gcloud alpha iap web get-iam-policy Stay organized with collections Save and categorize content based on your preferences.
- NAME
- gcloud alpha iap web get-iam-policy - get IAM policy for an IAP IAM resource
- SYNOPSIS
gcloud alpha iap web get-iam-policy[--region=REGION--resource-type=RESOURCE_TYPE--service=SERVICE--version=VERSION][--filter=EXPRESSION][--limit=LIMIT][--page-size=PAGE_SIZE][--sort-by=[FIELD,…]][GCLOUD_WIDE_FLAG …]
- DESCRIPTION
(ALPHA)gcloud alpha iap web get-iam-policydisplaysthe IAM policy associated with an IAP IAM resource. If formatted as JSON, theoutput can be edited and used as a policy file for set-iam-policy. The outputincludes an "etag" field identifying the version emitted and allowing detectionof concurrent policy updates; see $gcloud alpha iap webset-iam-policy for additional details.- EXAMPLES
- To get the IAM policy for the web accesses to the IAP protected resources withinthe active project, run:
gcloudalphaiapwebget-iam-policyTo get the IAM policy for the web accesses to the IAP protected resources withina project, run:
gcloudalphaiapwebget-iam-policy--project=PROJECT_IDTo get the IAM policy for the web accesses to the IAP protected resources withinan App Engine application, run:
gcloudalphaiapwebget-iam-policy--resource-type=app-engineTo get the IAM policy for the web accesses to the IAP protected resources withinan App Engine service, run:
gcloudalphaiapwebget-iam-policy--resource-type=app-engine--service=SERVICE_IDTo get the IAM policy for the web accesses to the IAP protected resources withinan App Engine service version, run:
gcloudalphaiapwebget-iam-policy--resource-type=app-engine--service=SERVICE_ID--version=VERSIONTo get the IAM policy for the web accesses to the IAP protected resources withinall backend services, run:
gcloudalphaiapwebget-iam-policy--resource-type=backend-servicesTo get the IAM policy for the web accesses to the IAP protected resources withina backend service, run:
gcloudalphaiapwebget-iam-policy--resource-type=backend-services--service=SERVICE_IDTo get the IAM policy for the web accesses to the IAP protected resources withina regional backend service, run:
gcloudalphaiapwebget-iam-policy--resource-type=backend-services--service=SERVICE_ID--region=REGION - FLAGS
--region=REGION- Region name. Not applicable for
resource-type=app-engine. Requiredwhenresource-type=backend-servicesand regional scoped. Notapplicable for global backend-services. Required whenresource-type=cloud-run. --resource-type=RESOURCE_TYPE- Resource type of the IAP resource.
RESOURCE_TYPEmust beone of:app-engine,backend-services,forwarding-rule,cloud-run. --service=SERVICE- Service name.
--version=VERSION- Service version. Should only be specified with
--resource-type=app-engine.
- LIST COMMAND FLAGS
--filter=EXPRESSION- Apply a Boolean filter
EXPRESSIONto each resource itemto be listed. If the expression evaluatesTrue, then that item islisted. For more details and examples of filter expressions, run $gcloud topic filters. This flaginteracts with other flags that are applied in this order:--flatten,--sort-by,--filter,--limit. --limit=LIMIT- Maximum number of resources to list. The default is
unlimited. Thisflag interacts with other flags that are applied in this order:--flatten,--sort-by,--filter,--limit. --page-size=PAGE_SIZE- Some services group resource list output into pages. This flag specifies themaximum number of resources per page. The default is determined by the serviceif it supports paging, otherwise it is
unlimited(no paging).Paging may be applied before or after--filterand--limitdepending on the service. --sort-by=[FIELD,…]- Comma-separated list of resource field key names to sort by. The default orderis ascending. Prefix a field with ``~´´ for descending order on thatfield. This flag interacts with other flags that are applied in this order:
--flatten,--sort-by,--filter,--limit.
- GCLOUD WIDE FLAGS
- These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$gcloud helpfor details. - NOTES
- This command is currently in alpha and might change without notice. If thiscommand fails with API permission errors despite specifying the correct project,you might be trying to access an API with an invitation-only early accessallowlist. These variants are also available:
gcloudiapwebget-iam-policygcloudbetaiapwebget-iam-policy
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-05-07 UTC.