Google Associate Cloud EngineerConfiguring access and securityMedium
A data engineering team needs to grant a newly created service account the ability to invoke Cloud Functions for data processing. This service account should only be able to trigger the function and not modify its configuration or deploy new versions. Which IAM role should be assigned to the service account?
- Aroles/iam.serviceAccountUser
- Broles/cloudfunctions.invoker
- Croles/cloudfunctions.developer
- Droles/editor
Show answer & explanationAnswer & explanation
Correct answer: B. roles/cloudfunctions.invoker
The 'Cloud Functions Invoker' role (roles/cloudfunctions.invoker) grants the specific permission to invoke Cloud Functions, which aligns with the requirement to trigger the function without granting broader development or administrative permissions.
Why the other options are wrong
- A. roles/iam.serviceAccountUser allows impersonating a service account, which is different from granting a service account permission to invoke a function itself.
- C. roles/cloudfunctions.developer grants broad permissions including deploying, updating, and deleting functions, which is more than just invoking.
- D. roles/editor provides broad read/write access across many services in a project, violating the principle of least privilege.
Cloud Functions Invoker Role
An IAM role that grants permission to trigger or invoke a Google Cloud Function.
- Contains the `cloudfunctions.functions.invoke` permission.
- Does not allow modifying, deploying, or deleting functions.
- Essential for services or users that only need to execute a function.
Memory trick: Invoker just triggers, Developer builds, Editor changes everything, Service Account User acts as another.