HEX
Server: Apache/2.4.65 (Ubuntu)
System: Linux ielts-store-v2 6.8.0-1036-gcp #38~22.04.1-Ubuntu SMP Thu Aug 14 01:19:18 UTC 2025 x86_64
User: root (0)
PHP: 7.2.34-54+ubuntu20.04.1+deb.sury.org+1
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: //snap/google-cloud-cli/394/help/man/man1/gcloud_beta_iam_policies_update.1
.TH "GCLOUD_BETA_IAM_POLICIES_UPDATE" 1



.SH "NAME"
.HP
gcloud beta iam policies update \- update the policy on the given attachment point with the given name



.SH "SYNOPSIS"
.HP
\f5gcloud beta iam policies update\fR \fIPOLICY_ID\fR \fB\-\-attachment\-point\fR=\fIATTACHMENT_POINT\fR \fB\-\-kind\fR=\fIKIND\fR \fB\-\-policy\-file\fR=\fIPOLICY_FILE\fR [\fB\-\-etag\fR=\fIETAG\fR] [\fIGCLOUD_WIDE_FLAG\ ...\fR]



.SH "DESCRIPTION"

\fB(BETA)\fR Update the policy on the given attachment point with the given
name.



.SH "EXAMPLES"

The following command updates the IAM policy \f5\fImy\-deny\-policy\fR\fR, which
is attached to the resource project \f5\fI123\fR\fR and has the etag
\f5\fIabc\fR\fR:

.RS 2m
$ gcloud beta iam policies update my\-deny\-policy \e
    \-\-attachment\-point=cloudresourcemanager.googleapis.com/\e
projects/123 \-\-kind=denypolicies \-\-policy\-file=policy.json \e
    \-\-etag=abc
.RE



.SH "POSITIONAL ARGUMENTS"

.RS 2m
.TP 2m
\fIPOLICY_ID\fR

Policy ID that is unique for the resource to which the policy is attached.


.RE
.sp

.SH "REQUIRED FLAGS"

.RS 2m
.TP 2m
\fB\-\-attachment\-point\fR=\fIATTACHMENT_POINT\fR

Resource to which the policy is attached. For valid formats, see
https://cloud.google.com/iam/help/deny/attachment\-point.

.TP 2m
\fB\-\-kind\fR=\fIKIND\fR

Policy type. Use \f5denypolicies\fR for deny policies.

.TP 2m
\fB\-\-policy\-file\fR=\fIPOLICY_FILE\fR

Path to the file that contains the policy, in JSON or YAML format. For valid
syntax, see https://cloud.google.com/iam/help/deny/policy\-syntax.


.RE
.sp

.SH "OPTIONAL FLAGS"

.RS 2m
.TP 2m
\fB\-\-etag\fR=\fIETAG\fR

Etag that identifies the version of the existing policy. It can be obtained by
running \f5gcloud iam policies get\fR. When deleting a policy, if the etag is
omitted, the policy is deleted regardless of its current etag. When updating a
policy, if the etag is omitted, the update uses the etag provided in the policy
file.


.RE
.sp

.SH "GCLOUD WIDE FLAGS"

These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.

Run \fB$ gcloud help\fR for details.



.SH "NOTES"

This command is currently in beta and might change without notice. These
variants are also available:

.RS 2m
$ gcloud iam policies update
.RE

.RS 2m
$ gcloud alpha iam policies update
.RE