Cx Platform Admin

作者 coralogixc0713729787b無授權條款121 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫昨天更新

Use this skill when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired keys", "send data keys", "IP allowlist", "IP access restrictions", "check IP whitelist", "add user", "deactivate user", "manage team groups", "user permissions", "role-based access", "manage scopes", "system roles", "API key admin", "team member keys", "group membership", or wants to audit, manage, or configure access controls for a Coralogix account.

AI 產生的概覽

透過 cx CLI 稽核與管理 Coralogix IAM 存取權限:使用者、角色、範圍、團隊群組、API 金鑰與 IP 限制。

功能
此技能引導代理使用 cx CLI 的 iam 指令完成 Coralogix 平台管理工作。涵蓋列出與搜尋使用者、角色、範圍、團隊群組與 API 金鑰,以及建立、更新、啟用、停用與刪除這些物件。它也提供逐步存取稽核流程,將使用者、角色、群組成員關係、API 金鑰與 IP 存取設定交叉比對後產生彙總報告,並說明安全的 API 金鑰輪換步驟。寫入操作需要互動確認,並說明了唯讀模式與代理模式。
適用情境
當有人詢問誰能存取某個 Coralogix 帳戶、需要稽核權限或角色、需要列出、建立、輪換或刪除 API 金鑰,或需要管理使用者、群組或 IP 存取限制時使用。也適用於審查存取控制或檢查 IP 允許清單的要求。
執行需求
需要 cx CLI,並具備可存取 Coralogix 帳戶的有效憑證或設定檔;指令使用 -o json 輸出,範例中以 jq 進行篩選。需要連線至 Coralogix 的網路存取。此技能不附帶指令碼,僅為說明文件。

Platform Admin Skill

Use this skill for managing access, authentication, and authorization in Coralogix. It covers API key management, role and scope definitions, user administration, team groups, and IP access restrictions.


Destructive Operation Safety

All write operations (create, update, delete, set-idp, set-active, set-status) require interactive confirmation. The CLI will prompt before executing. To skip the prompt in scripts, pass --yes.

IMPORTANT: NEVER pass --yes without explicit user approval. Before executing any write operation:

  1. Describe the exact operation to the user (what will be created/modified/deleted)
  2. Wait for the user to confirm
  3. Only then execute with --yes

Read-only operations (list, get, search, system, sp-params, send-data-keys) do not require confirmation and can be run freely.

Read-Only Mode

Use --read-only (or CX_READ_ONLY=1) to block all write operations at the CLI level. This is useful for safe exploration - you can query any IAM resource without risk of accidental modifications.

Agent Mode

When running inside an AI agent (Claude Code, Cursor, Codex, etc.), cx automatically detects the agent environment and fails fast on write operations instead of hanging on a stdin prompt. The error message instructs you to get user confirmation first, then re-run with --yes.


CLI Commands

API Keys

CommandPurpose
cx iam api-keys listList all API keys
cx iam api-keys get <id>Get a single API key
cx iam api-keys create --from-fileCreate an API key
cx iam api-keys update --from-file <id>Update an API key
cx iam api-keys delete <id>Delete an API key
cx iam api-keys send-data-keysList send-data API keys
cx iam api-keys admin listList all team members' keys
cx iam api-keys admin delete --ids <id1> <id2>Bulk delete keys
cx iam api-keys admin set-status --ids <id1> --active true/falseActivate/deactivate keys

Roles & Scopes

CommandPurpose
cx iam roles listList custom roles
cx iam roles get <id>Get a role definition
cx iam roles create --from-fileCreate a custom role
cx iam roles update --from-file <id>Update a custom role
cx iam roles delete <id>Delete a custom role
cx iam roles systemList system (built-in) roles
cx iam scopes listList all scopes
cx iam scopes get <id>Get a scope definition
cx iam scopes create --from-fileCreate a scope
cx iam scopes update --from-fileUpdate a scope
cx iam scopes delete <id>Delete a scope

Users & Groups

CommandPurpose
cx iam users searchSearch users (optional --query, --status)
cx iam users get <user-id>Get a single user
cx iam users create --from-fileCreate user(s)
cx iam users update --from-fileUpdate user(s)
cx iam users set-status --user-ids <id> --status ACTIVE/INACTIVEActivate/deactivate users
cx iam groups listList all team groups
cx iam groups get <id>Get a group by ID
cx iam groups get-by-name <name>Get a group by name
cx iam groups users <group-id>List users in a group
cx iam groups create --from-fileCreate a group
cx iam groups update --from-file <id>Update a group
cx iam groups delete <id>Delete a group

IP Access

CommandPurpose
cx iam ip-access getGet IP access settings
cx iam ip-access create --from-fileCreate IP access rules
cx iam ip-access update --from-fileUpdate IP access rules
cx iam ip-access deleteDelete IP access settings

All commands support -o json for structured output and -p <profile> for profile selection.


Access Audit Workflow

Use this workflow to produce a comprehensive access report:

Step 1: List All Users

bash
cx iam users search -o jsoncx iam users search -o json | jq '[.[] | {id, name: .user_name, status, role_ids}]'

Step 2: List Roles

bash
cx iam roles list -o jsoncx iam roles system -o json

Cross-reference user role IDs with role definitions to understand permissions.

Step 3: List Groups and Memberships

bash
cx iam groups list -o jsoncx iam groups list -o json | jq '[.[] | {id, name, member_count: (.members | length)}]'

For each group, check members:

bash
cx iam groups users <group-id> -o json

Step 4: Inventory API Keys

bash
cx iam api-keys list -o jsoncx iam api-keys admin list -o jsoncx iam api-keys send-data-keys -o json

Identify old or unused keys:

bash
cx iam api-keys list -o json | jq '[.[] | {id, name, created_at, active}] | sort_by(.created_at)'

Step 5: Check IP Restrictions

bash
cx iam ip-access get -o json

Step 6: Cross-Reference

Produce a summary: which users have admin roles, which API keys are old, which groups have broad access.


API Key Rotation

Safe key rotation workflow:

  1. List current keys: cx iam api-keys list -o json
  2. Identify keys to rotate: filter by age or name
  3. Create replacement key: cx iam api-keys create --from-file new-key.json --yes (after user approval)
  4. Deploy the new key to all systems using the old key
  5. Verify the new key works in all integrations
  6. Delete the old key: cx iam api-keys delete <old-key-id> --yes (after user approval)

WARNING: Never delete an API key before its replacement is deployed and verified. Deleting an active key immediately breaks all integrations using it.


Safety Callouts

Deleting API keys breaks any integration using that key immediately. Always create a replacement first.

Deactivating users (cx iam users set-status --status INACTIVE) takes effect immediately. The user loses access with no grace period.

Deleting IP access rules (cx iam ip-access delete) removes all IP restrictions immediately, potentially exposing the account.


Key Principles

  • Audit before modifying - run the full access audit workflow before making changes
  • Never delete keys without replacement - create new key → deploy → verify → delete old
  • Use -o json for structured reports - enables jq filtering for precise access analysis
  • Multi-profile for cross-environment audits - use -p <profile> or --all-profiles to audit staging + production
  • Template from existing - cx iam roles get <id> -o json > role.json before creating new roles

Related Skills

  • cx-cost-optimization - review what API keys are used for and whether they're still needed

來源與署名

來源:coralogix/cx-cli位於skills/cx-platform-admin提交c071372

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架