delete-role
dci delete-role <id>
Deletes a custom role. Preset roles cannot be deleted, and a role still assigned to users must be unassigned first. A service account of a parent tenant can delete a descendant tenant's role by setting X-Tenant-Id to that tenant's customer ID.
id— The unique ID of the role to delete.
Output
On success, this command produces no response data.
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 409 | 21 | RESOURCE_CONFLICT | The operation conflicts with the resource's current state. |
| 500 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- create-role — Create role
- get-role — Get role
- list-roles — List roles
- update-role — Update role
- API reference: DELETE /iam/v1/roles/{id}
Aliases: deleterole