Skip to content


Use this data source to get list of the Cloud Identity Group Memberships within a given Group.

Example Usage

/*Provider bindings are generated by running cdktf get.
See for more details.*/
import * as google from "./.gen/providers/google";
/*The following providers are missing schema information and might need manual adjustments to synthesize correctly: google.
For a more precise conversion please use the --provider flag in convert.*/
new google.dataGoogleCloudIdentityGroupMemberships.DataGoogleCloudIdentityGroupMemberships(
    group: "groups/123eab45c6defghi",

Argument Reference

  • group - The parent Group resource under which to lookup the Membership names. Must be of the form groups/{group_id}.

Attributes Reference

In addition to the arguments listed above, the following attributes are exported:

  • memberships - The list of memberships under the given group. Structure is documented below.

The memberships block contains:

  • name - The resource name of the Membership, of the form groups/{group_id}/memberships/{membership_id}.

  • roles - The MembershipRoles that apply to the Membership. Structure is documented below.

  • memberKey - (Optional) EntityKey of the member. Structure is documented below.

  • preferredMemberKey - (Optional) EntityKey of the member. Structure is documented below.

The roles block supports:

  • name - The name of the MembershipRole. One of OWNER, MANAGER, MEMBER.

The memberKey block supports:

  • id - The ID of the entity. For Google-managed entities, the id is the email address of an existing group or user. For external-identity-mapped entities, the id is a string conforming to the Identity Source's requirements.

  • namespace - The namespace in which the entity exists. If not populated, the EntityKey represents a Google-managed entity such as a Google user or a Google Group. If populated, the EntityKey represents an external-identity-mapped group.

The preferredMemberKey block supports:

  • id - The ID of the entity. For Google-managed entities, the id is the email address of an existing group or user. For external-identity-mapped entities, the id is a string conforming to the Identity Source's requirements.

  • namespace - The namespace in which the entity exists. If not populated, the EntityKey represents a Google-managed entity such as a Google user or a Google Group. If populated, the EntityKey represents an external-identity-mapped group.