Impersonation is the most direct GCP escalation: a permission on a target service account lets you act as it without deploying anything. The roles/iam.serviceAccountTokenCreator role (and the individual permissions below) is the hinge, and it is frequently granted too broadly.
The primitives#
- getAccessToken: mint a short-lived OAuth token for the target directly.
- signJwt and signBlob: forge a signed JWT or blob as the target, then exchange it for a token.
- Token Creator grant: grant yourself Token Creator on the target with
serviceAccounts.setIamPolicy, then impersonate. - Implicit delegation: chain through an intermediate account to reach one you cannot call directly.
- Key creation: create a long-lived JSON key for durable access and persistence.
Using an impersonated identity#
Most gcloud commands accept the impersonation flag once you hold the permission:
gcloud <command> --impersonate-service-account=<target-sa>@<project>.iam.gserviceaccount.com
gcloud auth print-access-token --impersonate-service-account=<target-sa>@...