# Does ECK 1.3.0 supports workload identity

**URL:** <https://discuss.elastic.co/t/does-eck-1-3-0-supports-workload-identity/263021>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 2, 2021, 6:01pm UTC](https://discuss.elastic.co/t/does-eck-1-3-0-supports-workload-identity/263021 "2021-02-02T18:01:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![knagasri](https://avatars.discourse-cdn.com/v4/letter/k/47e85d/32.png) [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Post date:** [February 2, 2021, 6:01pm UTC](https://discuss.elastic.co/t/does-eck-1-3-0-supports-workload-identity/263021/1 "2021-02-02T18:01:37Z")

</div>

For ECK 1.3.0 , does operator supports workload identity feature instead of creating k8s secrets(service account credentials JSON file which has storage admin permissions for that GCS bucket) manually for easticsearch backup and restore.

If it is not supported in current version. Do we have future road map

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [February 3, 2021, 8:56am UTC](https://discuss.elastic.co/t/does-eck-1-3-0-supports-workload-identity/263021/2 "2021-02-03T08:56:10Z")

</div>

What you are looking for is currently not supported in the Google Cloud Storage Repository Plugin. This is not a limitation at the operator level.

This was discussed here:

> [@Using GKE workflow identity to snapshot and restore elasticsearch data](https://discuss.elastic.co/t/using-gke-workflow-identity-to-snapshot-and-restore-elasticsearch-data/223156/2):
>
> If I am reading the [plugin docs](https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs-usage.html#repository-gcs-service-authentication) correctly, this is expected: The plugin must authenticate the requests it makes to the Google Cloud Storage service. It is common for Google client libraries to employ a strategy named [application default credentials](https://cloud.google.com/docs/authentication/production#providing_credentials_to_your_application). However, that strategy is not supported for use with Elasticsearch. The plugin operates under the Elasticsearch process, which runs with the security manager enabled. The security manager obstructs the "automatic" credential discovery. Therefore, y…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:23am UTC](https://discuss.elastic.co/t/does-eck-1-3-0-supports-workload-identity/263021/3 "2022-11-04T08:23:10Z")

</div>


