Topic 02 / 08 · 03 articles

GCP, IAM & Security

About this topic

130 words

Identity and access management is the part of cloud engineering that is invisible when it is right and catastrophic when it is wrong. A single over-broad role or a service-account key sitting in a CI secret is often all an attacker needs.

This topic collects practical guides for getting Google Cloud IAM right without drowning in policy documents: granting access to groups instead of people, giving every workload its own service account, replacing downloaded keys with Workload Identity Federation, scoping Secret Manager access to individual secrets, and verifying tokens once at the edge instead of in every service.

Every guide includes the exact gcloud commands or configuration I use, the mistakes I have seen in real projects, and a checklist you can run against your own organisation in an afternoon.

01Start here

02All articles in GCP, IAM & Security