A gaming studio's CI system runs outside Google Cloud and authenticates with a downloaded service account JSON key. Policy now forbids long-lived keys and an organization policy blocks key creation, but deployments must still push images to Artifact Registry and deploy Cloud Run revisions. Which two actions should you take? (Choose TWO.)
Choose 2.
- A.
Create a workload identity pool and OIDC provider trusting the CI issuer, with an attribute condition on repository and branch.
- B.
Grant the federated principal set roles/iam.workloadIdentityUser on the deployer service account so CI can impersonate it.
- C.
Store the existing JSON key in Secret Manager and fetch it at the start of each pipeline run.
- D.
Grant the CI system's user account roles/owner on the project.
- E.
Create a second service account whose key expires after 90 days and rotate it on a schedule.
Show answer
Answer: A, B
Workload Identity Federation exchanges the CI system's own OIDC token for short-lived Google credentials, so no service account key is ever created.
- A. A workload identity pool with an OIDC provider and an attribute condition establishes trust in the CI issuer while limiting it to the intended repository and branch.
- B. roles/iam.workloadIdentityUser on the deployer service account lets the federated identity impersonate it and receive short-lived tokens instead of a key.
- C. Secret Manager improves where the key is stored but the credential is still long-lived and exfiltratable, so the policy is not satisfied.
- D. Granting Owner violates least privilege spectacularly and does not remove the need for a credential that CI can present to Google Cloud.
- E. This still produces a downloadable service account key, which the new policy forbids and the organization policy constraint blocks outright.
