# Connect Google Cloud

> Coming soon, not available yet. Create a Google Cloud project and a service account with the Compute roles Rowsafe needs, and a JSON key for it, so Rowsafe can create database servers (Compute Engine VMs) there. The roles, the custom role alternative, and how to revoke it.

Source: https://rowsafe.sh/docs/guides/cloud-accounts/google-cloud

> **Coming soon: you can't connect Google Cloud yet:** Rowsafe can't create servers in Google Cloud yet: it has only been tested against a stand-in for Google Cloud's API, not a real account, so the dashboard shows Google Cloud as coming soon. This page describes how connecting it will work. Today, use [DigitalOcean](https://rowsafe.sh/docs/guides/cloud-accounts/digitalocean), [AWS](https://rowsafe.sh/docs/guides/cloud-accounts/aws) or [OVHcloud](https://rowsafe.sh/docs/guides/cloud-accounts/ovh), or [Rowsafe Cloud](https://rowsafe.sh/docs/guides/rowsafe-cloud).

To [create servers for you](https://rowsafe.sh/docs/guides/create-a-server) in Google Cloud, Rowsafe needs a **service account key** for a project of its own. You create both in the Google Cloud console and paste the key into the dashboard once. It takes about five minutes.

## Create the service account and its key

### Create a project

In the [Google Cloud console](https://console.cloud.google.com), create a new project just for these databases (the project picker at the top, **New project**), and make sure billing is turned on for it. The roles below reach the whole project, so a project of its own keeps everything else out of reach.

### Turn on the APIs

Open **APIs & Services**, click **Enable APIs and services**, and turn on **Compute Engine API** and **Cloud Resource Manager API**.

### Create the service account

Open **IAM & Admin**, then **Service accounts**, and click **Create service account**. Name it `rowsafe`. Give it the roles &#x2A;*Compute Instance Admin (v1)**, **Compute Network Admin** and **Compute Security Admin** (or a [custom role](#what-access-this-gives-rowsafe) with exactly the permissions Rowsafe needs), then click **Done**.

### Create a key

Open the new service account, go to **Keys**, click **Add key**, **Create new key**, choose **JSON** and click **Create**. A file downloads.

If Google says key creation is turned off by an organization policy, an administrator of your Google Cloud organization has to allow service account keys for this project.

### Paste it into Rowsafe

Open the file and copy everything in it. In the Rowsafe dashboard, open **Settings → Cloud accounts** (or **Create a server for me**), click **Connect a cloud account**, choose **Google Cloud**, paste it into &#x2A;*Service account key (JSON)**, give the account a name your team will recognize, and click **Connect**. Leave **Project ID** empty to use the project the service account belongs to.

Then delete the downloaded file: Rowsafe keeps the key encrypted, and you don't need another copy.

Rowsafe checks the key before it saves it: that it works, that it sees the project, and that it has every permission it needs, without creating anything. If a permission is missing, it says which.

## What access this gives Rowsafe

The three roles, on the project:

| Role                        | ID                               |
| --------------------------- | -------------------------------- |
| Compute Instance Admin (v1) | `roles/compute.instanceAdmin.v1` |
| Compute Network Admin       | `roles/compute.networkAdmin`     |
| Compute Security Admin      | `roles/compute.securityAdmin`    |

They let the key manage every VM, disk, firewall rule and address in the project, nothing outside Compute Engine, and nothing in other projects. For less, create a custom role (**IAM & Admin**, **Roles**, **Create role**) with exactly these permissions and give the service account that instead:

```text
compute.projects.get
compute.regions.get
compute.regions.list
compute.instances.create
compute.instances.delete
compute.instances.get
compute.instances.list
compute.instances.setMetadata
compute.instances.setLabels
compute.instances.setTags
compute.instances.setMachineType
compute.instances.start
compute.instances.stop
compute.disks.create
compute.disks.setLabels
compute.images.useReadOnly
compute.networks.get
compute.networks.updatePolicy
compute.subnetworks.use
compute.subnetworks.useExternalIp
compute.firewalls.create
compute.firewalls.delete
compute.firewalls.get
compute.firewalls.list
compute.firewalls.update
compute.addresses.create
compute.addresses.delete
compute.addresses.get
compute.addresses.use
compute.addresses.setLabels
compute.zoneOperations.get
compute.regionOperations.get
compute.globalOperations.get
```

Rowsafe itself creates, for each server, a Debian 12 VM with its disk, a static public address, and firewall rules on the project's `default` network that let in only the addresses you chose, all labelled `rowsafe=1`. Your SSH keys go on the VM only if you give them (Rowsafe never adds its own), and project-wide SSH keys are blocked on it. It creates them only when someone in your organization clicks and confirms. The key is stored encrypted, never shown again, and used only for those servers. See [what Rowsafe does with your cloud account](https://rowsafe.sh/docs/guides/create-a-server#what-rowsafe-does-with-your-cloud-account).

## Revoke it

- **In Google Cloud:** **IAM & Admin**, **Service accounts**, `rowsafe`, **Keys**: delete the key. Or delete the service account.
- **In Rowsafe:** **Settings → Cloud accounts**, **Remove**. Rowsafe forgets the key; nothing in your project changes. You can remove an account once its servers are deleted.

After you revoke the key, your servers keep running and stay protected, but Rowsafe can no longer resize them, change their firewall or delete them. Do that in the Google Cloud console.

## Good to know

- Prices in the dashboard are "about": estimates from Google Cloud list prices in one region. Other regions differ, and your Google Cloud bill is what counts.
- The project needs its **`default` network**. A new project has one; if it was deleted, Rowsafe says so when you connect.
