Google Associate Cloud EngineerSetting up a cloud solution environmentMedium

A company is onboarding new developers who need to interact with Google Cloud resources from their local machines. They are using Python for application development. The company wants to ensure that these developers can easily authenticate to GCP services without explicitly managing service account keys or user credentials in their code. Which authentication method should be recommended?

  1. AUsing `gcloud auth activate-service-account` with a downloaded JSON key file.
  2. BEmbedding API keys directly into their Python code for each service call.
  3. CUsing `gcloud auth login` and then manually exporting environment variables.
  4. DRelying on Application Default Credentials (ADC) after running `gcloud auth application-default login`.
Show answer & explanation

Correct answer: D. Relying on Application Default Credentials (ADC) after running `gcloud auth application-default login`.

Application Default Credentials (ADC) is the recommended strategy for authentication from local developer environments. After running `gcloud auth application-default login`, ADC finds credentials in a standard location, allowing client libraries to automatically authenticate without hardcoding.

Why the other options are wrong

  • A. While valid for service accounts, this involves managing key files and is not ideal for individual developer environments.
  • B. Embedding API keys is insecure and not recommended for most authentication scenarios, especially for user access to GCP services.
  • C. `gcloud auth login` authenticates the CLI, but doesn't automatically set up ADC for client libraries without further manual steps that ADC simplifies.

Application Default Credentials (ADC)

Application Default Credentials (ADC) is a strategy used by Google Cloud client libraries to automatically find credentials, allowing applications to authenticate to Google Cloud services without explicit credential management.

  • Standard authentication for client libraries.
  • Finds credentials in a predefined order (environment var, config file, metadata service).
  • Setup for local dev via `gcloud auth application-default login`.

Memory trick: For easy app authentication, use ADC, it's the best local key.

More Setting up a cloud solution environment questions