-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support GCP Workload Identity in the repository-gcs plugin #11224
Comments
hi @davidchong-glean, |
This capability alongside the projected volume one on the operator #459 |
@sachinpkale : Can you please provide an ETA? |
@vinodhreddyg I am not working on it. As OpenSearch is community driven project, contributions are welcome. |
Is your feature request related to a problem? Please describe.
Storing snapshots with the repository-gcs plugin requires a gcp service account key that's stored as a kubernetes secret. We'd like to avoid this secret as it requires additional overhead like periodically rotating the secret for security. GCP's Workload Identity feature would be a better alternative that avoids the need for a secret.
Describe the solution you'd like
Use GCP's workload identity feature for authentication in the repository-gcs plugin.
Describe alternatives you've considered
A clear and concise description of any alternative solutions or features you've considered.
Additional context
Add any other context or screenshots about the feature request here.
The text was updated successfully, but these errors were encountered: