NAME

gcloud kms keyrings set-iam-policy - set the IAM policy for a keyring

SYNOPSIS

gcloud kms keyrings set-iam-policy KEYRING POLICY_FILE [--location=LOCATION] [GCLOUD_WIDE_FLAG ...]

DESCRIPTION

Sets the IAM policy for the given keyring as defined in a JSON or YAML file.

See https://cloud.google.com/iam/docs/managing-policies for details of the policy file format and contents.

EXAMPLES

The following command will read am IAM policy defined in a JSON file 'policy.json' and set it for the keyring fellowship with location global:

$ gcloud kms keyrings set-iam-policy fellowship policy.json \ --location=global

POSITIONAL ARGUMENTS

KEYRING

Name of the key ring whose IAM policy to update.

POLICY_FILE

JSON or YAML file with the IAM policy

FLAGS

--location=LOCATION

Location of the keyring.

GCLOUD WIDE FLAGS

These flags are available to all commands: --access-token-file, --account, --billing-project, --configuration, --flags-file, --flatten, --format, --help, --impersonate-service-account, --log-http, --project, --quiet, --trace-token, --user-output-enabled, --verbosity.

Run $ gcloud help for details.

NOTES

These variants are also available:

$ gcloud alpha kms keyrings set-iam-policy

$ gcloud beta kms keyrings set-iam-policy