GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy-operator
Simplify Workload Identity Federation for Cloud SQL workloads
未关闭
priority: p2
type: feature request
- 主要语言
- Go
- 星标
- 120
- 派生
- 18
- PR 合并指标
- 30 天内没有已合并 PR
描述
[Workload identity federation](https://cloud.google.com/sql/docs/mysql/connect-kubernetes-engine) makes it possible to log in to the databases using the identity managed by K8s principals and an IAM service account. This is tricky to set up.
Consider ways that the operator could assist with the configuration. Perhaps the user specify an IAM principal in the AuthProxyWorkload, then the operator could automatically configure the K8s service accounts to apply the correct K8s principal to the pods where the AuthProxyWorkload is attached.
See https://github.com/GoogleCloudPlatform/cloud-sql-proxy-operator/issues/705
贡献指南
评估
这个 Issue 还没有评估数据。