Google Associate Cloud EngineerConfiguring access and securityMedium
A startup is building a serverless application using Cloud Functions. They need to grant a newly created service account the ability to invoke specific Cloud Functions within their project. However, they want to ensure this service account cannot deploy, delete, or modify the functions. Which IAM role should be assigned to the service account?
- ACloud Functions Invoker
- BCloud Functions Viewer
- CProject Editor
- DCloud Functions Developer
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Functions Invoker
The Cloud Functions Invoker role grants permission to invoke (call) a Cloud Function. This role aligns perfectly with the principle of least privilege, as it allows execution without granting deployment or management capabilities, which is exactly what the scenario requires.
Why the other options are wrong
- B. This role only provides read-only access to Cloud Functions, which is insufficient for invoking them.
- C. This role grants broad editing permissions across an entire project, violating the principle of least privilege.
- D. This role grants permissions to deploy, delete, and manage Cloud Functions, exceeding the requirement.
Cloud Functions Invoker Role
The Cloud Functions Invoker role grants permission to execute a Cloud Function.
- Allows invocation of published Cloud Functions.
- Does not grant permissions to deploy, delete, or manage functions.
- Essential for service accounts or users that need to trigger functions programmatically.
Memory trick: Invoker just triggers, doesn't build or destroy.