Google Associate Cloud EngineerConfiguring access and securityMedium

You are setting up a new Google Cloud project for an internal application. The application will use a service account to access various Google Cloud services. As a security best practice, you want to ensure that this service account does not have a static key file that could be compromised. How should you configure the service account for authentication?

  1. AGenerate a key file and store it securely in a dedicated Cloud Storage bucket.
  2. BEmbed the service account's email and password directly into the application code.
  3. CAttach the service account directly to the Compute Engine or GKE resource.
  4. DCreate a custom IAM role with `serviceAccount.keys.create` permission.
Show answer & explanation

Correct answer: C. Attach the service account directly to the Compute Engine or GKE resource.

Attaching a service account directly to a Compute Engine instance, GKE node, or Cloud Function allows the resource to obtain short-lived credentials automatically through the metadata server, eliminating the need for static key files.

Why the other options are wrong

  • A. Storing key files, even in Cloud Storage, still presents a risk of compromise and requires careful management and rotation, which is what we want to avoid.
  • B. Embedding credentials in code is a severe security vulnerability and should never be done.
  • D. Creating a custom IAM role with `serviceAccount.keys.create` permission would allow *creating* static key files, which is the opposite of the desired outcome.

Service Account Keyless Authentication

The practice of using Google Cloud service accounts without generating and managing static key files, typically by attaching the service account directly to a Google Cloud resource.

  • Relies on the instance metadata server to provide short-lived credentials.
  • Reduces the risk of key compromise and simplifies key management.
  • Recommended for Compute Engine, GKE, Cloud Functions, App Engine, etc.

Memory trick: Attach, don't store, for a keyless secure core.

More Configuring access and security questions