A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?
Granting roles/artifactregistry.writer on the specific repository in Project B satisfies least privilege: the role permits pushing and reading artifacts but not deleting repositories or managing IAM, and scoping the binding to the repository rather than the whole project limits the service account to exactly the target it needs.
Why this answer
The Artifact Registry Writer role (roles/artifactregistry.writer) grants permissions to push and pull artifacts, which is exactly what the service account needs to push containers. Assigning it at the repository level in Project B follows least privilege by limiting access to only that repository. This role includes the necessary permissions like artifactregistry.repositories.uploadArtifacts without granting broader admin rights.
Exam trap
PCA often tests the difference between project-level and repository-level IAM, and candidates may choose Admin or Reader roles instead of the precise Writer role for push access.
How to eliminate wrong answers
Option A is wrong because Storage Object Admin is for Cloud Storage buckets, not Artifact Registry; Artifact Registry uses its own IAM roles. Option C is wrong because Artifact Registry Admin grants full control, including delete and manage permissions, which violates least privilege. Option D is wrong because Artifact Registry Reader only allows pulling, not pushing, so the service account could not upload containers.