Review permissions of a VM’s default service account

Configure a service account and least-privilege permissions for the VM’s purpose.

Description

Sharing the default Compute Engine service account across VMs can make permissions harder to separate and revoke. The default account does not always have full access; review its actual IAM roles.

Potential impact

If the account has broad roles, a compromised workload can access other resources within those permissions.

Remediation

Create a purpose-specific service account, grant only required IAM roles, and attach it through the email field in service_accounts. Manage Ansible execution credentials separately from the attached VM identity.

Examples

The revised excerpt specifies a previously prepared vm_service_account_email. It does not grant IAM roles. For existing VMs, use a supported account-change procedure and verify the attached identity.

Before

yaml
- name: create a instance1
  google.cloud.gcp_compute_instance:
    name: test-object1
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    state: present

- name: create a instance4
  google.cloud.gcp_compute_instance:
    name: test-object4
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ project_number }}-compute@developer.gserviceaccount.com"
    state: present

After

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ vm_service_account_email }}"
        scopes:
          - https://www.googleapis.com/auth/cloud-platform
    state: present

References