Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A development team is deploying a new application to Google Kubernetes Engine (GKE). The application needs to access Google Cloud Storage, Cloud SQL, and publish messages to a Pub/Sub topic. The security team mandates that no service account keys (JSON files) should be distributed or stored in the GKE cluster. How should the application be configured to securely access Google Cloud services?

  1. AUse Workload Identity to link Kubernetes service accounts to Google Cloud service accounts.
  2. BCreate a custom IAM role with all necessary permissions and assign it directly to the GKE nodes.
  3. CEmbed a base64-encoded service account key directly into the application container image.
  4. DMount a Kubernetes Secret containing a service account key file to the application pods.
Show answer & explanation

Correct answer: A. Use Workload Identity to link Kubernetes service accounts to Google Cloud service accounts.

Workload Identity is the recommended way for applications running in GKE to securely access Google Cloud services. It allows you to link Kubernetes service accounts to Google Cloud service accounts, enabling applications to authenticate as the Google Cloud service account without needing to store or distribute service account keys.

Why the other options are wrong

  • B. Assigning a broad role to GKE nodes grants all pods on that node the same permissions, violating the principle of least privilege and not allowing per-application segmentation.
  • C. Embedding keys in container images is a major security risk and violates the mandate against storing keys.
  • D. This violates the security mandate of not distributing or storing service account keys.

Workload Identity (GKE)

A Google Cloud feature that allows Kubernetes service accounts in GKE to act as Google Cloud service accounts, enabling secure access to Google Cloud services without exposing service account keys.

  • Eliminates the need for service account key files.
  • Provides granular, per-pod identity for Google Cloud resources.
  • Uses short-lived credentials for enhanced security.

Memory trick: Workload Identity Works Wonders for Kubernetes.

More Configuring access within a cloud solution environment questions