Reinstate a suspended person or agent
This runbook applies to any installation with the Identity Service enabled, which means both identity.enabled and identity.clientIntegration.enabled are true in the istari-platform chart values. The Helm values that enable the Identity Service set both.
Administrators normally reactivate a suspended person or agent in the web app. When nobody who could do that is available, an operator can reactivate them from the command line with reinstate-principal.
For example, a Platform Administrator suspends the only tenant they belong to, which suspends them too, and the other Platform Administrators are unavailable. Reactivating the tenant afterwards does not help, because reactivating a tenant reactivates none of its people.
The Identity Service refuses to suspend a tenant or a person, or to revoke a role, when that would leave no active human Platform Administrator. If none of the remaining Platform Administrators can act anyway, for example because they are unavailable or have left, first make someone who is not suspended a Platform Administrator, as in Create the first Platform Administrator. If the first step below calls for granting a membership, the new Platform Administrator can grant it, or reactivate people in the web app.
Prerequisites
kubectlaccess to the cluster.- The Identity Service image tag you deployed, 2.0.0 or later. Earlier images do not include
reinstate-principal. - The
istari-identitysecret and thedocker-pull-secretimage pull secret, in the namespace where the Identity Service runs. The command below uses them; if yours have other names, change them in the command.
Steps
-
Make sure the person or agent holds a membership in an active tenant.
- A person suspended directly, rather than through their tenant, keeps their memberships.
- Under the default revocation setting (
TENANT_DEACTIVATION_REVOCATION_CASCADE), suspending a tenant revokes its members' memberships, so expect to grant one in an active tenant.
A Tenant Administrator of that tenant or a Platform Administrator grants a membership in the web app or through
POST /api/v2/tenants/{id}/members. The image'sgrant-tenant-rolecommand cannot grant it, because it refuses a suspended person. Without a membership,reinstate-principalrefuses withholds no granted membership; grant one first via POST /api/v2/tenants/{id}/members. -
Run
reinstate-principalas a one-off pod in the namespace where the Identity Service runs. Add-n <namespace>if that is not your current namespace. In the command, replace:<tag>with the Identity Service image tag;-emailand<email>with one flag from the table below and its value.
kubectl run reinstate-principal --rm -i --restart=Never \--image=istaridigital.jfrog.io/customer-docker/identity-service:<tag> \--overrides='{"spec":{"imagePullSecrets":[{"name":"docker-pull-secret"}],"containers":[{"name":"reinstate-principal","image":"istaridigital.jfrog.io/customer-docker/identity-service:<tag>","command":["/reinstate-principal"],"args":["-database-url-env","ISTARI_DIGITAL_IDENTITY_SERVICE_DATABASE_URL","-email","<email>"],"envFrom":[{"secretRef":{"name":"istari-identity"}}]}]}}'Flag Identifies -emailA person, by email address. The command prints the identity it resolved; use -principalif it is not the right one.-principalA person, by identity principal UUID. The -emailform prints it.-agentAn agent, by client ID: the clientIdfield of its credentials file.The pod loads the
istari-identitysecret. It supplies the database connection string for-database-url-env, and anyAUDIT_*settings there decide where the command's audit events go. The command prints one of:reinstated human <id>orreinstated agent <client id>: the person or agent is back in service;already in service: there was nothing to do.
Running the command again changes nothing that is already in place.
-
Restore roles. Reinstating does not restore roles the suspension revoked. If it revoked any, an administrator grants them again in the web app:
- Tenant Administrator, in the Platform Admin Console or the tenant's Admin Panel;
- Platform Administrator, in the Platform Admin Console. If no Platform Administrator is left, restore the role as in Create the first Platform Administrator.
-
Verify. The person signs in, or the agent's next start registers it, and the web app shows them as active.