Several Compute Engine VMs were launched months ago with the project's default service account, which still holds the Editor role. Security has created a least-privilege user-managed service account named analytics-sa@project-id. The running VMs must start using this new identity without having to be rebuilt. What should an engineer do to attach the new service account to each VM instance?
Grant the VM's default service account the same IAM roles as analytics-sa@project-id; no changes to the instances are required.
Copy a JSON key for analytics-sa@project-id onto each VM and set the GOOGLE_APPLICATION_CREDENTIALS environment variable.
Run gcloud compute instances update to modify the access configuration and specify the new service account while the VM keeps running.
Stop the VM, run gcloud compute instances set-service-account INSTANCE --service-account=analytics-sa@project-id --scopes=needed-scopes, then start the VM.
A Compute Engine VM's service account can be changed only while the instance is stopped. The correct procedure is to
stop (terminate) the VM,
run gcloud compute instances set-service-account specifying the desired service account email and any required OAuth scopes, and then
start the VM again. This operation updates the instance metadata so that the metadata server issues tokens for the new account. Merely updating IAM bindings, changing access configs, or copying key files does not switch the identity that the metadata server provides to the guest workload.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why must the VM be stopped to attach a new service account?
Open an interactive chat with Bash
What is the purpose of OAuth scopes when setting a service account?
Open an interactive chat with Bash
What is the metadata server, and how does it interact with service accounts?
Open an interactive chat with Bash
What is a service account in Google Cloud Platform (GCP)?
Open an interactive chat with Bash
Why do VMs need to be stopped to change the service account?
Open an interactive chat with Bash
What does `gcloud compute instances set-service-account` do?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .