gcloud alpha compute instance-groups managed test-iam-permissions

NAME
gcloud alpha compute instance-groups managed test-iam-permissions - test IAM permissions for a Compute Engine managed instance group
SYNOPSIS
gcloud alpha compute instance-groups managed test-iam-permissions NAME --permissions =[PERMISSION,…] [--region =REGION | --zone =ZONE] [GCLOUD_WIDE_FLAG]
DESCRIPTION
(ALPHA) gcloud alpha compute instance-groups managed test-iam-permissions tests the IAM permissions that a caller has on a Compute Engine managed instance group.

Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may "fail open" without warning.

EXAMPLES
To test if the caller has compute.instanceGroupManagers.get and compute.instanceGroupManagers.update permissions on a zonal managed instance group my-mig in zone us-central1-a, run:
gcloudalphacomputeinstance-groupsmanagedtest-iam-permissionsmy-mig--zone=us-central1-a--permissions=compute.instanceGroupManagers.get,compute.instanceGroupManagers.update

To test permissions on a regional managed instance group my-rmig in region us-central1, run:

gcloudalphacomputeinstance-groupsmanagedtest-iam-permissionsmy-rmig--region=us-central1--permissions=compute.instanceGroupManagers.get,compute.instanceGroupManagers.update
POSITIONAL ARGUMENTS
NAME
Name of the managed instance group to test IAM permissions for.
REQUIRED FLAGS
--permissions=[PERMISSION,…]
The set of permissions to check for the resource.
OPTIONAL FLAGS
At most one of these can be specified:
--region=REGION
Region of the managed instance group to test IAM permissions for. If not specified, you might be prompted to select a region (interactive mode only).

A list of regions can be fetched by running:

gcloudcomputeregionslist 

Overrides the default compute/region property value for this command invocation.

--zone=ZONE
Zone of the managed instance group to test IAM permissions for. If not specified, you might be prompted to select a zone (interactive mode only).

A list of zones can be fetched by running:

gcloudcomputezoneslist 

Overrides the default compute/zone property value for this command invocation.

GCLOUD WIDE FLAGS
These flags are available to all commands: --access-token-file , --account , --billing-project , --configuration , --flags-file , --flatten , --format , --help , --impersonate-service-account , --log-http , --project , --quiet , --trace-token , --user-output-enabled , --verbosity .

Run $ gcloud help for details.

NOTES
This command is currently in alpha and might change without notice. If this command fails with API permission errors despite specifying the correct project, you might be trying to access an API with an invitation-only early access allowlist.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026年06月23日 UTC.