IAM từ hành động đến binding
Principal → role → permissions chưa đủ; cần thêm scope và inheritance. User/group phù hợp human access; service account/workload identity phù hợp application. Policy binding có thể ở organization/folder/project/resource và inherited access làm effective permissions rộng hơn binding nhìn thấy tại resource.
Least privilege
Bắt đầu từ task: developer cần đọc logs, deployer cần deploy service, app cần đọc bucket. Chọn predefined role nhỏ nhất, đặt scope nhỏ nhất, review group membership/expiry và test deny path. Custom role cần rationale, owner, version và tránh wildcard.
Credential safety
Không commit service account JSON key. Ưu tiên attached service account, workload identity hoặc impersonation; nếu legacy key bắt buộc, có rotation/revocation/monitoring/secret storage.
Bài tập
Tạo access matrix và migration plan khỏi Owner. Dùng get-iam-policy read-only, xác định direct/inherited binding và viết evidence cho việc role mới vẫn đủ task nhưng không có quyền thừa.