Google Cloud Workload Identity
A Google Cloud workload with an attached service account can request a Google-signed OIDC identity token from the metadata server. Mixlayer verifies that token and exchanges it for a short-lived Mixlayer access token.
This flow uses Google Cloud as the identity provider. You do not need to create a Google workload identity pool or download a service-account key.
1. Attach a service account
Run the workload with a dedicated Google service account. Grant the service account only the Google Cloud permissions the workload itself needs.
Get its stable numeric ID:
The numeric ID appears in the identity token’s sub claim and remains stable if the service account’s display name changes.
2. Configure the Mixlayer provider
Create an OIDC provider in Workload Identity with:
Map the stable service-account identity:
Admit only the expected numeric service-account ID:
Use the actual value from $GOOGLE_SERVICE_ACCOUNT_ID. Treat the email as a readable attribute, not the primary authorization identifier.
Use true as the final authorization rule and grant only the permissions the workload needs.
3. Request a Google identity token
From the Google Cloud workload, request an identity token for the same audience configured in Mixlayer:
The metadata server is available only from supported Google Cloud environments. Do not proxy or expose it outside the workload.
4. Exchange and use the Google token
Google identity tokens last one hour. Cache the Mixlayer token in memory until shortly before expiry, then request and exchange a new identity token.
GKE workloads
GKE workloads can use either a metadata-server identity token from an attached Google service account or a projected Kubernetes ServiceAccount token. For the projected-token approach, follow the Kubernetes guide with the GKE cluster issuer.
Troubleshooting
- A
404from the metadata endpoint usually means the service does not expose that endpoint or the workload lacks an attached service account. - Compare the token’s exact
iss,aud, andsubwith the provider. The requested audience must match one of the provider’s allowed audiences. - If an email transformation fails, request
format=fullor remove that optional mapping and authorize using the numericsub. - Keep production and non-production service accounts in separate providers or admission policies.