# Google Cloud: credentials

You create a service-account JSON key, store it under Cloud accounts, and let MainPath create GKE clusters and databases in your Google Cloud project.

> Source: https://www.mainpath.ai/en/docs/gcp-cloud-credentials/

Under [Cloud accounts]({{< relref "cloud-accounts" >}}) you store a service account for Google Cloud. MainPath uses it to create [Kubernetes clusters]({{< relref "kubernetes-integration" >}}) (GKE) and optional databases (Cloud SQL) in your project.

## Create a service account and JSON key

1. Open the [Google Cloud console](https://console.cloud.google.com/) and select the project where the clusters should live.
2. Go to **IAM & Admin** → **Service Accounts** → **Create service account**.
3. Choose a descriptive name such as `application-platform`.
4. Assign roles that can create GKE clusters, networks, and Cloud SQL instances, for example **Kubernetes Engine Admin**, **Cloud SQL Admin**, and **Compute Network Admin**. In a dedicated project for MainPath, **Editor** is often enough.
5. Open the new service account → **Keys** → **Add key** → **Create new key** with type **JSON**.
6. Download the file. Google shows the private key only in that download.

The official guide is [Create and delete service account keys](https://cloud.google.com/iam/docs/keys-create-delete).

## Add the account in MainPath

1. Open **Cloud accounts** and click **Add cloud account**.
2. Choose **Google Cloud**.
3. Enter a name, slug, and these values:

| Platform field | Source |
|---|---|
| Service account JSON | full contents of the JSON file |
| GCP project ID | the `project_id` field in that file; if you leave it empty, MainPath takes the value from the JSON |
| Region | Google Cloud region, for example `europe-west3` for Frankfurt |

4. Save. Then select the account when you create a cluster under **Kubernetes clusters**.

## See also

- [Cloud accounts]({{< relref "cloud-accounts" >}})
- [Kubernetes clusters]({{< relref "kubernetes-integration" >}})
- [AWS: credentials]({{< relref "aws-cloud-credentials" >}})
- [Azure: credentials]({{< relref "azure-cloud-credentials" >}})
- [Open Telekom Cloud: credentials]({{< relref "otc-cloud-credentials" >}})

