Explain IAM roles and service accounts in GCP.
Assesses fundamental understanding of Google Cloud conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
GCP IAM binds principals to roles on resources. A service account is a special identity for workloads rather than humans.
- Principals: users, groups, service accounts, domains.
- Roles: basic (owner, editor, viewer), predefined, or custom. Roles are collections of permissions.
- Policy: a binding of principal, role, and resource, inherited down the hierarchy.
Service accounts:
- Identified by an email such as sa@project.iam.gserviceaccount.com.
- Prefer attaching them to resources such as Compute Engine, GKE Workload Identity, or Cloud Run so workloads get short-lived tokens.
- Avoid downloading long-lived JSON keys; if you must, rotate them and store them in Secret Manager.
gcloud iam service-accounts create reader --display-name="Reader"
gcloud projects add-iam-policy-binding my-proj \
--member="serviceAccount:reader@my-proj.iam.gserviceaccount.com" \
--role="roles/storage.objectViewer"
Follow least privilege and prefer Workload Identity Federation over keys.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.