Skip to main content

Privileged Access Manager

Privileged Access Manager (PAM) grants a role for a limited time when a person asks for it, instead of a standing binding. The GCP Enterprise Baseline uses it for every Owner and organization-admin grant of the lead groups, with a 12-hour maximum and a second lead's approval where the scope is wide.

What it does​

An entitlement names the roles it grants, the resource it grants them on (an organization, a folder or a project), the principals eligible to request it and the longest grant they may ask for. A request carries a justification. When the entitlement has an approval workflow, a named approver must accept the request, with a justification of their own, before the grant starts. The grant is a temporary IAM binding that Privileged Access Manager removes when it expires, and every request, approval and grant is written to the audit logs.

How BuiltForProd uses it​

The pam unit (environments/core/identity/global) creates four entitlements:

GCP/acme-gcp-platform-baseline/modules/pam/main.tf (lines 32-37)
entitlements = var.enable_pam ? {
"platform-leads-core" = { parent = local.core, group = var.group_emails["platform_leads"], approvers = [], roles = ["roles/owner"] }
"platform-leads-plat" = { parent = local.plat, group = var.group_emails["platform_leads"], approvers = [], roles = ["roles/owner"] }
"devops-leads-plat" = { parent = local.plat, group = var.group_emails["devops_leads"], approvers = [var.group_emails["platform_leads"]], roles = ["roles/owner"] }
"platform-leads-org" = { parent = local.org, group = var.group_emails["platform_leads"], approvers = [var.group_emails["platform_leads"]], roles = ["roles/resourcemanager.organizationAdmin", "roles/orgpolicy.policyAdmin"] }
} : {}
EntitlementGrantsOnEligibleApproval
acme-platform-leads-coreOwnerfolder coreacme-platform-leadsnone
acme-platform-leads-platOwnerfolder platacme-platform-leadsnone
acme-devops-leads-platOwnerfolder platacme-devops-leadsone platform lead
acme-platform-leads-orgOrganization Administrator, Organization Policy Administratorthe organizationacme-platform-leadsanother platform lead

Every request may last at most 12 hours (max_request_duration = 43200s) and needs a justification. pam_notification_emails in environments/core/identity/identity.hcl adds mailboxes that hear about every request besides the approvers; it is empty by default. The unit also grants the organization's PAM service agent the role it needs before any entitlement can exist.

Without an active grant the leads keep only the viewer bundle that Identity and Access Management gives them, so day-to-day work happens read-only and every change of the landing zone goes through a pull request that CI applies.

The switch. enable_pam = true is the default in identity.hcl. With false the pam unit creates nothing and groups-iam binds Owner on the folders to the lead groups as standing access, with no time limit and no approval.

Terms you will see​

TermMeaning
EntitlementThe definition of a grant someone may request: roles, scope, eligibility.
Eligible principalA group whose members may request the entitlement.
GrantOne approved, time-bound activation of an entitlement.
Approval workflowThe step in which a named approver must accept a request.
max_request_durationThe longest grant a requester may ask for: 12 hours.

Where to read more​