gcloud iam workload-identity-pools managed-identities create

NAME
gcloud iam workload-identity-pools managed-identities create - create a workload identity pool managed identity
SYNOPSIS
gcloud iam workload-identity-pools managed-identities create(MANAGED_IDENTITY :--location=LOCATION--namespace=NAMESPACE--workload-identity-pool=WORKLOAD_IDENTITY_POOL)[--async][--description=DESCRIPTION][--disabled][GCLOUD_WIDE_FLAG]
DESCRIPTION
Create a workload identity pool managed identity.
EXAMPLES
The following command creates a workload identity pool managed identity with theIDmy-managed-identity:
gcloudiamworkload-identity-poolsmanaged-identitiescreatemy-managed-identity--location="global"--workload-identity-pool="my-workload-identity-pool"--namespace="my-namespace"--description="My managed identity description"--disabled
POSITIONAL ARGUMENTS
Workload identity pool managed identity resource - Workload identity poolmanaged identity to create. The arguments in this group can be used to specifythe attributes of this resource. (NOTE) Some attributes are not given argumentsin this group but can be set in other ways.

To set theproject attribute:

  • provide the argumentmanaged_identity on the command line with afully specified name;
  • provide the argument--project on the command line;
  • set the propertycore/project.

This must be specified.

MANAGED_IDENTITY
ID of the workload identity pool managed identity or fully qualified identifierfor the workload identity pool managed identity.

To set themanaged_identity attribute:

  • provide the argumentmanaged_identity on the command line.

This positional argument must be specified if any of the other arguments in thisgroup are specified.

--location=LOCATION
The location name.

To set thelocation attribute:

  • provide the argumentmanaged_identity on the command line with afully specified name;
  • provide the argument--location on the command line.
--namespace=NAMESPACE
The ID to use for the namespace. This value must be 2-63 characters, and maycontain the characters [a-z0-9-]. The prefixgcp- is reserved foruse by Google, and may not be specified.To set thenamespace attribute:
  • provide the argumentmanaged_identity on the command line with afully specified name;
  • provide the argument--namespace on the command line.
--workload-identity-pool=WORKLOAD_IDENTITY_POOL
The ID to use for the pool, which becomes the final component of the resourcename. This value should be 4-32 characters, and may contain the characters[a-z0-9-]. The prefixgcp- is reserved for use by Google, and maynot be specified.To set theworkload-identity-pool attribute:
  • provide the argumentmanaged_identity on the command line with afully specified name;
  • provide the argument--workload-identity-pool on the command line.
FLAGS
--async
Return immediately, without waiting for the operation in progress to complete.
--description=DESCRIPTION
A description of the managed identity.
--disabled
Whether the managed identity is disabled. If disabled, credentials may no longerbe issued for this identity. Existing credentials may continue to be accepteduntil they expire.
GCLOUD WIDE FLAGS
These flags are available to all commands:--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.

Run$gcloud help for details.

API REFERENCE
This command uses theiam/v1 API. The full documentation for thisAPI can be found at:https://cloud.google.com/iam/

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025-05-07 UTC.