gcloud iam service-accounts disable - disable an IAM service account
gcloud iam service-accounts disable SERVICE_ACCOUNT [GCLOUD_WIDE_FLAG ...]
Disable an IAM service account. After the service account is disabled, credential generation and API requests using this service account will fail. Using gcloud iam service-accounts enable to re-enable it.
If the service account does not exist, this command returns a PERMISSION_DENIED error.
To disable a service account from your project, run:
$ gcloud iam service-accounts disable \ my-iam-account@my-project.iam.gserviceaccount.com
- ServiceAccount resource - The IAM service account to disable. This represents a
Cloud resource. (NOTE) Some attributes are not given arguments in this group but can be set in other ways. To set the project attribute:
- —
provide the argument service_account on the command line with a fully specified name;
- —
set the property core/project;
- —
provide the argument --project on the command line.
This must be specified.
- SERVICE_ACCOUNT
ID of the serviceAccount or fully qualified identifier for the serviceAccount. To set the service_account attribute:
provide the argument service_account on the command line.
These flags are available to all commands: --access-token-file, --account, --billing-project, --configuration, --flags-file, --flatten, --format, --help, --impersonate-service-account, --log-http, --project, --quiet, --trace-token, --user-output-enabled, --verbosity.
Run $ gcloud help for details.
This command uses the iam/v1 API. The full documentation for this API can be found at: https://cloud.google.com/iam/
These variants are also available:
$ gcloud alpha iam service-accounts disable
$ gcloud beta iam service-accounts disable