Skip to content

Validate and productize Google Cloud federation #35

Description

The GCP federation implementation and learning documents exist, but no Google agent, VPN, or federated SPIRE environment is currently deployed.

Acceptance criteria:

  • Rebuild the GCP project, VPN, SPIRE federation, and Google caller from a clean Azure environment.
  • Validate the numeric service-account unique ID as the Entra FIC subject.
  • Pass cross-cloud mTLS, RBAC, JWT, risk, and tag scenarios.
  • Test partial-failure recovery and teardown.
  • Reconcile the how-to with the verified deployment.

Durable references:

  • GOOGLE-FEDERATION-HOWTO.md
  • docs/platform-learnings/Google-Cloud-Federation.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:federationCross-cloud and GitHub federationarea:identityEntra identity and token exchangearea:spiffeSPIFFE and SPIRE runtimepriority:P2Planned expansion worksecuritySecurity hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions