Google Associate Cloud EngineerDeploying and implementing a cloud solutionMedium
A developer is writing code that needs to securely access a Cloud Storage bucket from a Compute Engine VM. The application should not store credentials directly on the VM. Which method should the developer use to grant the VM appropriate permissions?
- AGrant the 'Owner' role to the default Compute Engine service account.
- BAttach a service account to the Compute Engine VM with the necessary Cloud Storage roles.
- CGenerate and embed a service account key file directly into the application code.
- DUse an API key configured for Cloud Storage access.
Show answer & explanationAnswer & explanation
Correct answer: B. Attach a service account to the Compute Engine VM with the necessary Cloud Storage roles.
Attaching a service account with specific roles to a Compute Engine VM is the recommended and most secure way to grant permissions. The application running on the VM automatically uses the attached service account's credentials, eliminating the need to store sensitive keys.
Why the other options are wrong
- A. Granting the 'Owner' role is a violation of the principle of least privilege and highly insecure for an application service account.
- C. Embedding service account key files is insecure and goes against best practices for credential management.
- D. API keys are typically for authenticating requests to public APIs and do not provide granular identity-based access control like service accounts.
Google Cloud Service Accounts
A special type of Google account used by non-human components (like VMs, applications, or other services) to authenticate and authorize access to Google Cloud resources.
- Represent an application or VM identity.
- Permissions granted via IAM roles.
- Avoids the need to store sensitive user credentials or API keys on VMs/in code.
Memory trick: Service Accounts 'serve' the 'account' for VMs.