Reinstate a suspended person or agent
Use reinstate-principal when a suspended person or agent needs to be active again and no administrator can do it in the web app. For example, a Platform Administrator suspends the only tenant they belong to, which suspends them too. Reactivating the tenant doesn't help: it reactivates none of its people.
If no Platform Administrator can act, first create one. They can then grant the membership in step 1, or reactivate people in the web app instead.
Prerequisites
- The Identity Service enabled, as in Scenario 10, and
kubectlaccess to its namespace. - An Identity Service image of 2.0.0 or later; earlier images don't include
reinstate-principal. - The
istari-identityanddocker-pull-secretsecrets. If yours have other names, change them in the command.
Steps
-
Give them a membership in an active tenant. Someone suspended through their tenant has usually lost their memberships (the default
TENANT_DEACTIVATION_REVOCATION_CASCADErevokes them); someone suspended directly keeps theirs. A Tenant Administrator of the tenant, or a Platform Administrator, grants one in the web app.grant-tenant-rolecan't, because it refuses a suspended person. Without a membership,reinstate-principalstops withholds no granted membership. -
Run
reinstate-principalas a one-off pod. Replace<tag>with your Identity Service image tag, and-emailand<email>with one flag from the table and its value. Add-n <namespace>if the Identity Service isn't in your current namespace.kubectl run reinstate-principal --rm -i --restart=Never \--image=istaridigital.jfrog.io/customer-docker/identity-service:<tag> \--overrides='{"spec":{"imagePullSecrets":[{"name":"docker-pull-secret"}],"containers":[{"name":"reinstate-principal","image":"istaridigital.jfrog.io/customer-docker/identity-service:<tag>","command":["/reinstate-principal"],"args":["-database-url-env","ISTARI_DIGITAL_IDENTITY_SERVICE_DATABASE_URL","-email","<email>"],"envFrom":[{"secretRef":{"name":"istari-identity"}}]}]}}'Flag Identifies -emailA person, by email address. The command prints the identity it resolved; use -principalif it is not the right one.-principalA person, by identity principal UUID. The -emailform prints it.-agentAn agent, by client ID: the clientIdfield of its credentials file.It prints
reinstated human <id>orreinstated agent <client id>, oralready in serviceif there was nothing to do. Running it again is safe. -
Restore roles. Reinstating doesn't bring back roles the suspension revoked. An administrator grants them again in the web app: Tenant Administrator in the Platform Admin Console or the tenant's Admin Panel, Platform Administrator in the Platform Admin Console.
-
Verify. The person signs in, or the agent's next start registers it, and the web app shows them as active.