The pod identity works in one place and fails when reused in a path with a stricter audience check. The explicit configuration seems correct, yet an inherited policy no longer …
A ServiceAccount token audience is correct for the main API call
The pod identity works in one place and fails when reused in a path with a stricter audience check. The explicit configuration seems correct, yet an inherited policy no longer resolves the same way under the cleaned hierarchy. Effective ownership looks correct at first glance, but one delegated path still reflects the old hierarchy. Nominal permissions look aligned, yet one delegated control path still reflects the retired operating model. Nominal access still looks aligned, yet one delegated path continues to reflect the previous layered administration model. Nominal access looks aligned, yet one delegated or inherited path still reflects the previous, more layered model.
시나리오
단서
구독하면 이어서 볼 수 있어요
이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.
먼저 볼 것
점검 체크리스트
복구와 재발 방지
같이 보면 좋은 질문
현장에서 본 비슷한 케이스