M4 · Identity and security
Authorization
27 / 61

IAM gets you to the cluster; RBAC limits what you can do inside it

Google identities authenticate through GKE. Kubernetes subjects such as users and groups then match RoleBindings or ClusterRoleBindings for API verbs and resources.

LayerQuestionShopwave pattern
Cloud IAMMay this principal obtain cluster credentials or use GKE APIs?Platform group receives the minimum container roles
Kubernetes RBACMay this subject get, list, patch or delete this resource?Team groups bind to namespace Roles
Workload IAMMay this Pod call a Google Cloud API?Kubernetes ServiceAccount principal gets one narrow IAM role
AuditWho attempted the action and what decided it?Cloud Audit Logs plus Kubernetes audit evidence

Use groups for humans, service accounts for automation, and never solve a namespace problem with cluster-admin.