M4 · Identity and security
Module 4
25 / 61
4

Give every workload a short-lived identity

Security starts by removing service-account keys, then layers node integrity, admission, secret delivery, sandboxing and policy evidence.

secret-manager iconsecurity iconsa icon

How does a Pod authenticate?

Workload Identity Federation exchanges a Kubernetes token for a short-lived Google credential.

Who may call the API?

IAM authenticates; Kubernetes RBAC authorizes Kubernetes verbs.

What may run?

Binary Authorization and policy can reject untrusted deployments.

How far can compromise spread?

Shielded nodes, Sandbox and least privilege reduce the blast radius.