gcloud compute machine-images remove-iam-policy-binding MACHINE_IMAGE --member=PRINCIPAL --role=ROLE [GCLOUD_WIDE_FLAG …]
gcloud compute machine-images remove-iam-policy-binding my-image --member='user:test-user@gmail.com' --role='roles/compute.admin'
To set the project attribute:
machine_image on the command line with a fully
specified name;
--project on the command line;
core/project.
MACHINE_IMAGEmachine_image attribute:
machine_image on the command line.
--member=PRINCIPALuser|group|serviceAccount:email or domain:domain.
Examples: user:test-user@gmail.com,
group:admins@example.com,
serviceAccount:test123@example.domain.com, or
domain:example.domain.com.
Deleted principals have an additional deleted: prefix and a
?uid=UID suffix, where is
a unique identifier for the principal. Example:
UIDdeleted:user:test-user@gmail.com?uid=123456789012345678901.
allUsers - Special identifier that represents anyone who is on the
internet, with or without a Google account.
allAuthenticatedUsers - Special identifier that represents anyone
who is authenticated with a Google account or a service account.
--role=ROLE--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
compute/v1 API. The full documentation for
this API can be found at: https://cloud.google.com/compute/
gcloud alpha compute machine-images remove-iam-policy-bindinggcloud beta compute machine-images remove-iam-policy-bindinggcloud preview compute machine-images remove-iam-policy-binding
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.