HEX
Server: Apache/2.4.65 (Ubuntu)
System: Linux ielts-store-v2 6.8.0-1036-gcp #38~22.04.1-Ubuntu SMP Thu Aug 14 01:19:18 UTC 2025 x86_64
User: root (0)
PHP: 7.2.34-54+ubuntu20.04.1+deb.sury.org+1
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: //snap/google-cloud-cli/396/help/man/man1/gcloud_iap_web_get-iam-policy.1
.TH "GCLOUD_IAP_WEB_GET\-IAM\-POLICY" 1



.SH "NAME"
.HP
gcloud iap web get\-iam\-policy \- get IAM policy for an IAP IAM resource



.SH "SYNOPSIS"
.HP
\f5gcloud iap web get\-iam\-policy\fR [\fB\-\-region\fR=\fIREGION\fR\ \fB\-\-resource\-type\fR=\fIRESOURCE_TYPE\fR\ \fB\-\-service\fR=\fISERVICE\fR\ \fB\-\-version\fR=\fIVERSION\fR] [\fB\-\-filter\fR=\fIEXPRESSION\fR] [\fB\-\-limit\fR=\fILIMIT\fR] [\fB\-\-page\-size\fR=\fIPAGE_SIZE\fR] [\fB\-\-sort\-by\fR=[\fIFIELD\fR,...]] [\fIGCLOUD_WIDE_FLAG\ ...\fR]



.SH "DESCRIPTION"

\fBgcloud iap web get\-iam\-policy\fR displays the IAM policy associated with an
IAP IAM resource. If formatted as JSON, the output can be edited and used as a
policy file for set\-iam\-policy. The output includes an "etag" field
identifying the version emitted and allowing detection of concurrent policy
updates; see $ gcloud iap web set\-iam\-policy for additional details.



.SH "EXAMPLES"

To get the IAM policy for the web accesses to the IAP protected resources within
the active project, run:

.RS 2m
$ gcloud iap web get\-iam\-policy
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
a project, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-project=PROJECT_ID
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
an App Engine application, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=app\-engine
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
an App Engine service, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=app\-engine \e
    \-\-service=SERVICE_ID
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
an App Engine service version, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=app\-engine \e
    \-\-service=SERVICE_ID \-\-version=VERSION
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
all backend services, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=backend\-services
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
a backend service, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=backend\-services \e
    \-\-service=SERVICE_ID
.RE

To get the IAM policy for the web accesses to the IAP protected resources within
a regional backend service, run:

.RS 2m
$ gcloud iap web get\-iam\-policy \-\-resource\-type=backend\-services \e
    \-\-service=SERVICE_ID \-\-region=REGION
.RE



.SH "FLAGS"

.RS 2m
.TP 2m
\fB\-\-region\fR=\fIREGION\fR

Region name. Should only be specified with
\f5\-\-resource\-type=backend\-services\fR if it is a regional scoped. Not
applicable for global scoped backend services.

.TP 2m
\fB\-\-resource\-type\fR=\fIRESOURCE_TYPE\fR

Resource type of the IAP resource. \fIRESOURCE_TYPE\fR must be one of:
\fBapp\-engine\fR, \fBbackend\-services\fR, \fBforwarding\-rule\fR.

.TP 2m
\fB\-\-service\fR=\fISERVICE\fR

Service name.

.TP 2m
\fB\-\-version\fR=\fIVERSION\fR

Service version. Should only be specified with
\f5\-\-resource\-type=app\-engine\fR.


.RE
.sp

.SH "LIST COMMAND FLAGS"

.RS 2m
.TP 2m
\fB\-\-filter\fR=\fIEXPRESSION\fR

Apply a Boolean filter \fIEXPRESSION\fR to each resource item to be listed. If
the expression evaluates \f5True\fR, then that item is listed. For more details
and examples of filter expressions, run $ gcloud topic filters. This flag
interacts with other flags that are applied in this order: \fB\-\-flatten\fR,
\fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.

.TP 2m
\fB\-\-limit\fR=\fILIMIT\fR

Maximum number of resources to list. The default is \fBunlimited\fR. This flag
interacts with other flags that are applied in this order: \fB\-\-flatten\fR,
\fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.

.TP 2m
\fB\-\-page\-size\fR=\fIPAGE_SIZE\fR

Some services group resource list output into pages. This flag specifies the
maximum number of resources per page. The default is determined by the service
if it supports paging, otherwise it is \fBunlimited\fR (no paging). Paging may
be applied before or after \fB\-\-filter\fR and \fB\-\-limit\fR depending on the
service.

.TP 2m
\fB\-\-sort\-by\fR=[\fIFIELD\fR,...]

Comma\-separated list of resource field key names to sort by. The default order
is ascending. Prefix a field with ``~'' for descending order on that field. This
flag interacts with other flags that are applied in this order:
\fB\-\-flatten\fR, \fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.


.RE
.sp

.SH "GCLOUD WIDE FLAGS"

These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.

Run \fB$ gcloud help\fR for details.



.SH "NOTES"

These variants are also available:

.RS 2m
$ gcloud alpha iap web get\-iam\-policy
.RE

.RS 2m
$ gcloud beta iap web get\-iam\-policy
.RE