gcloud iam workload-identity-pools set-iam-policy (WORKLOAD_IDENTITY_POOL : --location=LOCATION) POLICY_FILE [GCLOUD_WIDE_FLAG …]
policy.json and sets it for the workload identity pool with ID
my-workload-identity-pool:
gcloud iam workload-identity-pools set-iam-policy my-workload-identity-pool policy.json --location="global"
To set the project attribute:
workload_identity_pool on the command line
with a fully specified name;
--project on the command line;
core/project.
WORKLOAD_IDENTITY_POOL
To set the workload_identity_pool attribute:
workload_identity_pool on the command line.
--location=LOCATIONlocation attribute:
workload_identity_pool on the command line
with a fully specified name;
--location on the command line.
POLICY_FILEget-iam-policy command is a valid file, as is any
JSON or YAML file conforming to the structure of a Policy.
--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
iam/v1 API. The full documentation for this
API can be found at: https://cloud.google.com/iam/
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.