<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Cloud Computing - 分类 - 种树的时间</title><link>https://zhongshutime.com/categories/cloud-computing/</link><description>Cloud Computing - 分类 - 种树的时间</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>plantatree2023@gmail.com (种树者)</managingEditor><webMaster>plantatree2023@gmail.com (种树者)</webMaster><copyright>This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.</copyright><lastBuildDate>Sat, 06 Jun 2026 21:57:40 +0800</lastBuildDate><atom:link href="https://zhongshutime.com/categories/cloud-computing/" rel="self" type="application/rss+xml"/><item><title>GCP中的IAM问答</title><link>https://zhongshutime.com/gcp-iam/</link><pubDate>Sat, 06 Jun 2026 21:57:40 +0800</pubDate><author>plantatree2023@gmail.com (种树者)</author><guid>https://zhongshutime.com/gcp-iam/</guid><description><![CDATA[<div class="details admonition question open">
    <div class="details-summary admonition-title">
        <i class="icon far fa-circle-question" aria-hidden="true"></i>问题<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content">什么是service account？</div>
    </div>
</div>
<div class="details admonition info open">
    <div class="details-summary admonition-title">
        <i class="icon fas fa-info" aria-hidden="true"></i>信息<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content">Service Account（服务账号）是一种特殊类型的 Google 账号，它通常代表一个应用、服务或虚拟机（VM）等非人类用户，而不是代表最终的终端用户。 它用于在不需要用户凭据（如密码或 OAuth 令牌）的情况下，让你的代码或服务能够安全地调用 Google Cloud APIs 并在 GCP 内进行身份验证与授权。
比如，当你写code去call BigQuery的GetTable API，你的code可以自动寻找你的service account。</div>
    </div>
</div>
<div class="details admonition question open">
    <div class="details-summary admonition-title">
        <i class="icon far fa-circle-question" aria-hidden="true"></i>问题<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content">service account的格式是什么？</div>
    </div>
</div>
<div class="details admonition info open">
    <div class="details-summary admonition-title">
        <i class="icon fas fa-info" aria-hidden="true"></i>信息<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content">用户自定义的Service Account的标准格式如 <code>[SA-NAME]@[PROJECT-ID].iam.gserviceaccount.com</code></div>
    </div>
</div>
<div class="details admonition question open">
    <div class="details-summary admonition-title">
        <i class="icon far fa-circle-question" aria-hidden="true"></i>问题<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content">P4SA是什么？</div>
    </div>
</div>
<div class="details admonition info open">
    <div class="details-summary admonition-title">
        <i class="icon fas fa-info" aria-hidden="true"></i>信息<i class="details-icon fas fa-angle-right" aria-hidden="true"></i>
    </div>
    <div class="details-content">
        <div class="admonition-content"><p>P4SA 全称为 Per-Product, Per-Project Service-Account，通常在 GCP 中被称为 Service Agent（服务代理）。</p>]]></description></item></channel></rss>