gcloud alpha projects get-ancestors-iam-policy - get IAM policies for a project and its ancestors
gcloud alpha projects get-ancestors-iam-policy PROJECT_ID [--include-deny] [--filter=EXPRESSION] [--limit=LIMIT] [--page-size=PAGE_SIZE] [--sort-by=[FIELD,...]] [GCLOUD_WIDE_FLAG ...]
(ALPHA) Get IAM policies for a project and its ancestors, given a project ID.
To get IAM policies for project example-project-id-1 and its ancestors, run:
$ gcloud alpha projects get-ancestors-iam-policy example-project-id-1
- Project id resource - ID for the project you want to get IAM policy for. This
represents a Cloud resource.
This must be specified.
- PROJECT_ID
ID of the project_id or fully qualified identifier for the project_id. To set the project_id attribute:
provide the argument project_id on the command line.
- --include-deny
Include deny policies on the project and its ancestors in the result
- --filter=EXPRESSION
Apply a Boolean filter EXPRESSION to each resource item to be listed. If the expression evaluates True, then that item is listed. For more details and examples of filter expressions, run $ gcloud topic filters. This flag interacts with other flags that are applied in this order: --flatten, --sort-by, --filter, --limit.
- --limit=LIMIT
Maximum number of resources to list. The default is unlimited. This flag interacts with other flags that are applied in this order: --flatten, --sort-by, --filter, --limit.
- --page-size=PAGE_SIZE
Some services group resource list output into pages. This flag specifies the maximum number of resources per page. The default is determined by the service if it supports paging, otherwise it is unlimited (no paging). Paging may be applied before or after --filter and --limit depending on the service.
- --sort-by=[FIELD,...]
Comma-separated list of resource field key names to sort by. The default order is ascending. Prefix a field with ``~'' for descending order on that field. This flag interacts with other flags that are applied in this order: --flatten, --sort-by, --filter, --limit.
These flags are available to all commands: --access-token-file, --account, --billing-project, --configuration, --flags-file, --flatten, --format, --help, --impersonate-service-account, --log-http, --project, --quiet, --trace-token, --user-output-enabled, --verbosity.
Run $ gcloud help for details.
This command is currently in alpha and might change without notice. If this command fails with API permission errors despite specifying the correct project, you might be trying to access an API with an invitation-only early access allowlist. These variants are also available:
$ gcloud projects get-ancestors-iam-policy
$ gcloud beta projects get-ancestors-iam-policy