Service account impersonation

Impersonation is the most direct GCP escalation: a permission on a target service account lets you act as it without deploying anything. The roles/iam.serviceAccountTokenCreator role (and the individual permissions below) is the hinge, and it is frequently granted too broadly.

The primitives#

  • getAccessToken: mint a short-lived OAuth token for the target directly.
  • signJwt and signBlob: forge a signed JWT or blob as the target, then exchange it for a token.
  • Token Creator grant: grant yourself Token Creator on the target with serviceAccounts.setIamPolicy, then impersonate.
  • Implicit delegation: chain through an intermediate account to reach one you cannot call directly.
  • Key creation: create a long-lived JSON key for durable access and persistence.

Using an impersonated identity#

Most gcloud commands accept the impersonation flag once you hold the permission:

bash
gcloud <command> --impersonate-service-account=<target-sa>@<project>.iam.gserviceaccount.com
gcloud auth print-access-token --impersonate-service-account=<target-sa>@...

References#

Cookie Consent

We use cookies to enhance your experience. Learn more