brash-air-25337
09/20/2023, 5:41 PMconstraints/iam.disableServiceAccountKeyCreation
, by asking for the key for the security account to be created & exported as part of module.infra.google_service_account_key.metaflow_kubernetes_workload_identity_service_account_key
.
My question: Is this necessary for the architecture?
As described here: https://cloud.google.com/kubernetes-engine/docs/how-to/service-accounts but does not seem to require sharing keys.