Skip to main content
A role binding grants a role on a resource to one or more subjects. It is separate from the resource manifest, so you can change access without editing the resource. Apply it with tfy apply, or with Create or update a role binding. Re-applying the same name updates that binding.
Use either one subject and many permissions, or many subjects and one permission. A binding cannot have many of both. To give several people several roles, split it into one binding per role. To grant the same access from the UI, use Access Control on the resource. See Manage User Roles & Permissions.