Skip to content

Google Cloud connects keylessly — one Cloud Shell command sets up Workload Identity federation. No service-account key is created or stored.

  1. In the Google Cloud console, open the project picker and copy the Project ID — the lowercase string like acme-prod, not the display name or the numeric project number.

  2. In Dave, go to Integrations → Add integration → Google Cloud.

  3. Paste the Project ID.

  4. Set a Label — the name you will use to refer to this project, e.g. prod.

  5. Choose Connect GCP Project. Dave shows the setup command.

  6. Open Cloud Shell and confirm the project:

    Terminal window
    gcloud config get-value project
    gcloud config set project YOUR_PROJECT_ID
  7. Run the command. It creates a Workload Identity pool, a service account, and a least-privilege grant, so you need Owner or comparable rights. Dave finishes connecting once the binding propagates.

The script prints each step and is safe to re-run. If GCP rejects the connection, check the project ID, re-run it, then use Fix connection.