Google Cloud Secret Manager

Required attributes

  • Project Id — the GCP project that owns the secrets.

Authentication methods

  • Service Account Key — Project Id, Service Account Key. Long-lived; rotate manually. Treat the JSON as a secret and store it inside another vault.
  • Default Credentials — Project Id only. Resolves to the attached service account on GCE/GKE/Cloud Run, or the developer's gcloud login locally. Convenient on GCP-hosted Polysync.
  • Workload Identity Federation ⭐ (recommended cross-cloud) — Project Id, Workload Identity Provider, Service Account Email. Federates Polysync's cloud identity into GCP, eliminating JSON keys — when Polysync is hosted on Azure, the subject token comes from the Azure managed identity (Azure IMDS).
  • Impersonated Service Account — Project Id, Source Service Account Key, Target Service Account Email. Useful for least-privilege chains.

Permissions checklist

  • The chosen identity must hold the Secret Manager Secret Accessor role (roles/secretmanager.secretAccessor) on each secret.
  • For Workload Identity Federation, configure a Workload Identity Pool and Provider that trusts the Polysync host identity.