Google Cloud Identity & Identity-Aware Proxy (IAP)

by Google Cloud

Cloud Identity manages users and groups; IAP provides an authorization layer in front of HTTPS apps and VM access (Google’s description).

Cloud Identity

Google’s Identity-as-a-Service: centrally manages users and groups, integrates with IAM, and federates with other identity providers such as Active Directory and Microsoft Entra ID. Editions: Free and Premium (feature comparison on the Cloud Identity editions page).

Identity-Aware Proxy

  • Protects, per Google’s overview: App Engine, Cloud Run, Compute Engine, GKE, on-premises apps (via connector), Cloud Storage buckets, and Cloud Load Balancing (external and internal HTTP(S)).
  • Authenticates with Google Accounts, Workforce Identity Federation or Identity Platform; authorises through IAM (for example the “IAP-secured Web App User” role).
  • Context-aware access for console/APIs, VMs (SSH/RDP) and web apps; IAP TCP forwarding lets you reach VMs without public SSH/RDP ports; works with VPC Service Controls.
  • Intended as an identity-based alternative to VPN for HTTP apps (zero-trust style; positioning, not verified here).

Signed headers (corrected)

  • IAP adds x-goog-iap-jwt-assertion (signed JWT) plus convenience headers x-goog-authenticated-user-email and x-goog-authenticated-user-id.
  • Verify the JWT: issuer https://cloud.google.com/iap; public keys at https://www.gstatic.com/iap/verify/public_key (or the -jwk variant); audience depends on the resource, e.g. Cloud Run /projects/PROJECT_NUMBER/locations/REGION/services/SERVICE_NAME, Compute Engine/GKE /projects/PROJECT_NUMBER/global/backendServices/SERVICE_ID.
  • Google warns that if an attacker bypasses IAP they can forge the unsigned headers, so never trust the email header alone. (An earlier version of this note pointed to the generic Google OAuth certs URL; that was wrong for IAP.)

Deployment notes

  • Enable IAP at one place per ingress path (service or load balancer), and make sure firewall/internal routing cannot bypass it.
  • IAP uses an OAuth client managed by Google; deleting it breaks flows.
  • Audit via Cloud Audit Logs.

Billing model

The fetched IAP overview does not discuss pricing; check the IAP and Cloud Identity pricing pages, and note that load balancer resources used with IAP are billed normally.

Sources

Open items

  • Whether IAP itself has a charge not confirmed; Chrome Enterprise Premium rename date not confirmed.