on it.

The shape of -profile follows the authentication method:

Method Profile
db_auth @{ roles = @(...) }
ldap_auth @{ assignGroups = @(...) }
rds_iam_user_auth @{ dbUser = '...' }
oracle_auth @{ roles = @(...); dbaRole = $true; sysdbaRole = $true; sysoperRole = $true }
mongo_auth @{ globalBuiltinRoles = @(...); databaseBuiltinRoles = @{ db = @(...) }; databaseCustomRoles = @{ db = @(...) } }
sqlserver_auth @{ globalBuiltinRoles = @(...); globalCustomRoles = @(...); databaseBuiltinRoles = @{ db = @(...) }; databaseCustomRoles = @{ db = @(...) } }

Pass a previous definition to -TargetDefinition to add another instance. A policy takes at most 1000 instances.

EXAMPLES

Example 1

New-UAPDatabaseTargetDefinition -instanceName My-Local-MySQL -instanceType MySQL -instanceId 197012 `
    -authenticationMethod db_auth -profile @{ roles = @('hr', 'MySQL_role') }

Defines a MySQL instance with local database authentication

Example 2

New-UAPDatabaseTargetDefinition -instanceName My-IAM-PostgreSQL -instanceType Postgres -instanceId 197015 `
    -authenticationMethod rds_iam_user_auth -profile @{ dbUser = 'postgres' }

Defines a PostgreSQL instance using an RDS IAM user

Example 3

$Targets = New-UAPDatabaseTargetDefinition -instanceName my-oracle-db -instanceType Oracle -instanceId 196946 `
    -authenticationMethod oracle_auth -profile @{ roles = @('Oracle_custom_role'); dbaRole = $true; sysdbaRole = $false; sysoperRole = $false }

$Targets = New-UAPDatabaseTargetDefinition -instanceName My-AD-Db2 -instanceType DB2 -instanceId 197019 `
    -authenticationMethod ldap_auth -profile @{ assignGroups = @('AD_Employees_Group') } -TargetDefinition $Targets

Defines two instances with different authentication methods

PARAMETERS

-instanceName

The name of the database instance.

Type: String
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-instanceType

The database type of the instance, for example MySQL, Postgres, Oracle, Mongo, MSSQL, MariaDB or DB2.

Type: String
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-instanceId

The identifier of the database instance.

Type: String
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-authenticationMethod

How policy members authenticate to the instance.

Type: String
Parameter Sets: (All)
Aliases: 
Accepted values: ldap_auth, db_auth, oracle_auth, mongo_auth, sqlserver_auth, rds_iam_user_auth

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-profile

The permissions policy members receive, shaped to match the authentication method.

Type: Hashtable
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-TargetDefinition

An existing target definition to add this instance to.

Type: PSObject[]
Parameter Sets: (All)
Aliases: 

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

NOTES