Project Id — the GCP project that owns the secrets.
Authentication methods
Service Account Key — Project Id, Service Account Key. Long-lived;
rotate manually. Treat the JSON as a secret and store it inside another
vault.
Default Credentials — Project Id only. Resolves to the attached
service account on GCE/GKE/Cloud Run, or the developer's gcloud login
locally. Convenient on GCP-hosted Polysync.
Workload Identity Federation ⭐ (recommended cross-cloud) —
Project Id, Workload Identity Provider, Service Account Email.
Federates Polysync's cloud identity into GCP, eliminating JSON keys — when
Polysync is hosted on Azure, the subject token comes from the Azure managed
identity (Azure IMDS).
Impersonated Service Account — Project Id, Source Service Account
Key, Target Service Account Email. Useful for least-privilege chains.
Permissions checklist
The chosen identity must hold the Secret Manager Secret Accessor role
(roles/secretmanager.secretAccessor) on each secret.
For Workload Identity Federation, configure a Workload Identity Pool and
Provider that trusts the Polysync host identity.