GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy-operator

Simplify Workload Identity Federation for Cloud SQL workloads

Open
#706 1 comment 0 reactions 1 assignee Claimed by @hessjcg View on GitHub
priority: p2 type: feature request
Dominant language
Go
Stars
120
Forks
18
PR merge metrics
No merged PRs in 30d

Description

[Workload identity federation](https://cloud.google.com/sql/docs/mysql/connect-kubernetes-engine) makes it possible to log in to the databases using the identity managed by K8s principals and an IAM service account. This is tricky to set up.

Consider ways that the operator could assist with the configuration. Perhaps the user specify an IAM principal in the AuthProxyWorkload, then the operator could automatically configure the K8s service accounts to apply the correct K8s principal to the pods where the AuthProxyWorkload is attached.

See https://github.com/GoogleCloudPlatform/cloud-sql-proxy-operator/issues/705

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.