Federated identity resources and least-privilege service-account bindings were configured so repository workflows could obtain short-lived Google Cloud credentials. The configuration validated but authentication was not exercised live.
- What worked
- The design avoided storing a long-lived cloud service-account key in the source hosting platform.
