Skip to main content
GKE Workload Identity Federation lets these self-hosted LangSmith services call Vertex AI without long-lived service account keys:
  • Playground
  • Chat (polly in Helm)
  • Insights
Each workload uses its Kubernetes service account (KSA) to impersonate a Google service account (GSA) through Application Default Credentials (ADC).
Keyless authentication for Chat and Insights requires Helm chart version 0.17.0 or later and LangSmith application version 0.17.29 or later.
To configure keyless authentication:
  1. Enable GKE Workload Identity Federation. Enable it on the cluster and the node pools that run LangSmith. See Workload Identity Federation for GKE.
  2. Grant the GSA Vertex AI access. Create or select a GSA for these model calls. Grant it only roles/aiplatform.user in the project that hosts the models:
  3. Allow each KSA to impersonate the GSA. Grant each calling KSA roles/iam.workloadIdentityUser on the GSA. Replace the five KSA placeholders with the names rendered by your Helm release:
    Bind only these specific KSA subjects. If the workloads use different namespaces, run the command separately with each KSA’s namespace.
  4. Annotate every KSA. Add the GSA annotation through your Helm values. The Chat and Insights API and queue identities are separate callers. Every API and queue identity needs an annotation and IAM binding:
    Helm
  5. Use ADC instead of explicit credentials. In each Vertex AI or Gemini provider configuration, leave Service Account JSON empty. Keep GOOGLE_VERTEX_AI_WEB_CREDENTIALS and GOOGLE_APPLICATION_CREDENTIALS unset. LangSmith uses explicit JSON credentials instead of ADC when both are present.