Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for secure access.
The google-cloud-recipe-auth skill provides expert guidance for authenticating and authorizing access to Google Cloud services and APIs. It helps users understand how to prove their identity to Google Cloud and ensures secure access to resources. By offering structured advice on human and service account authentication, Application Default Credentials (ADC), and best practices for managing credentials, this skill addresses the complexity of setting up secure authentication workflows in diverse environments.
Key features of this skill include clarifying questions to determine the identity type and execution context, guidance on authenticating human users via Google-managed accounts, federation, and workforce identity federation, and methods for developers and administrators to access Google Cloud resources through consoles, CLI, or ADC. The skill also covers service identities and best practices for using client libraries securely. It provides links to official documentation for further reference, ensuring that users follow Google Cloud's recommended patterns for identity management and access control.
This skill is primarily targeted at developers, administrators, and IT professionals who manage Google Cloud environments. Use cases include setting up secure authentication for development environments, automating service account access for applications, and implementing identity federation for workforce users. It is particularly useful for organizations seeking to maintain compliance and security standards while enabling efficient access to Google Cloud APIs and resources.
Human users can authenticate using Google-managed accounts, federated identities through Cloud Identity or Google Workspace, or workforce identity federation. Authentication methods include using the Google Cloud Console, gcloud CLI, or Application Default Credentials for development purposes.
Yes. The skill provides guidance on using service identities and Application Default Credentials (ADC) to authenticate applications running locally or on Google Cloud, allowing client libraries to securely access APIs without manual credential management.
Authentication guidance covers local laptops, Compute Engine, Google Kubernetes Engine (GKE), Cloud Run, and other cloud environments. It helps determine the correct approach based on where code or applications are running.
No. Workforce identity federation supports syncless, attribute-based single sign-on, which allows external identities to authenticate and authorize without synchronizing them into Google Cloud accounts.
Yes. High-level client libraries in languages like Python, Java, and Node.js typically handle Application Default Credentials automatically, allowing code to authenticate securely without additional manual configuration.
Quick Setup:
.claude/skills/Repository
google/skills