Keys are now blocked by default for newer organizations.
A long-lived JSON credential, valid indefinitely until manually revoked.
The rule
constraints/iam.disableServiceAccountKeyCreation enforced by default for orgs created on or after May 3, 2024
Older orgs
Apply the constraint explicitly — dry-run first, per Ch 1
A leaked open-source repo key stayed live for 8 months because nothing tracked key age. Fix: immediate revocation, migration to Workload Identity Federation, and a recurring Cloud Asset Inventory query hunting keys older than 90 days.