> For the complete documentation index, see [llms.txt](https://docs.untab.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.untab.io/setup/setting-up-access-on-gcp.md).

# Setting up access on Google Cloud Platform

1. Create new service account. Note the service account ID for use in the below instructions.
2. Assign roles to account:
   * BigQuery Job User
   * Compute Engine Viewer
3. Assign IAM policy to account:\
   `gcloud iam service-accounts get-iam-policy $SERVICE_ACCOUNT_ID > policy.yml`
4. edit policy.yml to add:

   <pre class="language-yaml" data-title="policy.yml"><code class="lang-yaml">bindings:
   - members:
   - serviceAccount:$SERVICE_ACCOUNT_ID
   role: roles/iam.serviceAccountTokenCreator
   </code></pre>
5. `gcloud iam service-accounts set-iam-policy $SERVICE_ACCOUNT_ID policy.yml`
6. In the Cloud API console enable the following APIs:
   * [IAM Service Account Credentials API](https://console.developers.google.com/apis/api/iamcredentials.googleapis.com/overview)
   * [Compute Engine API](https://console.developers.google.com/apis/api/compute.googleapis.com/overview)
   * [BigQuery API](https://console.developers.google.com/apis/api/bigquery-json.googleapis.com/overview)
7. Create a service account key for the new account
   * Go to <https://console.cloud.google.com/apis/credentials>
   * Click on "create credentials"
   * Select "service account key"
   * Select the new service account and JSON key format
   * Save the resulting JSON
8. Set up billing
   * Go to <https://console.cloud.google.com/billing>
   * Select "Billing export"
   * Enable big query export
9. Enter the following details on the [Infrastructure Provider settings page](https://app.untab.io/settings/providers)
   * The credentials JSON
   * The Google Cloud Project ID
   * The Google Cloud billing account ID
   * The name of the BigQuery dataset with the billing export
