An IAM policy binding must already grant this namespace and ServiceAccount roles/iam.workloadIdentityUser on the target GCP service account
Add the iam.gke.io/gcp-service-account annotation naming that service account.
A raw PATCH needs patch alone.
The get that kubectl sends first is a CLI artifact
Already-running pods pick up the new identity within seconds with no restart, so no pod-level access is needed and recycling pods is not a mitigation
Tokens then carry exactly that service account IAM roles, so its cloud permissions become reachable from inside the cluster
Rights needed, any one set:
· any one; the annotation is the same write
· any one; the annotation is the same write

