An IAM policy binding must already grant this namespace and ServiceAccount roles/iam.workloadIdentityUser on the target GCP service account
Add the iam.gke.io/gcp-service-account annotation naming that service account
Pods using the ServiceAccount obtain GCP tokens carrying exactly that account's IAM roles
Rights needed, any one set:
· any one; the annotation is the same write
· any one; the annotation is the same write
