Professional Cloud ArchitectManage implementationMedium
A large enterprise is modernizing its legacy monolithic application to a microservices architecture on Google Cloud. The new microservices need to communicate securely and reliably with each other, both within the same project and across different projects, using service accounts. The security team insists on a solution that provides fine-grained access control and strong authentication for inter-service communication without managing complex network configurations. Which Google Cloud service should you recommend to manage service-to-service authentication and authorization?
- AVPC Service Controls for creating a data perimeter.
- BIdentity and Access Management (IAM) for service accounts and roles.
- CCloud Load Balancing for secure traffic distribution.
- DCloud VPN for secure connectivity between projects.
Show answer & explanationAnswer & explanation
Correct answer: B. Identity and Access Management (IAM) for service accounts and roles.
Identity and Access Management (IAM) is the foundational service for managing authentication and authorization for Google Cloud resources. Service accounts, combined with IAM roles, provide fine-grained control over which microservices can access other services, both within and across projects, without complex network configurations.
Why the other options are wrong
- A. VPC Service Controls protect against data exfiltration and apply network perimeters, but they don't directly manage service-to-service authentication or authorization.
- C. Cloud Load Balancing distributes traffic and can enforce some security, but it's not the primary mechanism for fine-grained inter-service authentication and authorization.
- D. Cloud VPN provides secure network connectivity but does not manage the authentication and authorization of service identities themselves.
IAM for Service-to-Service Auth
Google Cloud Identity and Access Management (IAM) utilizes service accounts and roles to define and enforce fine-grained permissions for how services interact with each other, ensuring secure authentication and authorization.
- Service accounts represent non-human users (services/applications).
- IAM roles grant specific permissions to service accounts.
- Allows secure communication across projects and organizations.
Memory trick: Services shaking hands need an ID and a guest list, which is IAM's job.