TrustsExternalIdentity
Target trusts an external/federated/workload principal - inbound cross-boundary access (incl. k8s IRSA/WI federation). Source can be an identity (principal), a resource policy, or a policy document (e.g., B2C trust policy) that declares the trust.
Role, ServiceAccount, ApplicationIdentity, ManagedIdentity, ResourcePolicy, TrustPolicy, GenericPolicy
── TrustsExternalIdentity ──▸
ExternalIdentity, FederatedIdentity, WorkloadIdentity
Source types
Target types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Rules that emit TrustsExternalIdentity 17
An Artifact Registry repo IAM binding for a Workload Identity Federation principalSet/principal with uploadArtifacts grants an external OIDC identity (e.g. GitHub Actions) direct push access - supply-chain from external CI into GCP workloads.
gcpderived
A CSR repo IAM binding for a WIF principalSet/principal with source.repos.update grants an external OIDC identity (e.g. GitHub Actions) direct push access without any long-lived GCP key - supply-chain injection from external CI.
gcpderived
awsexplicit
awsexplicit
An IAM role whose trust policy Federated principal matches an EKS cluster OIDC issuer URL trusts that cluster's projected SA tokens.
awsexplicit
An IAM role whose trust policy Service principal includes pods.eks.amazonaws.com is eligible for EKS Pod Identity associations.
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
azureexplicit
azureexplicit
azureexplicit
azureexplicit
azureexplicit
gcpexplicit
gcpexplicit