Featured
Swap service account keys in GitHub secrets for short-lived OIDC tokens, lock the trust to your own repo, and deploy to Cloud Run with no JSON key.
14 min
Topic 02 / 08 · 03 articles
About this topic
130 words
Identity and access management is the part of cloud engineering that is invisible when it is right and catastrophic when it is wrong. A single over-broad role or a service-account key sitting in a CI secret is often all an attacker needs.
This topic collects practical guides for getting Google Cloud IAM right without drowning in policy documents: granting access to groups instead of people, giving every workload its own service account, replacing downloaded keys with Workload Identity Federation, scoping Secret Manager access to individual secrets, and verifying tokens once at the edge instead of in every service.
Every guide includes the exact gcloud commands or configuration I use, the mistakes I have seen in real projects, and a checklist you can run against your own organisation in an afternoon.
Featured
Swap service account keys in GitHub secrets for short-lived OIDC tokens, lock the trust to your own repo, and deploy to Cloud Run with no JSON key.
14 min
· 14 min
Where secrets should live when staging, production and admin tooling sit in separate projects, and how to grant, rotate and audit access across them.
14 min
· 13 min
How I structure Google Cloud IAM so people get access through groups, workloads get one keyless service account each, and every grant is small and auditable.
13 min
· 14 min
Swap service account keys in GitHub secrets for short-lived OIDC tokens, lock the trust to your own repo, and deploy to Cloud Run with no JSON key.
14 min