GCP IAM Authentication and Authorization 101

Stefanie Lai
8 min readDec 20, 2020

Just a few days ago, on 14th Dec., Google IAM experienced a 50-minute outage🔥 and resulted in the unavailability of all the user verification services that rely on it worldwide. Youtube alone lost 1.7 million💸 in advertising revenue, while the losses of other websites were utterly incalculable.

Google outrage influence
  • What is Google IAM?
  • Why does this matter so much?
  • How much do you know about Authentication and Authorization on GCP?
  • How do you align GCP IAM with Kubernetes RBAC?
GCP Authentication & Authorization, by author

What’s a User

Traditional web systems often have independent user designs, storing data containing basic user information, such as ages, names, birthdays, emails, phone numbers, etc., in the database. The most important data is user passwords, using which users log in to the website after inputting the username.

There are a wider variety of users in the cloud era, though the user definition has not changed much. Google users are no longer limited to Google only. Many websites have integrated Google’s third-party login now, and by obtaining the users’ basic information after user…

--

--

Stefanie Lai
Stefanie Lai

Written by Stefanie Lai

Learning to be a good mother

No responses yet