Identity and Access Management (IAM) in GCP
- Get link
- X
- Other Apps
1. Identity and Access Management (IAM) in GCP
IAM = Identity and Access Management
IAM in Google Cloud controls who can access which resources and what actions they can perform.
Key idea
Who → can do what → on which resource
Example:
A developer may be allowed to view and restart Compute Engine VMs, but not delete them.
1. Identity — Who?
An identity can be:
- Google account — individual user
- Service account — application/workload identity
- Google group — collection of users
- Cloud Identity / Google Workspace account — organization users
2. Role — What can they do?
A role is a collection of permissions.
For example:
-
Viewer→ can view resources -
Editor→ can modify many resources -
Owner→ broad control, including IAM management - Service-specific roles → permissions for a particular service
There are three important types:
| Role type | Meaning |
|---|---|
| Basic roles | Owner, Editor, Viewer |
| Predefined roles | Google-created roles with specific permissions |
| Custom roles | Roles created by your organization |
3. Permission — Exact action
A permission represents a specific operation.
Example:
compute.instances.start
means the identity can start a Compute Engine instance.
Important: You normally don't assign individual permissions directly. You assign a role, and the role contains the permissions.
4. Resource — Where?
IAM policies can be applied at different levels:
Organization ↓ Folder ↓ Project ↓ Resource
Permissions inherited from a higher level can apply to resources below it.
Example:
Project ↓ Compute Engine VM ↓ IAM permissions inherited
5. IAM Policy
An IAM policy connects an identity with a role on a resource.
Think:
User → Role → Resource
Example:
shivam@example.com ↓ Compute Instance Admin ↓ Project XYZ
This means the user has the permissions included in that role for that project.
6. Service Accounts
A service account is an identity used by applications or workloads rather than a human.
Example:
Application ↓ Service Account ↓ IAM Role ↓ Cloud Storage
If a VM needs to access a Cloud Storage bucket, you can attach a service account to the VM and give that service account the required role.
7. Least Privilege
One of the most important IAM concepts:
Give only the permissions that are actually required.
For example, if someone only needs to read Cloud Storage objects, don't give them a role that allows them to delete objects.
Instead:
Required: Read ↓ Give: Storage Object Viewer
rather than:
Required: Read ↓ Give: Owner ❌
Easy way to remember
IAM IDENTITY ↓ WHO? ROLE ↓ WHAT CAN THEY DO? RESOURCE ↓ WHERE? POLICY ↓ WHO + WHAT + WHERE
Exam/lab point: IAM is primarily about authentication + authorization:
- Authentication (AuthN) → Who are you?
- Authorization (AuthZ) → What are you allowed to do?
- Get link
- X
- Other Apps
Comments
Post a Comment