Connect using service accounts


This document describes how to use a service account to connect to Compute Engine virtual machine (VM) instances using SSH. Setting up SSH for a service account enables you to configure apps to use SSH , which can help you to automate your workloads.

Before you begin

  • Create a service account .
  • If you haven't already, set up authentication . Authentication verifies your identity for access to Google Cloud services and APIs. To run code or samples from a local development environment, you can authenticate to Compute Engine by selecting one of the following options:
    1. Install the Google Cloud CLI. After installation, initialize the Google Cloud CLI by running the following command:

      gcloud  
      init

      If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity .

    2. Set a default region and zone .

Manually connect to VMs as a service account

To connect to VMs as a service account, use one of the following methods:

Permissions required for this task

To perform this task, you must have the following permissions :

Use the gcloud CLI --impersonate-service-account flag to connect directly to a VM using a service account's identity. Run the following command to connect to a VM as a service account:

gcloud compute ssh VM_NAME 
\
    --impersonate-service-account= SERVICE_ACCOUNT_EMAIL 

Replace the following:

  • VM_NAME : the name of the VM you want to connect to the service account as.
  • SERVICE_ACCOUNT_EMAIL : the email address associated with the service account.

Permissions required for this task

To perform this task, you must have the following permissions :

You must additionally assign your service account to a VM and set the cloud-platform access scope on the VM.

Impersonate a service account from another VM by doing the following:

  1. Connect to the VM that runs as a service account .
  2. From the VM that runs as a service account, connect to other VMs using the same methods.

What's next

Create a Mobile Website
View Site in Mobile | Classic
Share by: