You need to deploy resources from your laptop to Google Cloud using Terraform. Resources in your Google Cloud environment must be created using a service account. Your Cloud Identity has the roles/iam.serviceAccountTokenCreator Identity and Access Management (IAM) role and the necessary permissions to deploy the resources using Terraform. You want to set up your development environment to deploy the desired resources following Google-recommended best practices. What should you do?
https://cloud.google.com/iam/docs/best-practices-for-managing-service-account-keys#file-system
Whenever possible, avoid storing service account keys on a file system. If you can't avoid storing keys on disk, make sure to restrict access to the key file, configure file access auditing, and encrypt the underlying disk.
https://cloud.google.com/iam/docs/best-practices-for-managing-service-account-keys#software-keystore
In situations where using a hardware-based key store isn't viable, use a software-based key store to manage service account keys. Similar to hardware-based options, a software-based key store lets users or applications use service account keys without revealing the private key. Software-based key store solutions can help you control key access in a fine-grained manner and can also ensure that each key access is logged.
Glynda
5 months agoGladis
5 months agoGwen
6 months agoJesse
6 months agoKati
6 months agoAnnmarie
6 months agoWenona
7 months agoBong
7 months agoVenita
7 months agoGaston
7 months agoYvonne
7 months agoLigia
8 months agoBulah
8 months agoBette
10 months agoPansy
10 months agoTenesha
10 months agoChandra
10 months agoGraciela
10 months agoDustin
8 months agoJudy
10 months agoWinfred
10 months agoCordelia
11 months agoIvan
9 months agoHuey
9 months agoJolanda
9 months agoRima
10 months agoAshlyn
10 months agoZena
11 months agoBasilia
11 months agoWillard
10 months agoParis
11 months agoEdna
11 months ago