gcloud container binauthz attestors remove-iam-policy-binding ATTESTOR --member=PRINCIPAL --role=ROLE [--all | --condition=[KEY=VALUE,…] | --condition-from-file=PATH_TO_FILE] [GCLOUD_WIDE_FLAG …]
roles/binaryauthorization.attestorsEditor for the user
test-user@gmail.com on attestor my_attestor, run:
gcloud container binauthz attestors remove-iam-policy-binding my_attestor --member='user:test-user@gmail.com' --role='roles/binaryauthorization.attestorsEditor'
To remove an IAM policy binding which expires at the end of the year 2018 for
the role of roles/binaryauthorization.attestorsEditor and the user
test-user@gmail.com on attestor my_attestor, run:
gcloud container binauthz attestors remove-iam-policy-binding my_attestor --member='user:test-user@gmail.com' --role='roles/binaryauthorization.attestorsEditor' --condition='expression=request.time <
timestamp("2019-01-01T00:00:00Z"),title=expires_end_of_2018,descrip\
tion=Expires at midnight on 2018-12-31'
To set the project attribute:
attestor on the command line with a fully
specified name;
--project on the command line;
core/project.
ATTESTORattestor attribute:
attestor on the command line.
--member=PRINCIPALuser|group|serviceAccount:email or domain:domain.
Examples: user:test-user@gmail.com,
group:admins@example.com,
serviceAccount:test123@example.domain.com, or
domain:example.domain.com.
Deleted principals have an additional deleted: prefix and a
?uid=UID suffix, where is
a unique identifier for the principal. Example:
UIDdeleted:user:test-user@gmail.com?uid=123456789012345678901.
allUsers - Special identifier that represents anyone who is on the
internet, with or without a Google account.
allAuthenticatedUsers - Special identifier that represents anyone
who is authenticated with a Google account or a service account.
--role=ROLE--all--condition=[KEY=VALUE,…]None (--condition=None), a
binding without a condition is removed. Otherwise, only a binding with a
condition that exactly matches the specified condition (including the optional
description) is removed. For more on conditions, refer to the conditions
overview guide: https://cloud.google.com/iam/docs/conditions-overview
When using the --condition flag, include the following key-value
pairs:
expression:) as the delimiter, do the
following: --condition=^:^title=TITLE:expression=EXPRESSION. For
more information, see https://cloud.google.com/sdk/gcloud/reference/topic/escaping.
titledescription--condition-from-file=PATH_TO_FILE--condition. Use a full or relative path
to a local file containing the value of condition.
--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
binaryauthorization/v1alpha2 API. The full
documentation for this API can be found at: https://cloud.google.com/binary-authorization/
gcloud alpha container binauthz attestors remove-iam-policy-bindinggcloud beta container binauthz attestors remove-iam-policy-binding
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.