Skip to content

feat(gcp-byoc-i): grant Kite workload identities - #151

Open
santiago-wjq wants to merge 1 commit into
masterfrom
fix-gcp-byoc-i-kite-workload-identity
Open

feat(gcp-byoc-i): grant Kite workload identities#151
santiago-wjq wants to merge 1 commit into
masterfrom
fix-gcp-byoc-i-kite-workload-identity

Conversation

@santiago-wjq

Copy link
Copy Markdown
Contributor

Summary

  • always merge vectorlake-kite/kite-coordinator and vectorlake-kite-pool/kite-index-pool-sa into the GCP BYOC-I storage service account Workload Identity members
  • preserve caller-provided identities and existing Terraform resource addresses
  • retain the cluster-scoped principalSet grant for runtime-created instance namespaces
  • document the explicit, auditable Kite grants

Existing dataplanes

The cluster-scoped grant already covers current GCP BYOC-I clusters. These explicit members make the fixed Kite contract visible in Terraform plans and backfill older module revisions when customers rerun terraform apply.

Validation

  • OpenTofu fmt -check -diff
  • isolated tofu init -backend=false and tofu validate for modules/gcp_byoc_i/iam
  • git diff --check

Related

AWS BYOC-I support was merged in #150. CloudFormation is intentionally out of scope because BYOC-I is provisioned through the customer Terraform modules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant