gke-workload-identity
Installation
SKILL.md
GKE Workload Identity Federation Troubleshooting Skill
Use this skill to systematically diagnose why a Pod using Workload Identity Federation for GKE cannot authenticate to Google Cloud APIs. Typical symptoms:
HTTP/403 ... Permission 'iam.serviceAccounts.getAccessToken' denied on resourcegoogle.auth.exceptions ... could not find default credentials/ComputeEngineCredentials cannot find the metadata server- API calls that unexpectedly use the node's default Compute Engine service account instead of the workload's identity.