M4 · Identity and security
Identity flow
26 / 61

Workload Identity Federation exchanges a Pod identity for a short-lived token

The application uses Application Default Credentials. The GKE metadata server intercepts the request and performs federation without placing a key file in the container.

1ApplicationRequests a Google Cloud access token through ADC.
2GKE metadata serverIdentifies the Pod and requests a Kubernetes ServiceAccount JWT.
3Kubernetes APISigns a bound token for the workload identity.
4Security Token ServiceExchanges the JWT for a short-lived federated token.
5Google APIIAM evaluates the workload principal's permissions.
Enabling federation grants no permission by itself; IAM policy must name the workload principal.