How to use GCP Workload Identity Federation from Slurm jobs on SUNK, including projected OIDC tokens, pyxis/enroot containers, and private Artifact Registry pulls without static service account keys.
How to configure CoreWeave Kubernetes Service for external OIDC authentication, then use kubelogin so kubectl users can sign in through Google OAuth or another identity provider.