Skip to main content
A service account key lets Arklow reach Google Cloud on your behalf. Supported Pub/Sub sources, Pub/Sub destinations, and Google Cloud scale targets can use it.

Required permissions

To use the credential for:

Sources

  • pubsub.subscriptions.consume (roles/pubsub.subscriber)

Destinations

  • pubsub.topics.publish (roles/pubsub.publisher)

Scale targets

All Google Cloud managed instance group targets need:
  • compute.instanceGroupManagers.get
  • compute.instanceGroupManagers.list
Targets that manage an autoscaler floor also need:
  • compute.autoscalers.get
  • compute.autoscalers.update
Targets that set the group’s desired replica count instead need:
  • compute.instanceGroupManagers.update
These permissions cover the managed instance group read, autoscaler update, and group resize operations Arklow uses. The same permission names apply to regional groups.

Create your credentials

Create a service account before getting started. For more information, see Create service accounts. Download the JSON key file. You’ll paste its contents into Arklow when creating the credential.

Add credentials to Arklow

1

Open the credentials page

Go to Credentials and click Create credential.
2

Pick the type

Set Credential Type to GCP Service Account.
3

Paste the key file

Open the JSON key file you downloaded and paste it into the Service Account JSON field.
4

Save

Click Create credential.