Google Associate Cloud EngineerConfiguring access and securityMedium

A development team is deploying a new application to Google Kubernetes Engine (GKE). The application needs to access data stored in a Cloud Storage bucket within the same Google Cloud project. To ensure the application has the necessary permissions while adhering to the principle of least privilege, which IAM role should be granted to the GKE service account for accessing the Cloud Storage bucket?

  1. Aroles/viewer
  2. Broles/storage.objectViewer
  3. Croles/storage.admin
  4. Droles/editor
Show answer & explanation

Correct answer: B. roles/storage.objectViewer

The application only needs to read data from the Cloud Storage bucket. The 'Storage Object Viewer' role (roles/storage.objectViewer) provides read-only access to objects, aligning with the principle of least privilege. Other roles provide broader, unnecessary permissions.

Why the other options are wrong

  • A. This role grants read-only access to all resources in a project, which is broader than necessary for just accessing a specific Cloud Storage bucket's objects.
  • C. This role grants full administrative control over Cloud Storage, which is excessive for an application merely needing to read data.
  • D. This role grants extensive permissions across most Google Cloud services in a project, far exceeding the requirement to read from a Cloud Storage bucket.

Storage Object Viewer Role

The `roles/storage.objectViewer` IAM role grants read-only access to objects within a Cloud Storage bucket.

  • Allows listing and getting objects.
  • Does not allow creating, updating, or deleting objects.
  • Adheres to the principle of least privilege for read-only access.

Memory trick: Remember, 'Viewer' sees, 'Admin' owns, 'Editor' changes.

More Configuring access and security questions