GKE Workload Identity is a way to associated a Google Service Account with a Kubernetes Service Account.
Google Service Account <=> Kubernetes Service Account
GSA <=> KSA
In this video, we'll automate the entire process of creating both the GSA and KSA and binding the 2 together. We'll use the Kubes toosl to do this. We'll use Kubes Hooks to create the Google Service Account: https://kubes.guru/docs/helpers/google/service-account/
We'll confirm everything is working with the gcloud
command.
Useful Commands
gcloud iam service-accounts get-iam-policy SERVICE_ACCOUNT@GOOGLE_PROJECT.iam.gserviceaccount.com
Links
Google GKE Kubernetes
3h 29m
Explore lesson as part of a learning path
Get full access to these great resources
All for less than the price of coffee a day