获取预留的 IAM 政策

检索 BigQuery 预留的 Identity and Access Management (IAM) 政策。该政策定义了哪些主账号拥有哪些角色,并用于查看资源的访问权限控制设置。

代码示例

Node.js

试用此示例之前,请按照 BigQuery 快速入门:使用客户端库中的 Node.js 设置说明进行操作。 如需了解详情,请参阅 BigQuery Node.js API 参考文档

如需向 BigQuery 进行身份验证,请设置应用默认凭证。如需了解详情,请参阅为客户端库设置身份验证

const {
  ReservationServiceClient,
} = require('@google-cloud/bigquery-reservation').v1;
const {status} = require('@grpc/grpc-js');

const client = new ReservationServiceClient();

/**
 * Gets the IAM policy for a reservation.
 * An IAM policy is a collection of bindings that associates one or more members,
 * such as service accounts or users, with a single role.
 *
 * @param {string} projectId - Google Cloud project ID, for example "example-project-id".
 * @param {string} location - Location of the reservation, for example "us-central1".
 * @param {string} reservationId - ID of the reservation, for example "example-reservation".
 */
async function getReservationIamPolicy(
  projectId,
  location = 'us-central1',
  reservationId = 'example-reservation',
) {
  const resource = `projects/${projectId}/locations/${location}/reservations/${reservationId}`;
  const request = {
    resource,
  };

  try {
    const [policy] = await client.getIamPolicy(request);

    console.log(`Policy for reservation ${reservationId}:`);
    if (policy.bindings && policy.bindings.length > 0) {
      console.log(JSON.stringify(policy.bindings, null, 2));
    } else {
      console.log('This reservation has no policy bindings.');
    }
  } catch (err) {
    if (err.code === status.NOT_FOUND) {
      console.log(
        `Reservation '${reservationId}' not found in project '${projectId}' at location '${location}'.`,
      );
    } else {
      console.error('Error getting IAM policy:', err);
    }
  }
}

Python

试用此示例之前,请按照 BigQuery 快速入门:使用客户端库中的 Python 设置说明进行操作。 如需了解详情,请参阅 BigQuery Python API 参考文档

如需向 BigQuery 进行身份验证,请设置应用默认凭证。如需了解详情,请参阅为客户端库设置身份验证

from google.api_core.exceptions import NotFound
from google.cloud import bigquery_reservation_v1

client = bigquery_reservation_v1.ReservationServiceClient()


def get_reservation_iam_policy(project_id: str, location: str, reservation_id: str):
    """Gets the IAM policy for a reservation.

    An IAM policy is a collection of bindings that associates one or more
    principals with a single role. This sample demonstrates how to retrieve
    the policy for a reservation.

    Args:
        project_id: The Google Cloud project ID.
        location: The geographic location of the reservation, such as "us-central1".
        reservation_id: The ID of the reservation to get the policy for.
    """
    resource = client.reservation_path(project_id, location, reservation_id)

    try:
        policy = client.get_iam_policy(resource=resource)

        print(f"Got IAM policy for reservation: {resource}")
        for binding in policy.bindings:
            print(f"  Role: {binding.role}")
            print(f"  Members: {binding.members}")
    except NotFound:
        print(f"Reservation not found: {resource}")

后续步骤

如需搜索和过滤其他 Google Cloud 产品的代码示例,请参阅Google Cloud 示例浏览器