Files
Sarath Francis e113a9c8b9 docs(gke): add Workload Identity IAM binding for adk deploy gke (#1811)
* docs(gke): add Workload Identity IAM binding for adk deploy gke

The automated deployment path (`adk deploy gke`) generates a manifest
that uses the `default` Kubernetes service account in the `default`
namespace, but the docs only documented the Workload Identity IAM
binding for the manual path (which uses a custom `adk-agent-sa`).

Without binding `roles/aiplatform.user` to the `default` service
account, agent pods start but model requests fail with
`403 PERMISSION_DENIED`.

Add a "Configure Workload Identity for Agent Platform" step under
Option 2 with the correct binding for the `default` service account,
and cross-reference it from the 403 troubleshooting entry.

Fixes #1254

* Update gke.md

---------

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
2026-06-12 14:39:16 -07:00
..
2026-04-22 05:10:38 -07:00