Even with unlimited, no-password required sudo, it provides a valuable addition: audit logging.<p>every command you run with sudo is logged, along with the user than ran it. On GCP each end user is provisioned a separate login user, and logs can be shipped to Stackdriver Logging where they cannot be modified. This makes access really verifiable.