Skip to main content

Identity and Access Management

Identity and Access Management (IAM) decides who may do what on which Google Cloud resource. The GCP Enterprise Baseline grants people access only through its 14 groups, from one access matrix written as data, and narrows every pipeline and workload grant to the resource it needs.

What it does​

An IAM binding joins a member (a user, group, service account or federated principal) to a role (a set of permissions) on a resource. A binding on the organization, a folder or a project is inherited by everything below it; a binding on a single resource, such as a bucket, a subnet or a DNS zone, reaches that resource only. Predefined roles come from Google; custom roles list exactly the permissions an organization chooses. A binding can carry an IAM condition that limits it further, for example to resource names with a given prefix.

How BuiltForProd uses it​

People. The groups-iam unit (environments/core/identity/global) turns the access matrix in modules/groups-iam/bindings.tf into bindings at the organization, on the core and plat folders and on each stage project. Three role bundles keep the matrix short:

GCP/acme-gcp-platform-baseline/modules/groups-iam/bindings.tf (lines 25-27)
editor_bundle = ["roles/editor", "roles/container.developer", "roles/iam.serviceAccountUser", "roles/secretmanager.viewer"]
viewer_bundle = ["roles/viewer", "roles/monitoring.viewer", "roles/logging.viewer"]
auditor_bundle = ["roles/iam.securityReviewer", "roles/securitycenter.adminViewer", "roles/orgpolicy.policyViewer", "roles/cloudasset.viewer", "roles/monitoring.viewer"]
Group (acme-<role>@company.com)core foldersandbox, devstagingprod
platform-leadsviewer, Owner through PAMviewer, Owner through PAMviewer, Owner through PAMviewer, Owner through PAM
platform-engineerseditoreditoreditorviewer
devops-leadsviewerviewer, Owner through PAMviewer, Owner through PAMviewer, Owner through PAM
devops-engineersviewereditoreditorviewer
lead-app-developers, lead-etl-engineers, lead-ai-engineersnoneeditoreditornone
app-developers, etl-engineers, ai-engineersnoneeditornonenone
all-engineersnonenonenoneviewer

Both auditor groups hold the auditor bundle at the organization (security reviewer, Security Command Center admin viewer, organization policy viewer, Cloud Asset viewer, monitoring viewer).

Owner for the lead groups exists only as a Privileged Access Manager entitlement; with enable_pam = false it becomes a standing binding. The lead auditors also hold roles/viewer at the organization. Auditors read logs only in acme-core-audit (Logs Viewer and Logs View Accessor on the central bucket's views) and metrics everywhere; IAM deny policies keep data and workload logs from them whatever role they hold. The stage's engineer groups also read its metrics and traces.

Resource-level grants. Across projects the Baseline grants on the resource, not on the project:

ResourceWhoRole
Each stage subnet of the Shared VPCThe stage's service agents, deployer and engineer groupsroles/compute.networkUser
The Shared VPC host projectEach stage deployercustom sharedVpcNetworkUse
Each stage DNS zoneThat stage's deployerroles/dns.admin on the zone
Each Artifact Registry repositoryReaders (GKE nodes, Cloud Run agents) and writers (code CI)repository reader and writer
The GitHub App secrets in acme-core-autoBaseline and web app CI accounts, the stage deployersroles/secretmanager.secretAccessor
Each SOPS keyLeads on every stage, engineers on sandbox and devroles/cloudkms.cryptoKeyEncrypterDecrypter

The custom role sharedVpcNetworkUse holds compute.networks.use alone, which a Private Service Connect endpoint in a stage project needs on the host's network; the predefined role would open every subnet. The Web App Blueprint adds its own custom role that only invalidates the Cloud CDN cache of its front end.

Grants that wait for the web app. webapp_gke_stages in environments/plat/plat.hcl lists the stages whose Web App Blueprint cluster exists. Only those stages get the Artifact Registry reader grant for the GKE node account and roles/dns.reader on acme-core-dns and acme-core-network for the two external-dns releases, because IAM refuses a binding to an account or workload identity pool that does not exist yet.

Terms you will see​

TermMeaning
BindingA member and a role on a resource.
Role bundleThe Baseline's editor, viewer or auditor set of roles, granted together.
Custom roleAn organization- or project-defined role, such as sharedVpcNetworkUse.
IAM conditionAn expression that limits a binding, such as "secrets not starting with platform--".
Access matrixThe matrix local in bindings.tf: every group, scope and role in one place.

Where to read more​