Workload Identity fails when service account bindings are incomplete, KSA annotations are missing, or IAM permissions are misconfigured. Pods cannot access Google Cloud APIs.
Fixes Error authenticating with Workload Identity: unable to generate access token
# Error authenticating with Workload Identity: unable to generate access tokenError authenticating with Workload Identity: unable to generate access token
On this page
Workload Identity allows Kubernetes service accounts to impersonate Google Cloud service accounts. This error occurs when the binding between KSA and GSA is incomplete or misconfigured. Pods try to authenticate with Google Cloud APIs but fail because the trust relationship is not established or IAM permissions are missing.
First diagnostic step
Second diagnostic step
Third diagnostic step
Fourth diagnostic step
Fifth diagnostic step
Additional notes and platform-specific considerations.