To allow Yuki to operate across your organization, the Yuki service account is granted a limited set of organization-level IAM roles.
These permissions allow Yuki to:
List projects, reservations, assignments, and query job history for optimization
Create and manage Yuki’s projects and reservations
List users from other projects and grant them access to Yuki’s resources
Grant the following roles at the organization level:
3. Enable required APIs
Enable the Cloud Resource Manager API in the project hosting the Yuki service account:
4. Generate a service account key
Generate a service account key for secure authentication with Yuki:
5. Upload the key to Yuki
Download the generated file:
Return to the Yuki onboarding wizard
Upload the key in the Upload Service Account Key step
After granting these permissions and uploading the key, Yuki will create and manage a dedicated project to enable automatic query routing and optimization.
6. Connect the Billing Account to Yuki
Yuki needs access to a billing account in order to create and manage BigQuery reservations in a dedicated Yuki project. In this step, you’ll connect a billing account directly to the Yuki-managed project.
What you need to do:
In the Yuki onboarding wizard, click Connect Billing Account to Yuki Project. You’ll be redirected to Google Cloud Console "Set Billing Account" page
Select the billing account you want Yuki-Project to use
Once the billing account is connected, grant the required permissions to allow Yuki to use the BigQuery Reservation API:
After linking the billing account and granting the required permissions, check the checkbox to confirm completion and continue.
After completing this step, Yuki will automatically create the required BigQuery reservation in the Yuki project. This may take a few minutes.
Summary
After completing this guide, Yuki will have:
A dedicated service account for BigQuery access
Dedicated Organization-level permissions to discover and optimize resources
Secure key-based authentication to your GCP environment
A dedicated Yuki project and reservation for optimized routing
Once this setup is complete, Yuki will automatically provision a fully hosted Yuki Proxy, enabling optimized queries routing.