Skip to content

Instantly share code, notes, and snippets.

@Neutrollized
Last active March 4, 2023 19:35
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Neutrollized/de6b4b397964d65595e43a725a01d99e to your computer and use it in GitHub Desktop.
Save Neutrollized/de6b4b397964d65595e43a725a01d99e to your computer and use it in GitHub Desktop.
Medium: Workload Identity explained using kaniko
apiVersion: v1
kind: Pod
metadata:
name: kaniko-wi
spec:
containers:
- name: kaniko
image: gcr.io/kaniko-project/executor:v1.9.1
args: ["--dockerfile=Dockerfile",
"--context=gs://${GCS_BUCKET}/path/to/context.tar.gz",
"--destination=gcr.io/${PROJECT_ID}/${IMAGE_NAME}:${IMAGE_TAG}",
"--cache=true"]
restartPolicy: Never
serviceAccountName: kaniko-wi-ksa
nodeSelector:
iam.gke.io/gke-metadata-server-enabled: "true"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment