Sets the IAM access control policy for an Engine. A NOT_FOUND error is returned if the resource does not exist.
Important: When setting a policy directly on an Engine resource, the only recommended roles in the bindings are: roles/discoveryengine.user and roles/discoveryengine.agentspaceUser. Attempting to grant any other role will result in a warning in logging.
HTTP request
POST https://discoveryengine.googleapis.com/v1/{resource=projects/*/locations/*/collections/*/engines/*}:setIamPolicy
The URL uses gRPC Transcoding syntax.
Path parameters
| Parameters | |
|---|---|
resource |
REQUIRED: The resource for which the policy is being specified. See Resource names for the appropriate value for this field. |
Request body
The request body contains data with the following structure:
| JSON representation |
|---|
{
"policy": {
object ( |
| Fields | |
|---|---|
policy |
REQUIRED: The complete policy to be applied to the |
Response body
If successful, the response body contains an instance of Policy.
Authorization scopes
Requires one of the following OAuth scopes:
https://www.googleapis.com/auth/cloud-platformhttps://www.googleapis.com/auth/discoveryengine.readwrite
For more information, see the Authentication Overview.
IAM Permissions
Requires the following IAM permission on the resource resource:
discoveryengine.engines.setIamPolicy
For more information, see the IAM documentation.