IAM
Service Accounts
gcloud iam service-accounts
policy binding gcloud projects add-iam-policy-binding $GOOGLE_CLOUD_PROJECT —member serviceAccount:test-service-account2@${GOOGLE_CLOUD_PROJECT}.iam.gserviceaccount.com —role roles/viewer
Activate
gcloud auth activate-service-account —key-file credentials.json
Storage
gcloud storage {ls,cp} gsutil acl get $PATH gsutil acl set private $PATH
ACL
(all accessible) gsutil iam ch allUsers:objectViewer gs://$MY_BUCKET_NAME_1