QuestionQ18

Bootstrapping and maintaining a Google Cloud organization

You are developing an application that runs on Cloud Run. The application must access a third-party API using an API key. You need to identify a secure method to store and use the API key in the application while following Google-recommended practices. What should you do?

Explanation

Google Cloud recommends storing sensitive dependency values, including API keys, in Secret Manager. Cloud Run can expose a Secret Manager secret to the container as a secret-backed environment variable, with access controlled through the service identity's Secret Manager permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!