Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

Automatically disable publicly exposed Service Account keys

Recently,I received the following from Google:

Service account keys must be kept private, and exposing them publicly can compromise your Google Cloud environment. A compromised Service Account Key could be used by bad actors to access, modify, or delete your data and/or consume expensive resources. We understand this could be disruptive to your organization and we are taking proactive measures to protect your environment.

To enhance the security of your environment, this organizational policy change will take effect on June 16, 2024. This change will proactively disable any publicly exposed Service Account Keys that we become aware of. This will affect all uses of the exposed Service Account Key.

What you need to do

You have the ability to modify this behavior ahead of time by taking one of the following actions:

  1. Opt-in early by setting the IAM.serviceAccountKeyExposureResponse constraint to DISABLE_KEY which will enable the protection immediately.
  2. Opt-out anytime by setting the IAM.serviceAccountKeyExposureResponse constraint to WAIT_FOR_ABUSE which will disable the protection.
  3. Do nothing, in which case Google will enable the protection on your behalf on June 16, 2024.
I need to understand the impact of enabling the protection on the existing functionality of the features offered by Google Cloud console so that we can perform the required steps..
 
Additionally, since we are using a single admin account for managing all our keys, we do not have an organization set up for the same. Because of this we are unable to modify/edit policy permissions as recommended in the email above. 
 
Any help on this will be appreciated.
2 1 276
1 REPLY 1

I have the same question, except I DO have an Org. So, can I move the apps under the org; they previously are under "No organization." WE NEED TO KNOW IF THIS WILL BREAK THINGS! Thanks!

Top Labels in this Space