Identity and Access Management
Identity and Access Management (IAM) decides who may do what on which Google Cloud resource. The GCP Enterprise Baseline grants people access only through its 14 groups, from one access matrix written as data, and narrows every pipeline and workload grant to the resource it needs.
What it does
An IAM binding joins a member (a user, group, service account or federated principal) to a role (a set of permissions) on a resource. A binding on the organization, a folder or a project is inherited by everything below it; a binding on a single resource, such as a bucket, a subnet or a DNS zone, reaches that resource only. Predefined roles come from Google; custom roles list exactly the permissions an organization chooses. A binding can carry an IAM condition that limits it further, for example to resource names with a given prefix.
How BuiltForProd uses it
People. The groups-iam unit (environments/core/identity/global) turns the access matrix in modules/groups-iam/bindings.tf into bindings at the organization, on the core and plat folders and on each stage project. Three role bundles keep the matrix short:
editor_bundle = ["roles/editor", "roles/container.developer", "roles/iam.serviceAccountUser", "roles/secretmanager.viewer"]
viewer_bundle = ["roles/viewer", "roles/monitoring.viewer", "roles/logging.viewer"]
auditor_bundle = ["roles/iam.securityReviewer", "roles/securitycenter.adminViewer", "roles/orgpolicy.policyViewer", "roles/cloudasset.viewer", "roles/monitoring.viewer"]
Group (acme-<role>@company.com) | core folder | sandbox, dev | staging | prod |
|---|---|---|---|---|
platform-leads | viewer, Owner through PAM | viewer, Owner through PAM | viewer, Owner through PAM | viewer, Owner through PAM |
platform-engineers | editor | editor | editor | viewer |
devops-leads | viewer | viewer, Owner through PAM | viewer, Owner through PAM | viewer, Owner through PAM |
devops-engineers | viewer | editor | editor | viewer |
lead-app-developers, lead-etl-engineers, lead-ai-engineers | none | editor | editor | none |
app-developers, etl-engineers, ai-engineers | none | editor | none | none |
all-engineers | none | none | none | viewer |
Both auditor groups hold the auditor bundle at the organization (security reviewer, Security Command Center admin viewer, organization policy viewer, Cloud Asset viewer, monitoring viewer).
Owner for the lead groups exists only as a Privileged Access Manager entitlement; with enable_pam = false it becomes a standing binding. The lead auditors also hold roles/viewer at the organization. Auditors read logs only in acme-core-audit (Logs Viewer and Logs View Accessor on the central bucket's views) and metrics everywhere; IAM deny policies keep data and workload logs from them whatever role they hold. The stage's engineer groups also read its metrics and traces.
Resource-level grants. Across projects the Baseline grants on the resource, not on the project:
| Resource | Who | Role |
|---|---|---|
| Each stage subnet of the Shared VPC | The stage's service agents, deployer and engineer groups | roles/compute.networkUser |
| The Shared VPC host project | Each stage deployer | custom sharedVpcNetworkUse |
| Each stage DNS zone | That stage's deployer | roles/dns.admin on the zone |
| Each Artifact Registry repository | Readers (GKE nodes, Cloud Run agents) and writers (code CI) | repository reader and writer |
The GitHub App secrets in acme-core-auto | Baseline and web app CI accounts, the stage deployers | roles/secretmanager.secretAccessor |
| Each SOPS key | Leads on every stage, engineers on sandbox and dev | roles/cloudkms.cryptoKeyEncrypterDecrypter |
The custom role sharedVpcNetworkUse holds compute.networks.use alone, which a Private Service Connect endpoint in a stage project needs on the host's network; the predefined role would open every subnet. The Web App Blueprint adds its own custom role that only invalidates the Cloud CDN cache of its front end.
Grants that wait for the web app. webapp_gke_stages in environments/plat/plat.hcl lists the stages whose Web App Blueprint cluster exists. Only those stages get the Artifact Registry reader grant for the GKE node account and roles/dns.reader on acme-core-dns and acme-core-network for the two external-dns releases, because IAM refuses a binding to an account or workload identity pool that does not exist yet.
Terms you will see
| Term | Meaning |
|---|---|
| Binding | A member and a role on a resource. |
| Role bundle | The Baseline's editor, viewer or auditor set of roles, granted together. |
| Custom role | An organization- or project-defined role, such as sharedVpcNetworkUse. |
| IAM condition | An expression that limits a binding, such as "secrets not starting with platform--". |
| Access matrix | The matrix local in bindings.tf: every group, scope and role in one place. |
Where to read more
- GCP Enterprise Baseline overview for people and pipeline access as a whole.
- Cloud Identity for the 14 groups the matrix names.
- Least privilege for why access narrows toward production.