Veltrix Design has hired a 30-person agency for six months. The agency's staff sign in to their employer's Okta tenant, and Veltrix policy forbids issuing Cloud Identity accounts to anyone who is not an employee. During the engagement they must use the Google Cloud console to read objects in one Cloud Storage bucket, and Veltrix wants no account lifecycle work of its own. What should you do?
- A.
Create 30 Cloud Identity accounts in the Veltrix domain, grant each roles/storage.objectViewer on the bucket, and delete the accounts after six months.
- B.
Create one service account, grant it roles/storage.objectViewer on the bucket, download a JSON key, and email the key to the agency.
- C.
Configure Workload Identity Federation so that Okta tokens are exchanged for credentials of a service account that has roles/storage.objectViewer on the bucket.
- D.
Configure Workforce Identity Federation: create a workforce pool with an OIDC provider for the agency's Okta tenant, then grant that pool's principalSet roles/storage.objectViewer on the bucket.
Show answer
Answer: D
Workforce Identity Federation lets external human users sign in to the console with their own IdP, so no Cloud Identity accounts are created and access is bound to the workforce pool.
- A. Creating Cloud Identity accounts directly violates the stated policy and adds exactly the account lifecycle work Veltrix wants to avoid.
- B. A shared, emailed service account key gives an untraceable shared identity, cannot be tied to an individual, and is the practice Google explicitly warns against.
- C. Workload Identity Federation is designed for applications and automated workloads; it does not give people an interactive Google Cloud console session.
- D. Workforce Identity Federation gives external human users console sign-in through their own IdP with IAM bound to the pool, and creates no Google accounts.