Configure GCP Device Settings with Routing, WIF Token, and AWS Role ARN Support
Use this procedure to add a GCP device in SaaS cloud-dc mode with routing, organization-level Workload Identity Federation (WIF) settings, temporary token support for on-demand and config-fetch discovery, push, bind operations, AWS Role ARN copy support, and standalone add, update, and view device settings.
- You have permissions to add or edit device connectors for KUBE certificate operations.
- Required GCP project and workload identity federation details are available.
-
Go to Menu > KUBE >
VISIBILITY > Server >
All.
The server certificate inventory page is displayed.
-
Open the required certificate, then open the connector or device action to
add a target GCP device.
The Add Device or connector configuration screen is displayed.
-
For standalone settings updates, open the existing GCP device settings in
edit or view mode as required.
The device settings page is available for add, update, or view operations.
-
Select GCP as the integration or device type and choose
the SaaS cloud-dc connectivity mode as applicable.
GCP-specific configuration fields are displayed.
-
Select the required authentication type from the available options and choose
the workload identity based option when applicable.
The device settings form displays the fields required for the selected authentication type.
-
Configure routing details required to reach GCP from the cloud-dc path.
Routing configuration is applied for GCP connectivity.
-
Set the authentication method to WIF (Workload Identity
Federation).
WIF input fields are enabled.
-
Configure the device settings at organization level and apply the required
workload identity values for the selected GCP integration.
Organization-level WIF settings are available to the configured GCP device flow.
-
Generate the AWS Role ARN using the selected data-center role mapping, then
use the copy action to copy the generated ARN value.
The AWS Role ARN is dynamically generated for the selected deployment path and is available to copy for integration use.
-
Provide the required role name, GCP service account details, or equivalent
linkage values needed to associate the AWS token with the GCP token.
The cross-cloud identity mapping values are configured in device settings.
-
Provide required WIF values and generate the temporary WIF token from the
configuration screen.
The WIF token is generated and attached to the current connector or add-device context.
-
Save the configuration, then trigger on-demand discovery or config-fetch
discovery for the required scope.
- Settings level discovery
- Project level discovery
- Child level service discovery
On-demand or config-fetch discovery runs with WIF-based temporary token authentication for the selected scope. -
Go to Menu > KUBE >
VISIBILITY > Server >
All and verify discovery status for the configured
connector.
The operation status confirms successful routing and WIF token usage.
-
Verify the organization-level settings and confirm that the expected GCP
projects are available through the configured integration.
The required projects are visible and aligned with the organization level configuration.
-
Set discovered certificates to Managed or
Monitored as required for your inventory policy.
Certificate lifecycle handling aligns with manage or monitor mode for discovered certificates.
-
Configure or run scheduled discovery for the same connector scope, if
required.
Scheduled discovery uses the same WIF-based authentication and respects configured discovery scope.
-
From the certificate workflow view, perform the required
Push or Bind action and
complete approvals as per policy.
The selected push or bind workflow is completed using WIF-based temporary token authentication.
GCP Add Device is configured with SaaS cloud-dc routing and WIF token generation, enabling supported on-demand discovery, config-fetch discovery, scheduled discovery, push, and bind flows. The generated AWS Role ARN can also be copied for the configured integration path, and organization-level settings apply to project verification. The same flow supports standalone add, update, and view of device settings.
- If token generation fails, verify WIF identity configuration and routing reachability to required GCP endpoints before retrying. For this flow, load-balancer support applies to Global Application Load Balancer scope.
- Supported routing patterns include GCP routing through a selected data center with AWS access through cloud-dc, the same data center, or an alternate data center as configured.
