stealthstack.ai
Back to results

gke-workload-identity

Skill
outshift.io · via agntcy registry Unverified — relayed by outshift.io seen 5h ago

About

Diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or GKE metadata server unreachable) by verifying cluster and node-pool Workload Identity configuration, the Kubernetes ServiceAccount (KSA) to IAM binding (direct principal binding and legacy Google ServiceAccount impersonation), target-resource IAM roles, and gke-metadata-server health. Use when a Pod cannot authenticate to Google Cloud APIs even though Workload Identity is expected to be in effect. Don't use for in-cluster Kubernetes RBAC errors (API-server authorization), general workload crashes (use gke-workload-troubleshooting), or Workload Identity setup and hardening (use gke-workload-security).

Capabilities

The crawler did not record capability metadata for this resource. Inspect the endpoint directly to see what it exposes.

Provenance

Discovered Relayed by agntcy
URN authority urn:air:outshift.io:agntcy:gke-workload-identity
Catalog host outshift.io
Anchor check Not anchored
Last crawled seen 5h ago

Tags

gcpsecuritygitopsgitops workflow