IAMPolicyArgs

data class IAMPolicyArgs(val folder: Output<String>? = null, val policyData: Output<String>? = null) : ConvertibleToJava<IAMPolicyArgs>

Import

IAM member imports use space-delimited identifiers; the resource in question, the role, and the account. This member resource can be imported using the folder, role, and member e.g.

$ pulumi import gcp:folder/iAMPolicy:IAMPolicy my_folder "folder roles/viewer user:foo@example.com"

IAM binding imports use space-delimited identifiers; the resource in question and the role. This binding resource can be imported using the folder and role, e.g.

$ pulumi import gcp:folder/iAMPolicy:IAMPolicy my_folder "folder roles/viewer"

IAM policy imports use the identifier of the resource in question. This policy resource can be imported using the folder.

$ pulumi import gcp:folder/iAMPolicy:IAMPolicy my_folder folder

IAM audit config imports use the identifier of the resource in question and the service, e.g.

$ pulumi import gcp:folder/iAMPolicy:IAMPolicy my_folder "folder foo.googleapis.com"

->Custom RolesIf you're importing a IAM resource with a custom role, make sure to use the full name of the custom role, e.g. organizations/{{org_id}}/roles/{{role_id}}. ->Conditional IAM BindingsIf you're importing a IAM binding with a condition block, make sure

$ pulumi import gcp:folder/iAMPolicy:IAMPolicy to include the title of condition, e.g. `google_folder_iam_binding.my_folder "folder roles/{{role_id}} condition-title"`

Constructors

Link copied to clipboard
fun IAMPolicyArgs(folder: Output<String>? = null, policyData: Output<String>? = null)

Functions

Link copied to clipboard
open override fun toJava(): IAMPolicyArgs

Properties

Link copied to clipboard
val folder: Output<String>? = null

The resource name of the folder the policy is attached to. Its format is folders/{folder_id}.

Link copied to clipboard
val policyData: Output<String>? = null

The gcp.organizations.getIAMPolicy data source that represents the IAM policy that will be applied to the folder. The policy will be merged with any existing policy applied to the folder.