--- title: "GCP Connection" description: "Learn how to configure a GCP Connection for Infisical." --- Infisical supports [service account impersonation](https://cloud.google.com/iam/docs/service-account-impersonation) to connect with your GCP projects. Using the GCP integration on a self-hosted instance of Infisical requires configuring a service account on GCP and configuring your instance to use it. ![Service Account API](/images/app-connections/gcp/service-account-credentials-api.png) ![Service Account IAM Page](/images/app-connections/gcp/service-account-overview.png) Create a new service account that will be used to impersonate other GCP service accounts for your app connections. ![Create Service Account Page](/images/app-connections/gcp/create-instance-service-account.png) Press "DONE" after creating the service account. Download the JSON key file for your service account. This will be used to authenticate your instance with GCP. ![Service Account Credential Page](/images/app-connections/gcp/create-service-account-credential.png) 1. Copy the entire contents of the downloaded JSON key file. 2. Set it as a string value for the `INF_APP_CONNECTION_GCP_SERVICE_ACCOUNT_CREDENTIAL` environment variable. 3. Restart your Infisical instance to apply the changes. 4. You can now use GCP integration with service account impersonation. ## Configure Service Account for Infisical ![Service Account Page](/images/app-connections/gcp/service-account-overview.png) Create a new service account with an ID that follows this requirement: Your service account ID must end with the first two sections of your Infisical organization ID. Example: - Infisical organization ID: `df92581a-0fe9-42b5-b526-0a1e88ec8085` - Required service account ID suffix: `df92581a-0fe9` ![Create Service Account](/images/app-connections/gcp/create-service-account.png) Add the required permissions for secret syncs: ![Assign Service Account Permission](/images/app-connections/gcp/service-account-secret-sync-permission.png) After configuring the appropriate roles, press "DONE". To enable service account impersonation, you'll need to grant the **Service Account Token Creator** role to the Infisical instance's service account. This configuration allows Infisical to securely impersonate the new service account. - Navigate to the IAM & Admin > Service Accounts section in your Google Cloud Console - Select the newly created service account - Click on the "PERMISSIONS" tab - Click "Grant Access" to add a new principal If you're using Infisical Cloud US, use the following service account: infisical-us@infisical-us.iam.gserviceaccount.com If you're using Infisical Cloud EU, use the following service account: infisical-eu@infisical-eu.iam.gserviceaccount.com ![Service Account Page](/images/app-connections/gcp/service-account-grant-access.png) ## Setup GCP Connection in Infisical Navigate to the **App Connections** page in the desired project. ![App Connections Tab](/images/app-connections/general/add-connection.png) Select the **GCP Connection** option from the connection options modal. ![Select GCP Connection](/images/app-connections/gcp/select-gcp-connection.png) Select the **Service Account Impersonation** method and click **Connect to GCP**. ![Connect via GCP impersonation](/images/app-connections/gcp/create-gcp-impersonation-method.png) Your **GCP Connection** is now available for use. ![Impersonation GCP Connection](/images/app-connections/gcp/gcp-app-impersonation-connection.png)