hardgcloud
Grant workload identity access so a Kubernetes SA can impersonate a Google SA
command
gcloud iam service-accounts add-iam-policy-binding SA_EMAIL --role roles/iam.workloadIdentityUser --member MEMBERalso accepted
gcloud iam service-accounts add-iam-policy-binding