Google Cloud
Enable one runtime service account for Google Cloud Storage backups and restores.
Create a service account scoped to the required buckets, objects, versions, and encryption keys. Encode its JSON key and configure the API process:
Restart the API. Towbar validates the enabled configuration before listening, shows Google Cloud Storage only when it is valid, and never stores or returns the service-account JSON. Confirm the effective IAM policy with a real resource backup and restore. Rotate by updating the environment, recreating the API container, verifying an operation, and then revoking the old key.
Last modified on September 9, 2026
