Description
The cloud-platform scope allows OAuth tokens to be used with many Google Cloud APIs; it does not itself grant permissions to all resources. The service account’s IAM roles restrict the operations it can perform.
Potential impact
Excessive IAM roles can be misused from a compromised VM. Removing a scope alone does not complete a permissions review.
Remediation
Limit a dedicated service account’s IAM roles to what the workload needs. Google recommends using the cloud-platform scope while controlling access through IAM.
Examples
The revised excerpt explicitly attaches a dedicated account whose permissions are restricted separately. Keeping the scope is intentional; VM creation settings alone do not remove IAM roles.
Before
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_accounts:
- email: "{{ vm_service_account_email }}"
scopes:
- https://www.googleapis.com/auth/cloud-platform
state: present
After
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_accounts:
- email: "{{ dedicated_service_account_email }}"
scopes:
- https://www.googleapis.com/auth/cloud-platform
state: present