File: //snap/google-cloud-cli/current/help/man/man1/gcloud_alpha_pam_grants_search.1
.TH "GCLOUD_ALPHA_PAM_GRANTS_SEARCH" 1
.SH "NAME"
.HP
gcloud alpha pam grants search \- search for and list all Privileged Access Manager grants you have created, have approved, or can approve
.SH "SYNOPSIS"
.HP
\f5gcloud alpha pam grants search\fR \fB\-\-caller\-relationship\fR=\fICALLER_RELATIONSHIP\fR (\fB\-\-entitlement\fR=\fIENTITLEMENT\fR\ :\ \fB\-\-folder\fR=\fIFOLDER\fR\ \fB\-\-location\fR=\fILOCATION\fR\ \fB\-\-organization\fR=\fIORGANIZATION\fR) [\fB\-\-filter\fR=\fIEXPRESSION\fR] [\fB\-\-limit\fR=\fILIMIT\fR] [\fB\-\-page\-size\fR=\fIPAGE_SIZE\fR] [\fB\-\-sort\-by\fR=[\fIFIELD\fR,...]] [\fIGCLOUD_WIDE_FLAG\ ...\fR]
.SH "DESCRIPTION"
\fB(ALPHA)\fR Search for and list all Privileged Access Manager (PAM) grants you
have created, have approved, or can approve.
.SH "EXAMPLES"
The following command searches for and lists all grants you have created which
are associated with an entitlement with the full name
\f5\fIENTITLEMENT_NAME\fR\fR:
.RS 2m
$ gcloud alpha pam grants search \-\-entitlement=ENTITLEMENT_NAME \e
\-\-caller\-relationship=had\-created
.RE
The following command searches for and lists all grants you have approved or
denied which are associated with an entitlement with the full name
\f5\fIENTITLEMENT_NAME\fR\fR:
.RS 2m
$ gcloud alpha pam grants search \-\-entitlement=ENTITLEMENT_NAME \e
\-\-caller\-relationship=had\-approved
.RE
The following command searches for and lists all grants you can approve which
are associated with an entitlement with the full name
\f5\fIENTITLEMENT_NAME\fR\fR:
.RS 2m
$ gcloud alpha pam grants search \-\-entitlement=ENTITLEMENT_NAME \e
\-\-caller\-relationship=can\-approve
.RE
.SH "REQUIRED FLAGS"
.RS 2m
.TP 2m
\fB\-\-caller\-relationship\fR=\fICALLER_RELATIONSHIP\fR
Whether to return grants you have created, have approved, or can approve.
\fICALLER_RELATIONSHIP\fR must be one of: \fBcan\-approve\fR,
\fBhad\-approved\fR, \fBhad\-created\fR.
.TP 2m
Entitlement resource \- Entitlement the grants are associated with. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
To set the \f5project\fR attribute:
.RS 2m
.IP "\(em" 2m
provide the argument \f5\-\-entitlement\fR on the command line with a fully
specified name;
.IP "\(em" 2m
provide the argument \f5\-\-project\fR on the command line;
.IP "\(em" 2m
set the property \f5core/project\fR. This resource can be one of the following
types: [privilegedaccessmanager.projects.locations.entitlements,
privilegedaccessmanager.folders.locations.entitlements,
privilegedaccessmanager.organizations.locations.entitlements].
.RE
.sp
This must be specified.
.RS 2m
.TP 2m
\fB\-\-entitlement\fR=\fIENTITLEMENT\fR
ID of the entitlement or fully qualified identifier for the entitlement.
To set the \f5entitlement\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5\-\-entitlement\fR on the command line.
.RE
.sp
This flag argument must be specified if any of the other arguments in this group
are specified.
.TP 2m
\fB\-\-folder\fR=\fIFOLDER\fR
The name of the folder
To set the \f5folder\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5\-\-entitlement\fR on the command line with a fully
specified name;
.IP "\(bu" 2m
provide the argument \f5\-\-folder\fR on the command line. Must be specified for
resource of type [privilegedaccessmanager.folders.locations.entitlements].
.RE
.sp
.TP 2m
\fB\-\-location\fR=\fILOCATION\fR
The resource location
To set the \f5location\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5\-\-entitlement\fR on the command line with a fully
specified name;
.IP "\(bu" 2m
provide the argument \f5\-\-location\fR on the command line.
.RE
.sp
.TP 2m
\fB\-\-organization\fR=\fIORGANIZATION\fR
The name of the organization
To set the \f5organization\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5\-\-entitlement\fR on the command line with a fully
specified name;
.IP "\(bu" 2m
provide the argument \f5\-\-organization\fR on the command line. Must be
specified for resource of type
[privilegedaccessmanager.organizations.locations.entitlements].
.RE
.sp
.RE
.RE
.sp
.SH "LIST COMMAND FLAGS"
.RS 2m
.TP 2m
\fB\-\-filter\fR=\fIEXPRESSION\fR
Apply a Boolean filter \fIEXPRESSION\fR to each resource item to be listed. If
the expression evaluates \f5True\fR, then that item is listed. For more details
and examples of filter expressions, run $ gcloud topic filters. This flag
interacts with other flags that are applied in this order: \fB\-\-flatten\fR,
\fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.
.TP 2m
\fB\-\-limit\fR=\fILIMIT\fR
Maximum number of resources to list. The default is \fBunlimited\fR. This flag
interacts with other flags that are applied in this order: \fB\-\-flatten\fR,
\fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.
.TP 2m
\fB\-\-page\-size\fR=\fIPAGE_SIZE\fR
Some services group resource list output into pages. This flag specifies the
maximum number of resources per page. The default is determined by the service
if it supports paging, otherwise it is \fBunlimited\fR (no paging). Paging may
be applied before or after \fB\-\-filter\fR and \fB\-\-limit\fR depending on the
service.
.TP 2m
\fB\-\-sort\-by\fR=[\fIFIELD\fR,...]
Comma\-separated list of resource field key names to sort by. The default order
is ascending. Prefix a field with ``~'' for descending order on that field. This
flag interacts with other flags that are applied in this order:
\fB\-\-flatten\fR, \fB\-\-sort\-by\fR, \fB\-\-filter\fR, \fB\-\-limit\fR.
.RE
.sp
.SH "GCLOUD WIDE FLAGS"
These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.
Run \fB$ gcloud help\fR for details.
.SH "API REFERENCE"
This command uses the \fBprivilegedaccessmanager/v1alpha\fR API. The full
documentation for this API can be found at:
https://cloud.google.com/iam/docs/pam\-overview
.SH "NOTES"
This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation\-only early access
allowlist. These variants are also available:
.RS 2m
$ gcloud pam grants search
.RE
.RS 2m
$ gcloud beta pam grants search
.RE