Skip to content

Unit 2: Google Workspace & GCP integration #42

@TeoSlayer

Description

@TeoSlayer

Scope

Google Workspace domain-restricted join rules and GCP Workload Identity for Kubernetes and Compute Engine.

Deliverables

  • OIDC preset for Google (accounts.google.com issuer)
  • Domain restriction: only @acme.com tokens accepted (hd claim validation)
  • GKE Workload Identity: pod-level identity via projected service account tokens
  • Compute Engine service account: metadata server token → OIDC token
  • Google Groups → Pilot network mapping (via Directory API or token claims)
  • Setup guide: Google Cloud project configuration, Workload Identity setup

Priority: HIGH

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions