Q: Your security team discovers that engineers have committed GCP service account JSON private keys into git repositories. Walk me through how you completely eliminate JSON keys in GKE using Workload Identity Federation without causing downtime for running microservices.
Step-by-step production runbook for eliminating compromised JSON service account keys in Google Kubernetes Engine (GKE) by binding Kubernetes Service Accounts directly to Google IAM Service Accounts with Workload Identity.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Enable Workload Identity on GKE Cluster & Node Pools
Ensure cluster and node pools have GKE Workload Identity enabled via Google Cloud CLI:
- Cluster Update: Executed
gcloud container clusters update prod-cluster --workload-pool=PROJECT_ID.svc.id.goog. - Node Pool Metadata: Updated node pools with
--workload-metadata=GKE_METADATAto enforce the GKE metadata server.
Create IAM Bindings between K8s SA and Google Service Account
Establish trust relationship using roles/iam.workloadIdentityUser:
- IAM Policy Binding: Bound the K8s service account in the cluster namespace to the Google Service Account (GSA).
- Command:
gcloud iam service-accounts add-iam-policy-binding GSA_NAME@PROJECT.iam.gserviceaccount.com --role roles/iam.workloadIdentityUser --member 'serviceAccount:PROJECT.svc.id.goog[default/app-ksa]'.
Annotate K8s ServiceAccount & Perform Rolling Pod Restart
Connect the Kubernetes SA to the Google Service Account via annotation:
- Annotate Manifest:
kubectl annotate serviceaccount app-ksa iam.gke.io/gcp-service-account=GSA_NAME@PROJECT.iam.gserviceaccount.com. - Remove Volume Mounts: Removed
GOOGLE_APPLICATION_CREDENTIALSenvironment variables and secret volume mounts from deployment specs. - Rolling Rollout: Executed
kubectl rollout restart deployment/app-deployment.
Revoke Legacy Keys & Enforce Org Policy Constraint
Permanently prevent future service account key creation across the GCP Organization:
- Key Deletion: Audited and permanently deleted all static JSON keys via
gcloud iam service-accounts keys delete. - Org Policy: Enforced
constraints/iam.disableServiceAccountKeyCreationorganization-wide to prevent regression.
- Enabled Workload Identity on the GKE cluster and node pools using the project workload pool.
- Bound Kubernetes Service Accounts to Google Service Accounts using roles/iam.workloadIdentityUser.
- Annotated K8s service accounts and removed volume mounts and GOOGLE_APPLICATION_CREDENTIALS env vars.
- Enforced constraints/iam.disableServiceAccountKeyCreation org policy to permanently block static keys.