Compute engine API – service accounts

Compute engine API enables different service accounts, I don’t understand how and why we require that ? I may sound dumb here please help

Celeste Wilson

I hope this is helpful: A service account is usually a compute resource that has an identity. This means that like you, a user with an identity, it can be assigned a role and complete functions on your behalf. When you create and enable different resources and services, google creates service accounts on your behalf to help you manage those resources. Different services and resources have different needs, which is why google sometimes creates different service accounts for different things. This is helpful in maintaining the IAM best practice of least privilege.

