Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy

A development team is deploying a new application to Google Kubernetes Engine (GKE) and requires the pods to securely access Google Cloud Storage (GCS) buckets. The security team mandates that no service account keys should be stored directly within the GKE pods or application code. Which Google Cloud IAM feature should the development team use to meet this requirement?

  1. AUse API keys with appropriate restrictions for GCS access.
  2. BCreate a new service account key and inject it as a Kubernetes Secret.
  3. CGrant the 'Storage Object Admin' role directly to the default GKE Compute Engine service account.
  4. DConfigure Workload Identity for the GKE cluster and link Kubernetes service accounts to Google Cloud service accounts.
Show answer & explanation

Correct answer: D. Configure Workload Identity for the GKE cluster and link Kubernetes service accounts to Google Cloud service accounts.

Workload Identity allows Kubernetes service accounts to act as Google Cloud service accounts, eliminating the need to store service account keys directly in pods. This is the recommended and most secure approach for GKE authentication to Google Cloud services.

Why the other options are wrong

  • A. API keys are generally used for unauthenticated or public access to certain APIs and are not suitable for fine-grained, identity-based access to GCS buckets from a GKE application.
  • B. Storing service account keys as Kubernetes Secrets is less secure than Workload Identity and violates the requirement of not storing keys directly.
  • C. Granting broad roles to the default Compute Engine service account can lead to over-permissioning and is not granular enough for specific application needs.

Workload Identity (GKE)

Workload Identity allows applications running in Google Kubernetes Engine (GKE) to authenticate to Google Cloud services as a Google Cloud service account, without needing to store or manage service account keys.

  • Eliminates the need for service account keys in pods.
  • Maps Kubernetes service accounts to Google Cloud service accounts.
  • Enhances security by using short-lived credentials.

Memory trick: GKE's Identity is Keyless.

More Configuring access within a cloud solution environment questions