IAM gets you to the cluster; RBAC limits what you can do inside it
Google identities authenticate through GKE. Kubernetes subjects such as users and groups then match RoleBindings or ClusterRoleBindings for API verbs and resources.
| Layer | Question | Shopwave pattern |
|---|---|---|
| Cloud IAM | May this principal obtain cluster credentials or use GKE APIs? | Platform group receives the minimum container roles |
| Kubernetes RBAC | May this subject get, list, patch or delete this resource? | Team groups bind to namespace Roles |
| Workload IAM | May this Pod call a Google Cloud API? | Kubernetes ServiceAccount principal gets one narrow IAM role |
| Audit | Who attempted the action and what decided it? | Cloud Audit Logs plus Kubernetes audit evidence |
Use groups for humans, service accounts for automation, and never solve a namespace problem with cluster-admin.