Posts

Roles in GCP IAM

  Roles in GCP IAM A role is a collection of permissions that can be granted to a user, group, or service account. Think: Identity → Role → Permissions → Resource 1. Basic Roles These are broad, legacy roles: Role What it means Viewer Can view resources, but cannot modify them Editor Can view and modify resources Owner Can view, modify, and manage access/IAM Example: User ↓ Viewer ↓ Can view VM Cannot start/delete VM ⚠️ In real projects, avoid broad Basic Roles when a more specific role is available. 2. Predefined Roles ⭐ These are Google-created roles designed for specific services and tasks. Examples: Compute Instance Admin → manage Compute Engine instances Storage Object Viewer → view objects in Cloud Storage Storage Object Admin → manage objects BigQuery Data Viewer → view BigQuery data BigQuery Job User → run BigQuery jobs Kubernetes Engine Developer → work with GKE resources Example: Developer ↓ Storage Object Viewer ↓ Can READ fil...

Identity and Access Management (IAM) in GCP

  1. Identity and Access Management (IAM) in GCP IAM = Identity and Access Management IAM in Google Cloud controls who can access which resources and what actions they can perform . Key idea Who → can do what → on which resource Example: A developer may be allowed to view and restart Compute Engine VMs , but not delete them. 1. Identity — Who? An identity can be: Google account — individual user Service account — application/workload identity Google group — collection of users Cloud Identity / Google Workspace account — organization users 2. Role — What can they do? A role is a collection of permissions. For example: Viewer → can view resources Editor → can modify many resources Owner → broad control, including IAM management Service-specific roles → permissions for a particular service There are three important types: Role type Meaning Basic roles Owner, Editor, Viewer Predefined roles Google-created roles with specific permissions Cust...