I use jcloud for create instance in GCE. It create instances without binded service Account. It not allow use GC resources from nodes.
For manually made instance it show serviceAccounts:
$ gcloud compute instances describe jenkins-master | grep -A3 serviceAccounts
- email: firstname.lastname@example.org
For instance made by jcloud plugin it doesn't have serviceAccounts:
$ gcloud compute instances describe jenkins-slave-ubuntu16-behat-f0e | grep -A3 serviceAccounts
It will be very helpful bind it automatically to account used for create instance.