Description
Sharing the default Compute Engine service account across VMs can make permissions harder to separate and revoke. The default account does not always have full access; review its actual IAM roles.
Potential impact
If the account has broad roles, a compromised workload can access other resources within those permissions.
Remediation
Create a purpose-specific service account, grant only required IAM roles, and attach it through the email field in service_accounts. Manage Ansible execution credentials separately from the attached VM identity.
Examples
The revised excerpt specifies a previously prepared vm_service_account_email. It does not grant IAM roles. For existing VMs, use a supported account-change procedure and verify the attached identity.
Before
- name: create a instance1
google.cloud.gcp_compute_instance:
name: test-object1
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
state: present
- name: create a instance4
google.cloud.gcp_compute_instance:
name: test-object4
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_accounts:
- email: "{{ project_number }}-compute@developer.gserviceaccount.com"
state: present
After
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_accounts:
- email: "{{ vm_service_account_email }}"
scopes:
- https://www.googleapis.com/auth/cloud-platform
state: present