Get roles for a keyring key and optionally write them to a file. See below for the options supported by the cloudkey commands.

<name>

Name to assign to a new cloud key.

--name

Select a cloud key by name. 

The command may also require its provider resource.

--region

Region containing or used for the key.

--keyvault

Key vault containing or associated with the key.

--managedhsm

Managed HSM containing or associated with the key.

--keyring

Keyring containing or associated with the key.

--handle

Identify a key by its handle where supported.

--description

Optional human-readable description of the key.

--cipher

Cipher to use for the key.

--protection_level

GCP protection level or EKM connection type.

--purpose

Intended purpose of the key.

--algorithm

Key algorithm.

--hardware_protected

Request hardware protection for the key.

--rekey_interval

Rekey interval for the key.

--no-expire

Specify that the key should not expire.

--expire_date

Expiration date in mm/dd/yyyy format or a number of days.

--relative_expiry

Specify whether the expiry value is relative: True or False.

--no-key-wide-expire

Specify that the key should not use key-wide expiry.

--key_wide_expire_date

Key-wide expiration date in mm/dd/yyyy format.

--expire_action

Expiration action: DISABLE, DELETE_FROM_CLOUD, or DELETE.

--operations

Operations to allow for the key.

--activation_date

Date when the key should become active.

--ekm_connection

EKM connection to associate with the key.

--dke_permissions

DKE permissions to configure for the key.

--dke_cache

DKE cache setting.

--oci_compartment_id

OCI compartment ID for the key.

--sfdc_data_type

Salesforce data type associated with the key.

--sfdc_use_derivation

Salesforce key-derivation setting.

--sfdc_cache_only_key

Salesforce cache-only-key setting.

--after_days

Number of days before scheduled key removal.

--cancel

Cancel a scheduled key removal.

--force_purge

Force-purge option for the purge operation.

--key

Tag name to set or clear.

--value

Value to assign to a tag.

--user_list

User list supplied to the cloud key command.

--admin_list

Administrator list supplied to the cloud key command.

--in

Input file for policy, role, KAJ policy, or EKM ACL data.

--out

Output file for policy or role data.

--guid

GUID of the key version to set as primary.