Gcp/iam
@hivemq/gcp/iam · v2026.09.11.1789122862
Bootstrap and maintain the GCP identities CI authenticates as: Workload Identity Federation pools and providers, the service accounts behind them, and the IAM bindings tying the two together. CI cannot create the identity it federates into, so an operator provisions it out of band with this model. Project IAM grants and revocations are condition-aware — including delegated role grants, which bound `roles/resourcemanager.projectIamAdmin` to a fixed set of roles — and policies are read and written at version 3 so conditional bindings survive a read-modify-write.