GKE Workload Identity Federation: Principal Scoping and Metadata Paths
Design GKE workload federation with Kubernetes principals, scoped IAM bindings, metadata-server verification, and a safe migration from service-account keys.
tag
5 posts
Design GKE workload federation with Kubernetes principals, scoped IAM bindings, metadata-server verification, and a safe migration from service-account keys.
How Artifact Registry manages container images and language packages with explicit locations, repository-level access, vulnerability analysis, and cleanup policies.
How Cloud Run turns containers into managed services and jobs, including scaling, traffic splitting, IAM, networking, observability, and cold-start tradeoffs.
Why legacy Container Registry is no longer the service to design around, what remains true about gcr.io URLs, and how to move safely to Artifact Registry.
How GKE divides control between Google and the customer across Autopilot and Standard modes, including scaling, identity, networking, upgrades, security, and cost.