Problem Statement
Which practice is recommended for Google Cloud service accounts?
Explanation
GCP guidance recommends avoiding long-lived user-managed keys. Use workload identity and scoped roles, create single-purpose service accounts, and disable unused accounts to reduce lateral movement risk.
Code Solution
SolutionRead Only
gcloud iam service-accounts disable svc@proj.iam.gserviceaccount.com // retire unused accounts
