What’s is it

Use k8s service account as a GCP IAM service account

KSA

Kubernetes Service Account

GSA

GCP Service Account

multipe KSA to one GSA

https://danielsig727.tw/posts/201907/190720_gke_workload_identity/