Class: Google::Iam::V1::Policy
- Inherits:
-
Object
- Object
- Google::Iam::V1::Policy
- Defined in:
- lib/google/cloud/tasks/v2/doc/google/iam/v1/policy.rb,
lib/google/cloud/tasks/v2beta2/doc/google/iam/v1/policy.rb,
lib/google/cloud/tasks/v2beta3/doc/google/iam/v1/policy.rb
Overview
Defines an Identity and Access Management (IAM) policy. It is used to specify access control policies for Cloud Platform resources.
A Policy is a collection of bindings. A binding binds one or more
members to a single role. Members can be user accounts, service accounts,
Google groups, and domains (such as G Suite). A role is a named list of
permissions (defined by IAM or configured by users). A binding can
optionally specify a condition, which is a logic expression that further
constrains the role binding based on attributes about the request and/or
target resource.
JSON Example
{
"bindings": [
{
"role": "roles/resourcemanager.organizationAdmin",
"members": [
"user:[email protected]",
"group:[email protected]",
"domain:google.com",
"serviceAccount:[email protected]"
]
},
{
"role": "roles/resourcemanager.organizationViewer",
"members": ["user:[email protected]"],
"condition": {
"title": "expirable access",
"description": "Does not grant access after Sep 2020",
"expression": "request.time <
timestamp('2020-10-01T00:00:00.000Z')",
}
}
]
}
YAML Example
bindings:
members:
- user:[email protected]
- group:[email protected]
- domain:google.com
- serviceAccount:[email protected] role: roles/resourcemanager.organizationAdmin
- members:
- user:[email protected] role: roles/resourcemanager.organizationViewer condition: title: expirable access description: Does not grant access after Sep 2020 expression: request.time < timestamp('2020-10-01T00:00:00.000Z')
For a description of IAM and its features, see the IAM developer's guide.
Instance Attribute Summary collapse
-
#bindings ⇒ Array<Google::Iam::V1::Binding>
Associates a list of
membersto arole. -
#etag ⇒ String
etagis used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. -
#version ⇒ Integer
Specifies the format of the policy.
Instance Attribute Details
#bindings ⇒ Array<Google::Iam::V1::Binding>
111 |
# File 'lib/google/cloud/tasks/v2/doc/google/iam/v1/policy.rb', line 111 class Policy; end |
#etag ⇒ String
111 |
# File 'lib/google/cloud/tasks/v2/doc/google/iam/v1/policy.rb', line 111 class Policy; end |
#version ⇒ Integer
111 |
# File 'lib/google/cloud/tasks/v2/doc/google/iam/v1/policy.rb', line 111 class Policy; end |