IAM workload theo chuỗi trust
Phân tách human → impersonate/actAs → service account → resource role. User có thể được phép chạy deployment nhưng workload không cần quyền của user; service account có quyền đọc bucket nhưng không nên có Editor project. Scope, inheritance và group membership quyết định effective access.
Credential lifecycle
Ưu tiên attached identity, Workload Identity hoặc impersonation với credential ngắn hạn. Nếu legacy key bắt buộc, phải có secret storage, rotation, monitoring và revoke date; không commit JSON vào repo/image/metadata. Audit log và deny test là evidence tốt hơn screenshot role.
Bài tập
Lập access matrix, thiết kế migration khỏi Editor/key, chạy read-only policy/role inspection và viết allow/deny/revoke evidence. Cleanup test binding/service account theo owner; không thao tác production.