delete-account-role
dci delete-account-role
Deletes a CloudConnect document for an AWS account.
Destructive
Removes the CloudConnect record for the account, so DoiT stops assuming the role. The
CLI requires confirmation: interactive terminals prompt, scripts pass --yes (or set
DCI_CONFIRM_DESTRUCTIVE=1). The IAM role itself stays in your AWS account.
Examples
# Preview the deletion locally without contacting the API.
dci delete-account-role <account-id> --dry-run
# Disconnect the account; an interactive terminal asks for confirmation first.
dci delete-account-role <account-id>
# Skip the confirmation prompt in scripts.
dci delete-account-role <account-id> --yes
Exit code 0 and no output; `dci get-aws-account <account-id>` then returns 404.
Output
On success, this command produces no response data.
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 500 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- create-account-role — Create or update an AWS account role
- get-aws-account — Get an AWS account
- update-aws-feature — Update an AWS feature
- get-cloud-connect-supported-features — Get supported features for a connected account
- API reference: DELETE /core/v1/cloudconnect/aws/accounts/{accountID}
Aliases: deleteaccountrole