Ch 3 · IAM & Identity
May 3, 2024 cutover
17 / 44

Keys are now blocked by default for newer organizations.

A long-lived JSON credential, valid indefinitely until manually revoked.

The rule

constraints/iam.disableServiceAccountKeyCreation enforced by default for orgs created on or after May 3, 2024

Older orgs

Apply the constraint explicitly — dry-run first, per Ch 1

A leaked open-source repo key stayed live for 8 months because nothing tracked key age. Fix: immediate revocation, migration to Workload Identity Federation, and a recurring Cloud Asset Inventory query hunting keys older than 90 days.