Kubetier
  1. An IAM policy binding must already grant this namespace and ServiceAccount roles/iam.workloadIdentityUser on the target GCP service account

  2. Add the iam.gke.io/gcp-service-account annotation naming that service account

  3. Pods using the ServiceAccount obtain GCP tokens carrying exactly that account's IAM roles

Rights needed, any one set:

K8s docs ↗