Status: IN
In Cloud Run first-gen single-container, the container identity owns the secret volume; in second-gen and first-gen multi-container, root owns the volume.
Source: entries/2026/03/11/cloudrun-secrets.md
JSON