A new operations engineer must be able to start, stop, and reconfigure Compute Engine VM instances in a production project, but must not be able to modify Cloud Storage buckets, BigQuery datasets, or IAM policies. Following Google-recommended practices, which role should you grant?
Choose one.
Cloud IAM offers basic roles (Owner, Editor, Viewer), predefined roles maintained by Google per service, and custom roles you assemble yourself. Predefined roles are the recommended default because they scope permissions to one service and one job function.
roles/compute.instanceAdmin.v1 contains the permissions to create, modify, start, and stop VM instances and their disks, but includes no Cloud Storage, BigQuery, or IAM-administration permissions. It exactly matches 'manage VMs, nothing else'. Editor and Owner are project-wide basic roles that sweep in every other service (Owner even adds IAM control), and compute.viewer cannot change instance state at all.
- List the actions the principal actually needs: start, stop, and reconfigure VM instances.
- Search the predefined roles for the Compute Engine role whose permission set matches that job — roles/compute.instanceAdmin.v1.
- Confirm the role does not include permissions on the services that must stay off-limits.
- Grant it at the project level with add-iam-policy-binding, and revisit if the scope of the job changes.
Exam tip: Prefer service-specific predefined roles over basic Owner/Editor — they are how least privilege is done on GCP.
Managing Cloud IAM: Roles, Policies, and Inheritance — the lesson that teaches this.