Skip to content

[GEP-26] Support workload identity tokens for cloud provider CLIs  #406

@petersutter

Description

@petersutter

What would you like to be added:
With GEP-26, a new WorkloadIdentity resource is introduced. This resource is comparable to ServiceAccounts, for which tokens can be requested by creating a security.gardener.cloud/v1alpha1.TokenRequest. This is similar to the TokenRequest API for service accounts.

It should be possible to request such tokens via gardenctl to configure the cloud provider CLIs. This is similar to how it is currently done with the provider-env command, which uses the static cloud infrastructure credentials stored as secrets in the garden cluster.

Why is this needed:

Metadata

Metadata

Assignees

No one assigned

    Labels

    component/gardenctlGardener CLIkind/enhancementEnhancement, improvement, extensionlifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.status/acceptedIssue was accepted as something we need to work on

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions