← Back to plugin index

User Sync Task

Description
A task that reads users using a source user store and writes the data using another user store.

It can be used to synchronise data (e.g. import data from an LDAP directory into a database for Airlock IAM) and to convert data.

Data may be modified while importing. When using LDAP / AD, all context data is treated as string data.

Type name
UserSyncTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.user.sync.UserSyncTaskConfig
May be used by
License-Tags
UserAggregation,UserProvisioning
Properties
Source User Store (sourceUserStore)
Description
The user store used to read user data from. Make sure to specify all context data attributes to be imported.

If the sync flag is configured, this user store will be used to reset the sync flag.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Target User Store (targetUserStore)
Description
The user store used to write user data with. Make sure to specify all context data attributes to be imported.

Note: If an imported user cannot be found using the target user store, the task attempts to restore the user (possibly removing a "deleted" flag). If restore was not successful, a new user is inserted.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Attribute Mappings (attributeMappings)
Description
Defines a list of mappings mapping source context data attributes to target context attributes.

NOTE: The context data attributes must be supported by the source and the target user store.

The username column doesn't need to be referenced here, because it is automatically mapped.

Attributes
Plugin-List
Optional
Assignable plugins
Import Roles (importRoles)
Description
If enabled, roles are imported from the source user store and stored using the target user store. Note, that if there are no roles in the source user store, existing roles in the target user store are deleted.
Attributes
Boolean
Optional
Default value
false
Import Auth Method (importAuthMethod)
Description
If enabled, the authentication method is imported from the source user store and stored using the target user store. If there is no authentication method in the source user store and no default authentication method is defined in the source user store (some plugins can do that), the authentication method in the target user store is deleted.
Attributes
Boolean
Optional
Default value
false
Insert Users (insertUsers)
Description
If enabled, users that only exist in the source user store are inserted in the target user store. When disabled, users are not inserted in the target user store.
Attributes
Boolean
Optional
Default value
true
Update Users (updateUsers)
Description
If enabled, users that exist in the source user store and the target user store are updated.
Attributes
Boolean
Optional
Default value
true
Delete Users (deleteUsers)
Description
If enabled, users that don't exist in the source user store are deleted in the target user store.
Attributes
Boolean
Optional
Default value
true
Sync Flag (syncFlag)
Description
If configured, only users with the configured flag set to true are synchronised. After successful synchronisation, this task modifies the user in the source user store by setting the sync flag to false.
Attributes
Plugin-Link
Optional
Assignable plugins
Data Transformers (dataTransformers)
Description
Lists data transformers applied in order of definition to transform the imported data.
  • The username is available as attribute "username".
  • The roles are available as attribute "roles".
  • The authentication method is available as attribute "authMethod".
  • Context data attributes of the source user are handed over to the transfomers. These attributes are not used by all transformers. Check the transformer documentation to learn if and how they can be used.
Attributes
Plugin-List
Optional
Assignable plugins
Continue On Errors (continueOnErrors)
Description
If enabled, the task is not stopped when an error occurs while inserting, updating, or deleting a user in the target user store. A warning is logged in this case.

Errors related to reading users from the source user store are not recoverable and cause the task to fail even if this option is enabled.

Attributes
Boolean
Optional
Default value
false
Realm (realm)
Description
If set, every user newly inserted into the target user store by this task is assigned to this realm. Existing target users are left untouched (their realm is not changed). The realm name must be 1-50 characters and contain only alphanumeric characters, dashes or underscores.
Attributes
String
Optional
Example
customer-portal
YAML Template (with default values)

type: UserSyncTask
id: UserSyncTask-xxxxxx
displayName: 
comment: 
properties:
  attributeMappings:
  continueOnErrors: false
  dataTransformers:
  deleteUsers: true
  importAuthMethod: false
  importRoles: false
  insertUsers: true
  realm:
  sourceUserStore:
  syncFlag:
  targetUserStore:
  updateUsers: true