Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A project manager needs to grant a new contractor temporary access to a specific Cloud Storage bucket for a data migration task. The contractor should only be able to read and write objects in that single bucket and must have their access automatically revoked after 48 hours. The security engineer wants to achieve this with minimal manual intervention. How should the security engineer configure access?

  1. ACreate a service account, grant it 'roles/storage.objectAdmin' on the bucket, and manually delete the service account after 48 hours.
  2. BGenerate a signed URL for each object in the bucket and provide them to the contractor.
  3. CGrant the contractor's user account 'roles/storage.objectAdmin' on the bucket with an IAM Condition that includes a time-based expiration.
  4. DGrant the contractor's user account 'roles/editor' on the project and remind them to revoke their own access after 48 hours.
Show answer & explanation

Correct answer: C. Grant the contractor's user account 'roles/storage.objectAdmin' on the bucket with an IAM Condition that includes a time-based expiration.

IAM Conditions allow you to grant a role binding conditionally based on various attributes, including time. By setting a time-based expiration on the role binding for the contractor's user account, access will be automatically revoked after 48 hours, adhering to the principle of least privilege and minimizing manual intervention.

Why the other options are wrong

  • A. While using a service account is possible, manually deleting it introduces human error and doesn't guarantee automatic revocation. A service account is also typically for automated workloads, not human contractors.
  • B. Signed URLs are for granting temporary access to *specific objects*, not for managing a contractor's role-based access to an entire bucket for multiple operations. It would be impractical for a data migration task involving many files.
  • D. Granting 'roles/editor' on the *project* is overly permissive and violates the principle of least privilege. Relying on the contractor to revoke their own access is a significant security risk.

IAM Conditions (Time-based)

A feature of Google Cloud IAM that allows you to grant access only if specified conditions are met, such as a specific time window, resource attributes, or request attributes.

  • Enforces granular, context-aware access control.
  • Supports `request.time` for time-based access (e.g., expiration).
  • Helps implement temporary access and least privilege.

Memory trick: IAM Conditions are the 'timer' for your 'access key'.

More Configuring access within a cloud solution environment questions