Connect your clouds
Connect Google Cloud
Connect a Google Cloud project with keyless access through Workload Identity Federation.
About 5 minutes
Zaysa connects to your Google Cloud project without a service account or key. You run one Cloud Shell script to set up Workload Identity Federation. For each scan, Google issues a token that lasts about one hour. Zaysa stores no long-lived cloud credential for this connection.
Choose how to connect
| Method | What Zaysa stores | How long it lives | Who rotates it | When to use it |
|---|---|---|---|---|
| Keyless (recommended) | No cloud secret | A token lasting about one hour per scan | Google issues temporary tokens | Use this. It is the default and needs no secret. |
| Access Keys / Secret | Encrypted service-account JSON key | Long-lived; does not expire on its own | You rotate the key in Google Cloud | Only if your company does not allow keyless access and allows service-account keys. |
Before you start
- A Zaysa account. New here? Start with Getting started.
- Owner access, or enough IAM rights to enable APIs, create a Workload Identity pool and change the project IAM policy.
- Google Cloud Shell, opened from the Google Cloud console. Select the project you want to connect. If needed, run
gcloud config set project YOUR_PROJECT_ID.
What Zaysa gets
| In your Google Cloud project | What the script does |
|---|---|
| APIs | Enables bigquery.googleapis.com cloudasset.googleapis.com compute.googleapis.com monitoring.googleapis.com recommender.googleapis.com logging.googleapis.com cloudresourcemanager.googleapis.com iam.googleapis.com container.googleapis.com sqladmin.googleapis.com storage.googleapis.com run.googleapis.com cloudfunctions.googleapis.com pubsub.googleapis.com artifactregistry.googleapis.com redis.googleapis.com file.googleapis.com and sts.googleapis.com. |
Pool zaysa-pool and provider zaysa-oidc | Creates them if missing and reuses them if present. The OIDC provider trusts https://zaysa.io and accepts only subjects beginning with zaysa:deploy:. |
| Project IAM roles | Grants roles/cloudasset.viewer roles/compute.viewer roles/monitoring.viewer roles/recommender.viewer roles/logging.viewer roles/browser roles/bigquery.jobUser roles/bigquery.dataViewer roles/container.viewer roles/cloudsql.viewer roles/storage.bucketViewer roles/run.viewer roles/cloudfunctions.viewer roles/pubsub.viewer roles/artifactregistry.reader roles/redis.viewer roles/file.viewer directly to your Zaysa federated identity. The BigQuery roles let Zaysa read a billing export for costs as Google invoices them. |
See the Permissions reference for each feature's exact grants and what happens without them.
No service account or key
Connect with keyless access
Option A: Cloud Shell script
Open the connection window
In Zaysa, open Resources → Cloud Accounts and click Connect account (1).
Choose Google Cloud and name the project
(1) Choose Google Cloud Platform as the Cloud Provider. (2) Name the connection, for example
Production GCP. (3) Leave Keyless selected. All Regions (Recommended) is right for most projects.Run the script in Google Cloud Shell
Scroll to Run this once in Google Cloud Shell. Click Open Cloud Shell (1). Check that the project shown at the top of the shell is the one you want to connect. Click Copy (2), paste the whole block into Cloud Shell and press Enter.
The script reads the selected project and its number, enables the APIs, sets up the pool and provider, grants the roles and prints the project number. It takes about 30 seconds and ends like this:
Google Cloud Shell→ Setting up keyless access for project my-project (123456789012)… Operation "operations/acat.p2-123456789012-a43e04eb-…" finished successfully. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. Updated IAM policy for project [my-project]. ✅ Done! Type this PROJECT NUMBER into Zaysa: 123456789012Prefer the console?
Choose Console, click by click next to Cloud Shell script. It lists the console screens and values to copy.Enter the project number
Type the number the script printed into GCP project number (1). Zaysa shows the full provider path under Zaysa will connect to:. If you used custom pool or provider names, choose Used custom pool / provider names? Paste the full path instead.
Click Connect Account
Scroll to the bottom and click Connect Account (1). The optional BigQuery billing export section above the button can be set up later.
Asked to sign in again?
Connecting a cloud account is a sensitive action. If you signed in more than 30 minutes ago, Zaysa asks you to sign in again with your email and password (and your authenticator code, if you use one), then brings you back to Cloud accounts. Open Connect account again and repeat the last two steps: the pool and provider in Google Cloud are already there.Wait for trust verification
Zaysa first says Cloud account connected — verifying the cloud trust…. It then says Cloud trust verified — scans & deploys will authenticate and shows Verify again.
Option B: Console, click by click
Choose Console, click by click (1) in Zaysa. Its New principals value is personalised for your Zaysa user and project number. Copy it from the guide.
Create the identity pool and OIDC provider
Open IAM & Admin → Workload Identity Federation → Create pool. Under Create an identity pool, set Name to
zaysa-pooland click Continue. Under Add a provider to pool, choose Select a provider →OpenID Connect (OIDC). Set Provider name tozaysa-oidc, Issuer (URL) tohttps://zaysa.io, and Audiences to Default audience. Do not add an allowed audience. Click Continue.Configure provider attributes
Under Configure provider attributes, set Google 1 (google.subject) to
assertion.sub, and Attribute Conditions toassertion.sub.startsWith('zaysa:deploy:'). Click Save.Grant read-only access
Open IAM & Admin → IAM and click Grant access. Copy the generated New principals value from Zaysa. Your project number is the digits on the console home Project info card. Add these Role values, using + Add another role between them:
Cloud Asset Viewer,Compute Viewer,Monitoring Viewer,Recommender Viewer,Logs Viewer,Browser,BigQuery Job User,BigQuery Data Viewer,Kubernetes Engine Viewer,Cloud SQL Viewer,Storage Bucket Viewer,Cloud Run Viewer,Cloud Functions Viewer,Pub/Sub Viewer,Artifact Registry Reader,Redis Viewer,Filestore Viewer. Click Save.Enable the APIs
Open APIs & Services → Library. Enable Cloud Asset API, Compute Engine API, Cloud Monitoring API, Recommender API, Cloud Logging API, Cloud Resource Manager API, Identity and Access Management (IAM) API, and Security Token Service API. Enter your project number in GCP project number in Zaysa and click Connect Account.
Beam also needs
For just-in-time human access, Beam must act as the connected deploy service account. That account needs roles/iam.serviceAccountAdmin to create and disable each grant's service account and roles/resourcemanager.projectIamAdmin to bind and remove its roles. Beam › Connections › Check readiness checks these permissions and gives the exact fix.
Connect with a service-account key
Choose Access Keys / Secret (1) when keyless is unavailable. Zaysa stores the JSON key encrypted, but the long-lived key never expires on its own. Some organizations block key creation.
Option A: Cloud Shell script
Create the service account and JSON key
In Zaysa, click Copy on the service-account key guide. Open Google Cloud Shell, select your project, paste the block, and press Enter. The script enables the scan APIs, creates or reuses
zaysa-reader, grants the eight read-only roles listed above, and creates one JSON key. Copy everything between the lines it prints into Service Account JSON. The guide's Expected identity iszaysa-reader@<your project id>.iam.gserviceaccount.com.
Option B: Google Cloud console
Create the service account and roles
Open IAM & Admin → Service Accounts → + Create service account. Set Service account name to
zaysa-reader, then click Create and continue. Under Select a role, addCloud Asset Viewer,Compute Viewer,Monitoring Viewer,Recommender Viewer,Logs Viewer,Browser,BigQuery Job User,BigQuery Data Viewer,Kubernetes Engine Viewer,Cloud SQL Viewer,Storage Bucket Viewer,Cloud Run Viewer,Cloud Functions Viewer,Pub/Sub Viewer,Artifact Registry Reader,Redis Viewer,Filestore Viewer, using + Add another role. Click Continue → Done.Download the JSON key and enable APIs
Open the account's Keys tab → Add key → Create new key. Set Key type to
JSON, click Create, then open the downloaded file and paste its whole contents into Service Account JSON. In APIs & Services → Library, enable Cloud Asset API, Compute Engine API, Cloud Monitoring API, Recommender API, Cloud Logging API, Cloud Resource Manager API, and Identity and Access Management (IAM) API. Click Test Connection, then Connect Account.
Rotate a key
Go to FinOps → Optimization. Under Connected cloud accounts, open the account's ⋮ menu, click Edit account & billing, paste the new JSON key, and click Save Credentials. Remove the old key in Google Cloud.
Add the billing export (optional)
A BigQuery billing export gives Zaysa real invoiced cost. Set it up while connecting or through Edit account & billing.
Create the dataset and find your billing account ID
Enter the export project in BigQuery Project ID and dataset in BigQuery Dataset, normally
billing_export. Click Open Cloud Shell (1) and Copy in the billing guide. Paste the personalised block into Cloud Shell and press Enter. It creates the dataset and prints the billing account ID. The verified run printed:Google Cloud ShellDataset 'my-project:billing_export' successfully created. ✅ Billing account id (type it into Zaysa): XXXXXX-XXXXXX-XXXXXX Dataset created: billing_export Now enable the export in the console (step 2) — Google has no command for that step.For the console path, open BigQuery Studio. In Explorer, click ⋮ next to your project → Create dataset. Set Dataset ID to
billing_export, Location type toMulti-region→US, then click Create dataset. Find the billing account ID on Cloud Billing.Enable the export in Cloud Billing
Click Open Cloud Billing (2), or open Cloud Billing. Select the billing account → Billing export → BigQuery export tab. Under Detailed usage cost, click Edit settings. Set Project to your export project and Dataset to
billing_export, then click Save. Google starts sending data within 24 hours, with no backfill of earlier months.Enter the billing account ID
Type the billing account ID into the billing guide. Zaysa fills BigQuery Table with
gcp_billing_export_resource_v1_<billing account id with underscores>. You can also copy the exact table name from BigQuery after the first export arrives.Check permissions and save
If the export is in the connected project and you used the setup script, the BigQuery roles are already granted. Click Save & Continue, or Skip for now. For an existing account, click Save Billing Config. If the export is in another project, grant the connected identity
roles/bigquery.dataViewerandroles/bigquery.jobUserthere. Use the personalised grant script in Zaysa with Cloud Shell, or open IAM & Admin → IAM → Grant access. Paste the generated New principals value, addBigQuery Data ViewerandBigQuery Job User, and click Save.
Check it worked
Click Check permissions on the card to see which features are ready in this connection; the Check permissions guide explains the results.
The account card shows Keyless, Connected (1), the region and the project number.
Run scan on the card takes you to the Cost Optimizer, where you scan the project to see what it costs and where the waste is. The first scan guide walks through it.
If something goes wrong
“No GCP project is selected in this Cloud Shell”
Run gcloud projects list, then gcloud config set project YOUR_PROJECT_ID. Paste the whole script again.
“Cannot read project”
Either the wrong project is selected or your Google account is not an Owner of it. Switch to a project you own with gcloud config set project YOUR_PROJECT_ID, then paste the script again.
“Trust not confirmed yet”
A new trust can take a minute to propagate. Wait and click Verify again. Check that you typed the project number, which contains only digits, rather than the project ID.
“Cloud Logging access denied — grant roles/logging.viewer”
Existing keyless connections need this read-only role once. Replace PROJECT_ID, PROJECT_NUMBER, and YOUR_USER_ID with the values for your connection; the subject has the same form as the setup script. Then run:
gcloud projects add-iam-policy-binding PROJECT_ID --member="principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/zaysa-pool/subject/zaysa:deploy:YOUR_USER_ID:gcp:PROJECT_NUMBER" --role="roles/logging.viewer" --condition=NoneThe new role can take about a minute to apply. Then reload Cloud History.
“organization policy blocks service-account keys”
Use Keyless if your organization enforces iam.disableServiceAccountKeyCreation.
“has no billing account linked”
Check that the selected project has a billing account and that you have billing.resourceAssociations.list.
Remove access
- In Google Cloud, open IAM & Admin → IAM. Remove the principal whose name contains
zaysa-pool/subject/zaysa:deploy:from the eight roles listed above. - If nothing else uses the provider and pool, delete them in the Google Cloud console or run these commands in Cloud Shell with the project selected:
gcloud iam workload-identity-pools providers delete zaysa-oidc --workload-identity-pool=zaysa-pool --location=global
gcloud iam workload-identity-pools delete zaysa-pool --location=globalFor a service-account key connection, delete its key or the zaysa-reader service account. To remove the account from Zaysa, click the bin icon on its card.