Securing GCP AppEngine Go1.11 Application with Identity-Aware Proxy and being able to access it.

There’s a lot have been said about how to secure it, but not that much said about what is it that you should do next? Use it, I guess? I’ve been struggling getting to know how the things may and should work and would like to share my somewhat painful experience.

Deploying your application