How Should You Secure Cloud Run with Browser SSO?
You run a web application on top of Cloud Run that is exposed to the internet with an Application Load Balancer. You want to ensure that only privileged users from your organization can access the application. The proposed solution must support browser access with single sign-on. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of Google Cloud access control mechanisms, specifically distinguishing between native IAM roles and network-level controls versus a dedicated secure gateway like IAP for web SSO.
Securing internet-exposed Cloud Run services requires a centralized authentication proxy that integrates with organizational identity. This page establishes why Identity-Aware Proxy is the correct architectural choice for enforcing browser-based single sign-on.
Learners often select Option A or C, mistakenly believing Cloud Run has a native authentication toggle or that IP-based firewall rules can handle user-level browser SSO without additional identity providers.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Identity-Aware Proxy (IAP) acts as a reverse proxy that intercepts HTTP/HTTPS requests before they reach the Cloud Run service. It handles user authentication against Google Cloud Identity, enabling seamless browser-based single sign-on, and enforces authorization using the specificIAP-secured Web App User IAM role. This architecture perfectly satisfies the requirement to restrict access to designated organizational users while maintaining internet exposure via the Application Load Balancer.Why the Other Options Are Wrong
Option A incorrectly assumes Cloud Run includes a built-in authentication switch; it actually delegates interactive web authentication to external proxies like IAP. Option B assigns theCloud Run User role, which grants management permissions rather than execution or access rights, providing zero authentication layer. Option C restricts traffic at the network layer using static IP whitelisting, which fails to authenticate individual users and contradicts the stated internet-facing ALB design.Community Comment Notes
Community consensus strongly favors this option, with multiple learners noting that IAP provides centralized access control and integrates natively with Google Identity. As one contributor summarized, this setup is the standard Google-recommended pattern for securing web workloads behind load balancers. The unanimous vote distribution confirms that test-takers recognize IAP as the definitive solution for browser SSO scenarios.Official Reference
Exam Strategy
When a question specifies browser access with single sign-on for an internet-facing workload, immediately look for a managed identity gateway like IAP. Avoid options that rely on native service toggles or static IP restrictions when user-level authentication and session management are explicitly required.
Frequently Asked Questions
Why isn't Cloud Run Invoker used for browser access?
Cloud Run Invoker grants permission to invoke the service programmatically or via service accounts, not for interactive browser sessions requiring SSO.
Can firewall rules replace IAP for user authentication?
No, firewall rules filter traffic by IP address only and cannot authenticate individual users or enforce single sign-on in a web browser.