Secure Cloud Run with IAP (Identity-Aware Proxy)

Google Cloud TechAbout 4 min readAug 22, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Identity Aware Proxy (IAP): A Google Cloud service that provides authentication and authorization for applications.
  • Cloud Run: A fully managed serverless execution environment for containerized applications.
  • Authentication: Verifying the identity of a user.
  • Authorization: Determining what a user is allowed to access.
  • Access Levels: Policies that define conditions for granting access to resources.
  • JSON Web Token (JWT): A standard for securely transmitting information between parties as a JSON object.
  • Workforce Identity Federation: Allows users from external identity providers (e.g., Okta) to access Google Cloud resources.
  • Zero Trust Security: A security model that assumes no user or device is trusted by default and requires verification for every access request.

IAP and Cloud Run Integration: A Simplified Setup

Ruchika, a product manager for enterprise security features of Cloud Run, demonstrates a simplified way to integrate Identity Aware Proxy (IAP) with Cloud Run. This integration allows developers to secure their Cloud Run services without implementing authentication logic in their application code.

Problem: Complex Authentication Setup

Previously, setting up authentication for Cloud Run services required more complex configurations, often involving load balancers. Developers requested a simpler solution.

Solution: Direct IAP Integration

The new integration enables IAP directly on a Cloud Run service through the Google Cloud Console.

Step-by-Step Process:

  1. Navigate to the Cloud Run service: Access the desired Cloud Run service in the Google Cloud Console.
  2. Go to the Security Tab: Select the "Security" tab.
  3. Enable "Requires Authentication": Choose the "Requires Authentication" option and select "IAP". This enables IAP directly on the Cloud Run service.
  4. Edit IAP Policy: Click on "Edit Policy" to add users or groups who should have access.
  5. Add Users/Groups: Enter the email addresses of users or groups. Ruchika adds her own account as an example.
  6. Configure Access Levels (Optional): Assign an access level or leave it blank for default access.
  7. Save Changes: Save the changes on both the "Edit Policy" page and the authentication card.

Demonstration

Ruchika demonstrates the process using a simple "HelloWorld" container deployed to Cloud Run. Initially, the service is public and accessible to anyone. After enabling IAP and adding a user, accessing the service redirects to a login page. Upon successful login with the authorized user's credentials, the "HelloWorld" page is displayed.

Cost and Availability

  • Cost: IAP is free of charge.
  • Availability: The integration was in public preview during the recording but may be in general availability by the time of viewing. Users should check the documentation for the current status.

Access Levels: Granular Control

Access levels allow for defining specific conditions for granting access.

Examples:

  • Restricting access by country (e.g., only allowing access from the US).
  • Requiring users to be on a trusted corporate network.
  • Ensuring devices are up-to-date with security patches.
  • Granting administrators access to specific URL paths (e.g., "/admin").
  • Creating custom access levels.

User Identification in Applications

IAP adds two headers to every request before it reaches the Cloud Run service, allowing the application to identify the current user.

  • The "HelloWorld" container demonstrates how to read these headers to display the user's email address.
  • Each request also includes a signed JSON Web Token (JWT) for added security, which can be validated by the application.

Code Example (from HelloWorld container): The container reads the headers to display the user's email.

User Management and Identity Federation

  • Initially, only users within the same domain as the project (and the project must be part of an organization) could be added. This restriction may be lifted in the future. Check the documentation for updates.
  • Users can also add groups of users.
  • For users who are not Google Cloud or Workspace users, Workforce Identity Federation can be used to integrate with external identity providers like Okta.

Zero Trust Security

The integration aligns with the principles of zero trust security by validating every request, regardless of the user's network or VPN. "Instead of trusting anyone on the current network or VPN, IAP validates every single request."

Conclusion

The new IAP integration with Cloud Run provides a simplified and centralized way to manage authentication and authorization for containerized applications. It enhances security, reduces application complexity, and aligns with zero trust security principles. The integration offers granular control through access levels and supports various user management scenarios, including Workforce Identity Federation.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.