Google Associate Cloud EngineerConfiguring access and securityMedium

A project manager needs to delegate the responsibility of managing virtual machine instances (creating, starting, stopping, deleting) within a specific Google Cloud project to a new operations engineer. The engineer should not have permissions to manage networking, IAM, or billing for the project. Which predefined IAM role is most appropriate for this task?

  1. AService Account User
  2. BCompute Network Admin
  3. CCompute Instance Admin (v1)
  4. DProject Editor
Show answer & explanation

Correct answer: C. Compute Instance Admin (v1)

The 'Compute Instance Admin (v1)' role (roles/compute.instanceAdmin.v1) provides comprehensive permissions for managing Compute Engine instances, including creating, starting, stopping, and deleting them, without granting broader project-level or other service-specific administrative privileges.

Why the other options are wrong

  • A. Service Account User allows impersonating service accounts, not managing Compute Engine instances directly.
  • B. Compute Network Admin is for managing networking resources, which the engineer should *not* have access to.
  • D. Project Editor grants broad read/write access across many services, including networking, which violates the least privilege principle for this specific task.

Compute Instance Admin (v1) Role

A predefined IAM role that grants full administrative control over Compute Engine virtual machine instances.

  • Includes permissions like `compute.instances.create`, `compute.instances.delete`, `compute.instances.start`, `compute.instances.stop`.
  • Does not include permissions for networking, IAM, or billing.
  • Ideal for operations teams managing VM lifecycles.

Memory trick: Instance Admin manages VMs, Network Admin manages wires, Editor changes all, and SA User just lends their attire.

More Configuring access and security questions