← Professional Cloud Developer: applications and production
02 / 7 · 35 MIN

Credentials, secrets, and access

Identify the effective principal and limit access capabilities.

Concept and mechanism

ADC searches credentials in a defined order: the file named by GOOGLE_APPLICATION_CREDENTIALS, a well-known local ADC file, and, where applicable, the attached service account obtained through the metadata server. The active gcloud account does not prove which source the library uses. During diagnosis, confirm the source and effective principal without printing secrets. In Google Cloud production, prefer attached identities with required roles; outside it, evaluate federation with conditions on trusted attributes. Authentication does not remove authorization and connectivity requirements. Cloud SQL Auth Proxy uses identity and a protected connection but depends on an existing IP path to the destination. It creates neither a private route nor application pooling.

Guided application

In a fictional reporting service, a signed URL grants an action on a resource for a period. Anyone holding it can use it; it is not automatically limited to the person receiving the email. Avoid exposing it in tickets and logs, and define validity and scope according to need. Secrets also need a release lifecycle. If instances read latest at startup, a change may affect only new instances, producing mixed behavior. Pinning a version allows controlled configuration validation and promotion while retaining recovery compatible with the system checking the secret. Disabling before destruction helps detect dependencies but does not replace assessment and approval. The goal is understanding effective capability rather than only a resource or account name.

IN PRACTICE

A correct CLI identity and an incorrect application identity can coexist on one laptop.

Common pitfalls

gcloud as ADC; proxy as VPN; signed URL as nontransferable personal access; latest as compatibility.

Related topics: State, caching, and asynchronous flows · Build, artifacts, and provenance · Tests, emulators, and AI assistance

Take this idea with you

Confirm identity, path, and scope before expanding permissions.

Create account

Reference: Application Default Credentials · Current linked guide; edition date unconfirmed (2026-09-30 inspection)