VPS Snaps

Connect Google Cloud without a sign-in

Connect a Google Cloud project through Workload Identity Federation: no key, no Google sign-in to expire, and access you revoke by deleting one pool.

A Google Cloud connection made by signing in with Google belongs to the person who signed in. A Google Workspace can end it every few hours, and it stops when they leave. A keyless connection has neither problem: VPS Snaps acts as a service account in your project through Workload Identity Federation, so no key is created and nobody's sign-in is involved.

What you need

  • The Google Cloud project's ID, shown on its dashboard next to the project name.
  • Owner of the project, or the IAM roles to enable APIs and create service accounts, workload identity pools and role bindings in it.
  • Cloud Shell, which has gcloud ready. Any terminal with gcloud signed in works too.

Connect

  • In VPS Snaps, go to Providers → Add provider → Google Cloud, and open Or connect without a Google sign-in.
  • Enter the project ID and choose Show the commands. They are written for your workspace and no other.
  • Open Cloud Shell, paste the commands and run them. The last one prints the project number.
  • Paste the project number and choose Verify and connect. VPS Snaps acts as the service account once and lists your instances before anything is saved.

To switch a connection you made by signing in, open it under Providers and choose Switch to a keyless connection. Its backup jobs keep running, and the old sign-in is no longer used.

What the commands create

  • A service account named vpssnaps. It gets Compute Instance Admin for machine images and the instances recovery servers and test restores build, Compute Security Admin for their firewall rules, and Compute Network Viewer to read addresses for failover.
  • A workload identity pool and provider, both named vpssnaps, that trust https://vpssnaps.com/oidc/gcp only for statements naming your VPS Snaps workspace.
  • A binding that lets that one workspace act as the service account.

No key is created at any point. VPS Snaps signs a five-minute statement with its own key, Google exchanges it for a one-hour token, and that token works only as the vpssnaps service account in your project.

Revoking it

Delete the vpssnaps workload identity pool, and VPS Snaps can no longer act in the project. You can delete the service account as well. A deleted pool keeps its name for 30 days, so to set it up again within that time, undelete the pool rather than creating a new one.

gcloud iam workload-identity-pools delete vpssnaps --location=global --project=PROJECT_ID

If verifying fails

  • Could not find the workload identity provider: check the project number, and that every command finished without an error.
  • Set up for a different VPS Snaps workspace: the commands were copied from another workspace. Run the ones shown in this one.
  • May not act as the service account: the last binding command, roles/iam.workloadIdentityUser, did not run.
  • Compute Engine refused to list instances: a role binding did not run, or the Compute Engine API was enabled moments ago. Wait a minute and verify again.

Still stuck?

Open the failed run under Backup History and copy the error text out of the log — pasting that into your first message is usually the difference between one reply and four.