Identity and Access Management (IAM) in GCP

 

1. Identity and Access Management (IAM) in GCP

IAM = Identity and Access Management

IAM in Google Cloud controls who can access which resources and what actions they can perform.

Key idea

Who → can do what → on which resource

Example:

A developer may be allowed to view and restart Compute Engine VMs, but not delete them.

1. Identity — Who?

An identity can be:

  • Google account — individual user
  • Service account — application/workload identity
  • Google group — collection of users
  • Cloud Identity / Google Workspace account — organization users

2. Role — What can they do?

A role is a collection of permissions.

For example:

  • Viewer → can view resources
  • Editor → can modify many resources
  • Owner → broad control, including IAM management
  • Service-specific roles → permissions for a particular service

There are three important types:

Role typeMeaning
Basic rolesOwner, Editor, Viewer
Predefined rolesGoogle-created roles with specific permissions
Custom rolesRoles created by your organization

3. Permission — Exact action

A permission represents a specific operation.

Example:

compute.instances.start

means the identity can start a Compute Engine instance.

Important: You normally don't assign individual permissions directly. You assign a role, and the role contains the permissions.

4. Resource — Where?

IAM policies can be applied at different levels:

Organization
    ↓
Folder
    ↓
Project
    ↓
Resource

Permissions inherited from a higher level can apply to resources below it.

Example:

Project
   ↓
Compute Engine VM
   ↓
IAM permissions inherited

5. IAM Policy

An IAM policy connects an identity with a role on a resource.

Think:

User → Role → Resource

Example:

shivam@example.com
        ↓
Compute Instance Admin
        ↓
Project XYZ

This means the user has the permissions included in that role for that project.

6. Service Accounts

A service account is an identity used by applications or workloads rather than a human.

Example:

Application
     ↓
Service Account
     ↓
IAM Role
     ↓
Cloud Storage

If a VM needs to access a Cloud Storage bucket, you can attach a service account to the VM and give that service account the required role.

7. Least Privilege

One of the most important IAM concepts:

Give only the permissions that are actually required.

For example, if someone only needs to read Cloud Storage objects, don't give them a role that allows them to delete objects.

Instead:

Required: Read
       ↓
Give: Storage Object Viewer

rather than:

Required: Read
       ↓
Give: Owner ❌

Easy way to remember

IAM

IDENTITY
   ↓
WHO?

ROLE
   ↓
WHAT CAN THEY DO?

RESOURCE
   ↓
WHERE?

POLICY
   ↓
WHO + WHAT + WHERE

Exam/lab point: IAM is primarily about authentication + authorization:

  • Authentication (AuthN) → Who are you?
  • Authorization (AuthZ) → What are you allowed to do?

Comments

Popular posts from this blog

Async/await

First negative in every window of size k

Valid Parentheses