google_api_cloud_asset v0.12.0 GoogleApi.CloudAsset.V1.Model.IamPolicySearchResult View Source
A result of IAM Policy search, containing information of an IAM policy.
Attributes
explanation
(type:GoogleApi.CloudAsset.V1.Model.Explanation.t
, default:nil
) - Explanation about the IAM policy search result. It contains additional information to explain why the search result matches the query.policy
(type:GoogleApi.CloudAsset.V1.Model.Policy.t
, default:nil
) - The IAM policy directly set on the given resource. Note that the original IAM policy can contain multiple bindings. This only contains the bindings that match the given query. For queries that don't contain a constrain on policies (e.g., an empty query), this contains all the bindings.To search against the
policy
bindings:- use a field query, as following:
- query by the policy contained members. Example:
policy : "amy@gmail.com"
- query by the policy contained roles. Example:
policy : "roles/compute.admin"
- query by the policy contained roles' implied permissions. Example:
policy.role.permissions : "compute.instances.create"
- query by the policy contained members. Example:
- use a field query, as following:
project
(type:String.t
, default:nil
) - The project that the associated GCP resource belongs to, in the form of projects/{PROJECT_NUMBER}. If an IAM policy is set on a resource (like VM instance, Cloud Storage bucket), the project field will indicate the project that contains the resource. If an IAM policy is set on a folder or orgnization, the project field will be empty.To search against the
project
:- specify the
scope
field as this project in your search request.
- specify the
resource
(type:String.t
, default:nil
) - The full resource name of the resource associated with this IAM policy. Example://compute.googleapis.com/projects/my_project_123/zones/zone1/instances/instance1
. See Cloud Asset Inventory Resource Name Format for more information.To search against the
resource
:- use a field query. Example:
resource : "organizations/123"
- use a field query. Example:
Link to this section Summary
Functions
Unwrap a decoded JSON object into its complex fields.
Link to this section Types
Specs
t() :: %GoogleApi.CloudAsset.V1.Model.IamPolicySearchResult{ explanation: GoogleApi.CloudAsset.V1.Model.Explanation.t(), policy: GoogleApi.CloudAsset.V1.Model.Policy.t(), project: String.t(), resource: String.t() }
Link to this section Functions
Specs
Unwrap a decoded JSON object into its complex fields.