Now that we have OpenID Connect we can use federated workload identity in GCP.
This works great for jobs, but prevents us removing the last key for pulling docker images from GCR as a executor.
It would be nice just to be able to configure the docker executor to work with OpenID Connect so that we can remove the last service account key