Help Center/ MapReduce Service/ API Reference/ API V2/ Agency Management/ Updating the Mapping Between a User (Group) and an IAM Agency - UpdateAgencyMapping
Updated on 2026-09-15 GMT+08:00

Updating the Mapping Between a User (Group) and an IAM Agency - UpdateAgencyMapping

Function

This API is used to update the mapping relationship between users (or user groups) and IAM agencies, and is used to configure the permission agency when the cluster accesses external cloud service resources. It can be used together with the API for querying the mapping relationship between users (or user groups) and IAM agencies to verify the update result.

Constraints

None

Debugging

You can debug this API in API Explorer. Automatic authentication is supported. API Explorer can automatically generate sample SDK code and supports sample SDK code debugging.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependency

    mrs:cluster:updateAgencyMapping

    Write

    cluster *

    • g:ResourceTag/<tag-key>

    • g:EnterpriseProjectId

    • mrs:cluster:syncUser
    • iam:agencies:pass
    • bms:servers:updateMetadata
    • ecs:cloudServers:updateMetadata

URI

  • URI format

    PUT /v2/{project_id}/clusters/{cluster_id}/agency-mapping

  • Parameter description
    Table 1 URI parameters

    Parameter

    Mandatory

    Type

    Description

    project_id

    Yes

    String

    Definition

    Project ID. For details about how to obtain the project ID, see Obtaining a Project ID.

    Constraints

    N/A

    Range

    The value must consist of 1 to 64 characters. Only letters and digits are allowed.

    Default Value

    N/A

    cluster_id

    Yes

    String

    Definition

    The cluster ID. For details about how to obtain the cluster ID, see Obtaining a Cluster ID.

    Constraints

    N/A

    Range

    The value can contain 1 to 64 characters, including only letters, digits, underscores (_), and hyphens (-).

    Default Value

    N/A

Request Parameters

Table 2 Request parameter

Parameter

Mandatory

Type

Description

agency_mappings

Yes

Array of AgencyMapping objects

Definition

The mapping between users or user groups and agencies. For details, see Table 3.

Constraints

N/A

Range

N/A

Default Value

N/A

Table 3 agency_mappings parameters

Parameter

Mandatory

Type

Description

agency

Yes

String

Definition

Name of the IAM agency bound to this mapping. You can obtain the relevant agency name from the IAM management console.

Constraints

N/A

Range

N/A

Default Value

N/A

identifier_type

Yes

String

Definition

The agency type. Available values are User and Group.

Constraints

N/A

Range

  • User: indicates that the mapping is for users. Enter the user name list in identifiers.
  • Group: indicates that the mapping is for user groups. Enter the user group name list in identifiers.

Default Value

N/A

identifiers

Yes

Array of String

Definition

List of user (or user group) names for the IAM agency mapping. The naming rules and constraints are the same as those required by the IAM service. Go to the IAM management console, choose Users or User Groups, and obtain the list of user/user group names.

Constraints

N/A

Range

N/A

Default Value

N/A

agency_id

Yes

String

Definition

Unique ID of the agency bound to the mapping. Log in to the IAM management console and choose Agencies in the left navigation pane. On the Agencies page that is displayed, move your cursor over the agency name to obtain the agency ID.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameter

Parameter

Type

Description

result

String

Definition

Result of the request for updating a mapping.

Range

  • succeeded: The operation is successful.
  • failed: The operation failed.

Status code: 400

Table 5 Response body parameters

Parameter

Type

Description

error_code

String

Definition

Error code.

Range

400: The operation failed.

error_msg

String

Definition

Error message.

Range

400: The operation failed.

Example Request

Example request for updating the mapping between a user or user group and an IAM agency

PUT https://{endpoint}/v2/{project_id}/clusters/{cluster_id}/agency-mapping

{
  "agency_mappings" : [ {
    "agency" : "agency01",
    "identifier_type" : "User",
    "identifiers" : [ "test" ],
    "agency_id" : "xxxx"
  } ]
}

Example Response

Status code: 200

Updating the mapping between a user or user group and an IAM agency is successful.

{
  "result" : "succeeded"
}

SDK Sample Code

The SDK sample code is as follows.

Update the mapping relationship between users (or user groups) and IAM agencies.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.mrs.v2.region.MrsRegion;
import com.huaweicloud.sdk.mrs.v2.*;
import com.huaweicloud.sdk.mrs.v2.model.*;

import java.util.List;
import java.util.ArrayList;

public class UpdateAgencyMappingSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");
        String projectId = "{project_id}";

        ICredential auth = new BasicCredentials()
                .withProjectId(projectId)
                .withAk(ak)
                .withSk(sk);

        MrsClient client = MrsClient.newBuilder()
                .withCredential(auth)
                .withRegion(MrsRegion.valueOf("<YOUR REGION>"))
                .build();
        UpdateAgencyMappingRequest request = new UpdateAgencyMappingRequest();
        request.withClusterId("{cluster_id}");
        AgencyMappingArray body = new AgencyMappingArray();
        List<String> listAgencyMappingsIdentifiers = new ArrayList<>();
        listAgencyMappingsIdentifiers.add("test");
        List<AgencyMapping> listbodyAgencyMappings = new ArrayList<>();
        listbodyAgencyMappings.add(
            new AgencyMapping()
                .withAgency("agency01")
                .withIdentifierType("User")
                .withIdentifiers(listAgencyMappingsIdentifiers)
                .withAgencyId("xxxx")
        );
        body.withAgencyMappings(listbodyAgencyMappings);
        request.withBody(body);
        try {
            UpdateAgencyMappingResponse response = client.updateAgencyMapping(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Update the mapping relationship between users (or user groups) and IAM agencies.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkmrs.v2.region.mrs_region import MrsRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkmrs.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]
    projectId = "{project_id}"

    credentials = BasicCredentials(ak, sk, projectId)

    client = MrsClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(MrsRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = UpdateAgencyMappingRequest()
        request.cluster_id = "{cluster_id}"
        listIdentifiersAgencyMappings = [
            "test"
        ]
        listAgencyMappingsbody = [
            AgencyMapping(
                agency="agency01",
                identifier_type="User",
                identifiers=listIdentifiersAgencyMappings,
                agency_id="xxxx"
            )
        ]
        request.body = AgencyMappingArray(
            agency_mappings=listAgencyMappingsbody
        )
        response = client.update_agency_mapping(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Update the mapping relationship between users (or user groups) and IAM agencies.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    mrs "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/mrs/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")
    projectId := "{project_id}"

    auth, err := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        WithProjectId(projectId).
        SafeBuild()

    if err != nil {
        fmt.Println(err)
        return
    }

    hcClient, err := mrs.MrsClientBuilder().
         WithRegion(region.ValueOf("<YOUR REGION>")).
         WithCredential(auth).
         SafeBuild()


    if err != nil {
        fmt.Println(err)
        return
    }

    client := mrs.NewMrsClient(hcClient)

    request := &model.UpdateAgencyMappingRequest{}
	request.ClusterId = "{cluster_id}"
	var listIdentifiersAgencyMappings = []string{
        "test",
    }
	var listAgencyMappingsbody = []model.AgencyMapping{
        {
            Agency: "agency01",
            IdentifierType: "User",
            Identifiers: listIdentifiersAgencyMappings,
            AgencyId: "xxxx",
        },
    }
	request.Body = &model.AgencyMappingArray{
		AgencyMappings: listAgencyMappingsbody,
	}
	response, err := client.UpdateAgencyMapping(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

See Status Codes.

Error Codes

See Error Codes.