I am new to Flink and kubernetes.
I am trying to run Flink job cluster using Google cloud Platform flink-on-k8s-operator. I am trying the example where jar file can be downloaded from gcs bucket which is here. I have setup the Kubernetes secret with the service account json file. I have correctly set the secret name in the yaml here
However when I deploy the job the initcontainer is in error state. When I debug it I get following error in the log
ServiceException: 401 Anonymous caller does not have storage.objects.get access to the Google Cloud Storage object.
However when I submit the same jar from the job manager UI console it works fine. The java code in the jar is a MinimalWordcount program which gets a text file from GCS and writes the word count back to gcs. So it seems when the jar is submitted from the UI then it is able to use the secret to authenticate and get the sample file and push back the results.
Please advice what am I missing in the setup.