Learn how to authenticate your Knative serving services with Workload Identity Federation for GKE to access Google Cloud APIs such as the Compute APIs, Storage and Database APIs, or Machine Learning APIs.
To authenticate your Knative serving services, you must:
- Enable Workload Identity Federation for GKE in your cluster
- Create a Kubernetes Service Account and grant it the required IAM roles
After following these steps, you can deploy a new Knative serving service that uses the identity that you created.
Enabling Workload Identity Federation for GKE on your cluster
To set up Workload Identity Federation for GKE with Knative serving, you can set up fleet Workload Identity Federation instead of using a Google Cloud Service Account JSON file.
Configure permissions to enable all metrics
To enable metrics, like reporting request count or request latency to
Google Cloud Observability, you need to grant write permissions for Cloud Monitoring. For
example, you can grant the
Monitoring Metric Writer role
(roles/monitoring.metricWriter) to the Kubernetes Service Account that is
associated with Knative serving because it includes the necessary
permissions for writing monitoring data.
Granting IAM roles to a Kubernetes Service Account
Any Knative serving service running as the Kubernetes Service Account that you configure automatically authenticates with its federated identity when accessing Google Cloud APIs. The Kubernetes Service Account must exist within the cluster and namespace of the Knative serving service for which you want to use Workload Identity Federation for GKE.
If a Kubernetes Service Account doesn't exist, create one in the same Kubernetes namespace as your Knative serving service; otherwise, skip to the next step:
kubectl create serviceaccount --namespace K8S_NAMESPACE KUBERNETES_SERVICEACCOUNT
Grant the required IAM roles directly to your Kubernetes Service Account:
gcloud projects add-iam-policy-binding RESOURCE_PROJECT_ID \ --member "principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/PROJECT_ID.svc.id.goog/subject/ns/K8S_NAMESPACE/sa/KUBERNETES_SERVICEACCOUNT" \ --role "ROLE_NAME" \ --condition=None
Replace:
- RESOURCE_PROJECT_ID with the Google Cloud project ID where the target Google Cloud resources reside.
- PROJECT_NUMBER with the project number of the Google Cloud project for the cluster where your Kubernetes Service Account and Knative serving services reside.
- PROJECT_ID with the ID of the Google Cloud project for the cluster where your Kubernetes Service Account and Knative serving services reside.
- K8S_NAMESPACE and KUBERNETES_SERVICEACCOUNT with the namespace and name of your Kubernetes Service Account.
- ROLE_NAME with the IAM role to assign to your
Kubernetes Service Account, such as
roles/monitoring.metricWriter.
Deploying a new service to use Workload Identity Federation for GKE
Deploy a new Knative serving service that uses the Workload Identity Federation for GKE you created.
Console
Go to Knative serving in the Google Cloud console:
Click Create Service if you are configuring a new service you are deploying to. If you are configuring an existing service, click on the service, then click Edit & Deploy New Revision.
Under Advanced settings, click Container.
Click the Service account dropdown and select the desired service account.
Click Next to continue to the next section.
In the Configure how this service is triggered section, select which connectivity you would like to use to invoke the service.
Click Create to deploy the image to Knative serving and wait for the deployment to finish.
Command line
For existing services, set the Kubernetes Service Account by running the
gcloud run services updatecommand with the following parameters:gcloud run services update SERVICE --service-account KUBERNETES_SERVICEACCOUNT
Replace:
- SERVICE with the name of your Knative serving service.
- KUBERNETES_SERVICEACCOUNT with the Kubernetes Service Account that you used to create the workload identity.
For new services, set the Kubernetes Service Account by running the
gcloud run deploycommand with the--service-accountparameter:gcloud run deploy --image IMAGE_URL --service-account KUBERNETES_SERVICEACCOUNT
Replace:
- IMAGE_URL with a reference to the container image, for
example,
gcr.io/cloudrun/hello. - KUBERNETES_SERVICEACCOUNT with the Kubernetes Service Account that you used to create the workload identity.
- IMAGE_URL with a reference to the container image, for
example,
YAML
You can download the configuration of an existing service into a
YAML file with the gcloud run services describe command by using the
--format=export flag.
You can then modify that YAML file and deploy
those changes with the gcloud run services replace command.
You must ensure that you modify only the specified attributes.
Download the configuration of your service into a file named
service.yamlon local workspace:gcloud run services describe SERVICE --format export > service.yaml
Replace SERVICE with the name of your Knative serving service.
In your local file, update the
serviceAccountName:attribute:apiVersion: serving.knative.dev/v1 kind: Service metadata: name: SERVICE spec: template: spec: serviceAccountName: KUBERNETES_SERVICEACCOUNT
Replace
- SERVICE with the name of your Knative serving service.
- KUBERNETES_SERVICEACCOUNT with the Kubernetes Service Account that you used to create the workload identity.
Deploy the configuration to your Knative serving service by running the following command:
gcloud run services replace service.yaml
Migrating existing services to use Workload Identity Federation for GKE
If you enabled Workload Identity Federation for GKE on an existing cluster, each service on that cluster for which you want to use Workload Identity Federation for GKE must be migrated. Learn how to migrate existing services.
Next steps
Learn how to manage access to your services.