TL;DR
They use Okta for SSO, GCP for Service Accounts (automation), vault for secrets, ca and tls, GKE generally, and this is how it all works.
That said, the article is good and the author has a good understanding of what's going on. Typically, you need to know how something works before you can form realistic opinion on whether or not it is secure. Too much of the industry is full of blind trust from people that can get things working but don't scratch beyond the surface of integration.
The author has likely had to understand this in order to explain it to InfoSec assurance, compliance and audit departments, but I think writing it down is really useful for people without the tech.
I think they could expand on why they use vault rather than the secrets engine directly, but I suspect that was because of integrations, protability, and the workload indentity functionality behing newer than their setup.