メインコンテンツへスキップ

delete-account-role

dci delete-account-role

Deletes a CloudConnect document for an AWS account.

Destructive

Removes the CloudConnect record for the account, so DoiT stops assuming the role. The CLI requires confirmation: interactive terminals prompt, scripts pass --yes (or set DCI_CONFIRM_DESTRUCTIVE=1). The IAM role itself stays in your AWS account.

Examples

# Preview the deletion locally without contacting the API.
dci delete-account-role <account-id> --dry-run
# Disconnect the account; an interactive terminal asks for confirmation first.
dci delete-account-role <account-id>
# Skip the confirmation prompt in scripts.
dci delete-account-role <account-id> --yes
Exit code 0 and no output; `dci get-aws-account <account-id>` then returns 404.

Output

On success, this command produces no response data.

Errors

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
40030VALIDATION_ERRORThe arguments or request body were rejected. Review the command's flags and payload.
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
50040API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: deleteaccountrole