Skip to content

Commit

Permalink
Merge branch 'publish' into tp-in-ag-go-live
Browse files Browse the repository at this point in the history
  • Loading branch information
addison-martin1 authored and GitHub Enterprise committed Mar 25, 2022
2 parents 59c354a + 112f31e commit 0d4bc2d
Show file tree
Hide file tree
Showing 12 changed files with 253 additions and 310 deletions.
9 changes: 6 additions & 3 deletions account-upgrade.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@

copyright:
years: 2015, 2022
lastupdated: "2022-02-18"

lastupdated: "2022-03-24"

keywords: account upgrade, paid account, upgrade to Pay-As-You-Go, upgrade to Subscription, upgrade my account

Expand Down Expand Up @@ -33,6 +34,8 @@ To upgrade your account, you must have an access policy with the Editor role or

## Upgrading to a Pay-As-You-Go account
{: #upgrade-paygo}
{: support}
{: help}

With a Pay-As-You-Go account, you pay for only what you use beyond the free runtime and service allowances. After you upgrade, you can continue to use any instances that you created with your Lite account.

Expand All @@ -46,7 +49,7 @@ After your payment information is processed, your account is upgraded and you ca

If you're upgrading to reactivate a deactivated account, your account might take a few days to be fully available. If your account continues to be in a pending state, see [Why can't I upgrade my account?](/docs/account?topic=account-ts_upgrade_cc) for help.

### Promotional credit for upgrading your account
## Promotional credit for upgrading your account
{: #promotional-credit-for-upgrading-your-account}

If your upgrade included a promotional credit, the credit might take a few hours to appear in your account. Any unused upgrade credit expires after the 30 day period ends. You are invoiced for any usage that exceeds the promotional credit. You can view the promotional credit on the [Promotions](/billing/promotions){: external} page or the [Invoices](/billing/invoices){: external} page in the console. The following table lists the current upgrade promotional amounts for different currencies:
Expand Down Expand Up @@ -95,7 +98,7 @@ To upgrade from a Lite account to a Subscription account, complete the following
Your subscription renews automatically. If you want to discontinue your subscription renewal, [contact support](/unifiedsupport/supportcenter).
{: note}

### Converting a Pay-As-You-Go account to a Subscription account
## Converting a Pay-As-You-Go account to a Subscription account
{: #paygo-to-subscription}

You can convert your Pay-As-You-Go account to a Subscription account at any time. Contact [{{site.data.keyword.Bluemix_notm}} Sales](https://cloud.ibm.com/catalog?contactmodule){: external} to get started.
6 changes: 2 additions & 4 deletions faqs-account.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

copyright:
years: 2015, 2022
lastupdated: "2022-03-16"
lastupdated: "2022-03-22"

keywords: account settings, delete account, account errors, reassign account, view tags, batch registration, transfer account ownership, upgrade, convert, trial, Lite, cancel account, terminate account, suspend account

Expand Down Expand Up @@ -42,7 +42,6 @@ If you can't log in to an {{site.data.keyword.Bluemix_notm}} account, [create an
## How do I update my credit card?
{: #updatepayment}
{: faq}
{: support}

If you have a Pay-As-You-Go account type that is billed in US Dollars, complete the following steps:
1. Go to the [Payments](/billing/payments) page.
Expand All @@ -63,7 +62,6 @@ If your credit card requires a MasterCard SecureCode that is sent to a mobile ph
## How do I upgrade my account?
{: #changeacct}
{: faq}
{: support}

To upgrade your Lite account, go to your [account settings](/account/settings). In the Account Upgrade section, click **Add credit card** to upgrade to a Pay-As-You-Go account, or click **Upgrade** for a Subscription account.

Expand All @@ -78,7 +76,6 @@ Yes, when you upgrade to a Pay-As-You-Go or Subscription account, you can contin
## Can I convert my account?
{: #convertacct}
{: faq}
{: support}

Yes, the following options are available depending on your account type:

Expand Down Expand Up @@ -303,6 +300,7 @@ When you register users for {{site.data.keyword.Bluemix_notm}}, you must registe
## What are tags?
{: #know-about-tags}
{: faq}
{: support}

Tags are `key:value` pairs that you use to organize your resources or control access to them.

Expand Down
3 changes: 2 additions & 1 deletion faqs-enterprise.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

copyright:
years: 2015, 2022
lastupdated: "2022-02-18"
lastupdated: "2022-03-22"

keywords: account settings, delete account, account errors, reassign account, view tags, batch registration, transfer account ownership

Expand All @@ -24,6 +24,7 @@ FAQs for your {{site.data.keyword.cloud}} enterprise might include questions abo
## How do I set up an enterprise account?
{: #enterprise-setup}
{: faq}
{: support}

To set up an enterprise, you must be the account owner or an administrator on the Billing account management service. You use the {{site.data.keyword.cloud_notm}} console to create an enterprise account, enter the name of your company, provide your company's domain, create your enterprise structure, and more. For more information, see [Setting up an enterprise](/docs/account?topic=account-enterprise-tutorial).

Expand Down
10 changes: 8 additions & 2 deletions faqs-iam.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@
copyright:

years: 2018, 2022
lastupdated: "2022-03-17"
lastupdated: "2022-03-25"


keywords: frequently asked questions for iam, iam faq, iam questions, identity and access management questions

Expand Down Expand Up @@ -193,7 +194,6 @@ The account owner can remove any users from the account, and any user with the f
## How do I require IBMid multifactor authentication for my account?
{: #multi-factor}
{: faq}
{: support}

1. In the {{site.data.keyword.cloud_notm}} console, go to **Manage** > **Access (IAM)**, and select **Settings**.
2. From the Account login section, select **Update** to select MFA for all users or non-federated users only.
Expand Down Expand Up @@ -350,3 +350,9 @@ When you establish trust with the Kubernetes service in a trusted profile, you a

For more information, see [Using Trusted Profiles in your Kubernetes and OpenShift Clusters](https://www.ibm.com/cloud/blog/using-trusted-profiles-in-your-kubernetes-and-openshift-clusters) and [Kubernetes namespace](https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/){: external}.

## How can I view dynamic members of access groups?
{: #dynamic-members}
{: faq}

To view a list of dynamic members in an access group, go to **Manage** > **Access (IAM)** > **Access groups** in the {{site.data.keyword.cloud_notm}} console. Select an access group and click **Users**. Dynamically added users are indicated by the type `Dynamic`. For more information, see [Viewing dynamic members of access groups](/docs/account?topic=account-rules&interface=ui#view-dynamic-users)

3 changes: 2 additions & 1 deletion faqs-resources.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
copyright:
years: 2015, 2022

lastupdated: "2022-02-18"
lastupdated: "2022-03-22"

keywords: resource FAQs, resource frequently asked questions, resource group, resource list, dashboard widget

Expand Down Expand Up @@ -48,6 +48,7 @@ When you have Cloud Foundry services that can be migrated to a resource group, y
## Why can't I add a resource to a resource group?
{: #create-add-resource}
{: faq}
{: support}

Most likely you're dealing with an access issue. You must have at least the Viewer role on the resource group itself and at least the Editor role on the service in the account. Learn more in [Adding resources to a resource group](/docs/account?topic=account-rgs#add_to_rgs).

Expand Down
49 changes: 30 additions & 19 deletions iam-accessgroup_rules.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
copyright:

years: 2018, 2022
lastupdated: "2022-03-13"

lastupdated: "2022-03-25"

keywords: dynamic rules,access groups,specific identity attributes,identity provider,federated ID,

Expand Down Expand Up @@ -34,19 +34,16 @@ Dynamic rules are created by setting conditions that must be matched by the data
To create a rule, follow these steps:

1. In the {{site.data.keyword.cloud_notm}} console, click **Manage** > **Access (IAM)**, and select **Access Groups**.
2. Select the name of the access group that you want to create a rule for to open the group details page.
2. Select the name of the access group that you want to create a rule for. This action opens the group **Details** page.
3. Select **Dynamic rules**.
4. Click **Add rule**.
5. Enter the information from your IdP that is dynamically provided for you on the Add rule page. The following list provides details for each required field.

You can think of an access group rule as a key:value pair. The key is what you add in the **`**Add users when** field, and the value is what you enter in the **Values** field.
You can think of an access group rule as a key:value pair. The key is what you add in the `Add users when` field, and the value is what you enter in the `Values` field.
{: tip}

For more information about the fields that are used to create dynamic rules, see [IAM condition properties](/docs/account?topic=account-iam-condition-properties).

Users added to access groups by using dynamic rules don't display as group members on the users list for the access group. To check a specific user's membership to an access group, you can select that user's name from the account **Users** page, and then click **Access groups**.
{: note}

## Setting up rules by using Terraform
{: #setup_rules_terraform}
{: terraform}
Expand Down Expand Up @@ -98,17 +95,31 @@ To create a rule by using Terraform, follow these steps:
```
{: pre}

## Example rule
{: #example}
For more information about the fields that are used to create dynamic rules, see [IAM condition properties](/docs/account?topic=account-iam-condition-properties).


## Viewing dynamic members of access groups
{: #view-dynamic-users}
{: ui}

You can view the users that are added to an access group by using dynamic rules. To view dynamic members of access groups, go to **Manage** > **Access (IAM)** > **Access groups** in the {{site.data.keyword.cloud_notm}} console. Select an access group and click **Users**. Dynamically added users are indicated by the type `Dynamic`.

The following users will not appear in the table:
- Dynamically added users who are not logged in yet
- Dynamically added users whose session expired

Dynamic users that are logged out but whose sessions are still valid continue to appear in the table until their sessions expire.

You can't remove a dynamic user manually. To remove a dynamic user, adjust your dynamic rules.
{: note}

### Viewing a user's dynamic membership
{: #view-dynamic-ag}

You can also view a list of access groups that a user is added to based on dynamic rules by completing the following steps:

The following example includes values for each of the fields on the **Add rule** page. In this rule, users who are identified as managers within the federated IdP are mapped to an {{site.data.keyword.Bluemix_notm}} access group that has specific access set for only managers.
1. Go to **Manage** > **Access (IAM)** > **Users** in the {{site.data.keyword.cloud_notm}} console.
1. Click on a user.
1. Click **Access groups**.
1. The access groups that a user is a dynamic member of is indicated by the type `Dynamic`.

| Field | Value |
|---------------------------------|---------------------------------|
| Name | Manager group rule |
| Identity provider | `https://idp.example.org/SAML2` |
| Expiration (in hours) | 12 |
| Add users when (attribute name) | isManager |
| Comparator | Equals |
| Value | true |
{: caption="Table 1. Example dynamic rule for access groups" caption-side="top"}
Loading

0 comments on commit 0d4bc2d

Please sign in to comment.