Help Center/ MapReduce Service/ API Reference/ API V2/ Agency Management/ Querying the Mapping Between a User (Group) and an IAM Agency - ShowAgencyMapping
Updated on 2026-09-15 GMT+08:00

Querying the Mapping Between a User (Group) and an IAM Agency - ShowAgencyMapping

Function

This API is used to retrieve the detailed information about the mapping relationship between users (or user groups) and IAM agencies. It is used to understand the permission agency configuration when the cluster accesses external cloud service resources, and can be used together with the API for updating the mapping relationship between users (or user groups) and IAM agencies.

Constraints

None

Debugging

You can debug this API in API Explorer. Automatic authentication is supported. API Explorer can automatically generate sample SDK code and supports sample SDK code debugging.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependency

    mrs:cluster:getAgencyMapping

    Read

    cluster *

    • g:ResourceTag/<tag-key>

    • g:EnterpriseProjectId

    -

    -

URI

  • URI format

    GET /v2/{project_id}/clusters/{cluster_id}/agency-mapping

  • Parameter description
    Table 1 URI parameters

    Parameter

    Mandatory

    Type

    Description

    project_id

    Yes

    String

    Definition

    Project ID. For details about how to obtain the project ID, see Obtaining a Project ID.

    Constraints

    N/A

    Range

    The value can contain 1 to 64 characters. Only letters and digits are allowed. No units are involved.

    Default Value

    N/A

    cluster_id

    Yes

    String

    Definition

    The cluster ID. For details about how to obtain the cluster ID, see Obtaining a Cluster ID.

    Constraints

    N/A

    Range

    The value can contain 1 to 64 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. No units are involved.

    Default Value

    N/A

Request Parameters

None

Response Parameters

Status code: 200

Table 2 Response parameter

Parameter

Type

Description

agency_mappings

Array of AgencyMapping objects

Definition

The mapping between users or user groups and agencies. For details, see Table 3.

Range

N/A

Table 3 agency_mappings parameters

Parameter

Type

Description

agency

String

Definition

The name of the IAM agency bound to the mapping.

Range

N/A

identifier_type

String

Definition

The agency type. Available values are User and Group.

Range

  • User: indicates that the mapping is for users. Enter the user name list in identifiers.
  • Group: indicates that the mapping is for user groups. Enter the user group name list in identifiers.

identifiers

Array of String

Definition

List of users or user groups mapped to the IAM agency. Log in to the IAM management console and choose Users or User Groups in the navigation pane to obtain the user or user group name list.

Range

N/A

agency_id

String

Definition

Unique ID of the agency bound to the mapping. Log in to the IAM management console and choose Agencies in the left navigation pane. On the Agencies page that is displayed, move your cursor over the agency name to obtain the agency ID.

Range

N/A

Status code: 400

Table 4 Response parameters

Parameter

Type

Description

error_code

String

Definition

Error code.

Range

400: The operation failed.

error_msg

String

Definition

Error message.

Range

400: The operation failed.

Example Request

None

Example Response

Status code: 200

Querying the mapping between a user or user group and an IAM agency is successful.

{
  "agency_mappings" : [ {
    "agency" : "agency01",
    "identifier_type" : "User",
    "identifiers" : [ "user01" ],
    "agency_id" : "092adc623c00d2ea4fdac01d4b637f0b"
  }, {
    "agency" : "agency02",
    "identifier_type" : "User",
    "identifiers" : [ "user02" ],
    "agency_id" : "065239307e00d3ae4f80c01d4bdafdfd"
  }, {
    "agency" : "groupAgency",
    "identifier_type" : "Group",
    "identifiers" : [ "group01", "group02", "group03" ],
    "agency_id" : "08467a446200d5ac4ff9c01d56670c3b"
  } ]
}

SDK Sample Code

The SDK sample code is as follows.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.mrs.v2.region.MrsRegion;
import com.huaweicloud.sdk.mrs.v2.*;
import com.huaweicloud.sdk.mrs.v2.model.*;


public class ShowAgencyMappingSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");
        String projectId = "{project_id}";

        ICredential auth = new BasicCredentials()
                .withProjectId(projectId)
                .withAk(ak)
                .withSk(sk);

        MrsClient client = MrsClient.newBuilder()
                .withCredential(auth)
                .withRegion(MrsRegion.valueOf("<YOUR REGION>"))
                .build();
        ShowAgencyMappingRequest request = new ShowAgencyMappingRequest();
        request.withClusterId("{cluster_id}");
        try {
            ShowAgencyMappingResponse response = client.showAgencyMapping(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkmrs.v2.region.mrs_region import MrsRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkmrs.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]
    projectId = "{project_id}"

    credentials = BasicCredentials(ak, sk, projectId)

    client = MrsClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(MrsRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = ShowAgencyMappingRequest()
        request.cluster_id = "{cluster_id}"
        response = client.show_agency_mapping(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    mrs "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")
    projectId := "{project_id}"

    auth, err := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        WithProjectId(projectId).
        SafeBuild()

    if err != nil {
        fmt.Println(err)
        return
    }

    hcClient, err := mrs.MrsClientBuilder().
         WithRegion(region.ValueOf("<YOUR REGION>")).
         WithCredential(auth).
         SafeBuild()


    if err != nil {
        fmt.Println(err)
        return
    }

    client := mrs.NewMrsClient(hcClient)

    request := &model.ShowAgencyMappingRequest{}
	request.ClusterId = "{cluster_id}"
	response, err := client.ShowAgencyMapping(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

See Status Codes.

Error Codes

See Error Codes.