Google Associate Cloud EngineerConfiguring access and securityMedium
A data engineering team needs a service account to run batch jobs on Compute Engine instances. These jobs will access data stored in Cloud Storage buckets. To minimize the attack surface, the security team mandates that the service account should not have any directly attached keys, and its credentials should be automatically managed by Google Cloud. Which authentication method should the team use for this service account?
- AOAuth 2.0 client IDs
- BWorkload Identity Federation for GKE
- CService account keyless authentication
- DUser-managed service account keys
Show answer & explanationAnswer & explanation
Correct answer: C. Service account keyless authentication
Service account keyless authentication (also known as attached service accounts or managed credentials) involves assigning a service account directly to a Compute Engine instance or other Google Cloud resource. Google Cloud then automatically manages the credentials for the service account, eliminating the need for user-managed keys and enhancing security.
Why the other options are wrong
- A. OAuth 2.0 client IDs are typically used for user authentication to applications, not for service accounts to authenticate to Google Cloud services directly without keys.
- B. Workload Identity Federation for GKE is specific to Kubernetes Engine pods accessing Google Cloud, not general Compute Engine instances without keys.
- D. User-managed service account keys are explicit files that can be downloaded, which violates the 'no directly attached keys' requirement.
Service Account Keyless Authentication
Service account keyless authentication refers to the practice of attaching a service account directly to a Google Cloud resource (like a VM) so that Google Cloud manages its credentials automatically.
- Eliminates the need to create, download, and manage service account keys.
- Reduces the risk of key compromise and improves security posture.
- The attached resource receives credentials automatically from the metadata server.
Memory trick: No keys, no worries; Google handles the locks.