Skip to main content
Version: 2026.09

Reinstate a suspended person or agent

Use reinstate-principal when a suspended person or agent needs to be active again and no administrator can do it in the web app. For example, a Platform Administrator suspends the only tenant they belong to, which suspends them too. Reactivating the tenant doesn't help: it reactivates none of its people.

If no Platform Administrator can act, first create one. They can then grant the membership in step 1, or reactivate people in the web app instead.

Prerequisites​

  • The Identity Service enabled, as in Scenario 10, and kubectl access to its namespace.
  • An Identity Service image of 2.0.0 or later; earlier images don't include reinstate-principal.
  • The istari-identity and docker-pull-secret secrets. If yours have other names, change them in the command.

Steps​

  1. Give them a membership in an active tenant. Someone suspended through their tenant has usually lost their memberships (the default TENANT_DEACTIVATION_REVOCATION_CASCADE revokes them); someone suspended directly keeps theirs. A Tenant Administrator of the tenant, or a Platform Administrator, grants one in the web app. grant-tenant-role can't, because it refuses a suspended person. Without a membership, reinstate-principal stops with holds no granted membership.

  2. Run reinstate-principal as a one-off pod. Replace <tag> with your Identity Service image tag, and -email and <email> with one flag from the table and its value. Add -n <namespace> if the Identity Service isn't in your current namespace.

    kubectl run reinstate-principal --rm -i --restart=Never \
    --image=istaridigital.jfrog.io/customer-docker/identity-service:<tag> \
    --overrides='{
    "spec":{
    "imagePullSecrets":[{"name":"docker-pull-secret"}],
    "containers":[{
    "name":"reinstate-principal",
    "image":"istaridigital.jfrog.io/customer-docker/identity-service:<tag>",
    "command":["/reinstate-principal"],
    "args":["-database-url-env","ISTARI_DIGITAL_IDENTITY_SERVICE_DATABASE_URL",
    "-email","<email>"],
    "envFrom":[{"secretRef":{"name":"istari-identity"}}]
    }]}
    }'
    FlagIdentifies
    -emailA person, by email address. The command prints the identity it resolved; use -principal if it is not the right one.
    -principalA person, by identity principal UUID. The -email form prints it.
    -agentAn agent, by client ID: the clientId field of its credentials file.

    It prints reinstated human <id> or reinstated agent <client id>, or already in service if there was nothing to do. Running it again is safe.

  3. Restore roles. Reinstating doesn't bring back roles the suspension revoked. An administrator grants them again in the web app: Tenant Administrator in the Platform Admin Console or the tenant's Admin Panel, Platform Administrator in the Platform Admin Console.

  4. Verify. The person signs in, or the agent's next start registers it, and the web app shows them as active.