apiVersion: iam.cnrm.cloud.google.com/v1beta1 kind: IAMPolicyMember metadata: name: bannerctl-workload-id spec: member: serviceAccount:${gcp_project_id}.svc.id.goog[bannerctl/bannerctl] resourceRef: name: bannerctl apiVersion: iam.cnrm.cloud.google.com/v1beta1 kind: IAMServiceAccount role: roles/iam.workloadIdentityUser