Class IamPolicySearchResult (2.8.0)

public sealed class IamPolicySearchResult : IMessage<IamPolicySearchResult>, IEquatable<IamPolicySearchResult>, IDeepCloneable<IamPolicySearchResult>, IBufferMessage, IMessage

A result of IAM Policy search, containing information of an IAM policy.

Inheritance

Object > IamPolicySearchResult

Namespace

Google.Cloud.Asset.V1

Assembly

Google.Cloud.Asset.V1.dll

Constructors

IamPolicySearchResult()

public IamPolicySearchResult()

IamPolicySearchResult(IamPolicySearchResult)

public IamPolicySearchResult(IamPolicySearchResult other)
Parameter
NameDescription
otherIamPolicySearchResult

Properties

Explanation

public IamPolicySearchResult.Types.Explanation Explanation { get; set; }

Explanation about the IAM policy search result. It contains additional information to explain why the search result matches the query.

Property Value
TypeDescription
IamPolicySearchResult.Types.Explanation

Policy

public Policy Policy { get; set; }

The IAM policy directly set on the given resource. Note that the original IAM policy can contain multiple bindings. This only contains the bindings that match the given query. For queries that don't contain a constrain on policies (e.g., an empty query), this contains all the bindings.

To search against the policy bindings:

  • use a field query:
  • query by the policy contained members. Example: policy:amy@gmail.com
  • query by the policy contained roles. Example: policy:roles/compute.admin
  • query by the policy contained roles' included permissions. Example: policy.role.permissions:compute.instances.create
Property Value
TypeDescription
Policy

Project

public string Project { get; set; }

The project that the associated GCP resource belongs to, in the form of projects/{PROJECT_NUMBER}. If an IAM policy is set on a resource (like VM instance, Cloud Storage bucket), the project field will indicate the project that contains the resource. If an IAM policy is set on a folder or orgnization, this field will be empty.

To search against the project:

  • specify the scope field as this project in your search request.
Property Value
TypeDescription
String

Resource

public string Resource { get; set; }

The full resource name of the resource associated with this IAM policy. Example: //compute.googleapis.com/projects/my_project_123/zones/zone1/instances/instance1. See Cloud Asset Inventory Resource Name Format for more information.

To search against the resource:

  • use a field query. Example: resource:organizations/123
Property Value
TypeDescription
String