IAM Authentication with Cloud Services (AWS/GCP)

We’re evaluating migrating from Teleport to Cloudflare Zero Trust.

Currently within Teleport at the moment we have a number of GCP CloudSQL services, which use IAM Authentication, rather than user/password auth. Teleport handles this natively and support IAM Auth to CloudSQL.

I was wondering if anyone here has been able to get some form of IAM Authentication working with Cloudflare Tunnel, or if we need rollout user/pass auth for CloudSQL if we want to use these with Cloudflare Zero Trust?