Review a VM’s Cloud API scopes and IAM permissions

Review the VM’s OAuth scopes together with its service account’s IAM roles.

Description

The cloud-platform scope allows OAuth tokens to be used with many Google Cloud APIs; it does not itself grant permissions to all resources. The service account’s IAM roles restrict the operations it can perform.

Potential impact

Excessive IAM roles can be misused from a compromised VM. Removing a scope alone does not complete a permissions review.

Remediation

Limit a dedicated service account’s IAM roles to what the workload needs. Google recommends using the cloud-platform scope while controlling access through IAM.

Examples

The revised excerpt explicitly attaches a dedicated account whose permissions are restricted separately. Keeping the scope is intentional; VM creation settings alone do not remove IAM roles.

Before

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ vm_service_account_email }}"
        scopes:
          - https://www.googleapis.com/auth/cloud-platform
    state: present

After

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ dedicated_service_account_email }}"
        scopes:
          - https://www.googleapis.com/auth/cloud-platform
    state: present

References