A company wants to ensure strict security for its Google Cloud projects. They require that only specific, pre-approved service accounts can be used to deploy resources in production projects. No individual user accounts should have direct deployment permissions in production. How can this be achieved using IAM?
- AUse IAM Conditions to restrict deployment based on IP address for user accounts.
- BAssign custom roles with deployment permissions to approved service accounts and grant 'Viewer' role to users.
- CGrant 'Project Editor' role to approved service accounts and remove it from all user accounts.
- DCreate a new organization policy that disallows user accounts from deploying resources.
Show answer & explanationAnswer & explanation
Correct answer: B. Assign custom roles with deployment permissions to approved service accounts and grant 'Viewer' role to users.
By creating custom roles with only the necessary deployment permissions and assigning these exclusively to approved service accounts, the company can ensure that only automated processes (via service accounts) deploy resources. Granting 'Viewer' or other less privileged roles to user accounts prevents direct human deployment while allowing them to monitor. This aligns with the principle of least privilege and automation for production deployments.
Why the other options are wrong
- A. IAM Conditions can restrict access but are not the primary mechanism to enforce 'only service accounts can deploy'. They typically layer on top of roles, and IP restrictions don't prevent a user with a deploy role from deploying if they meet the IP condition.
- C. 'Project Editor' is a broad predefined role; custom roles are better for least privilege. Simply removing it from users doesn't enforce service account-only deployment.
- D. Organization Policies primarily enforce constraints on resource configurations or locations, not directly on who (user vs. service account) can perform specific actions, which is the domain of IAM roles.
IAM: Service Account Deployment Strategy
To enforce service account-only deployment in Google Cloud, create custom IAM roles with specific deployment permissions and assign them exclusively to approved service accounts, while granting user accounts only view-level access.
- Leverages custom roles for granular permission control.
- Service accounts perform automated deployments.
- User accounts are restricted to monitoring and management, not direct deployment.
- Adheres to the principle of least privilege.
Memory trick: Custom 'R'oles for 'R'obots, 'R'estricted 'R'ights for 'R'eal people.