Identity Translation

Translate EKS IRSA (IAM Roles for Service Accounts) bindings to GKE Workload Identity. Maps every annotated ServiceAccount to a Google Service Account, translates AWS IAM policies into the closest GCP IAM role set, produces additive bindings on both sides for co-existence, and emits a verification plan. Use after gke-landing-zone, when "translate IRSA to Workload Identity", "set up identity for the GKE migration", or "what's the identity plan".

geoffsdesk Updated

File contents

geoffsdesk/portage/tree/main/skills/identity-translation commit a1b6c1dc9f

Frequently asked questions

npx skillmds@latest add geoffsdesk/identity-translation