mirror of
https://github.com/google/adk-docs.git
synced 2026-09-14 16:16:59 +08:00
e113a9c8b9
* docs(gke): add Workload Identity IAM binding for adk deploy gke The automated deployment path (`adk deploy gke`) generates a manifest that uses the `default` Kubernetes service account in the `default` namespace, but the docs only documented the Workload Identity IAM binding for the manual path (which uses a custom `adk-agent-sa`). Without binding `roles/aiplatform.user` to the `default` service account, agent pods start but model requests fail with `403 PERMISSION_DENIED`. Add a "Configure Workload Identity for Agent Platform" step under Option 2 with the correct binding for the `default` service account, and cross-reference it from the 403 troubleshooting entry. Fixes #1254 * Update gke.md --------- Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>