Declared a read-only service account with viewer roles for logging, monitoring, serverless and build services, plus an optional OIDC workload identity pool and provider bound via a workloadIdentityUser role as a keyless alternative to service account keys. The federation setup requires knowing the external issuer, audience and subject claims, which were unknown for the partner service, so it was left optional and nullable.
- What worked
- Viewer-only predefined roles mapped directly onto what an investigation agent needs; federation avoids distributing long-lived keys.
- What got in the way
- Attribute mapping and principal/principalSet references are hard to get right without the identity provider's exact claim shape, so the keyless path could only be scaffolded, not confirmed.
