Rotation Type: Dual-PhaseThis rotation maintains two active credential sets with overlapping validity, ensuring zero-downtime during rotation cycles.
This rotation needs a GCP app connection. This guide walks you through creating a project-scoped app connection.
Prerequisites
- A project with secrets configured
- A GCP service account that your applications authenticate as with a key
- A role that lets you grant roles on that service account, such as Service Account Admin
- The
iam.disableServiceAccountKeyCreationorganization policy not enforced on the service account’s project (if it’s enforced, nobody can create keys in that project)
Step 1: Configure the service account for Infisical
Infisical needs a GCP connection whose service account has the Service Account Key Admin role on the service account you want to rotate. The role lets Infisical create and delete keys for the service account you want to rotate. Infisical manages the keys through the Identity and Access Management (IAM) API, so that API must be enabled on the project that contains the connection’s service account.1
If you don’t have a GCP connection yet, create the connection’s service account and let Infisical impersonate it, as described in Configure service account for Infisical.
2
Enable the IAM API (
iam.googleapis.com) on the project that contains the connection’s service account. This is a different API from the IAM Service Account Credentials API that the connection setup enables. You can enable it from the Google Cloud console or with the command line, replacing projectId with your GCP project ID:3
In the Google Cloud console, go to IAM & Admin > Service Accounts and select the service account you want to rotate.
4
Open the Principals with access tab and select Grant access.
5
In New principals, enter the email of the connection’s service account. Under Select a role, choose Service Account Key Admin, then select Save.

Step 2: Set up the rotation in Infisical
1
In your Secrets Manager project, open the dashboard, select Add New, then select Add Secret Rotation.
Then, select the GCP Service Account Key option.
Then, select the GCP Service Account Key option.
2
Under Configuration, choose the app connection and when the rotation runs:
Then select Continue.
- Environment: The project environment the rotated secret is stored in
- GCP Connection: The app connection the rotation uses
- Rotation Interval (In Days): The number of days between rotations
- Rotate At (Local Time): The time of day the rotation runs
- Auto-Rotation Enabled: When enabled, the key rotates on the schedule; turn it off to rotate manually only
- Create a new app connection
- Use an existing connection
Under GCP Connection, select Create Connection in the dropdown, then fill in:
- Name: A name for the connection
- Description (optional): What the connection is for
- Method: Service Account Impersonation
- Service Account Email: The email of the connection’s service account from Step 1
This creates a connection scoped to the current project. To share the connection across other projects, create it at the organization level first, then select it here.
Then select Continue.3
Under Parameters, enter the service account whose keys Infisical rotates:
-
Service Account Email: The email of the service account you want to rotate, such as
[email protected](you can’t change it after you create the rotation)
4
Under Mappings, choose the name of the Infisical secret that holds the rotated key:
-
Service Account Key: The name of the secret that holds the JSON key file
5
Give the rotation a Name and an optional Description. The name must be slug-friendly.
Then select Continue.
Then select Continue.6
Review your GCP Service Account Key Rotation configuration, then select Create secret rotation.


The JSON key file is now available through the mapped secret. If auto-rotation is enabled, the key rotates on your configured schedule.

Frequently asked questions
How do I use the key in my application?
How do I use the key in my application?
The secret holds the contents of a JSON key file. Google Cloud client libraries read the key from a file whose path is in the
GOOGLE_APPLICATION_CREDENTIALS environment variable, so write the secret’s value to a file and set the variable to that file’s path. Some client libraries can also take the JSON contents directly.How many keys does the rotation keep on the service account?
How many keys does the rotation keep on the service account?
Infisical keeps two keys: the current key, which the secret holds, and the previous key, which keeps working until the next rotation deletes it. During a rotation, Infisical creates the new key before it deletes the previous key, so the service account needs room for a third key under GCP’s limit of 10 keys per service account.Infisical doesn’t change or delete keys that it didn’t create. After your applications read the key from Infisical, delete any keys you created by hand so they stop working.
Can a new key fail right after a rotation?
Can a new key fail right after a rotation?
Yes, for a short time. GCP usually accepts a new key within seconds, but Google documents that it can take a minute or more. Infisical updates the secret as soon as GCP creates the key, so an application that reads the secret right after a rotation can briefly fail to authenticate.The previous key keeps working until the next rotation, so applications that still hold it aren’t affected. If your application reads the secret right after it changes, retry authentication for a short time.
Can I use this rotation with a key expiry policy?
Can I use this rotation with a key expiry policy?
Yes. If your Google Cloud organization enforces the
iam.serviceAccountKeyExpiryHours policy, every key expires after the policy’s duration, including the keys Infisical creates. Each key stays valid for two rotation intervals (first as the current key, then as the previous key), so set the rotation interval to at most half of the expiry. For example, with a 90-day expiry, rotate every 45 days or less.Next steps
GCP
Set up the GCP connection that Infisical uses to manage service account keys.
Overview
Learn how dual-phase and single-phase rotations work.