GCP supports workload identity federation with
external identity providers. Using this, you can allow identities managed by an external identity provider to
impersonate a service account in your GCP project.
In this scenario the external identity provider is Concourse and the identities are teams/pipelines/jobs. This means you
are able to grant a specific pipeline or job permission to perform actions in GCP (like deploying something), all
without managing service account keys or dealing with long-lived credentials.
Set the provider's issuer_uri to the external URL of your Concourse server (or the --oidc-issuer-url if you're
using a separate OIDC issuer -
see Configuring a Separate OIDC Issuer).
Map google.subject to assertion.sub so the pipeline's identity carries through to the impersonation check below.
For allowed_audiences, the full workload identity provider resource name is recommended, as shown below.
Note
You have to use the same audience string later in the configuration of your idtoken var source.
terraform{required_providers{google={source="hashicorp/google"version="6.9.0"}}}variable"gcp_concourse_url"{description="Concourse URL"type=stringdefault="https://ci.concourse-ci.org"}variable"project_id"{description="GCP Project ID"type=string}variable"project_number"{description="GCP Project Number"type=string}resource"google_iam_workload_identity_pool""concourse_pool"{workload_identity_pool_id="concourse-pool"display_name="Concourse"description="Identity pool for Concourse pipelines"}resource"google_iam_workload_identity_pool_provider""concourse_provider"{workload_identity_pool_id=google_iam_workload_identity_pool.concourse_pool.workload_identity_pool_idworkload_identity_pool_provider_id="concourse-provider"attribute_mapping={"google.subject"="assertion.sub"}oidc{issuer_uri=var.gcp_concourse_urlallowed_audiences=["https://iam.googleapis.com/projects/${var.project_number}/locations/global/workloadIdentityPools/concourse-pool/providers/concourse-provider"]}}
Now you can use the gcloud CLI's external account credential support
to impersonate your service account via a JWT issued by Concourse. Since gcloud reads external credentials from a
config file rather than a single flag, the task writes the token to a file first, then assembles a small credential
config pointing at it: