How I built a fully keyless CI/CD pipeline from GitLab to Google Cloud — with Workload Identity Federation, Binary Authorization, vulnerability scanning, and progressive delivery. No service account keys were harmed.