Skip to content

User

Snowflake Documentation | Snowcap CLI label: user

A user in Snowflake.

Note: RSA_PUBLIC_KEY_FP and RSA_PUBLIC_KEY_2_FP are read-only fingerprint fields computed by Snowflake and cannot be managed through Snowcap.

Note: rsa_public_key and rsa_public_key_2 are Snowflake's legacy key-pair properties. Named key pairs, which support role restriction, expiration, and rotation with a grace period, are declared with a key_pairs: list on the user or as standalone UserKeyPair resources.

Rotating on the legacy properties is the two-step flow Snowflake documents: set rsa_public_key_2 to the new key and apply, move clients over, then set rsa_public_key to the new key and apply again. Both keys are read back from Snowflake, so each step settles to an empty plan. Keys may be given with or without their PEM delimiters.

Removing the retired key is the one step Snowcap cannot do for you: an empty or absent value means "not managed" everywhere in Snowcap, so deleting rsa_public_key_2 from your config plans nothing and leaves the old key live. Retire it with ALTER USER someuser UNSET RSA_PUBLIC_KEY_2. Named key pairs have no such gap — rotation retires the prior key on a timer you set.

Examples

YAML

users:
  - name: some_user
    owner: USERADMIN
    email: some.user@example.com
    type: PERSON

Python

user = User(
    name="some_user",
    owner="USERADMIN",
    email="some.user@example.com",
    type="PERSON",
)

Fields

  • name (string, required) - The name of the user.
  • owner (string or Role) - The owner of the user. Defaults to "USERADMIN".
  • password (string) - The password of the user.
  • login_name (string) - The login name of the user. Defaults to the name in uppercase.
  • display_name (string) - The display name of the user. Defaults to the name in lowercase.
  • first_name (string) - The first name of the user.
  • middle_name (string) - The middle name of the user.
  • last_name (string) - The last name of the user.
  • email (string) - The email of the user.
  • must_change_password (bool) - Whether the user must change their password. Defaults to False.
  • disabled (bool) - Whether the user is disabled. Defaults to False.
  • days_to_expiry (int) - The number of days until the user's password expires.
  • mins_to_unlock (int) - The number of minutes until the user's account is unlocked.
  • default_warehouse (string) - The default warehouse for the user.
  • default_namespace (string) - The default namespace for the user.
  • default_role (string) - The default role for the user.
  • default_secondary_roles (list) - The default secondary roles for the user. Use [] for NONE or ['ALL'] for ALL.
  • mins_to_bypass_mfa (int) - The number of minutes until the user can bypass Multi-Factor Authentication.
  • rsa_public_key (string) - The RSA public key for the user.
  • rsa_public_key_2 (string) - The RSA public key for the user.
  • comment (string) - A comment for the user.
  • network_policy (string) - The network policy for the user.
  • allowed_interfaces (list) - The allowed interfaces for the user.
  • workload_identity (string) - The workload identity for the user.
  • type (string or UserType) - The type of the user. Defaults to "NULL".
  • tags (dict) - Tags for the user.