Collect context before changing permissions
In a fictional reconciliation incident, the terminal works and the application fails. Record project, Region, resource, operation, and observed principal without exposing tokens. Success in a personal session does not establish process access. A change script should declare its intended project and validate it before writing. The service name or prompt appearance is insufficient target evidence. This preparation reduces changes to wrong accounts and helps developers, cloud staff, and APS exchange a clear diagnosis.
Follow the process ADC lookup
An ADC-enabled library first looks for GOOGLE_APPLICATION_CREDENTIALS configuration, then the local ADC file, and, where applicable, attached identity through the metadata server. On a VM, an inherited variable can select another identity before the attached account. Do not assume the variable always contains a key: it can reference approved federation configuration. Confirm effective source and principal using nonsecret information. Changing attached-account grants without this check can increase privilege without changing the observed error.
Separate CLI, deployer, and service identity
gcloud credential configuration and ADC configuration are not the same. Also, being able to deploy a revision with a service account does not mean that account can access application data. Draw three separate actions: operator or pipeline prepares deployment, the platform executes with the selected identity, and that identity requests resource access. A denied bucket read should be connected to runtime principal and bucket scope. Correct the minimum required grant and review diagnostic grants that no longer make sense.
Check token recipient and permission
A call between private Cloud Run services needs applicable authentication and authorization. In the example without a custom audience, A obtains an ID token intended for B and calls B’s endpoint. The request path /settle is not itself the audience. A valid token does not automatically grant run.invoker either. If audience is wrong, granting Owner does not fix it. Record token type, expected recipient, and principal without copying the token into the ticket. Administrative testing does not replace checking the calling identity.
Prepare APIs and quota for the window
An API enabled in one project is not necessarily enabled in production. Confirm the target before requesting more permissions. For quota, calculate the peak while old and new instances coexist: 56 used units plus four eight-unit instances equals 88, above the explicit limit of 80. This model lacks eight units. Approve extra capacity or adapt rollout before the window while retaining availability requirements. The calculation does not establish guaranteed physical capacity or remove limits at another scope; those assumptions need separate checks.
Distinguish a Google API from a partner destination
Private Google Access can let a VM without an external IP reach supported Google APIs with suitable configuration. It does not represent general egress to every HTTPS partner. When batch starts calling an external supplier, identify approved egress, such as NAT or a proxy, along with DNS, routes, and rules. Google API connectivity is not evidence of partner access. Avoid publishing VM ingress when the requirement is only initiating egress; also confirm return traffic and destination policy.
Build a reproducible diagnosis sequence
Start with the failed request and retain context. Check target and API, credential source, principal, token where needed, networking path, and resource grant. Order can adapt to evidence: a timeout before HTTP suggests starting with networking, while an identified denial can point to authorization. Change one hypothesis at a time and repeat a representative synthetic operation. In handover, retain evidence of which identity worked and which permissions were removed after diagnosis. Do not declare recovery merely because a more privileged account succeeded.
An ADC variable points to test identity on a production VM. Changing attached-account grants does not change the error; confirming effective principal reveals the cause.
Common pitfalls
Confusing gcloud login and ADC; granting the wrong account; using caller audience; confusing API enablement with authorization; applying Private Google Access to every partner.
Related topics: IAM and federation · Private networking and project context
Diagnosis should connect the request to a concrete identity and target before changing access.
Reference: Application Default Credentials · Standard exam guide linked 2026-09-29; edition date unconfirmed