Skip to main content

Frequently Asked Questions

How is a GCP service account different from a regular user account?

A service account isn't tied to a person — it's an identity your code, VM, or pipeline authenticates as, and it exists as its own IAM-manageable resource (with an email like name@project.iam.gserviceaccount.com). You grant it roles just like a user, but nobody logs into it interactively. It's also the identity you attach to Compute Engine VMs or Cloud Run services so the workload can call other GCP APIs without embedding credentials in code.

What's the biggest security mistake teams make with GCP service accounts?

Downloading a long-lived JSON key file and hardcoding it into an app or committing it to a repo. Keys don't expire on their own and are a top cause of GCP credential leaks. The safer pattern is attaching the service account directly to the compute resource (Workload Identity for GKE, or the VM's attached identity) or using short-lived impersonation via `gcloud auth print-access-token --impersonate-service-account`, avoiding a static key entirely.