diff --git a/modules/osd-release-notes-Q3-2025.adoc b/modules/osd-release-notes-Q3-2025.adoc index b3ba2656c0..190e7684ae 100644 --- a/modules/osd-release-notes-Q3-2025.adoc +++ b/modules/osd-release-notes-Q3-2025.adoc @@ -15,6 +15,7 @@ The default IAM permissions for WIF in the link:https://github.com/openshift/man ** The `osd-deployer` service account no longer uses the `iam.serviceAccounts.signBlob` permission. This has been replaced with the `iam.serviceAccountTokenCreator` role, which is now specifically assigned to the service accounts that require it. ** The `osd-deployer` service account no longer uses the `iam.serviceAccounts.actAs` permission. This has been replaced with the `iam.serviceAccountUser` role, which is now specifically assigned to the service accounts that require it. ++ If you have existing `wif-config` instances, you can get these new, less permissive permissions by running the `ocm gcp update wif-config` command. For more information, see link:https://docs.redhat.com/en/documentation/openshift_dedicated/4/html/openshift_dedicated_clusters_on_google_cloud/osd-creating-a-cluster-on-gcp-with-workload-identity-federation#wif-configuration-update_osd-creating-a-cluster-on-gcp-with-workload-identity-federation[Updating a Workload Identify Federation configuration]. * **Workload Identify Federation (WIF) is now the default authentication type for {product-title} clusters on {GCP}.** diff --git a/osd_whats_new/osd-whats-new.adoc b/osd_whats_new/osd-whats-new.adoc index 092a14fc6a..7e1de147d7 100644 --- a/osd_whats_new/osd-whats-new.adoc +++ b/osd_whats_new/osd-whats-new.adoc @@ -1,6 +1,7 @@ :_mod-docs-content-type: ASSEMBLY [id="osd-whats-new"] = What's new with {product-title} + include::_attributes/attributes-openshift-dedicated.adoc[] :context: osd-whats-new