This definitely seems like an improvement over the existing permissions system, but still seems to lack the granularity in resources to do things like per-bucket permissions in GCS.
It's a little silly to have to give a machine full read access to GCS if it just needs to download some packages/binaries but doesn't need access to things like database backups.