Kubetier
  1. An IAM policy binding must already grant this namespace and ServiceAccount roles/iam.workloadIdentityUser on the target GCP service account

  2. Add the iam.gke.io/gcp-service-account annotation naming that service account.

    A raw PATCH needs patch alone.

    The get that kubectl sends first is a CLI artifact

  3. Already-running pods pick up the new identity within seconds with no restart, so no pod-level access is needed and recycling pods is not a mitigation

  4. Tokens then carry exactly that service account IAM roles, so its cloud permissions become reachable from inside the cluster

Rights needed, any one set:

K8s docs ↗