Google Associate Cloud EngineerSetting up a cloud solution environmentHard

A company is onboarding new developers who need to interact with Google Cloud resources from their local machines using Python client libraries. They want to ensure that these developers can authenticate securely without storing long-lived credentials directly on their machines. Which authentication method should be recommended?

  1. AInstruct developers to run `gcloud auth application-default login`.
  2. BUse API keys for authentication with the client libraries.
  3. CRequire developers to manually set `GOOGLE_APPLICATION_CREDENTIALS` environment variable.
  4. DGenerate and distribute service account keys to each developer.
Show answer & explanation

Correct answer: A. Instruct developers to run `gcloud auth application-default login`.

The `gcloud auth application-default login` command authenticates a user's Google account and sets up Application Default Credentials (ADC) for their local environment. This allows client libraries to automatically find and use the user's credentials, which are short-lived tokens, without requiring the storage of sensitive long-lived service account keys on local machines.

Why the other options are wrong

  • B. API keys are for authenticating projects to public APIs, not for authenticating user or service accounts to access private resources, and they grant very limited permissions.
  • C. Manually setting `GOOGLE_APPLICATION_CREDENTIALS` typically points to a service account key file, which is what the question aims to avoid due to security concerns.
  • D. Distributing service account keys is insecure as they are long-lived and could be compromised if stored locally.

Application Default Credentials (ADC) for Users

Application Default Credentials (ADC) allow Google Cloud client libraries to automatically find and use credentials, often generated via `gcloud auth application-default login` for user accounts, providing secure, short-lived authentication.

  • Provides credentials for client libraries.
  • Uses short-lived tokens from user's Google account.
  • Avoids storing long-lived service account keys locally.
  • Simplifies authentication for local development.

Memory trick: For 'ADC' with 'Developers', 'Auth App-Default Login' is the 'C'hoice.

More Setting up a cloud solution environment questions