Concept and mechanism
Network, application, and service controls are not interchangeable. IAP can provide authentication and authorization for the protected path, but architecture determines whether bypass exists. With IAP on the load balancer and a Cloud Run backend, the direct URL needs separate treatment; IAP directly on the Cloud Run service has different scope. Do not enable both indiscriminately. For VMs and GKE, protecting backend paths and validating signed assertions avoids trusting only a header a client can supply. Cloud Armor adds application policies with priority ordering. In simple header-only cases, smaller numbers have higher priority; body-related rules have processing nuances requiring separate analysis.
Guided application
In a fictional reporting application, the corporate domain requires login while run.app returns data directly. The main test did not demonstrate complete protection. Restrict the observed path and validate every entry point. A WAF rule in preview can match a request without enforcing a block; use that phase to evaluate impact and false positives with logging configured. Public NAT is another mechanism: it permits outbound traffic and established-connection responses rather than automatically publishing ports for unsolicited ingress. Finally, VPC Service Controls restricts service contexts and operations through perimeters. If a request violates that control, adding another IAM read role does not change the perimeter decision. Diagnose the deciding layer before expanding access.
Allow 100 wins over deny 200 in the non-preview header-only example.
Common pitfalls
One protected URL as full coverage; preview as blocking; NAT as publishing; IAM as perimeter override.
Related topics: Federation and temporary access · IAM, deny, and inheritance · Connectivity and perimeter migration
Validate every path and each control’s effective mode.
Reference: Identity-Aware Proxy overview · Current linked guide; edition date unconfirmed (2026-09-30 inspection)