Google Associate Cloud EngineerSetting up a cloud solution environmentMedium
A large enterprise is migrating a complex application to Google Cloud. The application requires access to various Google Cloud services (e.g., Cloud Storage, BigQuery, Compute Engine) across multiple projects. Security best practices dictate that credentials should not be stored directly within the application code or configuration files. How should the application be configured to authenticate to Google Cloud services when deployed on a Compute Engine instance?
- AUse `gcloud auth login` on the Compute Engine instance after deployment.
- BAssign a service account to the Compute Engine instance and grant it the necessary IAM roles.
- CMount a service account key file directly into the Compute Engine instance and configure the application to use it.
- DEmbed API keys as environment variables in the instance's startup script.
Show answer & explanationAnswer & explanation
Correct answer: B. Assign a service account to the Compute Engine instance and grant it the necessary IAM roles.
Assigning a service account to a Compute Engine instance is the recommended and most secure method for applications running on GCP to authenticate. The instance's metadata server provides temporary, automatically rotated credentials, eliminating the need to manage key files.
Why the other options are wrong
- A. `gcloud auth login` is for interactive user authentication, not for automated application authentication on a Compute Engine instance.
- C. Mounting key files is less secure as it involves managing static credentials; the metadata server approach is preferred.
- D. Embedding API keys or any credentials in environment variables or startup scripts is insecure and not recommended for production applications.
Service Accounts for GCP Instances
Service accounts are identities used by applications or Compute Engine instances to make authenticated API calls to Google Cloud services without user intervention. They are the recommended secure way to grant permissions to workloads running on GCP.
- Recommended for applications on Compute Engine, GKE, Cloud Run, etc.
- Credentials provided by instance metadata server (automatically rotated).
- Permissions granted via IAM roles to the service account.
Memory trick: Assign a service account to your instance for secure, automatic access.