Defines a Cloud Organization Policy
which is used to specify Constraints
for configurations of Cloud Platform resources.
JSON representation |
---|
{ "version": integer, "constraint": string, "etag": string, "updateTime": string, // Union field |
Fields | |
---|---|
version |
Version of the |
constraint |
The name of the A list of available constraints is available. Immutable after creation. |
etag |
An opaque tag indicating the current version of the When the When the When the A base64-encoded string. |
updateTime |
The time stamp the A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: |
Union field A Providing a *_policy that is incompatible with the Attempting to set a |
|
listPolicy |
List of values either allowed or disallowed. |
booleanPolicy |
For boolean |
restoreDefault |
Restores the default behavior of the constraint; independent of |
ListPolicy
Used in policyType
to specify how listPolicy
behaves at this resource.
ListPolicy
can define specific values and subtrees of Cloud Resource Manager resource hierarchy (Organizations
, Folders
, Projects
) that are allowed or denied by setting the allowedValues
and deniedValues
fields. This is achieved by using the under:
and optional is:
prefixes. The under:
prefix is used to denote resource subtree values. The is:
prefix is used to denote specific values, and is required only if the value contains a ":". Values prefixed with "is:" are treated the same as values with no prefix. Ancestry subtrees must be in one of the following formats: - "projects/supportsUnder
field of the associated Constraint
defines whether ancestry prefixes can be used. You can set allowedValues
and deniedValues
in the same Policy
if allValues
is ALL_VALUES_UNSPECIFIED
. ALLOW
or DENY
are used to allow or deny all values. If allValues
is set to either ALLOW
or DENY
, allowedValues
and deniedValues
must be unset.
JSON representation |
---|
{
"allowedValues": [
string
],
"deniedValues": [
string
],
"allValues": enum ( |
Fields | |
---|---|
allowedValues[] |
List of values allowed at this resource. Can only be set if |
deniedValues[] |
List of values denied at this resource. Can only be set if |
allValues |
The policy allValues state. |
suggestedValue |
Optional. The Google Cloud Console will try to default to a configuration that matches the value specified in this |
inheritFromParent |
Determines the inheritance behavior for this By default, a Setting For example, suppose you have a The following examples demonstrate different possible layerings for Example 1 (no inherited values): Example 2 (inherited values): Example 3 (inheriting both allowed and denied values): Example 4 (RestoreDefault): Example 5 (no policy inherits parent policy): Example 6 (ListConstraint allowing all): Example 7 (ListConstraint allowing none): Example 10 (allowed and denied subtrees of Resource Manager hierarchy): Given the following resource hierarchy O1->{F1, F2}; F1->{P1}; F2->{P2, P3}, |
AllValues
This enum can be used to set Policies
that apply to all possible configuration values rather than specific values in allowedValues
or deniedValues
.
Setting this to ALLOW
will mean this Policy
allows all values. Similarly, setting it to DENY
will mean no values are allowed. If set to either ALLOW
or DENY,
allowedValuesand
deniedValues
must be unset. Setting this to
ALL_VALUES_UNSPECIFIEDallows for
setting
allowedValuesand
deniedValues`.
Enums | |
---|---|
ALL_VALUES_UNSPECIFIED |
Indicates that allowedValues or deniedValues must be set. |
ALLOW |
A policy with this set allows all values. |
DENY |
A policy with this set denies all values. |
BooleanPolicy
Used in policyType
to specify how booleanPolicy
will behave at this resource.
JSON representation |
---|
{ "enforced": boolean } |
Fields | |
---|---|
enforced |
If Suppose you have a The following examples demonstrate the different possible layerings: Example 1 (nearest Example 2 (enforcement gets replaced): Example 3 (RestoreDefault): |
RestoreDefault
This type has no fields.
Ignores policies set above this resource and restores the constraintDefault
enforcement behavior of the specific Constraint
at this resource.
Suppose that constraintDefault
is set to ALLOW
for the Constraint
constraints/serviceuser.services
. Suppose that organization foo.com sets a Policy
at their Organization resource node that restricts the allowed service activations to deny all service activations. They could then set a Policy
with the policyType
restoreDefault
on several experimental projects, restoring the constraintDefault
enforcement of the Constraint
for only those projects, allowing those projects to have all services activated.