Skip to main content
compliance · gcp

GCP service accounts with downloadable user-managed keys

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

GCP service accounts with user-managed keys have long-lived private key files that never expire by default and work from anywhere they are copied. ZopNight flags each service account that has at least one such key, listed by `gcloud iam service-accounts keys list --managed-by=user`, and recommends Workload Identity Federation or attached service accounts instead.

Signal and threshold

How ZopNight evaluates GCP service accounts with downloadable user-managed keys.
Field Value
Rule IDsRC-131
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdat least one user-managed key
SourceZopNight
Permissions usediam.serviceAccounts.list · iam.serviceAccountKeys.list

What makes a user-managed key risky

Service accounts have two kinds of key pairs: Google-managed, which Google rotates and never hands out, and user-managed, where you download the private key. Google’s key management best practices put it bluntly: having the private key is similar to knowing a user’s password, and the main threats are credential leakage and privilege escalation.

The file is portable and quiet. It works from any machine, it does not go through your SSO or MFA, and it ends up in places nobody tracks: laptops, CI variables, container images, source control. Google’s key creation page adds that a service account can have up to 10 keys and that by default keys never expire.

Finding user-managed keys

Terminal window
for sa in $(gcloud iam service-accounts list --format="value(email)"); do
echo "== $sa"
gcloud iam service-accounts keys list --iam-account="$sa" --managed-by=user
done

The CREATED_AT and EXPIRES_AT columns show when each key was made and whether it has an expiry.

When the rule fires

ZopNight checks two things for each identity it inventories: the principal is a service account, and ZopNight has recorded that the account has at least one user-managed key. Both must hold. The key’s age is not considered here; age is the job of GCP Service Account Key Not Rotated Within 90 Days. One finding is raised per service account, not per key.

Accounts that produce no finding

Service accounts with only Google-managed keys are silent, and so are users and groups. If ZopNight has no confirmed record of user-managed keys for an account, it does not assume they exist.

Credential risk, no saving

This finding carries a $0 saving. The risk is a leaked key giving an outsider the account’s permissions until someone notices and deletes it, and Google notes a leaked key might take bad actors days or weeks to discover, so you rarely know the moment it happened.

Removing the need for key files

  1. Find where each key is used. Google’s service account insights and the Key Authentication Events metric show whether and when each key was last used.
  2. On GKE, use Workload Identity Federation for GKE and bind the Kubernetes service account.
  3. On Cloud Run, Compute Engine and other Google Cloud runtimes, attach the service account to the resource so it gets short-lived credentials automatically.
  4. Outside Google Cloud, configure Workload Identity Federation with your identity provider.
  5. Disable the key first, watch for failures, then delete it: gcloud iam service-accounts keys disable KEY_ID --iam-account=SA_EMAIL, followed by gcloud iam service-accounts keys delete KEY_ID --iam-account=SA_EMAIL.
  6. Enforce iam.disableServiceAccountKeyCreation so new keys cannot be created.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·