gcloud iam workload-identity-pools add-attestation-rule (WORKLOAD_IDENTITY_POOL : --location=LOCATION) --google-cloud-resource=GOOGLE_CLOUD_RESOURCE [--async] [GCLOUD_WIDE_FLAG …]
my-pool.
gcloud iam workload-identity-pools add-attestation-rule my-pool --location="global" --google-cloud-resource="//run.googleapis.com/projects/123/type/Service/*"
To set the project attribute:
workload_identity_pool on the command line
with a fully specified name;
--project on the command line;
core/project.
WORKLOAD_IDENTITY_POOL
To set the workload_identity_pool attribute:
workload_identity_pool on the command line.
--location=LOCATIONlocation attribute:
workload_identity_pool on the command line
with a fully specified name;
--location on the command line.
--google-cloud-resource=GOOGLE_CLOUD_RESOURCE--async--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.