Learn how to securely manage access to the Service Account with Owner role that is central to your Glean self-hosted deployment
glean-admin@<gcp project name>.iam.gserviceaccount.com
) will revoke Glean’s access to the GCP components that store sensitive company data, such as the CloudSQL databases and the Kubernetes cluster.
For serious infrastructure issues, Glean may require time-bound access to the service account for inspection, repair, or restoration. In this scenario, access is limited to senior Glean Engineering or Support team members and must be documented and approved by Glean management. All actions performed by Glean staff are recorded within the audit logs of the GCP project. Glean encourages regular monitoring of these logs and endorses GCP’s guidance on monitoring service account usage patterns.
Navigate to IAM and Admin
Find the service account
glean-admin
).Access menu
Toggle status
Navigate to Service Accounts
Create new service account
glean-admin
), and click Create and Continue.Grant Owner role
Complete creation
Manage keys
glean-admin
. Click the three vertical dots on the right side to open the menu, and select Manage Keys.Create new key
Share key securely
How does Glean securely store the account key?