如何通过IAM为普通用户授予API Credentials访问权限?无适配预定义角色
Got it, let's work through this together. Since there's no predefined Google Cloud IAM role that directly lets a regular user manage their own OAuth credentials (without involving service accounts), you'll need to create a custom role with targeted permissions and a condition to restrict access to their own resources. Here's how to set this up:
Step 1: Define the Required Permissions
First, identify the permissions that let a user create, view, and delete their OAuth 2.0 client IDs. These are the key ones you'll need:
oauth2.clientIds.create: Create new OAuth client credentialsoauth2.clientIds.get: View details of a specific OAuth clientoauth2.clientIds.list: List all OAuth clients associated with the useroauth2.clientIds.delete: Delete an existing OAuth client- (Optional)
oauth2.clientIds.update: Edit existing OAuth client settings
Step 2: Create a Custom Role with a Restrictive Condition
The critical part here is adding a condition to ensure the user can only manage their own credentials (not everyone else's in the project).
Using the Google Cloud Console
- Navigate to IAM & Admin > Roles in your Google Cloud project.
- Click Create Role at the top of the page.
- Give the role a clear name (e.g.,
Custom_OAuth_Credentials_Manager) and description (e.g., "Allows a user to manage their own OAuth 2.0 client IDs"). - Under Permissions, click Add Permissions and search for each of the permissions listed above, then select them.
- Click Add Condition to set up the restriction:
- For the condition expression, enter:
resource.name.contains(principal.email) - Give the condition a title like
RestrictToOwnCredentials - This ensures the user can only interact with OAuth clients linked to their own email address.
- For the condition expression, enter:
- Save the role.
Using the gcloud CLI
If you prefer command-line tools, run this command (replace PROJECT_ID with your actual project ID):
gcloud iam roles create CustomOAuthCredentialsManager \ --project=PROJECT_ID \ --title="Custom OAuth Credentials Manager" \ --description="Allows managing own OAuth 2.0 client IDs" \ --permissions=oauth2.clientIds.create,oauth2.clientIds.get,oauth2.clientIds.list,oauth2.clientIds.delete \ --condition="expression: resource.name.contains(principal.email), title: RestrictToOwnCredentials"
Step 3: Assign the Custom Role to Your User
Once the custom role is ready:
- Go to IAM & Admin > IAM in the Console.
- Find the user you want to grant access to, or click Add to invite a new user.
- In the Role dropdown, search for and select the custom role you just created.
- Save the changes.
Step 4: Verify Access
Have the user log into the Google Cloud Console and go to APIs & Services > Credentials. They should now be able to create, view, and delete their own OAuth client IDs—without being able to modify other users' credentials or service accounts.
Quick Notes
- If you also want the user to manage API keys (not just OAuth clients), add relevant
apikeys.*permissions (likeapikeys.create,apikeys.list) to the custom role, keeping the same restrictive condition. - Double-check the condition to make sure it's applied correctly—this prevents over-granting access to the entire project's credentials.
内容的提问来源于stack exchange,提问作者dmux

