-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Description
Scope
Google Workspace domain-restricted join rules and GCP Workload Identity for Kubernetes and Compute Engine.
Deliverables
- OIDC preset for Google (accounts.google.com issuer)
- Domain restriction: only
@acme.comtokens accepted (hd claim validation) - GKE Workload Identity: pod-level identity via projected service account tokens
- Compute Engine service account: metadata server token → OIDC token
- Google Groups → Pilot network mapping (via Directory API or token claims)
- Setup guide: Google Cloud project configuration, Workload Identity setup
Priority: HIGH
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels