Reference documentation and code samples for the Google Cloud Policy Troubleshooter V1 Client class ExplainedPolicy.
Details about how a specific IAM Policy contributed to the access check.
Generated from protobuf message google.cloud.policytroubleshooter.v1.ExplainedPolicy
Namespace
Google \ Cloud \ PolicyTroubleshooter \ V1Methods
__construct
Constructor.
data
array
Optional. Data for populating the Message object.
↳ access
int
Indicates whether this policy
provides the specified permission to the specified member for the specified resource. This field does not
indicate whether the member actually has the permission for the resource. There might be another policy that overrides this policy. To determine whether the member actually has the permission, use the access
field in the TroubleshootIamPolicyResponse
.
↳ full_resource_name
string
The full resource name that identifies the resource. For example, //compute.googleapis.com/projects/my-project/zones/us-central1-a/instances/my-instance
. If the sender of the request does not have access to the policy, this field is omitted. For examples of full resource names for Google Cloud services, see https://cloud.google.com/iam/help/troubleshooter/full-resource-names
.
↳ policy
Google\Cloud\Iam\V1\Policy
The IAM policy attached to the resource. If the sender of the request does not have access to the policy, this field is empty.
↳ binding_explanations
array< Google\Cloud\PolicyTroubleshooter\V1\BindingExplanation
>
Details about how each binding in the policy affects the member's ability, or inability, to use the permission for the resource. If the sender of the request does not have access to the policy, this field is omitted.
↳ relevance
int
The relevance of this policy to the overall determination in the TroubleshootIamPolicyResponse . If the sender of the request does not have access to the policy, this field is omitted.
getAccess
Indicates whether this policy provides the specified permission to the specified member for the specified resource.
This field does not
indicate whether the member actually has the
permission for the resource. There might be another policy that overrides
this policy. To determine whether the member actually has the permission,
use the access
field in the TroubleshootIamPolicyResponse
.
int
setAccess
Indicates whether this policy provides the specified permission to the specified member for the specified resource.
This field does not
indicate whether the member actually has the
permission for the resource. There might be another policy that overrides
this policy. To determine whether the member actually has the permission,
use the access
field in the TroubleshootIamPolicyResponse
.
var
int
$this
getFullResourceName
The full resource name that identifies the resource. For example, //compute.googleapis.com/projects/my-project/zones/us-central1-a/instances/my-instance
.
If the sender of the request does not have access to the policy, this field is omitted. For examples of full resource names for Google Cloud services, see https://cloud.google.com/iam/help/troubleshooter/full-resource-names .
string
setFullResourceName
The full resource name that identifies the resource. For example, //compute.googleapis.com/projects/my-project/zones/us-central1-a/instances/my-instance
.
If the sender of the request does not have access to the policy, this field is omitted. For examples of full resource names for Google Cloud services, see https://cloud.google.com/iam/help/troubleshooter/full-resource-names .
var
string
$this
getPolicy
The IAM policy attached to the resource.
If the sender of the request does not have access to the policy, this field is empty.
hasPolicy
clearPolicy
setPolicy
The IAM policy attached to the resource.
If the sender of the request does not have access to the policy, this field is empty.
$this
getBindingExplanations
Details about how each binding in the policy affects the member's ability, or inability, to use the permission for the resource.
If the sender of the request does not have access to the policy, this field is omitted.
setBindingExplanations
Details about how each binding in the policy affects the member's ability, or inability, to use the permission for the resource.
If the sender of the request does not have access to the policy, this field is omitted.
$this
getRelevance
The relevance of this policy to the overall determination in the TroubleshootIamPolicyResponse .
If the sender of the request does not have access to the policy, this field is omitted.
int
setRelevance
The relevance of this policy to the overall determination in the TroubleshootIamPolicyResponse .
If the sender of the request does not have access to the policy, this field is omitted.
var
int
$this