IAM and service accounts
As with all other products and services in the Google Cloud catalog, IAM is a major component of Google's security model. For Compute Engine, this manifests in two primary manners—IAM policies for administrative operations on Compute Engine resources and IAM policies for actions that a given Compute Engine instance may take.
Administrative operations
Compute Engine IAM roles can be grouped into three broad categories—instance resource management, network management, and security management. Compared to other services in the GCP catalog, there are very many IAM roles, designed to fit a large number of potential human roles within an organization. Some of these roles are currently in beta.
General roles
As we've seen in previous chapters, primitive roles may be used to grant general permissions at the project or organization level. These primitive roles apply to Compute Engine resources in the same manner as other resources. Project and organization owners and editors...