Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A company is migrating several legacy monolithic applications to Google Cloud. These applications currently connect to an on-premises Oracle database using a specific username and password stored in configuration files. The security team wants to modernize this, eliminate hardcoded credentials, and ensure that the new microservices running on Compute Engine can securely connect to a Cloud SQL for PostgreSQL instance. Which IAM capability should be used to achieve this without distributing secrets?

  1. AStore database credentials in Secret Manager and retrieve them programmatically.
  2. BEmbed the database username and password as environment variables in the Compute Engine instances.
  3. CConfigure Cloud SQL IAM database authentication for the Compute Engine service account.
  4. DUse API keys for Cloud SQL database access.
Show answer & explanation

Correct answer: C. Configure Cloud SQL IAM database authentication for the Compute Engine service account.

Cloud SQL IAM database authentication allows Compute Engine service accounts to authenticate to Cloud SQL instances directly, leveraging the service account's identity instead of traditional usernames and passwords. This eliminates the need to store or distribute database credentials, enhancing security.

Why the other options are wrong

  • A. While Secret Manager is good for secrets, Cloud SQL IAM database authentication is even better as it removes the need for *any* secret for database access from a service account. Secret Manager would still require the application to retrieve and manage a secret.
  • B. Embedding credentials as environment variables is insecure and violates the goal of eliminating hardcoded credentials.
  • D. API keys are not used for authenticating to Cloud SQL databases; they are for API calls to Google Cloud services.

Cloud SQL IAM Database Authentication

Cloud SQL IAM database authentication allows users and service accounts to connect to Cloud SQL instances using their IAM identity rather than traditional database usernames and passwords.

  • Eliminates static database credentials.
  • Leverages IAM for database access control.
  • Supports both user and service account authentication.

Memory trick: IAM authenticates to SQL, no secrets needed.

More Configuring access within a cloud solution environment questions