Professional Data EngineerBuilding and operationalizing data processing systemsHard
A data engineer is implementing a custom data processing job on Compute Engine. This job needs to read data from a Cloud Storage bucket, process it, and then write the results to a BigQuery table. The engineer wants to grant the Compute Engine instance the necessary permissions securely and follow the principle of least privilege. Which Google Cloud identity should be associated with the Compute Engine instance to achieve this?
- AA user-managed service account with Storage Object Admin and BigQuery Data Editor roles.
- BA user-managed service account with Storage Object Viewer and BigQuery Data Editor roles.
- CA Google-managed service account with Project Editor role.
- DThe default Compute Engine service account with Storage Object Admin and BigQuery Admin roles.
Show answer & explanationAnswer & explanation
Correct answer: B. A user-managed service account with Storage Object Viewer and BigQuery Data Editor roles.
A user-managed service account allows for fine-grained control over permissions. The instance needs `Storage Object Viewer` to read from Cloud Storage and `BigQuery Data Editor` to write to BigQuery, adhering to the principle of least privilege.
Why the other options are wrong
- A. `Storage Object Admin` is excessive; `Storage Object Viewer` is sufficient for reading. `BigQuery Data Editor` is correct for writing.
- C. A Google-managed service account (like default App Engine) is not for custom Compute Engine instances. Project Editor is too broad.
- D. The default Compute Engine service account often has broad permissions by default, violating least privilege. `BigQuery Admin` is also excessive; `BigQuery Data Editor` is sufficient for writing data.
Google Cloud Service Account
Special Google accounts used by applications or Compute Engine instances to make authorized API calls.
- Acts as an identity for non-human components.
- Permissions are granted via IAM roles.
- User-managed service accounts allow for custom, fine-grained permissions.
Memory trick: Service accounts are the robots with specific job badges.