A software company uses Google Cloud Secret Manager to store API keys for various third-party services. They want to ensure that access to these secrets is granted only to specific service accounts and that these service accounts can only retrieve the latest active version of a secret. Which IAM roles and conditions should be applied?
- ASecret Manager Secret Viewer role with a condition on 'secretmanager.secretVersion.access' method.
- BSecret Manager Secret Accessor role with a condition on 'secretmanager.secretVersion.access' method and 'resource.name' ending with '/versions/latest'.
- CSecret Manager Secret Accessor role with a condition on 'resource.name' for specific secrets.
- DSecret Manager Secret Version Manager role with a condition on 'secretmanager.secretVersion.get' method.
Show answer & explanationAnswer & explanation
Correct answer: B. Secret Manager Secret Accessor role with a condition on 'secretmanager.secretVersion.access' method and 'resource.name' ending with '/versions/latest'.
The 'Secret Manager Secret Accessor' role grants permission to access secret payloads. Combining this with a condition on the 'secretmanager.secretVersion.access' method ensures they can only retrieve versions, and the 'resource.name' ending with '/versions/latest' specifically restricts access to only the latest active version, fulfilling both requirements.
Why the other options are wrong
- A. The 'Secret Viewer' role can only view metadata, not access the secret payload. The condition is correct for accessing payload, but the role is wrong.
- C. This role grants access to all versions of the specified secret, not just the latest, and doesn't explicitly restrict to the access method.
- D. The 'Secret Version Manager' role is for managing secret versions (e.g., destroying, disabling), not for accessing the payload, and the condition is on a non-existent method for this role's purpose.
Secret Manager Access with IAM Conditions
Using IAM roles combined with IAM Conditions to grant granular access to Secret Manager resources, such as restricting access to only the latest version of a secret or specific actions.
- Role 'Secret Manager Secret Accessor' grants payload access.
- IAM Conditions filter access based on resource attributes or request properties.
- 'resource.name' can filter by secret or version path.
- 'secretmanager.secretVersion.access' is the method for payload retrieval.
Memory trick: To unlock a secret, combine the right role with a strict condition, or risk over-permission!