Posts

Roles in GCP IAM

  Roles in GCP IAM A role is a collection of permissions that can be granted to a user, group, or service account. Think: Identity → Role → Permissions → Resource 1. Basic Roles These are broad, legacy roles: Role What it means Viewer Can view resources, but cannot modify them Editor Can view and modify resources Owner Can view, modify, and manage access/IAM Example: User ↓ Viewer ↓ Can view VM Cannot start/delete VM ⚠️ In real projects, avoid broad Basic Roles when a more specific role is available. 2. Predefined Roles ⭐ These are Google-created roles designed for specific services and tasks. Examples: Compute Instance Admin → manage Compute Engine instances Storage Object Viewer → view objects in Cloud Storage Storage Object Admin → manage objects BigQuery Data Viewer → view BigQuery data BigQuery Job User → run BigQuery jobs Kubernetes Engine Developer → work with GKE resources Example: Developer ↓ Storage Object Viewer ↓ Can READ fil...

Identity and Access Management (IAM) in GCP

  1. Identity and Access Management (IAM) in GCP IAM = Identity and Access Management IAM in Google Cloud controls who can access which resources and what actions they can perform . Key idea Who → can do what → on which resource Example: A developer may be allowed to view and restart Compute Engine VMs , but not delete them. 1. Identity — Who? An identity can be: Google account — individual user Service account — application/workload identity Google group — collection of users Cloud Identity / Google Workspace account — organization users 2. Role — What can they do? A role is a collection of permissions. For example: Viewer → can view resources Editor → can modify many resources Owner → broad control, including IAM management Service-specific roles → permissions for a particular service There are three important types: Role type Meaning Basic roles Owner, Editor, Viewer Predefined roles Google-created roles with specific permissions Cust...

Configuring VPC Network Peering

Image
  Configuring VPC Network Peering Configuring VPC Network Peering VPC Network Peering in Google Cloud allows two VPC networks to communicate privately using internal IP addresses , without sending traffic over the public internet. Simple example Suppose you have: VPC-A VPC-B 10.10.0.0/16 10.20.0.0/16 │ │ VM-A ───── VPC Peering ───── VM-B 10.10.0.5 10.20.0.5 VM-A can communicate with VM-B using: 10.20.0.5 There is no need for an external/public IP for this communication. How it works Normally: VPC-A ❌ VPC-B They are isolated. After peering: VPC-A ←──── private connection ────→ VPC-B Routes are automatically exchanged between the peered VPC networks. Important points to remember Concept VPC Peering Communication Private Uses internal IPs ✅ Public internet required ❌ Same organization Not required Same project Not required Different projects ✅ Different organizations ✅ Autom...