Knowledgebase

Google Cloud Identity and Access Management Print

  • googletechnology, google, permissions, guide, howto, solution, zillionkinghost, hosting
  • 0

Controlling who can do what.

WHAT THE MODEL IS

Permissions granted through roles, assigned to identities, at a scope.

WHAT IDENTITIES EXIST

User accounts Groups Service accounts, for applications Federated identities from other providers

WHAT ROLE TYPES EXIST

Basic roles, which are very broad Predefined roles, scoped to a service Custom roles, defined by you

WHAT TO AVOID

Basic roles, particularly owner and editor.

WHY

They grant far more than almost any task requires.

WHAT TO ASSIGN

The narrowest predefined role that permits the work.

WHAT SCOPE TO ASSIGN AT

The narrowest: a resource rather than a project, a project rather than a folder.

WHAT TO ASSIGN TO

Groups, not individuals.

WHY

Individual assignments accumulate and are never removed.

WHAT A SERVICE ACCOUNT IS

An identity for an application rather than a person.

WHAT TO NEVER DO

Create service account keys and distribute them.

WHY

They are long-lived credentials that leak.

WHAT TO USE INSTEAD

Attached identities, or workload identity federation.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot