Kubernetes Service account with Workload ID

apiVersion: v1
kind: ServiceAccount
  name: bradley
  annotations: <gservice account email>

You will need to grant the GCP SA the below roles[NAMESPACE/KSA]

As well as:


These need to be granted to the GCP SA in GCP

See Workload Identity

