Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A security engineer is tasked with ensuring that all service account keys (JSON files) used by applications within a Google Cloud project are rotated quarterly. Currently, applications are using long-lived service account keys that are stored directly on compute instances. The engineer wants to automate the rotation process and eliminate the need for manual key management and distribution. How should the engineer achieve this?

  1. AConfigure Workload Identity to allow applications running on GKE or Compute Engine to impersonate service accounts.
  2. BImplement a Cloud Function that periodically generates new service account keys and updates application configurations.
  3. CUse API keys instead of service account keys for all applications and rotate them manually.
  4. DStore service account keys in Cloud Storage and use a cron job to replace them every quarter.
Show answer & explanation

Correct answer: A. Configure Workload Identity to allow applications running on GKE or Compute Engine to impersonate service accounts.

Workload Identity is the recommended and most secure way to grant Google Kubernetes Engine (GKE) or Compute Engine applications access to Google Cloud services. It allows a Kubernetes service account or a Compute Engine VM to act as a Google Cloud service account, automatically obtaining short-lived credentials without the need for managing and rotating long-lived service account keys (JSON files).

Why the other options are wrong

  • B. While a Cloud Function could automate key generation, it still involves managing the distribution and updating application configurations, which Workload Identity aims to eliminate. It doesn't solve the fundamental problem of long-lived key files.
  • C. API keys are not suitable for authenticating applications to Google Cloud services for authorized access to resources. They are typically for public APIs and don't provide identity or fine-grained IAM control.
  • D. Storing service account keys in Cloud Storage is a security anti-pattern, as it centralizes sensitive credentials in a potentially accessible bucket. A cron job for replacement still involves managing and distributing these long-lived files, which is what Workload Identity avoids.

Workload Identity (GCP)

A feature that allows workloads running on Google Kubernetes Engine (GKE) or Compute Engine to securely access Google Cloud services by acting as a Google Cloud service account, eliminating the need for service account key files.

  • Provides short-lived, automatically rotated credentials.
  • Enhances security by removing long-lived key files.
  • Integrates Kubernetes service accounts with Google Cloud service accounts.

Memory trick: Workload Identity 'retires' old keys for 'fresh' ones, automatically.

More Configuring access within a cloud solution environment questions