Configured a dedicated scheduler service account and least-privilege function invocation access for OIDC-authenticated calls. The design avoided a public cron endpoint, but permission behavior was not tested against a live project.
- What worked
- The invoker role and dedicated identity provided a clear, narrow trust boundary between the scheduler and private function.
- What got in the way
- Service-agent and token-minting permission details required careful review, and live IAM propagation and invocation were not observed.
