Google Associate Cloud EngineerConfiguring access and securityMedium
A project manager needs to delegate the responsibility of managing virtual machine instances (creating, starting, stopping, deleting) within a specific Google Cloud project to a new operations engineer. The engineer should not have permissions to manage networking, IAM, or billing for the project. Which predefined IAM role is most appropriate for this task?
- AService Account User
- BCompute Network Admin
- CCompute Instance Admin (v1)
- DProject Editor
Show answer & explanationAnswer & explanation
Correct answer: C. Compute Instance Admin (v1)
The 'Compute Instance Admin (v1)' role (roles/compute.instanceAdmin.v1) provides comprehensive permissions for managing Compute Engine instances, including creating, starting, stopping, and deleting them, without granting broader project-level or other service-specific administrative privileges.
Why the other options are wrong
- A. Service Account User allows impersonating service accounts, not managing Compute Engine instances directly.
- B. Compute Network Admin is for managing networking resources, which the engineer should *not* have access to.
- D. Project Editor grants broad read/write access across many services, including networking, which violates the least privilege principle for this specific task.
Compute Instance Admin (v1) Role
A predefined IAM role that grants full administrative control over Compute Engine virtual machine instances.
- Includes permissions like `compute.instances.create`, `compute.instances.delete`, `compute.instances.start`, `compute.instances.stop`.
- Does not include permissions for networking, IAM, or billing.
- Ideal for operations teams managing VM lifecycles.
Memory trick: Instance Admin manages VMs, Network Admin manages wires, Editor changes all, and SA User just lends their attire.