Securing Google Cloud Functions

Access control is granted on a per-function basis via Cloud IAM. This allows for access control over two sets of actions:

  • Developer operations: creating, updating, and deleting functions, as well as managing access to functions.

  • Function invocation: causing a function to be executed.

Functions also have their own identity, which is used when calling Google Cloud services or other functions. The permissions associated with this identity can be restricted in order to give functions least privilege access.



